Attachment A CISA Basic SOW 3_23_12.docx
DOCX document 49 KB Posted
- Attached to
- Clinical Immunization Safety Assessment (CISA) Federal contract opportunity
- Solicitation number
- 2012-N-14296
About this file
SOW
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT A
THE CLINICAL IMMUNIZATION SAFETY ASSESSMENT (CISA) PROJECT: BASIC STATEMENT OF WORK
C. 1 Background and Need
Vaccines are one of the most effective means of reducing or eliminating morbidity and mortality from selected infectious diseases.[endnoteRef:1] However, no vaccine is completely effective or safe. The licensed vaccines currently in routine use in the United States have been judged by the Food and Drug Administration (FDA), with input from its advisory committee, to be safe and effective.[endnoteRef:2] Serious adverse events following immunization (AEFI), which may or may not be causally related to vaccines, are rare. However, clinical trials may not be large enough to detect these rare events and AEFI may not be observed until the vaccine is widely used in populations after clinical trials are complete.[endnoteRef:3] Similarly, special populations, such as persons with autoimmune diseases or immunodeficiency, may be excluded from or not be adequately represented in clinical trials; AEFI in these populations may not be detected until after licensure. [1: ] [2: ] [3: ]
A comprehensive vaccine safety system exists in the United States.4 The Centers for Disease Control and Prevention’s (CDC) Immunization Safety Office (ISO) and FDA co-manage the Vaccine Adverse Event Reporting System (VAERS).[endnoteRef:4],[endnoteRef:5] The main goal of VAERS is to identify potential vaccine safety problems (“signals”) that can be further assessed in other systems, such as CDC’s Vaccine Safety Datalink.[endnoteRef:6] The VAERS form collects information on demographics, health history, vaccine(s) received, and signs and symptoms of the adverse events experienced.5 Information from the reports is entered into a database that is maintained by the VAERS contractor. Medical records are requested for non-manufacturer reports coded as serious (i.e., death, life-threatening, hospitalization, prolongation of hospitalization or permanent disability) and for other reports of interest. [4: ] [5: ] [6: ]
Consistent with good pharmacovigilance practices, CDC and FDA staff review and analyze VAERS reports at the individual and aggregate levels.[endnoteRef:7] While aggregate analysis is especially useful to look for disproportionate reporting patterns, the International Society of Pharmacoepidemiology (ISPE) has stated that “careful descriptions of relevant clinical features in published case reports can contribute to the growth in understanding about the safety of medical products.”[endnoteRef:8] Information from individual case reviews contributes to the understanding of biologic mechanisms for AEFI and may also help generate and refine hypotheses about risk factors for AEFI that could be further studied. In a recent report from the Institute of Medicine (IOM), information from published case reviews of AEFI helped provide mechanistic evidence for causality assessments.[endnoteRef:9] [7: ] [8: ] [9: ]
To advance knowledge of vaccine safety and inform clinical and public health practice, high quality epidemiological and clinical research is also essential. CDC’s Immunization Safety Office Scientific Agenda highlights several vaccine safety research needs[endnoteRef:10] and new research needs continue to emerge. Studies are needed to identify risk factors for AEFI, including host and genomic risk factors, especially in vulnerable populations. In addition, studies are needed to identify and evaluate preventive strategies for AEFI. It is essential for vaccine safety infrastructure to keep pace with new research and development technologies in vaccinology, as well as advances in the fields of genomics and biomarkers. Having a project that facilitates CDC’s collaboration with vaccine safety researchers at prominent academic medical centers or health care institutions strengthens national capacity for innovative vaccine safety research. [10: ]
Educating and assisting healthcare providers who assess patients who may have AEFI is also important. Healthcare providers must frequently communicate with parents and patients about the benefits and risks of vaccination and address difficult questions about vaccine safety.[endnoteRef:11] In recent years, this task has become more challenging for several reasons, including a more complex immunization schedule, heightened public attention to vaccine safety issues, and the widespread use of the internet and social networking to receive health information. CDC responds to questions about vaccine safety from healthcare providers and other constituents, including state health departments, other federal agencies, and professional societies (e.g., the American Academy of Pediatrics).[endnoteRef:12] Two primary sources of immunization inquiries to CDC have been the CDC telephone information line (1-800-CDC-INFO/1-800-232-4636) and the CDC vaccine e-mail account (nipinfo@cdc.gov [NIPINFO is the commonly used term for the National Immunization Program]).1,3,5 ISO is referred complex vaccine safety inquires that cannot be addressed by the experienced NIPINFO staff who respond to these vaccine queries. Inquiries may also come directly to ISO staff, particularly from state health departments. Since 2002, ISO has maintained an inquiry tracking system for vaccine safety inquiries.12 While the most common reason for inquires during 2002-2009 was to address questions about VAERS data, 21% of the inquires ISO received during this time period were for clinical advice about a vaccine safety concern.12 During this time, some of the clinical cases of AEFI received by ISO, particularly those in need of clinical advice, were referred to the Clinical Immunization Safety Assessment (CISA) Project for assessment. [11: ] [12: ]
Mission
The overall mission of the Clinical Immunization Safety Assessment (CISA) Project is to improve understanding of adverse events following immunization (AEFI) at the individual-patient level.
Goals
1) To serve as a vaccine safety resource for consultation on clinical vaccine safety issues, including individual case reviews, and assist with immunization decision-making
2) To assist CDC in developing strategies to assess individuals who may be at increased risk for AEFI
3) To conduct and contribute to studies to identify risk factors and preventive strategies for AEFI, particularly in special populations
C.2 Project Objective
CDC seeks to re-establish the CISA Project to improve vaccine safety at the individual-patient level. The proposed CISA Project builds on the experience of the previous CISA network, which is currently a contract between CDC and America’s Health Insurance Plans to subcontract with six academic sites with vaccine safety experts. The contract has been in place from 2001.13 The scope of the new CISA project is responsive to recommendations from a 2010 external program review of the previous CISA network14 and aligns with objectives in the US 2010 National Vaccine Plan.15
The purpose of this CISA Project indefinite delivery, indefinite quantity (IDIQ) contract is to provide the CDC’s Division of Health Care Quality Promotion (DHQP), Immunization Safety Office (ISO) with an “as needed” mechanism to obtain required services, including an ongoing service for expert consultation, through the issuance of individual Task Orders. These Task Orders would support vaccine safety monitoring and evaluation that meet public health needs for CDC. CDC may make multiple awards to contract with certain organizations (e.g., academic centers or health plans) in the United States. The CISA Project will be a resource to address clinical vaccine safety issues and provide a public health service to the nation. The project will also contribute to or conduct studies to answer questions about why certain individuals experience AEFI that may be causally linked to vaccines, and how to prevent them. Results from such studies shall provide evidence to better inform vaccination practices.
C. 3 Contract Structure
The basic IDIQ contract will establish the general scope and ordering period for Task Orders to be issued against this contract. The basic contract shall be for a base period of twelve (12) months from date of award with five (5) twelve (12) month option periods extending the ordering period. It is anticipated that multiple Task Orders will be issued to the contractors to work on CISA in areas identified in this Scope of Work described below. Each Task Order shall have a discreet period of performance independent of the basic contract and no Task Order shall extend more than twelve(12) months beyond the expiration date of the basic contract.
Individual Task Orders exceeding $3,000 not awarded to all contractors will be competed in accordance with the fair opportunity process described in the Federal Acquisition Regulation (FAR) 16.505(b)(1) unless an exception to fair opportunity in documented in accordance with FAR 16.505(b)(2). All Tasks Orders will be solicited by email. Contractors will have at a minimum 10 days to respond, except during a public health emergency.
C.4 Scope of Work
The Contractor shall provide all labor, supervision, equipment, materials, supplies, travel, transportation, and perform all work necessary to provide public health, scientific, and technical services in support of advancing vaccine safety activities, as specifically required under individual Task Orders under this contract.
The two main requirements for this CISA IDIQ contract include:
1. Clinical case reviews and evaluation of vaccine safety issues, and coordination activities to support this function.
2. Research studies to advance knowledge of vaccine safety and inform clinical and public health practices.
C.5 Technical Requirements
C.5.1 - Requirement 1: Clinical case reviews and evaluation of vaccine safety issues, and coordination activities to support this function.
As specified in individual Task Orders, the Contractor may conduct work under this technical requirement. Work will include all activities, as identified by the Government, regarding vaccine safety. Under this requirement, Contractors may participate in clinical review and evaluation activities conducted within the CISA Project.
The Contractor may conduct clinical reviews of vaccine safety cases to assist the Government in responding to practicing clinicians and/or health department personnel. The Contractor may also conduct case reviews to assist the Government with surveillance for AEFI, for example by reviewing a striking case report of a novel AEFI reported to VAERS. The Contractor may also develop a systematic approach for a clinical inquiry response service, which can assist healthcare workers or public health professionals who have vaccine safety questions. The Contractor should be capable of evaluating vaccine safety cases and issues that affect children and adults.
The Contractor may provide a synthesis of the clinical case reviews, and other emerging vaccine safety issues. This work may lead to a broader understanding of vaccine safety issues and inform clinical or public health practices. For example, the Contractor may be asked to assist CDC to synthesize vaccine safety evidence for the Advisory Committee on Immunization Practices (ACIP).16 The Contractors may also help to generate and refine hypotheses on risk factors for AEFI that are in need of further study.
The Contractor may provide clinical expertise in various disciplines. In this capacity, the Contractor may need input from experts who can participate in the clinical review, synthesis and evaluation activities. In addition to knowledge of vaccine safety, examples of the areas of expertise include pediatrics, internal medicine, allergy, neurology, and obstetrics and gynecology. The Contractor may also provide selected subject matter expertise to CDC for other ongoing activities regarding vaccine safety.
Examples of other activities that Contractors may be asked to undertake as part of this clinical evaluation requirement include: 1) Developing vaccine safety algorithms to assist practicing clinicians in the assessment and management of patents with vaccine safety concerns; 2) Facilitating biological specimen collection and transfer from individuals who experienced serious AEFI, to a specified biological repository; 3) Identifying and contacting individuals with AEFIs who were identified through VAERS or other sources, to obtain consent and enroll them for participation in vaccine safety studies supported by the Government (the contractor may or may not be a co-investigator in these studies).
The Contractors may also develop an Emergency Response plan. This plan will outline activities to rapidly support enhanced vaccine safety clinical case reviews and evaluation activities, in the case of an urgent public health incident or emergency situation necessitating implementation of an emergency vaccination program. For example, in 2009-10 CISA conducted clinical case reviews of AEFI to support the US emergency response to H1N1 pandemic influenza.[endnoteRef:13] In the event of an emergency, Task Orders may be issued to Contractors for the execution of the Emergency Response plan. [13: ]
The Contractor may conduct activities that support the management and development of the clinical requirement within CISA as specified in the applicable Task Orders. Examples of such services include logistical activities needed to prepare cases for presentation to clinical working groups (e.g., coordinating schedules for subject matter expert participation); clinical case tracking; organizing phone conferences and preparing minutes; providing cost reports; maintaining a secure internal website. The Contractor may also provide the appropriate facilities, data management, and other equipment necessary for conducting this requirement. This includes the appropriate office facilities, record keeping, disaster recovery plans, computer hardware and software, communication, and conferencing equipment.
Deliverables: to be specified within specific Task Orders
C.5.2 Requirement 2: Research studies to advance knowledge of vaccine safety and inform clinical and public health practice
As specified in individual Task Orders, the Contractor may conduct work under this technical requirement. The Contractor shall perform all work necessary to develop, conduct and/or participate in research studies, as specifically required under individual Task Orders under this contract. The Contractor may lead or participate as co-investigators in research conducted for single or multi-site studies, which meet CDC’s public health vaccine safety needs. The project period for these studies may be up to five years. CDC may elect to issue two types of Task Orders for some studies: 1) Contractor to lead the study and, 2) Contractor(s) to contribute data and / or participate as co-investigators in the study. Studies may seek to identify risk factors for AEFI, including host and genetic risk factors, particularly in special populations that may be at increased risk for vaccine preventable disease or AEFI. Studies may also assess the safety of newly licensed or recommended vaccines or evaluate strategies to prevent AEFI.
Under this contract requirement, Contractors may conduct all activities that would support the management and development of this research requirement within CISA as required in the applicable Task Orders. Activities include those directly related to conduct of the study such as enrolling patients, collecting patient data (including biological specimens), and analyzing data. In addition, the Contractor may obtain Institutional Review Board (IRB) documentation, organize phone conferences and meetings, prepare minutes, and provide cost reports to CDC. The Contractor may also provide the appropriate facilities, data management, and other equipment necessary for conducting this requirement. This includes the appropriate office facilities, record keeping, disaster recovery plans, computer hardware and software, communication, and conferencing equipment.
Deliverables: to be specified within specific Task Orders
C.6 Place of Performance Services will be performed at vendor specified site in the United States (50 states or the District of Columbia). All aspects of work related to this contract must be performed in the U.S.; this includes work performed by the Contractor and any sub-Contractors. Under the technical input from CDC, internationally based subject matter experts may participate in specified discussions.
C.7 Reporting Schedule The Contractor’s reporting requirements will be defined in each individual Task Order. Reports may include weekly, monthly, or quarterly reports, along with a final report.
C.8 Travel Any required travel will be identified on individual Task Orders as necessary. The Contractor shall coordinate all travel requirements with the CDC Contracting Officer’s Technical Representative (COTR) and obtain written approval from the Contracting Officer prior to beginning such travel.
The Government will reimburse the Contractor for travel related costs. The Contractor shall submit receipts for airfare, lodging, car rentals, and other incidental travel-related expenses. Travel costs shall not exceed the maximum per diem rates set forth in the Federal Travel Regulation (FTR). The Federal Travel Regulation per diem rates and regulations can be found at the following website: http://www.gsa.gov/portal/category/21287
C.9 Training The Contractor, at its own expense, shall perform training for their professional staff associated with required competencies for each Task Order. The Government shall be responsible to provide orientation and training on specific department, unit, site, programs or education requirements, policies, and procedures peculiar to the work to be performed by the Contractor and unique to CDC operations if required for specific Task Orders and approved in advance by the Contracting Officer and the COTR. The Government will not authorize training for Contractor employees to attend seminars, symposiums, or user group conferences unless determined that attendance is mandatory or deemed likely to enhance the performance of Task Order requirements and such training is approved in advance by the Contracting Officer. The Contractor shall assume full responsibility for keeping Contractor professional employees abreast of advances in relevant state-of-the-art technologies.
C.10 Special Considerations These shall be specified as applicable on an individual Task Order basis:
C.10.1 Vaccine Adverse Event Reporting System (VAERS) Access for Clinical Evaluation and Research
a. Some Task Orders may require the Contractor to have access to data and information from VAERS. The VAERS public site is located at: http://vaers.hhs.gov/index. When applicable, the Contractor shall identify essential staff that need routine access to VAERS reports and records with personal identifiers. The Contractors will coordinate with CDC to obtain the VAERS Virtual Private Network (VPN) access. The VAERS VPN is an internal government service. The Contractor will provide essential staff of the CISA project access to select reports of VAERS reports.
b. The VAERS VPN allows authorized users to establish a secure connection to the VAERS application. The VAERS VPN provides a secure computer network that uses the Internet to allow remote offices or individual users with secure access to the VAERS application and database. Access would be limited to a subset of the VAERS reports stored in the VAERS data repository, including text and images. CDC would provide the VAERS’s Contractor with a listing of VAERS reports / VAERS ID’s to be flagged for CISA access. Access would be modeled after the current read-only access by the Government, and should provide the CISA Project participants with the ability to:
1. Search for reports by VAERS ID, Patient First and Last Name, Date Range, and Vaccine Type; and
2. View the all of the available VAERS report information, including images of the associated documents.
c. The Contractors will coordinate with CDC to obtain the VAERS Virtual Private Network (VPN) access and provide essential staff of the CISA Project access to select reports of VAERS reports.
d. The Contractor may have access to the CDC’s VAERS external search tool. This tool will allow the Contractor to search the database, and is particularly useful for conducting aggregate case analyses for more than one AEFI. For example this tool may be used to search for all reported cases of anaphylaxis after influenza vaccine. Note: This database is similar to the database used by the CDC staff and is not publically available. The limitations of VAERS will apply, see http://vaers.hhs.gov/data/index
e. The Contractor shall meet Government security requirements for access to the VAERS system, and have signed appropriate data use and privacy agreements for the Government and for VAERS. The Contractor’s staff shall complete the VAERS rules of behavior form. They may be provided with authorization for access to the VAERS VPN, once this is completed.
f. The Contractor shall comply with the safeguarding procedures for report forms, records, and electronic data as required by the National Childhood Vaccine Injury Act (NCVIA) - 42 U.S.C. 300aa-25, and the provisions of the Privacy Act’s Epidemiologic Studies and Surveillance of Disease Problems System Notice 09-20-0136. The Contractor shall maintain a system to ensure that information which could identify an individual (such as name, street address, telephone number of the person who received the vaccine and that person’s legal representative) shall not be made available to any person, except the duly authorized staff of CDC, FDA and other participating federal entities. The restriction on access to identifying information applies to all information received from the VAERS activity, regardless of physical form (paper, electronic, other).
C.10.2 Human Research Protection
a. All Contractors or sub-Contractors involved in research studies must adhere to federal and institutional polices for human subjects protection. Information on the federal policy can be found at: http://www.hhs.gov/ohrp/humansubjects/guidance/45cfr46.html
C.10.3 CDC Scientific Review and Clearance
a. All Contractors or sub-Contractors must adhere to CDC policies for scientific review and clearance of protocols, abstracts, and manuscripts. Information on this policy can be found at: http://www.cdc.gov/maso/Policy/PublicUse.pdf
C.10.4 Assurance of Confidentiality Section 308(d)
a. In the event an Assurance of Confidentiality is needed, which is covered by Section 308(d) of the Public Health Service Act (42 U.S.C. 242m), the Contractor shall complete such an agreement. Information can be found at: http://www.law.cornell.edu/uscode/text/42/242m.
C.10.5 Rehabilitation ACT
a. Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, and the Architectural and Transportation Barriers Compliance Board’s Electronic and Information (EIT) Accessibility provisions (36 CFR part 1194), require that, unless an exception applies, all Electronic and Information products and services developed, acquired, maintained, or used by any Federal department or agency permit:(1) Federal employees with disabilities to have access to and use information and data that is comparable to the access and use of information and data by Federal employees who are not individuals with disabilities; and (2) Members of the public with disabilities seeking information or services from a Federal agency to have access to and use of information and data that is comparable to the access and use of information and data by members of the public who are not individuals with disabilities.
C.10.6 Information Security and Confidentiality In addition to the specifications in HHS Acquisition Regulation (HHSAR) 352.239-70, 352.239-71, 352.239-72, in Section H, the Contractor should adhere to the following CDC’s National Center for Emerging and Zoonotic Infectious Diseases (NCEZID) specifications regarding informational technology, security, and privacy.
Addition to HHSAR 352.239-72 (c) (1) (i) (B):
The Contractor shall identify and document appropriate types of information for Federal Information Systems/applications using NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories Vol.1 and Vol. 2.
Addition to HHSAR 352.239-72 (c) (4) (i):
Appropriate security templates will be provided to the Contractor by the NCEZID’s Security Staff. Completed documents will be sent to the CDC Chief Information Security Officer (CISO) for review, approval and subsequent issuance of an Authority To Operate (ATO)
1. Baseline System Information (BSI)
1. Privacy Impact Assessment (PIA)
1. Host Characterization Worksheet (HCW)
1. System Security Plan (SSP)
1. Security Baseline Worksheet (SBW)
1. Business Continuity Plan (BCP)
1. Risk Assessment Report (RAR)
Addition to HHSAR 352.239-72:
The following security associated requirements applies to the Contractor:
(1) Position Sensitivity Designations CDC requires a Public Trust Level 5 for the following The following position sensitivity designations and associated clearance and investigation requirements apply under this licensing contract:
Level 5: Public Trust - Moderate Risk (Requires Suitability Determination with NACIC, MBI or LBI). Licensor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency Check and Inquiry Investigation plus a Credit Check (NACIC), a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).
Upon award, the Contractor will be required to submit a roster of all staff (including sub-Contractor staff) working under the Contractor that will have the ability to access NCEZID sensitive information from the system. The roster shall be submitted to the Project Officer/ Technical Monitor, with a copy to the Contracting Officer, within 14 calendar days of the effective date of the contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer shall notify the Contractor of the appropriate level of suitability investigations to be performed, but the Contractor’s employees and subcontractors who have met investigative requirements within the last five years may only require an updated or upgraded investigation. An electronic template, “Roster of Employees Requiring Suitability Investigations,” is available for Contractor use at: http://ais.nci.nih.gov/forms/Suitability-roster.xls. Upon receipt of the Government’s notification of applicable suitability investigations required, the Contractor shall complete and submit the required forms within 30 days of the notification.
Non-Disclosure Agreements.
The Contractor and any sub-Contractors or employees are forbidden from sharing any technical or logistical information they may gain in conjunction with matters related to this task order that could jeopardize the physical or information security of CDC or its employees, projects, or information systems.
The following apply to Contractor employees and their subcontractors associated with the project:
1. Personnel may not begin work under the contract until the Contractor has submitted the employee roster and non-disclosure agreements as described above.
1. Personnel without necessary background investigations will not have access to sensitive project data.
1. Violation of these conditions may lead to termination of the contract.
It is the Contractor’s responsibility to ensure that all employees have met CDC and federal requirements, such as, for example, completion of background checks, before gaining or utilizing access to CDC information technology resources.
(2) Privacy Compliance The Contractor in conjunction with CDC Center ISSO shall conduct and maintain an initial Privacy Impact Assessment (PIA) as defined by Section 208 of the E-Government Act of 2002. Periodic reviews shall be conducted by the system owner, with assistance from the CDC Center Information System Security Officer (ISSO) and Contractor, to determine if a major change to the system has occurred, and if a PIA update is needed.
(3) Contractor’s Official Responsible for Information Security The Contractor shall include the provider’s name and title of its official who will be responsible for all information security requirements regarding this contract.
(4) Rules of Behavior The Contractor’s employees and subcontractors shall comply with the HHS Information Technology General Rules of Behavior, available at: http://www.hhs.gov/ocio/policy/hhs-ocio-2010-0002.001s_hhs_rules_of_behavior.html
(5) Information Security Training HHS policy requires that contractors and subcontractors shall receive security training commensurate with their responsibilities for performing work under the terms and conditions of their contractual agreements. The Contractor shall be responsible for assuring that each employee, including subcontractors, has completed the HHS Computer Security Awareness Training course (or another course designated by CDC) prior to performing any contract work, and thereafter completing the HHS-specified annual refresher course during the period of performance of the contract. This would be provided at the Contractor’s expense and would be the Contractor’s responsibility to plan and arrange. The Contractor shall maintain a listing of all individuals who have completed this training and shall submit this listing to the project officer.
C.11 Government Furnished Property / Information To be specified on individual Task Orders.
File details come from the government source that posted it. Updated .