Solicitation_2015-N-16841_Admendment_1.doc

DOC document 456 KB Posted

Attached to
Immunization Consulting and Research ARM (ICRA) Federal contract opportunity
Solicitation number
2015-N-16841
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

Revised Proposal Due Date June 30 2015 at 5 00 PM EST.

View the file

Other files for this federal contract opportunity

Other files attached to Immunization Consulting and Research ARM (ICRA), newest first.
File Type Posted
ICRA_Solicitation_2015-N-16841_Revised_Version_2.docx DOCX document
ICRA_Solicitation_2015-N-16841_Revised.docx DOCX document
Attachment_4__Full_and_Open_Task_Order__2.docx DOCX document
Solicitation_2015-N-16841_Question_and_Answer.docx DOCX document
Attachment_3__Full_and_Open_Task_Order__1.docx DOCX document
Attachment_5__Small_Business_Set-Aside_Task_Order.docx DOCX document
Attachment_4__Full_and_Open_Task_Order__2.docx DOCX document
Attachment_5__Small_Business_Set-Aside_Task_Order.docx DOCX document
Attachment_2_-_CONTRACTING_OFFICERS_REPRESENTATIVE_(COR)_EVALUATION_REPORT.docx DOCX document
Attachment_1_-_CONTRACTORS_PERFORMANCE_ASSESSMENT_REPORTING_SYSTEM_(CPARS)_RATINGS.docx DOCX document
Solicitation_2015-N-16841.doc DOC document
Attachment_3__Full_and_Open_Task_Order__1.docx DOCX document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION, OFFER AND AWARD

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

RATING

PAGE OF

2. CONTRACT NO.

3. SOLICITATION NO.

2015-N-16841

4. TYPE OF SOLICITATION

X

NEGOTIATED (RFP)

5. DATE ISSUED

05/08/2015

6. REQUISITION/PURCHASE NO.

000HCVG1-2015-74398

7. ISSUED BY
CODE
2543
8. ADDRESS OFFER TO (If other than Item 7)

Centers for Disease Control and Prevention

Procurement and Grants Office

2920 Brandywine Rd, RM 3000

Atlanta, GA 30341-5539

Approved as to Form and Legality: _____________________________

NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”

SOLICITATION

9. Sealed offers in original and handcarried, in the depository located in CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME

Christina Mcmillian

B. TELEPHONE (NO COLLECT CALLS)

AREA CODE NUMBER: EXT:

(770) 488-2697

C. E-MAIL ADDRESS

WPN6@CDC.GOV

11. TABLE OF CONTENTS

(x)

DESCRIPTION

(x)

DESCRIPTION

PART I – THE SCHEDULE
PART II – CONTRACT CLAUSES
X
A
SOLICITATION/CONTRACT FORM
1
X
I
CONTRACT CLAUSES
35
X
B
SUPPLIES OR SERVICES AND PRICES/COSTS
2
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X
C
DESCRIPTION/SPECS./WORK STATEMENT
5
X
J
LIST OF ATTACHMENTS
50
X
D
PACKAGING AND MARKING
14
PART IV – REPRESENTATIONS AND INSTRUCTIONS

X

E
INSPECTION AND ACCEPTANCE
15

REPRESENTATIONS, CERTIFICATIONS, AND

X
F
DELIVERIES OR PERFORMANCE
16
X
K
OTHER STATEMENTS OF OFFERORS
51
X
G
CONTRACT ADMINISTRATION DATA
17
X
L
INSTRS., CONDS., AND NOTICES TO OFFERORS
58
X
H
SPECIAL CONTRACT REQUIREMENTS
21
X
M
EVALUATION FACTORS FOR AWARD
68

OFFER (Must be fully completed by offeror)

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52-232-8)

10 CALENDAR DAYS

20 CALENDAR DAYS

30 CALENDAR DAYS

AMENDMENT NO.
DATE
AMENDMENT NO.
DATE

CODE

FACILITY

16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER

15B. TELEPHONE NO.

AREA CODE NUMBER EXT.

15C. CHECK IF REMITTANCE ADDRESS

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE

18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED

20. AMOUNT

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

21. ACCOUNTING AND APPROPRIATION

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

(4 copies unless otherwise specified)

ITEM

24. ADMINISTERED BY (If other than Item 7)
CODE
2543
25. PAYMENT WILL BE MADE BY
CODE
434

Centers for Disease Control and Prevention

Procurement and Grants Office

2920 Brandywine Rd, RM 3000

Atlanta, GA 30341-5539

Centers for Disease Control and Prevention (FMO)

PO Box 15580 404-718-8100

Atlanta, GA 30333-0080

26. NAME OF CONTRACTING OFFICER (Type or print)

27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION

STANDARD FORM 33 (REV. 9-97)

PREVIOUS EDITION IS UNUSABLE

Prescribed by GSA

FAR (48 CFR) 53.214©

Section B - Supplies Or Services And Prices/Costs Indefinite Delivery, Indefinite Quantity Contract with Task Orders either Firm Fixed Price or Time and Material Base Period:

ITEM
SUPPLIES / SERVICES
QTY / UNIT
NOT TO EXCEED
NOT TO EXCEED
0001
IIS IDIQ

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems

Period of Performance: 09/30/2015 - 09/29/2017

To Be Determined
$_______________
$_______________

Option Period One:

ITEM
SUPPLIES / SERVICES
QTY / UNIT
NOT TO EXCEED
NOT TO EXCEED
0002
IIS IDIQ

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems Period of Performance: 09/30/2017 - 09/29/2019

To Be Determined
$_______________
$_______________

Option Period Two:

ITEM
SUPPLIES / SERVICES
QTY / UNIT
NOT TO EXCEED
NOT TO EXCEED
0003
IIS IDIQ

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems

Period of Performance: 09/30/2019 - 09/29/2021

To Be Determined
$_______________
$_______________

Option Period Three:

ITEM
SUPPLIES / SERVICES
QTY / UNIT
NOT TO EXCEED
NOT TO EXCEED
0004
IIS IDIQ

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems

Period of Performance: 09/30/2021 - 09/29/2023

To Be Determined
$_______________
$_______________

Option Period Four:

ITEM
SUPPLIES / SERVICES
QTY / UNIT
NOT TO EXCEED
NOT TO EXCEED
0005
IIS IDIQ

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems Period of Performance: 09/30/2023 - 09/29/2025

To Be Determined
$_______________
$_______________

B.1 General

The Contract is a multiple award, indefinite delivery, indefinite quantity (IDIQ) contract to provide a broad range of information technology services to support the global health mission of the CDC. The Contractor, acting as an independent contractor and not as an agent of the government, shall furnish all materials, personnel, facilities, support and management necessary to provide the services as set forth below in accordance with the Statement of Work.

(End of Clause) B.2 Ordering of Services

Orders for services will be conducted through the issuance of individual task orders in accordance with Paragraph H.13, Award of Task Orders, and the Ordering Clauses in Section I.

(End of Clause) B.3 Base and Option Periods The term of this IDIQ contract is a two (2) year base period and four (4) two-year option periods, comprising a ten (10) year ordering period if all options are exercised by the Government.

(End of Clause)

B.4 Type of Contract

This is a multiple award, IDIQ-type contract. At the discretion of the Contracting Officer, the government may use a variety of task order types under this contract, including Firm Fixed Price (FFP), Time and Materials (T&M), Labor-Hour (LH) or a combination thereof.

Each Request for Task Order Proposal (RFTOP) issued under this contract will identify the Government’s determination of task order type.

(End of Clause)

B.5 Minimum and Maximum Ordering Amounts

The Government shall place orders totaling a minimum of $1,000 over the life of the contract. The maximum amount of all orders issued and awarded under the contracts over the ten (10) year period of performance shall not exceed $170,000,000.00 The maximum ceiling amount of this contract may be increased to accommodate additional needs of the Agency that are within the scope of the contract only upon execution of a modification by an authorized Contracting Officer.

(End of Clause)

B.6 Service Contract Act The contract labor categories are considered executive and professional labor and generally exempt from the Service Contract Act. Each RFTOP will be reviewed for applicability.

(End of Clause)

Section C – Performance Work Statement

Comprehensive Technical, Operation, Research and Support for Immunization Information Systems in the National Center for Immunization and Respiratory Diseases

BACKGROUND

The Centers for Disease Control and Prevention (CDC), headquartered in Atlanta, Georgia, USA, is an agency of the Department of Health and Human Services (DHHS). The National Center for Immunization and Respiratory Diseases (NCIRD) is one of the major centers within CDC. NCIRD has an ongoing need for Comprehensive Technical, Operation, Research, and Support for Immunization Information Systems (IIS).

IIS are confidential, population-based, computerized databases that record all immunization doses administered by participating providers to persons residing within a given geopolitical area. At the point of clinical care, an IIS can provide consolidated immunization histories for use by a vaccination provider in determining appropriate client vaccinations and improving immunization practice. At the population level, an IIS provides aggregate data on vaccinations for use in surveillance and program operations, and in guiding public health action with the goals of improving vaccination rates and reducing vaccine-preventable disease.

IIS play a critical role supporting public health and in clinical decision support at the provider level. IIS help immunization programs identify populations at high risk for vaccine-preventable diseases and target interventions and resources efficiently. Additionally, IIS combine immunization information from different sources into a single record and provide official immunization records for school, day care, and camp entry requirements. IIS remind families when an immunization is due or has been missed. IIS help providers and parents determine when immunizations are due and help ensure that children get only the vaccinations they need. IIS are capable of exchanging immunization information with immunization healthcare providers. Data exchange between IIS and other information systems helps ensure timely immunizations, consolidation of records, and allows immunization providers to work more efficiently.

In 1997, President directed the Secretary of Health and Human Services (HHS) “to start working with the states on an integrated immunization registry system.” As a result, an Initiative on Immunization Registries was undertaken by the National Vaccine Advisory Committee (NVAC). A Workgroup was formed to develop a plan to facilitate and coordinate a nationwide network of community- and state-based immunization registries. The Workgroup identified four issues that provide the conceptual framework for the plan: 1) protecting the privacy of individuals and the confidentiality of information, 2) ensuring provider participation, 3) overcoming technical and operational challenges, and 4) determining resources needed to develop and maintain immunization registries.

Substantial progress has been made by CDC and state and local immunization programs to address each of the four key factors. Standards and specifications have been developed to protect privacy and confidentiality of immunization registry information, functional standards and interoperability guidelines have been developed and continue to evolve to address technical and operational challenges.

IIS and associated operations have evolved to arguably become the most mature and robust public health information system used in state and local public health. The IIS community has evolved from having over 250 local registries in the late ‘90’s each doing their own thing, to a much more consolidated network of increasingly inter-connected systems, coalescing around more harmonized and standardized ways of capturing and exchanging data. The continuous development of immunization registries is now focused on best practices, integration with the workflows and systems of clinical care providers, and enhancing the value of the services provided by immunization registries.

OBJECTIVE

The objective of NCRID’s IIS strategic roadmap and the related implementation projects is to help NCIRD realize the future state of immunization management in the United States. As implementation projects in the five focus areas are planned and initiated, NCIRD will require support from qualified contractors and partners to provide a wide range of consultative, research, and support services around IIS.

The high-level objectives of this 120-month IDIQ contract are to:

a. Ensure CDC has ongoing timely, high quality, cost effective, efficient, innovative, and comprehensive research and management consulting contractual services as needed leveraging industry best practices and professional standards;

b. Ensure related and interdependent functions and disciplines are covered in the contract services;

c. Provide nationwide, secure, information management service and support as needed

d. Provide a comprehensive performance and solutions-based contract;

e. Contribute to the achievement of NCIRD’s IIS program goals and IIS Strategic Plan.

SCOPE OF WORK

The scope of this contract covers the breadth of research and management consulting services related to immunization information systems including but not limited to the following below:

a. Program/project management and execution – Support the planning, requirements analysis, specification development, strategy validation, technical and schedule review, deliverable tracking, risk management and overall status reporting on the performance and execution of initiatives to ensure consistency with NCIRD strategic plan goals and objectives.

b. Program evaluation metrics – Evaluate progress toward achieving programmatic and IIS strategic goals by clearly defining metrics. Develop and implement strategies, tools and process to evaluate new and existing metrics.

c. Technical, business, and operational analysis, documentation and assistance – Provide operational support to NCIRD including technical and business assistance , analysis and documentation services that could be used to achieve the goals of IIS strategic plan.

d. Technical integration services – Perform System Integration services to bring disparate systems/processes together in the delivery of capabilities that the different systems by themselves could not achieve.

e. Strategic communications – Implement or update NCIRD Organizational Change Management (OCM) and related communications plans. Develop, define, and implement communication strategies to enable cultural and behavioral changes within the IIS environment. Collaborate with the IIS Community to maintain comprehensive current-state perspective on the issues, risks, challenges and opportunities that have a direct or indirect relationship or effect on NCIRD IIS Strategic Plan goals and objectives.

f. Facilitation of general meetings and consensus-building efforts – Engage a diverse pool of subject matter experts to identify, assess, and conduct analysis on challenges, barriers and opportunities that could potentially threaten or benefit the NCIRD IIS Strategic Plan goals and objectives. Plan, develop and execute the framework for forums and other input building modalities.

g. Public and clinical healthcare integration, evaluation, and service delivery – Conduct ongoing analyses, process and outcome evaluations, and support efforts, that could potentially impact NCIRD IIS goals and objectives. These include but are not limited to the facilitation of the development and/or evaluation of robust functional capacities in IIS such as Clinical Decision Support (CDS), data integration, vaccine ordering and supply integration, vaccine barcoding, functional standards, operational development and implementations, messaging and other data exchange both intrastate and interstate, data analysis, data quality, and data reporting capabilities in IIS.

h. Data analytics and evaluation – Use data mining, business intelligence, epidemiological and statistical analysis techniques capable of both exploratory and confirmatory data analysis to produce analytic and data use best practices for IIS and evaluate clinical and public health immunization outcomes at the national, state and local levels. Provides support for data analytics and data quality improvement for IIS data.

i. Program certification methods – Provide support for planning, developing and implementation related to the establishment of certification processes for immunization centric EHRs and for IIS certification activities.

j. Research, program evaluation, and assessment support – Collect, analyze, and use information to answer questions about projects, policies, and programs effectiveness and efficiency. Evaluate programs to identify whether the intended outcome is produced within program project constraints. Identify program improvements, program value within the IIS portfolio, an analysis of alternatives, and an understanding of any unintended consequences.

k. Survey design, development, and implementation – Identify and determine objective(s) of survey. Develop appropriate data collection tools to carry out survey objectives. Review and vet data collection instruments with appropriate stakeholders. Implement survey design, analyze and report results.

l. Policy and legislative issues – Support NCIRD in the continuous development, implementation and recommendations for nationwide policy approaches that can be used to address challenges in the IIS.

m. Program management including pre and post award contracts – Support project management to ensure NCIRD receives the maximum return on its strategic investments. Advise NCIRD on identification and analysis of gaps and needs, support acquisition planning and development, Statement of Work production; provide logistical support for proposal evaluation, selection, and negotiation as appropriate. Perform support roles in contract execution, risk management, performance monitoring, and results reporting.

n. National and program standards development support – Provide support identifying, reviewing and updating standards and regulations to assist in the development of standards specifications and implementation guides. Facilitate IIS community collaboration on standards.

o. General management consulting activities: Provide project management, administration support, and training development/ implementation support for NCIRD IIS related initiatives.

REPORTING SCHEDULE

Reporting schedules will be established within Task Orders.

GOVERNMENT FURNISHED MATERIALS

Government furnished materials will be defined within Task Orders.

SPECIAL CONSIDERATIONS

Minimum Requirements

The successful offeror shall have experience working with state and local public health departments’ immunization information systems or at the national level for national standards, operational improvements, and technical development and support, or evaluation efforts around information immunization systems.

Security and Privacy

IT Contractor performance and resulting deliverables must adhere to all federal, HHS, and/or CDC IT security policies and procedures. Based upon the scope of this contract, the following HHSAR IT Security clauses are applicable to this contract and require contractor compliance with:

a. 352.239-70 Standard for Security Configurations

b. 352.239-71 Standard for Encryption Language

c. 352.239-72 Security requirements for Federal Information Technology Resources.

The above clauses may be found at: http://www.hhs.gov/policies/hhsar/subpart352. Specific HHSAR IT security clauses for work conducted by the Contractor on behalf of the government apply. If task order objectives include a cloud-based hosting solution, the GSA FedRAMP Standard Contract Clauses apply. Additional information is available on the OCISO website at http://intranet.cdc.gov/ociso/pandp/fedramp.html.

The below information is extracted from HHS-OCIO Policy for Information Systems Security and Privacy (IS2P) - Handbook, HHS Contractor Oversight Guide, and FAR 39.101(d)

This SOW requires the successful offeror(s) to have the ability to host and maintain a system for data collection, management, use, and reporting to support activities funded by the federal government. IMPORTANT NOTE TO OFFERORS: The following information shall be addressed in a separate section of the Technical Proposal entitled, “Information Security.” Information Security is applicable to this solicitation because all information systems developed, operated, or used by or on behalf of the federal government must comply with Federal Information Security laws, policies and standards. We provide the following information to assist in the preparation of proposals in order to assure that the existing data system, which would be licensed for use by CDC grantees and CDC employees, meets the security standards described below.

First, The EGovernment Act of 2002, (Federal Information Management Act) and the below federal policies dictate the framework for assuring information security for data systems operated by or on behalf of the federal government. These are summarized below.

OMB Circular A-130 (http://www.whitehouse.gov/omb/Circulars_a130_a130trans4/) establishes policy for the management of Federal information resources, pursuant to a number of laws and regulations, including the Paperwork Reduction Act of 1980 (amended in 1995), the Computer Security Act of 1987, and other laws. Circular A-130 requires all federal information systems to have security plans, emergency response capabilities, designated individuals who are responsible for security, security awareness training, and regular review of the system. Appendix III of Circular A-130, entitled “Security of Federal Automated Information Resources,” establishes a minimum set of controls to be included in Federal automated information security programs; assigns Federal agency responsibilities for the security of automated information; and links agency automated information security programs (such as the DHHS AISSP) with OMB Circular No. A-123.

The Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) (http://csrc.nist.gov/policies/FISMA-final.pdf) requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, offeror (including sub-offeror), or other source. The National Institute of Standards and Technology (NIST) has issued a number of publications that provide guidance in the establishment of minimum security controls for management, operational, and technical safeguards needed to protect the confidentiality, integrity, and availability of a Federal information system and its information.

Pursuant to Federal and HHS Information Security Program Policies the following standards and guidelines apply:

· FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf),

· FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf)

· NIST Special Publication 800-18, Guide to Developing Security Plans for Federal Information Systems (http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf)

· NIST Special Publication 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories Vol. 1 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf) and Vol. 2 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf).

· NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations (http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final-errata.pdf).

· NIST Special Publication 800-63, Electronic Authentication Guideline (http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf)

Second, the Offeror should demonstrate understanding of security requirements by attaching a Draft Data System Security Plan or information system security plan (SSP). The SSP should be a brief and general narrative description of the system and its integration with the CDC Network Infrastructure.

The initial draft and all subsequent versions of the SSP must be prepared and submitted by the Offeror to the CDC contracting officer and to the CDC technical monitor, in Microsoft Word compatible format. The successful Offeror shall be responsible for ensuring that the security plan is acceptable to the CDC technical monitor and the CDC Information System Security Officer as well as any subsequent federal reviewers (e.g., Center and/or HHS officials, OMB officials). Comments shall be conveyed to the Offeror by the technical monitor and/or the contracting officer.

Once an award is made, the technical monitor and the contracting officer will review the draft SSP and any subsequent versions and submit recommendations/comments to the Offeror within 14 working days after receipt. The Offeror shall incorporate the technical monitor’s recommendations and submit paper and electronic copies of the security plan to the contracting officer and to the technical monitor within five working days after receipt of the technical monitor's comments. The resultant contract will require the draft SSP to be finalized in coordination with the Project Officer/ technical monitor no later than 90 calendar days after contract award. Also, the successful Offeror, in conjunction with the CDC Center ISSO, is required to update and resubmit its SSP to CDC every three years following award or when a modification has been made to its internal system. In addition to developing and maintaining an SSP, the successful Offer or shall be responsible for continuously assessing and assuring information security for the project and for updating the security plan as needed throughout the duration of the agreement.

The SSP is part of the Certification and Accreditation (C&A) process required by the EGovernment Act of 2002 and NIST Special Publication 800-37 and will include selected mandatory controls required by NIST Special Publication 800-53, Volume I & II. The Offeror, in conjunction with the Center Information System Security Officer (ISSO), will submit C&A documentation to the CDC Chief Information System Officer (CISO). The successful completion of the C&A documents will result in an award of an Authority To Operate. Based on guidance in FIPS 199 and NIST SP 800-60 (information type D.14.2), the system will be assigned an overall security category (SC) of MODERATE based on (confidentiality, MODERATE), (integrity, MODERATE), and (availability, LOW) impact levels. Therefore, details contained in the Offeror’s draft SSP shall include NIST SP 800-53 security control baselines for moderate impact systems.

The Offeror shall allocate staff and specify a budget line item for maintaining computer and data security on the licensing contract and for maintaining the SSP. In conjunction with the CDC Center ISSO, the Offeror will help complete the necessary additional documents to obtain a CDC Certification and Accreditation. Those documents included are listed below. Normally, these documents will be completed by the CDC Center ISSO/Security Steward with information provided by the Offeror. Templates of the documents will be provided to the offeror after award.

· Baseline System Information (BSI)

· Privacy Impact Assessment (PIA)

· Host Characterization Worksheet (HCW)

· System Security Plan (SSP)

· Security Baseline Worksheet (SBW)

· Business Continuity Plan (BCP)

· Risk Assessment Report (RAR)

Third, the Offeror shall respond to the following seven security–associated requirements in the application:

(1) Position Sensitivity Designations

The following position sensitivity designations and associated clearance and investigation requirements apply under this licensing contract:

Level 5: Public Trust - Moderate Risk (Requires Suitability Determination with NACIC, MBI or LBI). Licensor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency Check and Inquiry Investigation plus a Credit Check (NACIC), a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

Upon award, the Licensor will be required to submit a roster of all staff (including sub-offeror staff) working under the contract that will have the ability to access HIV prevention program information from the system. The roster shall be submitted to the Project Officer/technical monitor, with a copy to the Contracting Officer, within 14 calendar days of the effective date of the contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer shall notify the licensor of the appropriate level of suitability investigations to be performed, but Licensor employees and subcontractors who have met investigative requirements within the last five years may only require an updated or upgraded investigation. An electronic template, “Roster of Employees Requiring Suitability Investigations,” is available for offeror use at: http://ais.nci.nih.gov/forms/Suitability-roster.xls. Upon receipt of the Government’s notification of applicable suitability investigations required, the Licensor shall complete and submit the required forms within 30 days of the notification.

Non-Disclosure Agreements The Offeror and any sub-Offerors or employees are forbidden from sharing any technical or logistical information they may gain in conjunction with matters related to this task order that could jeopardize the physical or information security of CDC or its employees, projects, or information systems. The following apply to Licensor employees and their subcontractors associated with the project:

1) Personnel may not begin work under the contract until the contractor has submitted the employee roster and non-disclosure agreements as described above.

2) Personnel without necessary background investigations will not have access to sensitive project data.

3) Violation of these conditions may lead to termination of the contract.

Note that CDC is not required to grant the successful Offeror access to CDC information technology resources (e.g., computers, network, and email). If CDC were to agree to grant the Offeror, or any of its employees, access to CDC information technology resources at any point in time, it would be the Offeror's responsibility to ensure that all of its employees to be granted such access complete any additional required information security courses that CDC specifies prior to gaining or utilizing such access.

It is the Offeror's responsibility to ensure that all employees have met CDC and federal requirements, such as completion of 0background checks, before gaining or utilizing access to CDC information technology resources.

(1) Privacy Compliance

While the Privacy Act is not applicable, the contractor shall comply with appropriate security controls and Rules of Behavior to protect the confidentiality, integrity, and availability of any, proprietary, sensitive, or Personally Identifiable Information (PII) the Contractor may encounter during the performance of this contract.

Licensor in conjunction with CDC Center ISSO shall conduct and maintain an initial Privacy Impact Assessment (PIA) as defined by Section 208 of the E-Government Act of 2002. Periodic reviews shall be conducted by the system owner, with assistance from the CDC Center ISSO and offeror, to determine if a major change to the system has occurred, and if a PIA update is needed.

(2) Offeror’s Official Responsible for Information Security

The Offeror shall include in the “Information Security” part of the Technical Proposal the name and title of its official who will be responsible for all information security requirements should the offeror be selected for an award.

(3) Rules of Behavior

The Offeror’s employees and subcontractors shall comply with the HHS Information Technology General Rules of Behavior.

(4) Information Security Training

HHS policy requires that contractors and subcontractors shall receive security training commensurate with their responsibilities for performing work under the terms and conditions of their contractual agreements. The successful Offeror shall be responsible for assuring that each employee, including subcontractors, has completed the HHS Computer Security Awareness Training course (or another course designated by CDC) prior to performing any contract work, and thereafter completing the HHS-specified annual refresher course during the period of performance of the contract. This would be provided at the Offeror's expense and would be the Offeror's responsibility to plan and arrange. The successful Offeror shall maintain a listing of all individuals who have completed this training and shall submit this listing to the project officer.

(5) Encryption

All sensitive CDC-funded data stored on desktop computers used on behalf of HHS shall be secured either through a FIPS 140-2 compliant encryption solution or through adequate physical security and operational controls at the desktop’s residing location.

All mobile devices, portable media and transfer data files (including e-mail attachments) that contain sensitive CDC- data shall be encrypted using FIPS 140-2 compliant algorithms.

508 Compliance

Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998, and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Provisions (36 CFR part 1194), require that, unless an exception applies, all EIT products and services developed, acquired, maintained, or used by any federal department or agency permit:

(1) Federal employees with disabilities to have access to and use information and data that is comparable to the access and use of information and data by Federal employees who are not individuals with disabilities; and

(2) Members of the public with disabilities seeking information or services from a federal agency to have access to and use of information and data that is comparable to the access and use of information and data by members of the public who are not individuals with disabilities.

Accordingly, any vendor submitting a proposal/quotation/bid in response to this solicitation must demonstrate compliance with the established EIT accessibility provisions. Information about Section 508 provisions is available at http://www.section508.gov/. The complete text of Section 508 Final Provisions can be accessed at http://www.access- board.gov/sec508/provisions.htm.

The Section 508 standards applicable to this solicitation are identified in the Statement of Work/Specification/Performance Work Statement. In order to facilitate the Government’s evaluation to determine whether EIT products and services proposed meet applicable Section 508 accessibility standards, Offerors must prepare an HHS Section 508 Product Assessment Template, in accordance with its completion instructions, and provide a binding statement of conformance. The purpose of the template is to assist HHS acquisition and program officials in determining that EIT products and services proposed support applicable Section 508 accessibility standards. The template allows vendors or developers to self-evaluate their products or services and document in detail how they do or do not conform to a specific Section 508 standard. Instructions for preparing the HHS Section 508 Product Assessment Template may be found at http://508.hhs.gov.

Respondents to this solicitation must also provide any additional detailed information necessary for determining applicable Section 508 standards conformance, as well as for documenting EIT products and/or services that are incidental to the project, which would constitute an exception to Section 508 requirements. If a vendor claims its products and/or services, including EIT deliverables such as electronic documents and reports, meet applicable Section 508 standards in its completed HHS Section 508 Product Assessment Template, and it is later determined by the Government – i.e., after award of a contract/order, that products and/or services delivered do not conform to the described accessibility in the Product Assessment Template, remediation of the products and/or services to the level of conformance specified in the vendor’s Product Assessment Template will be the responsibility of the Contractor at its expense.

The applicable provisions of Section 508 are as follows:

36 CFR 1194.21, .22, .31, .41.

Acceptance checklists for applicable document formats are available at http://www.hhs.gov/web/508. Checklists for websites, applications, and other acceptance criteria are available from the CDC Section 508 helpdesk at 508helpdesk@cdc.gov.

Section D - Packaging And Marking There are no terms and conditions in this section.

Section E - Inspection And Acceptance

FAR SOURCE
TITLE AND DATE

52.246-4

52.246-6 Inspection of Services – Fixed-Price (Aug 1996)

Inspection – Time and Material and Labor Hour (May 2001)

E.1 INSPECTION AND ACCEPTANCE (Jul 1999)

Inspection and acceptance of the articles, services, and documentation called for herein shall be accomplished by the Contracting Officer, or his duly authorized representative (who for the purposes of this contract shall be the Project Officer) at the destination of the articles, services or documentation.

(End of Clause)

Section F - Deliveries Or Performance

FAR SOURCE
TITLE AND DATE
52.242-15
Stop-Work Order (Aug 1989)

F.1 Period of Performance

The period of performance shall be for a 24-month base period from 9/30/2015 – 9/29/2017 with four additional 24-month option periods.

(End of Clause)

F.2 Place of Performance

Place of performance will be defined within each individual Task Order.

(End of Clause)

F.3 Deliverable(s) Schedule (Jul 1999)

Each deliverable shall be electronically submitted to the Contracting Officer’s Representative (COR) and Contracting Officer (CO).

Each Task Order solicited under this IDIQ will define specific deliverables at the time of solicitation.

(End of Clause)

Section G - Contract Administration Data G.1 Contract Representative

Contracting Officer (CO) responsible for this contract:

Alan W. Sims

Centers for Disease Control and Prevention (CDC)

Procurement and Grants Office (PGO)

2920 Brandywine Road, MS K-14

Atlanta, GA 30341-5539

Telephone Number: 770.488.2896

Email: ASims1@cdc.gov

Contract Administrator (CA) responsible for this contract:

Christina McMillian

Centers for Disease Control and Prevention (CDC)

Procurement and Grants Office (PGO)

2920 Brandywine Road, MS K-14

Atlanta, GA 30341-5539

Telephone Number: 770-488-6397

Email: wpn6@cdc.gov

Contracting Officer’s Representative (COR) responsible for this contract:

TBD

Centers for Disease Control and Prevention (CDC)

(End of Clause)

G.2 Contracting Officer (Jul 1999)

(a) The Contracting Officer is the only individual who can legally commit the Government to the expenditures of public funds. No person other than the Contracting Officer can make any changes to the terms, conditions, general provisions, or other stipulations of this contract.

(b) No information, other than that which may be contained in an authorized modification to this contract, duly issued by the Contracting Officer, which may be received from any person employed by the United States Government, or otherwise, shall be considered grounds for deviation from any stipulation of this contract.

(End of Clause)

G.3 Contracting Officer’s Representative (COR)

(a) A Contracting Officer’s Representative (COR) as a minimum, and possibly a Technical Monitor (TM), will be assigned to this delivery order. The Contracting Officer will provide under separate cover the duties and responsibilities of the COR and Technical Monitor. This document will be provided to the COR, TM and the Contractor. The COR and/or the TM are not authorized to alter the requirements of this delivery order without written approval of the Contracting Officer. COR/TM is not authorized to obligate any funds.

(b) Performance of the work hereunder shall be subject to the technical directions of the designated Contracting Officer’s Technical Representative (COR) for this contract. Technical Monitors will report to the COR

(c) For purposes of this agreement, Technical Monitor duties for individual delivery/task orders are the same as the COR’s duties. Hereinafter in this clause, the duties and responsibilities described for the COR also apply to the Technical Monitors under the individual delivery/task order for which the Technical Monitors are responsible.

(d) As used herein, technical directions are directions to the Contractor which fill in details, suggests possible lines of inquiry, or otherwise completes the general scope of work set forth herein. These technical directions must be within the general scope of work, and may not alter the scope or work or cause changes of such a nature as to justify an adjustment in the stated contract price/cost, or any stated limitation thereof. In the event that the Contractor feels that full implementation of any of these directions may exceed the scope of the contract, he or she shall notify the originator of the technical direction and the Contracting officer in a letter separate of any required report(s within two (2) weeks of the date of receipt of the technical direction and no action shall be taken pursuant to the direction. If the Contractor fails to provide the required notification within the said two (2) week period that any technical direction exceeds the scope of the contract, then it shall be deemed for purposed of this contract that the technical direction was within the scope. No technical direction, nor its fulfillment, shall alter or abrogate the rights and obligations fixed in this contract.

(e) The Government COR is not authorized to change any of the terms and conditions of this contract. Changes shall be made only by the Contracting Officer by properly written modification(s) to the contract.

(f) The Government will provide the Contractor with a copy of the delegation memorandum for the COR. Any changes in COR delegation will be made by the Contracting Officer in writing with a copy being furnished to the Contractor.

(End of Clause)

G.4 Contractor Performance Assessment Reporting System (CPARS) Requirements

In accordance with FAR 42.15, the Centers for Disease Control and Prevention (CDC) will review and evaluate contract performance. FAR 42.1502 and 42.1503 requires agencies to prepare evaluations of contractor performance and submit them to the Past Performance Information Retrieval System (PPIRS). The CDC utilizes the Department of Defense (DOD) web-based Contractor Performance Assessment Reporting System (CPARS) to prepare and report these contractor performance evaluations. All information contained in these assessments may be used by the Government, within the limitations of FAR 42.15, for future source selections in accordance with FAR 15.304 where past performance is an evaluation factor.

The CPARS system requires a contractor representative to be assigned so that the contractor has appropriate input into the performance evaluation process. The CPARS contractor representative will be given access to CPARS and will be given the opportunity to concur or not-concur with performance evaluations before the evaluations are complete. The CPARS contractor representative will also have the opportunity to add comments to performance evaluations.

The assessment is not subject to the Disputes clause of the contract, nor is it subject to appeal beyond the review and comment procedures described in the guides on the CPARS website. Refer to: www.cpars.gov for details and additional information related to CPARS, CPARS user access, how contract performance assessments are conducted, and how Contractors participate. Access and training for all persons responsible for the preparation and review of performance assessments is also available at the CPARS website.

The contractor must provide the CDC contracting office with the name, e-mail address, and phone number of their designated CPARS representative who will be responsible for logging into CPARS and reviewing and commenting on performance evaluations. The contractor must maintain a current representative to serve as the contractor representative in CPARS. It is the contractor’s responsibility to notify the CDC contracting office, in writing (letter or email), when their CPARS representative information needs to be changed or updated. Failure to maintain current CPARS contractor representative information will result in the loss of an opportunity to review and comment on performance evaluations.

Provide the current CPARS representative information below.

PRINT OR TYPE NAME

EMAIL ADDRESS AND PHONE NUMBER

[End of Provision]

G.5 Contract Communications/Correspondence (Jul 1999)

The Contractor shall identify all correspondence, reports, and other data pertinent to this contract by imprinting thereon the contract number from Page 1 of the contract.

(End of Clause)

G.6 Payment by Electronic Funds Transfer (Dec 2005)

(a) The Government shall use electronic funds transfer to the maximum extent possible when making payments under this contract. FAR 52.232-33, Payment by Electronic Funds Transfer – Central Contractor Registration, in Section I, requires the contractor to designate in writing a financial institution for receipt of electronic funds transfer payments.

(b) In addition to Central Contractor Registration, the contractor shall make the designation by submitting the form titled “ACH Vendor/Miscellaneous Payment Enrollment Form” to the address indicated below. Note: The form is either attached to this contract (see Section J, List of Attachments) or may be obtained by contacting the Contracting Officer or the CDC Financial Management Office at (404) 498-4050.

(c) In cases where the contractor has previously provided such designation, i.e., pursuant to a prior contract/order, and been enrolled in the program, the form is not required unless the designated financial institution has changed.

(d) The completed form shall be mailed after award, but no later than 14 calendar days before an invoice is submitted, to the following address:

The Centers for Disease Control and Prevention

Financial Management Office (FMO)

P.O. Box 15580

Atlanta, GA 30333

Or – Fax copy to: 404-638-5342

(End of Clause)

G.7 Invoice Submission - Part 1 (Mar 2006)

(a) The Contractor shall submit the original contract invoice/voucher to the shown below:

The Centers for Disease Control and Prevention Financial Management Office (FMO) P.O. Box 15580 Atlanta, GA 30333

(b) Please do not forget to submit a copy of each invoice directly to the Project Officer and Contracting Officer or Contract Administrator concurrently with submission to the Financial Management Office (FMO). It saves time, postage, and speeds up the payment processing by emailing the invoices to the 3 listed email addresses below:

Financial Management Office (FMO): Email: FMOAPINV@CDC.GOV Contract Specialist: Christina McMillian, wpn6@cdc.gov, 770-488-2397

COR: TBD

(c) The Contractor is required to submit a copy of each invoice directly to the Project Officer concurrently with submission to the Contracting Officer.

(d) In accordance with 5 CFR part 1315 (Prompt Payment), CDC's Financial Management Office is the designated billing office for the purpose of determining the payment due date under FAR 32.904.

(e) The Contractor shall include (as a minimum) the following information on each invoice:

(1) Contractor’s Name & Address

(2) Contractor’s Tax Identification Number (TIN)

(3) Purchase Order/Contract Number and Task Order Number, if Appropriate

(4) Invoice Number

(5) Invoice Date

(6) Contract Line Item Number and Description of Item

(7) Quantity

(8) Unit Price & Extended Amount for each line item

(9) Shipping and Payment Terms

(10) Total Amount of Invoice

(11) Name, title and telephone number of person to be notified in the event of a defective invoice

(12) Payment Address, if different from the information in (e)(1).

(13) DUNS + 4 Number

(End of Clause)

Section H - Special Contract Requirements H.1 Non-Disclosure Agreement for Contractor and Contractor Employees (Mar 2006)

(a) The contractor shall prepare and submit a Non-Disclosure Agreement (NDA) to the Contracting Officer prior to access of government information or the commencement of work at CDC.

(b) The NDA made part of this clause, exhibit I and II , is required in service contracts where positions and/or functions proposed to be filled by contractor’s employees will have access to non-public and procurement-sensitive information. The NDA also requires contractor’s employees properly identify themselves as employees of a contractor when communicating or interacting with CDC employees, employees of other governmental entities (when communication or interaction relates to the contractor’s work with the CDC), and members of the public. The Federal Acquisition Regulation (FAR) 37.114 (c), states “All contractor personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public or Congress that they are Government officials, unless, in the judgment of the agency, no harm can come from failing to identify themselves. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.”

(c) The Contractor shall inform employees of the identification requirements by which they must abide and monitor employee compliance with the identification requirements.

(d) During the contract performance period, the Contractor is responsible to ensure that all additional or replacement contractors’ employees sign a NDA and it is submitted to the Contracting Officer prior to commencement of their work with the CDC.

(e) Contractor employees in designated positions or functions that have not signed the appropriate NDA shall not have access to any non-public, procurement sensitive information or participate in government meeting where sensitive information may be discussed.

(f) The Contractor shall prepare and maintain a current list of employees working under NDAs and submit to the Contracting Officer upon request during the contract period of performance. The list should at a minimum include: contract number, employee’s name, position, date of hire and NDA requirement.

EXHIBIT I

Centers for Disease Control and Prevention (CDC)

Contractor…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .