2015-N-17649_-_DCIPHER_for_Ebola_Event_Response_Platform.pdf

PDF 382 KB Posted

Attached to
DCIPHER for Ebola Event Response Platform Federal contract opportunity
Solicitation number
2015-N-17649
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

RFP 2015-N-17649 DCIPHER for Ebola Event

View the file

Other files for this federal contract opportunity

Other files attached to DCIPHER for Ebola Event Response Platform, newest first.
File Type Posted
Amendment_0001 _Continuation_Pages.docx DOCX document
DCIPHER_for_Ebola _Amendment_0001.pdf PDF
Atch_3 _Major_IT_Business_Case_Examples.pdf PDF
Atch_1 _Rules_of_Behavior.pdf PDF
Atch_5 _Exhibits_I_and_II.pdf PDF
Atch_4 _SF_3881_ACH_Vendor-Misc_Pmt_Enrollment_Form.pdf PDF
Atch_2 _Appendix_A.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGES

15A. NAME

AND

ADDRESS

OF

OFFEROR

SEC. PAGE(S) SEC. PAGE(S)

(Date)(Hour)

CALENDAR DAYS

14. ACKNOWLEDGMENT OF AMENDMENTS

(The offeror acknowledges receipt of amend-ments to the SOLICITATION for offerors and related documents numbered and dated:

(Type or Print)

SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

RATING

PAGE OF

1 71

2. CONTRACT NO.

200-2015-

3. SOLICITATION NO.

2015-N-17649

4. TYPE OF SOLICITATION

SEALED BID (IFB)

X NEGOTIATED (RFP)

5. DATE ISSUED

11/04/2015

6. REQUISITION/PURCHASE

NO.

0000HCVL-2015-90346

7. ISSUED BY CODE 8219 8. ADDRESS OFFER TO (If other than Item 7)

Centers for Disease Control and Prevention (CDC) Procurement and Grants Office (PGO) 2920 Brandywine Road Atlanta, GA 30341-5539

Centers for Disease Control and Prevention Attention: Pat Billins

Approved as to Form and Legality: _____________________________ NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”

SOLICITATION

9. Sealed offers in original and 1 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in email until 2:00p local time 12/04/2015

CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME

Pat Billins

B. TELEPHONE (NO COLLECT CALLS)

AREA CODE NUMBER: EXT:

(770) 488-2058

C. E-MAIL ADDRESS

pbillins@cdc.gov

11. TABLE OF CONTENTS

(x) DESCRIPTION (x) DESCRIPTION

PART I – THE SCHEDULE PART II – CONTRACT CLAUSES

X A SOLICITATION/CONTRACT FORM 1 X I CONTRACT CLAUSES 44

X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.

X C DESCRIPTION/SPECS./WORK STATEMENT 7 X J LIST OF ATTACHMENTS 58

X D PACKAGING AND MARKING 19 PART IV – REPRESENTATIONS AND INSTRUCTIONS

X E INSPECTION AND ACCEPTANCE 26 REPRESENTATIONS, CERTIFICATIONS, AND

X F DELIVERIES OR PERFORMANCE 27 X K OTHER STATEMENTS OF OFFERORS 59

X G CONTRACT ADMINISTRATION DATA 27 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 64

X H SPECIAL CONTRACT REQUIREMENTS 29 X M EVALUATION FACTORS FOR AWARD 70

OFFER (Must be fully completed by offeror) NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52-232-8)

10 CALENDAR DAYS

20 CALENDAR DAYS

30 CALENDAR DAYS

AMENDMENT NO. DATE AMENDMENT NO. DATE

CODE FACILITY 16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER

15B. TELEPHONE NO.

AREA CODE NUMBER EXT.

15C. CHECK IF REMITTANCE ADDRESS

IS DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE

18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

21. ACCOUNTING AND APPROPRIATION

10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( ) 23. SUBMIT INVOICES TO ADDRESS SHOWN IN (4 copies unless otherwise specified)

ITEM

24. ADMINISTERED BY (If other than Item 7) CODE 8219 25. PAYMENT WILL BE MADE BY CODE 434

See Block 7 Centers for Disease Control and Prevention (FMO) PO Box 15580 (404) 718-8100 Atlanta, GA 30333-0080

26. NAME OF CONTRACTING OFFICER (Type or print)

27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)

PREVIOUS EDITION IS UNUSABLE Prescribed by GSA

FAR (48 CFR) 53.214©

K

Section B - Supplies Or Services And Prices/Costs

ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE

0001 Base Period

Data Collation and Integraton for Public Health Event Responses (DCIPHER)

FIRM FIXED PRICE

DCIPHER for Ebola Event Response Platform in accordance with (IAW) Performance Work Statement (PWS) Paragraphs C.2.1 through C.2.10.

Period of Performance: 12 Months

1 Job

0002 Software License Fee and Training

FIRM FIXED PRICE

1 Each

0003 Server and Operating Software

FIRM FIXED PRICE

The Server and Operating Software for this requirement shall be IAW Section C, Paragraph C.1.4.2.17.

0004 Other Direct Costs (ODC)

COST REIMBURSEMENT

ODC for this requirement shall be IAW Section C, Paragraph C.2.11.

1 Job NOT TO EXCEED:

0005 Travel

COST REIMBURSEMENT

Travel for this requirement shall be IAW Section C, Paragraph C.2.12.

1001 Option Period 1

Annual Operation and Maintenance

FIRM FIXED PRICE

Annual Operation and Maintenance for Contract Line Item Numbers (CLINs) 0001 and 0002 of the DCIPHER for Ebola Event Response Platform developed in the Base Period IAW PWS Paragraphs C.2.13 and C.2.14.

2001 Option Period 2

Annual Operation and Maintenance for CLINs 0001 and 0002 of the DCIPHER for Ebola Event Response Platform developed in the Base Period and as updated in Option Period 1 IAW PWS Paragragh C.2.13 and C.2.14.

3001 DCIPHER Module A

FIRM FIXED PRICE

DCIPHER for Module A Platform IAW PWS Paragraphs C.2.1 through C.2.10.

Period of Performance: To be determined

3002 Software License Fee and Training for Module A

3003 Server and Operating Software for

Module A

The Server and Opeating Software for this requirement shall be IAW Section C, 3004 Other Direct Costs

ODC for this requirement shall be IAW Section C, Paragraph C.2.11.

3005 Travel

Travel for this requirement shall be IAW Section C, Paragraph C.2.12.

4001 Annual Operation and Maintenance Module A

FIRM FIXED PRICE

Annual Operation and Maintenance for the DCIPHER for the Module Response Platform developed in CLINs 3001 and 3002 IAW PWS Paragraphs C.2.13 and C.2.14.

Period of Performance: To be determined

1 Job

5001 Annual Operation and Maintenance Module A

FIRM FIXED PRICE

Annual Operation and Maintenance for DCIPHER for Module A Event Response Platform developed in CLIN 3001 and 3002 and updated in CLIN 4001 IAW PWS Paragraphs C.2.13 and C.2.14.

Period of Performance: 12 Months after Exercising CLIN 4001

6001 DCIPHER Module B

FIRM FIXED PRICE

DCIPHER for Module B Platform IAW PWS Paragraphs C.2.1 through C.2.10.

6002 Software License Fee and Training for Module B

6003 Server and Operating Software for Module B

FIRM FIXED PRICE

The Server and Operating Software for this requirement shall be IAW PWS

6004 Other Direct Costs

ODC for this requirement shall be IAW PWS Paragraph C.2.11.

6005 Travel

COST REIMBURSEMENT

Travel for this requirement shall be IAW PWS Paragraph C.2.12.

Period of Performance: To be determined

1 Job

7001 Annual Operation and Mantenance for Module B

FIRM FIXED PRICE

Annual Operation and Maintenance for DCIPHER for Module B Platform developed in CLINs 6001 and 6002 IAW PWS Paragraphs C.2.13 and C.2.14.

Period of Performance: 12 Months after exercising CLIN 6001

8001 Annual Operation and Maintenance for

Module B

FIRM FIXED PRICE

Annual Operation and Maintenance for DCIPHER for Module B developed in CLINs 6001 and 6002 and updated in

CLIN 7001.

Period of Performance: 12 Months after exercising CLIN 7001

There are no clauses/provisions included in this section.

Section C - Description/Specification/Work Statement

PERFORMANCE WORK STATEMENT

Data Collation and Integration for Public Health Module Responses (DCIPHER) for Ebola Event Response Platform

C.1. GENERAL

C.1.1. BACKGROUND.

C.1.1.1. CDC plays a critical role in the detection, response, and recovery during public health emergencies, infectious disease outbreaks, and public health surveillance. Management of such Modules and effective allocation of medical countermeasures require situational awareness of disease risk, validated analytics, pathogen characteristics, spread, and impacts to society and critical infrastructure. During large-scale Modules, CDC is required to make rapid public health decisions based on multiple data sources (e.g., laboratory, epidemiological, resources, population characteristics, situational awareness, etc.), and needs to rapidly collate, analyze and share these data with internal and external partners.

C.1.1.2. Currently data integration, analysis, visualization, data and staff management, and reporting for the CDC’s mission critical response effort for the ongoing outbreak of Ebola virus disease are being done in several different spreadsheets and databases, using several different tools and applications. Data processes and workflows are still largely manual, labor-intensive, time-consuming, and are not standardized. CDC requires an integrated approach and technical solution to manage epidemiological, laboratory, contact tracing and other related information to support the Ebola response.

C.1.2. OBJECTIVES.

This project addresses the CDC’s urgent need for a rapidly deployable web-based IT platform that can integrate, manage, analyze, visualize, report on and share epidemiological, laboratory, mortality, contact tracing, travelers screening, and other data related to support public health response activities during Ebola or other viral hemorrhagic fever Modules in the United States and abroad. This platform will be conceptualized and designed with the intent to expand beyond Ebola to other public health Module responses and other surveillance activities, and be adopted as an all-hazards platform. The project will support the following objectives for data integration, management, analysis, visualization, and sharing:

C.1.2.1. Collate and integrate critical epidemiological, laboratory, and contact tracing information, as well as other known and ad hoc data collections and systems using a platform designed with standardized processes.

C.1.2.2. Provide role-based access to data.

C.1.2.3. Create a web-based platform that facilitates stakeholder collaboration and allows secure realtime data sharing among state, local and other federal partners.

C.1.2.4. Develop a data management platform that is:

C.1.2.4.1. In compliance with CDC security requirements;

C.1.2.4.2. Driven by analytic requirements;

C.1.2.4.3. Scalable;

C.1.2.4.4. Adaptable to other public health activities beyond Ebola; and

C.1.2.4.5. Interoperable with existing IT systems.

C.1.2.5. Create a flexible and powerful analytic interface.

C.1.2.6. Develop user-friendly visualization tools to appropriately display data to support Module response activities.

C.1.3. INTEGRATION WITH OTHER CONTRACTOR STAFF.

The contractor shall work in conjunction with a mix of contractors from various companies and Full Time Equivalents (FTEs) to implement a data integration platform that facilitates data visualizations and sharing. This will be required through the entire software development lifecycle to design, implement, test, and deploy the software using the most appropriate resources available.

C.1.4. SCOPE OF WORK.

C.1.4.1. The Contractor shall provide a commercial off the shelf (COTS) product and related support services for the management and implementation of the DCIPHER platform to support the above objectives. The Contractor shall provide a structured method for documenting detailed workflows and process flows to support CDC’s ongoing response to the Ebola virus outbreak. The purpose is to implement the existing data model and platform requirements, as well as define, model, and document other complex public health, laboratory and administrative business processes needed to support the Ebola response and translate them into additional platform requirements to be implemented in the DCIPHER platform.

C.1.4.2. The following elements are required for this project:

C.1.4.2.1. Integration of information and disparate data sets from multiple user groups needed to support the ongoing Ebola response (refer to Task 2, Sub-Task 1 for list).

C.1.4.2.2. All hazards data management inclusive of scientific and non-scientific data (e.g., risk communications and messaging, logistics and resource management, and records management).

C.1.4.2.3. Interoperability with other internal and external systems, applications, and tools.

C.1.4.2.4. Working with CDC staff to set standards for integrated data elements.

C.1.4.2.5. Integration of legacy, existing, and future analytic applications and datasets.

C.1.4.2.6. Working with CDC and contractor staff and stakeholders to develop business process mapping artifacts, including As-is and To-be business process modeling, data modeling (conceptual, logical, and physical), object models, architecture, and fit/gap analyses.

C.1.4.2.7. Elicitation and documentation of processes from CDC programs and staff.

C.1.4.2.8. Development of appropriate use cases that support stakeholder workflows.

C.1.4.2.9. Implementation of reusable workflows in the platform.

C.1.4.2.10. Development and automation of processes and linkages that reduce the need for manual manipulation of data.

C.1.4.2.11. Provision and management of dedicated platform software (i.e., this will not be shared across another project), including patches and updates to include the following environment: production, staging, test, development, and disaster recovery.

C.1.4.2.12. Management of the technical development of the platform.

C.1.4.2.13. Provision of operational support services (support staff, engineers, etc.) for users during the entire period of performance.

C.1.4.2.14. Development of graphics and/or mockups and user interface.

C.1.4.2.15. Development/Configuration of data analysis and visualization to support reporting.

C.1.4.2.16. Training of administrators, superusers, and end users on the platform.

C.1.4.2.17. Provision and management of dedicated CDC-compatible physical server hardware (i.e., vendor supplies physical servers that will not be shared across another project) to include the following environments: production, staging, test, development, and disaster recovery and software needed to support DCIPHER, including provision of, patches and updates to server software.

C.1.4.2.18. Utilization of an Agile or similar approach with iterative design input cycles from stakeholders and users.

C.1.4.2.19. Planning and support for Continuity of Operations for platform and all data residing in the platform.

C.1.4.2.20. Surge operations necessary to quickly and effectively support the current or related emergency responses (e.g., a resurgence of infected individuals, or additional infected individuals in the US).

C.1.4.3. DCIPHER will support the following agency goals:

C.1.4.3.1. Enhance the accountability, resource use, workforce and innovation for surveillance at CDC and in support of State, Tribal, Local and Territorial agencies.

C.1.4.3.2. Accelerate the utilization of emerging tools and approaches to improve the availability, quality, and timeliness of surveillance data.

C.1.4.3.3. Through cross-cutting agency initiatives, improve surveillance by addressing data availability, system usability, redundancies, and incorporation of new information technologies in major systems or activities.

C.2. TASKS

Platform functional and non-functional requirements are attached as Appendix A as foundational requirements and support for the below tasks and sub-tasks.

C.2.1. DATA COLLATION. Collate and organize all data as they are ingested into the system.

C.2.1.1. Sub-Task 1: Assemble and order all information coming into the system.

C.2.1.2. Sub-Task 2: Tag or assign metadata to each incoming piece of information such that data can be sorted, searched and queried, and each piece of information’s lineage and system of origin can be traced.

C.2.2. DATA INTEGRATION. Provide ingestion, integration and data linkages (where linking variables are available) in the platform.

C.2.2.1. Sub-Task 1: Ingest, integrate and link the data streams listed below, as well as other known and unknown or ad hoc data both directly (i.e., uploading files or manual data entry) or via third party applications. These data streams will be in varying formats, including spreadsheets, databases, structured and semi-structured, questionnaires, maps, Adobe Acrobat PDF files, images and emails. The data themselves will vary, ranging from raw, uncleaned data, to refined output from other applications and tools, to summary/aggregate data. All data must be ingested and linked where possible, and overlaid where linkages are not possible (e.g., burial data and Ebola Treatment Units

(ETU’s) plotted on the same map as Ebola cases and contacts of Ebola cases). Data sources include (but are not limited to):

C.2.2.1.1. Situation Reports from Ebola-affected countries, including cases, deaths, and health care worker information

C.2.2.1.2. Contact tracing data from the Epi Info Viral Hemorrhagic Fever system

C.2.2.1.3. Burial survey and mortuary data, including location and capacity

C.2.2.1.4. International Ebola Treatment Units, including location, status, and bed availability

C.2.2.1.5. Travelers screening data, including active monitoring of returning and domestic travelers from Ebola-affected countries, and Do Not Board lists

C.2.2.1.6. Travel Notification via the Epidemic Information Exchange (Epi-X), which is the system by which one jurisdiction transfers the active monitoring of a traveler or an epidemiological case (i.e., an Ebola patient) to a second jurisdiction

C.2.2.1.7. Domestic Ebola assessment hospitals and treatment facilities, including location and capacity

C.2.2.1.8. Pathogen sequencing data, including metadata, from internal CDC laboratories and from the National Center for Biotechnology Information

C.2.2.1.9. Emergency Operations Center (EOC) staffing and personnel deployment

C.2.2.1.10. CDC partner deployments (e.g., World Health Organization, Doctors Without Borders)

C.2.2.1.11. Logistics, including supplies, air ambulance, biocontainment, patient care coordination, and emergency travel for returning staff

C.2.2.1.12. Medical countermeasures, including vaccine deployment from the strategic national stockpile

C.2.2.1.13. Security information, including security for individuals and the platform

C.2.2.1.14. Other data as needed to manage the current response

C.2.2.2. Sub-Task 2: Link data by multiple user-defined key data fields.

C.2.2.3. Sub-Task 3: Link unstructured data to any other data field.

C.2.2.4. Sub-Task 4: Develop a translational data map template for non-technical users to assign or reassign revised/new data to existing data fields, e.g., ingesting a new laboratory report with non-standardized formats and mapping those data fields to the standardized data fields in use within the platform. Once the manual data linkage is complete, metadata about that linkage should be recorded in the same way as any other piece of information’s lineage and system of origin is recorded (e.g., that this was a manual link, the user’s name, date, and time stamp, etc.).

C.2.2.5. Sub-Task 5: Automatically propagate revised or new data across the platform in real time.

C.2.3. DATA ANALYSIS AND VISUALIZATION. Provide search and query capabilities, configurable user interfaces for the various areas/modules of the platform, the graphical user interfaces (GUI’s) itemized below (Sub- Task 3), and analysis and visualizations on-the-fly:

C.2.3.1. Sub-Task 1: A single common landing page for all users of the system that provides access to all applications, data sources and dashboards that the user is authorized to access.

C.2.3.2. Sub-Task 2: A line list editor for epidemiological cases that includes epidemiological, laboratory, and clinical information, and that can be modified by users as needed to include additional information.

C.2.3.3. Sub-Task 3:

C.2.3.3.1. A GUI that allows data entry, editing and display for the following functions:

C.2.3.3.1.1. Epidemiological case management;

C.2.3.3.1.2. EOC staffing and personnel deployment management;

C.2.3.3.1.3. Domestic Ebola assessment hospitals and treatment facilities;

C.2.3.3.1.4. Active monitoring of travelers coming into the US from Ebola-affected countries, including where the traveler went, when/how he/she came into the US, basic clinical information about the traveler (e.g., signs and symptoms), illness status, and laboratory information for those who become ill.

C.2.3.3.2. All of the GUI’s developed for this platform must meet the needs unique to Ebola (e.g., ETU location and status) while also being adaptable/reusable for future Modules.

C.2.3.4. Sub-Task 4: Search capabilities based on Boolean operators (<, >, =, etc.) or similar search logic and fuzzy matching that can be run against all data in the platform and all data names (e.g., database name, common name, aliases, labels, etc.).

C.2.3.5. Sub-Task 5: Group, multi-layer sort, and rearrange search and query results/output.

C.2.3.6. Sub-Task 6: Displays of data in multiple formats (geospatial, temporal, time series, etc.) using interactive visualizations.

C.2.3.7. Sub-Task 7: Descriptive, exploratory and basic univariate statistics for structured data.

C.2.3.8. Sub-Task 8: Word or tag clouds, lists/clusters of topics and other unstructured text analytics, e.g., what word or topic clusters are trending.

C.2.3.9. Sub-Task 9: Dendrograms/phylogenetic trees showing alignment (the genetic distances between whole genome sequences or snippets of sequences) that is based on user-defined thresholds and/or algorithms, and other hierarchical clustering techniques which would yield data on relatedness of sequencing data.

C.2.3.10. Sub-Task 10: Display, manipulate, and store manipulated dendrogram trees, including naming or assigning/linking existing data to “leaves”, e.g., map epidemiological variables onto leaves or trees.

C.2.3.11. Sub-Task 11: Subset data based on trees, e.g., be able to select a clade of the tree and pull all data from that clade for additional analysis.

C.2.3.12. Sub-Task 12: Assign and perform analysis based on genotypic features, e.g., character or binary data, such as the presence/absence/type of antibiotic resistance genes present in an organism.

C.2.3.13. Sub-Task 13: Conduct other genetic sequence data analyses, including basic multiple sequence alignment, sequence similarity searches, sequence mapping (output formats such as SAM/BAM, FASTA), variant files (VCF format), and the processing of phylogenetic trees (NWK format) and distance matrices.

C.2.3.14. Sub-Task 14: Display and manipulate genetic and protein sequence datasets, including features and relevant metadata (GBK, ASN.1 formats).

C.2.4. DATA MANAGEMENT. DCIPHER will be the system of record for some programs such that robust data management functions are needed for all variables and data in the platform. Provide the following data management capabilities:

C.2.4.1. Sub-Task 1: Ability for CDC to control access to the data via user groups with roles and rights, including creation/inactivation of user accounts and resetting of passwords.

C.2.4.2. Sub-Task 2: Ability to create a new “event” within the system that has its own set of users with roles and rights distinct from other events (e.g., each outbreak would be its own event and have a different set of users with roles and rights that are different than previous outbreaks or other activities occurring simultaneously).

C.2.4.3. Sub-Task 3: Ability to relate or link multiple events to one another, for example, when initially separate events are found to have commonality that makes it necessary to manage them together.

C.2.4.4. Sub-Task 4: Implementation of a core relational database model that can be leveraged by all programs, events, and workflows.

C.2.4.5. Sub-Task 5: Ability to link and overlay data not imposed within a relational data model.

C.2.4.6. Sub-Task 6: Manipulate and edit any data values and fields, such as modifying pick lists and updating data values to reflect new information as part of the “off the shelf” functionality (i.e., DCIPHER will be the primary source system and data will need to be updated within DCIPHER regularly).

C.2.4.7. Sub-Task 7: Delete data, such as erasing erroneous data values that were previously entered.

C.2.4.8. Sub-Task 8: Create and store distance matrix and dendrogram tree files based on alignment/distances between sequences.

C.2.4.9. Sub-Task 9: Ability to undo or revert back data manipulations via a logging interface that allows a user to select a modification to previous versions.

C.2.4.10. Sub-Task 10: Ability to trace back lineage and pedigree of all changes made to every piece of information in the platform.

C.2.4.11. Sub-Task 11: Customize and configure displays and dashboards to support critical functions.

C.2.4.12. Sub-Task 12: Ability to onboard external users via Secure Access Management Services (SAMS) and directly creating external users and assigning them to editable user groups that govern their access and rights (i.e., not via an authentication protocol such as CDC’s Lightweight Directory Access Protocol).

C.2.4.13. Sub-Task 13: Adhere to established data standards, including industry standard messaging (Public Health Information Network Messaging Standard/PHIN MS, HL7, and other XML payloads) and vocabularies (SNOMED, LOINC, ICD, PHIN Vocabulary Access and Distribution System/VADS, etc.).

C.2.5. DATA SHARING. Provide the following capabilities to share, report on and export data:

C.2.5.1. Sub-Task 1: Extract data into common data file types (e.g., MS Excel, XML, etc.).

C.2.5.2. Sub-Task 2: Extract data into statistical data file types (e.g. SAS, SPSS, Epi Info).

C.2.5.3. Sub-Task 3: Export all data in all data streams and all data types.

C.2.5.4. Sub-Task 4: Create reusable, standardized reports as needed for the data streams listed in Task 2. Data Integration Sub-Task 1, including analyses and visualizations, into multiple report formats (e.g., MS Excel, MS Word, MS PowerPoint, etc.).

C.2.5.5. Sub-Task 5: Transmit data to other EOC and related applications (e.g., Red Sky, http://www.cdc.gov/phpr/science/documents/Red-Sky-New-Tool-for-Health-Threats-6272014.pdf).

C.2.6. DEVELOP BUSINESS PROCESS WORKFLOWS IN THE PLATFORM. Develop and implement reusable, standardized workflows based on Current-State and Future-State business processes in the EOC and other CDC programs to support data streams listed in Task 2. Data Integration Sub-Task 1.

C.2.6.1. Sub-Task 1: Develop workflows needed to support the outbreak and surveillance activities associated with CDC’s ongoing Ebola response operations. How many and which activities and data streams will require workflows will be decided based on discussion between CDC and the Contractor.

C.2.6.2. Sub-Task 2: Develop workflows to support the management of epidemiological cases, contacts, laboratory information and other related data, such that one individual can be followed across all relevant data streams.

C.2.6.3. Sub-Task 3: Develop workflows to support other data transport, collection, linking, visualizing and analysis, as determined via discussion between CDC and the Contractor.

C.2.7. AUTOMATION OF DATA PROCESSES. Automate data-related processes to replace existing manual process and alleviate the need for manual processes in the future. Processes that need automation include the creation of new databases to support new events, concatenation or aggregation of data, linking of data sets that originate from different sources, extraction of data to support analyses, and creation of reports.

C.2.7.1. Sub-Task 1: Automate the data-related processes and workflows wherever possible that will allow reuse by other CDC programs in order to maximize the utility of the product and its use by various CDC staff.

C.2.7.2. Sub-Task 2: Once reusable workflows have been identified and developed, provide these workflows as common templates (e.g., infectious disease outbreak, environmental disaster, infectious disease surveillance, chronic disease surveillance, etc.) as a starting point for other users to modify on their own.

C.2.8. SYSTEM ARCHITECTURE AND PERFORMANCE. The system must:

C.2.8.1. Sub-Task 1: Run in a CDC-compatible web browser that does not require software installation on any device and is compatible with the previous two versions of the browser, including Microsoft Internet Explorer, Microsoft Edge, Mozilla Firefox, Google Chrome and Apple Safari.

C.2.8.2. Sub-Task 2: Support stand-alone configuration on which to run a client as a separate, disconnected unit, with auto-sync enabled once re-connected to a network.

C.2.8.3. Sub-Task 3: Be able to scale horizontally to quickly accommodate an increase in number of users and data sources and sizes.

C.2.8.4. Sub-Task 4: Send and consume data via web services (Service-Oriented Architecture/SOA).

C.2.8.5. Sub-Task 5: Implement SOA to deliver platform functions (e.g., data ingestion, visualization, and export) as a “service” with a Representational State Transfer (REST) and Web Services Description Language (WSDL) to provide server-to-server interface via the web.

C.2.8.6. Sub-Task 6: Embed or integrate external third party Application Program Interfaces (APIs) as needed to support ingestion of data and other functionality (e.g., specialized mapping tools, mathematical modeling and forecasting software, etc.).

C.2.8.7. Sub-Task 7: Meet Section 508 accessibility compliance requirements.

C.2.8.8. Sub-Tasks 8: Implement WebGL APIs to enable 3D and 2D dynamic graphics.

C.2.8.9. Sub-Task 9: Meet the response time requirements for system operations and importing/exporting data (see requirements in Appendix A).

C.2.8.10. Sub-Task 10: Be able to scale up data volume to at least two (2) terabytes without response delays or performance issues.

C.2.8.11. Sub-Task 11: Have one single user interface across all applications available within the platform with a single sign-on.

C.2.9. PLATFORM AND DATA SECURITY. Provide security for the system and data that meets CDC and other federal requirements (e.g., HHSAR 352.239-72 (c) (4) (i)) as described in Section H, Special Contract Requirements.

C.2.9.1. Sub-Task 1: Restrict each user’s access to information based on data tagging that he/she is cleared to access down to the data field level, as well as to modules of the platform that the user is authorized to access (e.g., only the dashboard and reports).

C.2.9.2. Sub-Task 2: Encrypt data in-transit and while at rest, as required.

C.2.9.3. Sub-Task 3: Provide platform, network and other information towards the completion of CDC IT security’s Certification and Accreditation process and documentation.

C.2.10. DESIGN, DEVELOP AND DEPLOY SYSTEM. All of the work outlined in the previous tasks must support and enable the design, development and deployment of DCIPHER.

C.2.10.1. Sub-Task 1: Carry out the activities described in this contract using an Agile or similar incremental, iterative design-develop-deploy approach.

C.2.10.2. Sub-Task 2: Develop DCIPHER, workflows, use cases, GUI’s and other views to meet the Priority Level 1 and 2 requirements outlined in Attachment 3, Appendix A.

C.2.10.3. Sub-Task 3: Deploy a platform that meets the needs of the CDC users onboarded onto DCIPHER.

C.2.10.4. Sub-Task 4: Support services. The Contractor shall provide services to maintain the equipment and software in good working order, keeping it free from material defects so that the equipment and software shall function properly and in accordance with the accepted level of performance. The Contractor shall provide services in all phases of DCIPHER software development lifecycle (planning, requirements, development, testing, and deployment).

C.2.11. OTHER DIRECT COSTS (ODC).

C.2.11.1. The contractor shall obtain preauthorization from the COR or contracting officer for any expenditure less than $1,000 under ODCs but shall obtain COR and contracting officer for any expenditure greater than $1,000 under ODCs. Each request shall include a detailed description of all anticipated services, materials and/or supplies. The COR and/or contracting officer will authorize a ceiling amount not to be exceeded. The contractor shall obtain competitive offers for each expenditure in order to obtain the best value for the Government. Reimbursement of expenditures for ODCs will be contingent solely on proper authorizations. If prior approval is not obtained, the contractor may not be reimbursed.

C.2.11.2. All materials purchased by the contractor for use or on behalf of the Government will become the property of the Government. The contractor shall document the transfer of material. The contractor shall provide an accounting of all materials consumed during the performance of individual elements of the contract.

C.2.12. TRAVEL.

C.2.12.1. The Contractor shall travel to CDC a minimum of six (6) times (2-3 people for 3-5 days) within the period of performance in order to carry out software implementation activities and provide on-going support services.

C.2.12.2. All travel requirements shall be pre-approved by the government including plans, agenda, itinerary, or dates. Costs for travel shall be billed in accordance with the regulatory implementation of Public Law 99-234 and FAR 31.205-46 Travel Costs and in accordance with Federal Travel Regulation and Joint Travel Regulations.

C.2.12.3. Travel requirements under this contract shall be met using the most economical form of transportation available. All travel shall be reimbursed at cost.

C.2.13. TECHNICAL SUPPORT SERVICES.

C.2.13.1. Sub-Task 1: Support services. The Contractor shall provide services to maintain the equipment and software in good working order, keeping it free from material defects so that the equipment and software shall function properly and in accordance with the accepted level of performance. The Contractor shall provide services in all phases of DCIPHER software development lifecycle (planning, requirements, development, testing, deployment and project management). The Contractor shall use commercially reasonable efforts to provide corrections or work-arounds for any errors reported and determined to be in the equipment or software. The Contractor shall also provide its own offices, computers, phones and equipment for contractors to work offsite.

C.2.13.2. Sub-Task 2: Service Response. The contractor shall make available to the client contact information for requesting service of the hardware, software or documentation. The client must be able to request services during normal business hours. Extended coverage may be required in the case of an emergency such as a public health event or critical system failure.

C.2.13.3. Sub-Task 3: Emergency Support. The Contractor shall also provide its own offices, computers, phones and equipment for contractors to work remotely, particularly in case of an emergency. The DCIPHER Continuity of Operations Plan documents the requirements and is designed to: ensure personnel accountability throughout the duration of an emergency; ensure operational capability within hours of a disruption; and establish reliable processes and procedures to acquire resources necessary to continue essential functions and sustain operations for up to 30 days. The plan also addresses requirements of Emergency Response and Management, Information Technology, Disaster Recovery, the Occupant Emergency Program (OEP), and is consistent with all other general emergency and crisis management plans and procedures set forth by the Department of Health and Human Services (HHS). The storage location of backup data will be decided after discussion between CDC and the Contractor.

C.2.13.4. Sub-Task 4: Platform software updates. The Contractor shall provide services to maintain the platform software, including patches and updates in all phases of DCIPHER software development lifecycle (planning, requirements, development, testing, and deployment) and to all environments (production, staging, test, development, and disaster recovery).

C.2.14. TRAINING AND MAINTENANCE AND OPERATIONS. Provide platform and user training during and after deployment.

C.2.14.1. Sub-Task 1: Provide end-user training on system functions and use.

C.2.14.2. Sub-Task 2: Provide training for CDC system administrators to perform routine administrative tasks and support; e.g., creating a new user account, resetting passwords, generating user reports.

C.2.14.3. Sub-Task 3: Backup data, update and patch system and servers as needed.

C.3. SCHEDULE OF DELIVERABLES AND MILESTONES

Deliverable/Milestone Frequency Date Format Deliver To

Kickoff meeting One-Time Within 10 days of award

N/A DCIPHER

leadership

Kickoff meeting minutes

One-Time Within 2 business days of the kickoff meeting

Electronic via Microsoft Office Suite

Contracting Officer’s Representative

(COR)

Project Plan and timelines

One-Time NLT 30 days after Kickoff meeting

Electronic via Microsoft Office Suite

COR

Risk Management Plan One-Time NLT 30 days after Kickoff meeting

Electronic via Microsoft Office Suite

COR

Summary Status Report Monthly 1st of the month, beginning NLT 30 days after contract award

Electronic Microsoft Office Suite

COR

Status meeting Bi-monthly 1st and 15th of the month

Teleconference or in-person

DCIPHER

leadership

Initial deployment of platform

One-Time NLT 30 days after Kickoff meeting

Electronic End users

Design documents As needed 1st set of documents within 60 days after kickoff meeting

Electronic via Microsoft Office Suite

COR

User Acceptance Plan (including performance measures)

Once per workflow 1st one NLT 90 days after Kickoff meeting

Electronic Microsoft Office Suite

COR

User Acceptance Summary Report

Once per implemented workflow

NLT 15 days after completion of User Acceptance Testing of each workflow

Electronic Microsoft Office Suite

COR

C&A supporting documentation

As needed 1st set of documents within 30 days after kickoff meeting

Electronic via format dictated by respective documents (Microsoft Word, Adobe Acrobat PDF, etc.)

COR

An Open Issue and Resolution Log

Bi-monthly 1st and 15th of the month

Electronic Microsoft Office Suite

COR

Earned Value Management Report

Monthly The end of each month

Electronic Microsoft Office Suite

COR

Audit report for CDC-selected data subset that shows all changes made

Twice during the period of performance

180 days after award, and 360 days after award

Electronic Microsoft Office Suite

COR

to the data, its sourcing, and how it has been accessed and used over time

Translational data map for ingesting new data and mapping to existing variables

A core data map, then once per workflow (e.g., outbreak, surveillance, etc.)

180 days after award, updates within 60 days of each workflow implementation

Electronic Microsoft Office Suite, Acrobat Adobe, or Microsoft Visio

COR

Compare a genetic sequence alignment analyzed in the platform to a known alignment processed outside of the platform

As needed 1st comparison NLT 60 days after completion of sequence alignment analysis capability

Electronic in

DCIPHER,

electronic comparison report in MS Office Suite

COR

Demonstrate that the platform identifies errors in CDC-selected fields

One-Time 180 days after award

Electronic in

DCIPHER

COR

Demonstrate linkage of datasets with common fields for linked records

One-Time 180 days after award

Electronic in

DCIPHER

COR

Data Dictionary A core data dictionary, then once per workflow

NLT 120 days after award, then within 30 days of each workflow implementation

Electronic via Microsoft Office Suite

COR

List of CDC administrative procedures

Once per workflow NLT 90 days after award, then within 30 days of each workflow implementation

Electronic via Microsoft Office Suite

DCIPHER

leadership

List of users with their respective roles, rights, and permissions

Once per workflow, and on demand

90 days after award, then within 30 days of each workflow implementation

Electronic via Microsoft Office Suite

DCIPHER

leadership

Visualization of data model implemented in platform

Once per workflow 210 days after award, then within 45 days of each workflow implementation

Demonstration DCIPHER leadership

Two standard (“canned”) reports

Once per workflow 210 days after award, NLT 45 days after each workflow is in production

Printed in Microsoft Word

COR

Diagram representation of high-level business

Once per workflow (e.g., outbreak, NLT 30 days after each workflow is in

Electronic via COR process workflows as implemented in

DCIPHER

surveillance, etc.) production Microsoft Visio

Graphical representation of server and network configuration that includes process for scalability

One-Time NLT 90 days after Kickoff meeting

Electronic via Microsoft Office Suite

COR

Pass CDC’s Section 508 compliance review (or complete exemption)

One-Time 240 days after award

Electronic via Microsoft Office Suite

COR

Documentation of platform response time for search/query function, and for data import using CDC-provided test database

One-Time 180 days after award

Electronic via Microsoft Office Suite

COR

Pass CDC’s IT security Certification and Accreditation

One-Time NLT 180 days after award

Electronic via Microsoft Office Suite

COR

Training materials for end users and CDC administrators

As Needed Within 1 week of 1st training session for each group (end users and CDC administrators)

Electronic via Microsoft Office Suite

COR

Final platform review and sign-off all stakeholders

One-Time End of first year In person DCIPHER leadership

C.4. PERFORMANCE MATRIX

Performance

Measure Number

Desired Outcomes

Required Services

SLA

Performance

Standard (completeness, cost, reliability, accuracy, timeliness, quality)

Acceptable Quality

Level (AQL) Monitoring

Method (Quality

Assurance Surveillance Plan/QASP)

Incentives/ Disincentives

1 Audit capability that shows all changes made to data, their sourcing, and how they have been accessed and used over time

Perform software configuration

All capabilities will be implemented based on requirements

100% Observation, analysis, review of monthly status report

Favorable or Unfavorable Performance Evaluation

2 Flexible and user-friendly data analysis and visualization capabilities

Perform software configuration

All capabilities will be implemented based on requirements

100% Observation, analysis

Favorable or Unfavorable Performance Evaluation

3 User interface to enter, edit and manage epidemiological case and other data

Perform software configuration

All capabilities will be implemented based on requirements

100% Observation Favorable or Unfavorable Performance Evaluation

4 Ability to interoperate with other CDC applications (e.g., Red Sky)

Perform software configuration

All capabilities will be implemented based on requirements

100% Observation, analysis, review of monthly status report

Favorable or Unfavorable Performance Evaluation

5 Implement workflows in the platform

Perform planning, requirements, development, testing, and deployment necessary to implement a workflow in the platform

All implementations and deliverables will be achieved within agreed-upon schedule between the COR and Project Lead.

All schedules variances for high level estimates across multiple phases of the project must be within +/- 25% 85% of the time.

Review of monthly status report, performance metrics and quarterly program reviews.

Favorable or Unfavorable

Evaluation

Number

Desired Outcomes

Required Services

SLA

Performance

Standard (completeness, cost, reliability, accuracy, timeliness, quality)

Acceptable Quality

Level (AQL) Monitoring

Method (Quality

Assurance Surveillance Plan/QASP)

Incentives/ Disincentives

6 Platform in use by EOC

Perform planning, requirements, development, testing, and deployment

All capabilities will be implemented based on requirements

≥80% of functionality is operational within 30 days of Kickoff meeting

Observation, analysis, review of monthly status report

Favorable or Unfavorable Performance Evaluation

7 Ability to perform accurate genetic alignment analysis

Perform planning, requirements, development, testing, and deployment necessary to perform genetic distance (alignment) analysis with CDC-defined algorithm

Perform Rand or Wallace, or similar test statistic

95% sequence identity and 100% agreement in the topology of the resulting phylogenetic tree

Written comparison report

Favorable or Unfavorable Performance Evaluation

8 The platform identifies data errors

Perform software configuration to support data validation checks for key fields (e.g., record identification and linking fields)

Perform data validation checks in the platform that identify data errors in a synthetic (i.e., realistic but not real) dataset against the known errors in the synthetic dataset

Identify ≥95% of errors in key fields

Electronic report Favorable or Unfavorable Performance Evaluation

9 Ability to link datasets with fields in common

Perform software configuration

All capabilities will be implemented based on requirements

≥95% of records linked; 100% of unlinked records marked for manual review

Electronic report Favorable or Unfavorable Performance Evaluation

10 (also see Appendix A for architecture requirements)

The platform meets CDC architecture requirements

Perform software design and platform architecture to support

DCIPHER

Must comply with all CDC and

HHS IT

standards, which includes Enterprise Architecture

100% Observation, Analysis

Favorable or Unfavorable

Number

Desired Outcomes

Required Services

SLA

Performance

Standard (completeness, cost, reliability, accuracy, timeliness, quality)

Acceptable Quality

Level (AQL) Monitoring

Method (Quality

Assurance Surveillance Plan/QASP)

Incentives/ Disincentives

11 Fast platform response time

Perform performance testing

Must comply with platform performance requirements

< 5 seconds (search/query , application)

< 60 seconds (data exports)

Performance test:

Tresponse=n/r – Tthink, where n=100 concurrent users (max) r=# requests per second the server receives

Tthink=avg think time (seconds)

Favorable or Unfavorable Performance Evaluation

12 (also see Appendix A for architecture requirements)

The platform meets CDC platform and data security requirements

Perform software design and platform architecture

Must comply with all CDC and HHS IT data and messaging standards (PHIN, SNOMED, LOINC, HL7)

100% Observation, Analysis

Favorable or Unfavorable Performance Evaluation

13 Trained end users and platform administrators

Perform user training

Must provide training to the following staff:

Minimum 15 trained end users

Minimum 2 trained platform administrators

100% Observation Favorable or Unfavorable Performance Evaluation

14 Maintain operations

Perform corrective maintenance on platform hardware

Mission-critical site hardware: 5 days x 8 hours (site time), <4 hours response;

next business day restore Non-mission-critical hardware: 5 days x 8 hours, next business day response and restore

99% of the time

Observation, Analysis

Favorable or Unfavorable Performance Evaluation

15 Software Development and Configuration

Perform coding changes to platform

All implementations, change requests and platform modifications will be achieved within agreed-upon schedule

All schedules variances must be within +- 10% 85% of the time.

Review of weekly status report, review of monthly status report

Favorable or Unfavorable

Number

Desired Outcomes

Required Services

SLA

Performance

Standard (completeness, cost, reliability, accuracy, timeliness, quality)

Acceptable Quality

Level (AQL) Monitoring

Method (Quality

Assurance Surveillance Plan/QASP)

Incentives/ Disincentives between the COR and Project Lead.

16 Platform development /Configuration

Perform

DCIPHER

modifications

All modifications to DCIPHER should not require more than 2 retests.

The number of retests shall not exceed 2.

Review of weekly status report, review of monthly status report

Favorable or Unfavorable

Evaluation.

17 Platform Deployment

Perform software development testing

There should be no more than 1% critical/showstop pers released into production.

Total number of critical/show stopper defects identified in production should not exceed 1% of the total defects

Review of weekly status report, review of monthly status report

Favorable or Unfavorable

Corrective Action Preventive Action Plan

(CAPA)

required.

18 Customer satisfaction

Provide good customer service

After a workflow is implemented, a customer satisfaction survey will be performed and a rating assigned must have a 85% Approval rating

Review of customer satisfaction survey

Favorable or Unfavorable Performance Evaluation

19 Annual customer feedback

Provide good customer service

An annual customer feedback survey will be performed and a rating assigned must have a 85% Approval rating

Review of annual customer feedback survey

Favorable or Unfavorable Performance Evaluation

20 Project IT deliverables / processes

Provide IT deliverables that meet project standards

Must comply with all agreed up project procedures, and IT standards and guidance including software usability, process mapping, testing

All requirements must be met.

Review of project deliverables

Favorable or Unfavorable

Number

Desired Outcomes

Required Services

SLA

Performance

Standard (completeness, cost, reliability, accuracy, timeliness, quality)

Acceptable Quality

Level (AQL) Monitoring

Method (Quality

Assurance Surveillance Plan/QASP)

Incentives/ Disincentives procedures, documentation and formatting, testing procedures, etc.

21 CDC IT

standards / processes

Adherence to

CDC IT

standards and processes

Must comply with all HHS IT standards which includes, Enterprise Architecture, Security, 508 Compliance, Enterprise Lifecycle development (EPLC), Capital Planning Investment Control (CPIC).

All requirements must be met.

Review of project deliverables

Favorable or Unfavorable Performance Evaluation

22 Production support incidents

Resolve production support issues

All incidents reported are closed in 0-1 day

65 % of the time

Review performance metric report

Favorable or Unfavorable Performance Evaluation

23 Production support incidents

Resolve production support issues

All incidents reported are closed in 2-7 days

20% of the time

Review performance metric report

Favorable or Unfavorable

C.5. DETAILED SYSTEM REQUIREMENTS/DETAILED SPECIFICATION OF ACTIVITIES

The Contractor must comply with all CDC policies and procedures, and IT standards and guidance. This includes deliverables and processes described in the Enterprise Lifecycle documents for all phases of the system development lifecycle.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .