PWS_HIPAA_05.04.15.pdf

PDF 590 KB Posted

Attached to
HIPAA Privacy and Security Policy Services Federal contract opportunity
Solicitation number
2015-Q-17159
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Pittsburgh

About this file

PWS

View the file

Other files for this federal contract opportunity

Other files attached to HIPAA Privacy and Security Policy Services, newest first.
File Type Posted
Questions.pdf PDF
Past-Present_Performance_Questionnaire.docx DOCX document
ACH-Vendor.pdf PDF
Relevant_Contracts_Reference_Sheet.docx DOCX document
Solicitation_2015-Q-17159.pdf PDF
HHSA_Security_Compliance.docx DOCX document
Supplemental_Instructions.pdf PDF
QASP.pdf PDF
Client_Authorization_Letter.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HIPAA Privacy and Security Policy Services

PWS

Performance Work Statement

HIPAA Privacy and Security

Policy Services

World Trade Center Health Program (WTCHP)

Table of Contents

1. DESCRIPTION OF SERVICES

1.1 Background

1.2 Scope

1.3 Non-personal Services

1.4 Definitions

1.5 Acronyms

2. SUMMARY OF REQUIREMENTS

2.1 Specific Requirements

2.1.1 Privacy Support

2.1.2 Complaint Resolution

2.1.3 Reporting Requirements Coordination

2.1.4 Policy Consultancy

2.1.5 Point of Contact

2.1.6 Policy Change Recommendations

2.1.7 Information Privacy Management

2.1.8 HIPAA Training

2.1.9 Meeting Attendance

2.1.10 General Communications Requirements

2.2 Contractor Experience and Credentials

2.3 General Requirements

2.3.1 Continuation of Services

2.3.2 Vacancies

2.3.3 Professionalism

2.4 Deliverables/Reporting Requirements

2.4.1 Quarterly Report

2.4.2 Monthly Status Report (MSR)

2.4.3 Quality Control Plan

2.4.4 General Guidance for Deliverables

2.4.5 COR Review of Contractor Deliverables

2.5 Services Summary and Method of Surveillance

2.6 Government Furnished Property/Information (GFP/GFI)

2.6.1 Documents

2.6.2 Local Area Network (LAN)

2.6.3 Workspace

2.7 Security Procedures

2.7.1 Security Provisions

2.7.2 Appointment with CDC Security Office…………

2.7.3 SF-85P (Public Trust)

2.8 Travel

2.8.1 Travel Reimbursement

2.8.2 Travel Guidance

2.8.3 Trip Report

2.9 Place of Performance

2.10 Work Schedule

2.10.1 Period of Performance

2.10.2 Hours

2.10.3 Scheduled Holidays

2.10.4 Facility Closures

2.11 Privacy of Information

2.11.1 Privacy Act of 1974

2.11.2 Need to Know

3.0 Applicable Publications

3.1 WTC Health Program Policies

APPENDIX A: Business Associate Agreement

1. DESCRIPTION OF SERVICES

1.1 Background

On November 13, 2012, the Department of Health and Human Services (HHS) designated the Centers for

Disease Control and Prevention (CDC) National Institute for Occupational Safety and Health (NIOSH), Office of the Director (OD), to the extent that it performs activities related to the World Trade Center Health Program

(WTCHP), a Health Care component of HHS pursuant to the Health Insurance Portability and Accountability

Act (HIPAA) of 1996. The WTC Health Program was established by Title I of the James Zadroga 9/11 Health and Compensation Act of 2010 (Zadroga Act), P.L. 111-347, to provide and pay for medical, monitoring, and treatment for eligible responders and survivors of September 11, 2001 terrorist attacks.

In accordance with its designation as a “Health Care component” the WTCHP must comply with the requirements of HIPAA regulations (45 C.F.R. 160, 162, and 164). The HIPAA regulations P.L. 104-191 (as amended), and its implementing regulations, 45 C.F.R. , Parts 160, 162, and 164 set parameters for the use and disclosure of protected health information by certain entities, referred to as “covered entities” and their business associates. To implement the HIPAA Rules, the WTCHP executed legal agreements (Business

Associate Agreement) with its WTCHP components (Contractors) that creates, receives, maintains, or transmits PHI on behalf of the Covered Entity (WTCHP) or in providing a service for the WTCHP that involves the use or disclosure of PHI. The Business Associate Agreements outlines responsibilities and obligations for compliance with HIPAA and the handling of PHI. Also, the WTCHP generated the “Notice of

Privacy Practices (NPP) document that describes how an individual’s PHI may be used/disclosed and outlines individual privacy rights, describes Covered Entity obligations under the HIPAA Privacy Rule, and outlines the process for filing a complaint. The WTCHP NPP is located at:

http://www.cdc.gov/wtc/pdfs/NPP%20_%20Full%20Page_%20WTC%20Health%20Program.pdf

For more information about the World Trade Center Health Program (WTCHP), see the NIOSH website:

http://www.cdc.gov/wtc

In an effort to fully comply with the HIPAA regulations and meet the increased demands of HIPAA, the

WTCHP, administered by the NIOSH, created a HIPAA Privacy and Security Risk Assessment Team (RAT).

The primary focus of the team is to serve as the focal point for HIPAA compliance issues, in support of the

WTC Health Program and all WTCHP Contractors. The team coordinates efforts through the HHS Office of

General Counsel (OGC). This interface includes Privacy Act issues/concerns, as well as HIPAA Privacy and security issues/concerns, to include breach notifications.

1.2 Scope

The objective of this requirement is for a single Contractor to assist the WTCHP with its HIPAA compliance goals and with the development of a WTCHP health information privacy and security training manual pursuant to HIPAA regulations for the following rules:

a. The Privacy Rule at 45 CFR Part 160 and Sub part A and E of Part 164.

b. The Security Rule at 45 CFR Part 160, 162 and Subparts A and C of Part 164.

c. The Breach Notification Rule at 45 CFR §§ 164.400-414.

http://www.cdc.gov/wtc/pdfs/NPP%20_%20Full%20Page_%20WTC%20Health%20Program.pdf http://www.cdc.gov/wtc

In support of this scope objective, the Contractor is expected to:

a. Conduct a comprehensive HIPAA risk analysis of the WTCHP.

b. Review and update HIPAA policies for the WTCHP.

c. Develop and conduct WTCHP Health Information Privacy and Security training (including the development of a training manual).

d. Investigate and address WTCHP HIPAA breaches (to include breach incident procedures).

e. Review and update the HIPAA Privacy web page.

f. Serve as a consultant to the WTCHP Privacy and Security Officers on HIPAA issues.

1.3 Non-personal Services

The Government will neither supervise the Contractor nor control the method by which the

Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for the Contractor. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are personal services, or give the perception of personal services. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s responsibility to notify the CO, immediately. These services shall not be used to perform work of a policy/decision making or management nature, i.e., inherently Governmental functions.

All decisions relative to programs supported by the Contractor shall be the sole responsibility of the

Government.

1.4 Definitions

“Accurately developed”: This term defines products and deliverables developed by the Contractor that need no corrections or further editing by either the Contracting Officer (CO) or the Contracting Officer’s

Representative (COR).

“Advisory and assistance services”: Services provided under contract by non-governmental sources to support or improve organizational policy development, decision-making; management and administration, program and/or project management and administration, or Research and Development activities. It can also be defined as professional advice or assistance rendered to improve the effectiveness of federal management processes or procedures (including those of an engineering and technical nature). In rendering the foregoing services, deliverables may take the form of information, advice, opinions, alternatives, analyses, evaluations, recommendations, training, and the day-to-day aid of support personnel needed for the successful performance of ongoing federal operations.

“Business Day”: Dates listed as business days are government working days (Monday through Friday except government holidays). All days referenced in this PWS that are not prefaced by “business” are considered to be calendar days.

“Contracting Officer’s Representative (COR)”: The individual(s) designated to perform quality assessment functions. They serve as on-site technical managers assessing the Contractor’s performance against contract performance standards.

“Contractor”: The Contractor is an independent entity and responsible for its own liability.

Contractor, when the word is capitalized, is a company and not an individual.

“National Agency Check with Inquires”: NACI is the type of personnel security investigation that the

Government conducts for the FTE performing under this contract. The Contractor performing the requirements under this contract is in a public trust position and requires a suitability determination and not an investigation for a security clearance higher than Unclassified.

“On Site”: On-site means at a Government’s facility (CDC NIOSH locations).

“Performance Threshold”: The minimum level of acceptable performance that the Contractor must meet in order to be considered satisfactory.

“Performance Work Statement (PWS)”: A statement of work for performance-based acquisitions that describes the required results in clear, specific, and objective terms with measurable outcomes.

“Services Summary”: A summary of the performance objectives and the performance thresholds required by the Government in evaluating the Contractor’s performance.

“Supported Entities”: Includes but is not limited to: HHS, CDC, NIOSH, and WTC Health

Program.

1.5 Acronyms

Acronym Definition

AQL Acceptable Quality Level

BAA Business Associate Agreement

CCE Clinical Centers of Excellence

CDC Centers for Disease Control and Prevention

CDD Certificate of Data Disposition

CFR Code of Federal Regulations

CHP Certification in Healthcare Privacy

CHPS Certification in Healthcare Privacy and Security

CO Contracting Officer

COB Close of Business

COR Contracting Officer’s Representative

DOB Date of Birth

DOJ U.S. Department of Justice

DSA Data Sharing Agreement

DUA Data Use Agreement e-QIP Electronic Questionnaires for Investigations Processing

FAR Federal Acquisition Regulation

FDNY Fire Department of New York City

FOIA Freedom of Information Act

FSS Federal Supply Schedule

FTC Federal Trade Commission

GAO Government Accountability Office

GFI Government Furnished Information

GFP Government Furnished Property

GSA General Services Administration

HHC NYC Health and Hospitals Corp. (Survivor Program)

HHS Department of Health and Human Services

HIPAA Health Insurance Portability and Accountability Act

ID/IQ Indefinite Delivery/Indefinite Quantity

LAN Local Area Network

Acronym Definition

LIJ/Q Long Island Jewish/Queens

MSR Monthly Status Report

MSSM Mount Sinai School of Medicine

NIOSH National Institute for Occupational Safety and Health

NACI National Agency Check and Inquiries

NDA Non-Disclosure Agreement

NPP Notice of Privacy Practices

NPN Nationwide Provider Network

NYU New York University, Bellevue Hospital

OCR HHS Office of Civil Rights

OGC Office of General Counsel, HHS

OMB Office of Management and Budget

PGI Procedures, Guidance, and Information

PM&A Program Management and Administration

PHI Protected Health Information

PIA Privacy Impact Assessment

PII Personally Identifiable Information

PoP Period of Performance

PWS Performance Work Statement

RAT Risk Assessment Team

RU Rutgers University (New Jersey)

SORN System of Record Notice

SSN Social Security Number

SUNY State University of New York

TR Trip Report

VCF The DOJ’s‘ September 11th Victims Compensation Fund

WTCHP World Trade Center Health Program

2. SUMMARY OF REQUIREMENTS

2.1 Specific Requirements

The Contractor shall provide HIPAA Privacy and Security Policy services while performing the requirements of this contract. The Contractor shall perform the following tasks.

2.1.1 Privacy and Security Support

The Contractor shall develop a Health Information Privacy and Security training manual pursuant to 45

C.F.F. § 164.308 (a covered entity or business associate must implement policies and procedure to prevent, detect, contain, and correct security violations; including implementing a security awareness and training program for all members of its workforce (including management).

● Ensure WTCHP policies and business practices comply with federal laws, regulations, and guidelines governing the privacy and security of PII/PHI, and in the development and in the development of

HIPAA regulations, instructions, policies and procedures.

● Provide guidance on the management and evaluation of potential risks and threats to the privacy and security of WTCHP members’ health information by performing a comprehensive review through:

- Evaluation of the privacy and security posture of the WTCHP by conducting the conducting a

HIPAA required Security Risk Assessment

- Conduct a performance of Compliance Risk Assessment throughout the WTCHP to evaluate Privacy and HIPAA compliance

- Establish an organization performance metrics to identify and measure potential compliance risks

- Evaluate the WTCHP data sharing processes between business associates and the

Interagency Agreement between the HHS/CDC/NIOSH/WTCHP and the U.S.

Department of Justice September 11th Victims Compensation Fund (VCF)

- Engage WTCHP workforce, including contractors, by developing and delivering education and awareness materials and annual Privacy and HIPAA training

- Provide recommendation on fully implementing applicable provisions of Privacy

Act, and the E-Government Act

The training and awareness materials should contain key privacy and security information pursuant to

HIPAA privacy, security and breach notification rules that will help the WTCHP workforce, stakeholders, and Contractors to understand the complex HIPAA privacy and security requirements.

2.1.2 Key elements of risk analysis: The Contractor risk analysis shall include the following:

● Identify and document reasonably anticipated and potential threats specific to the WTCHP HIPAA operating environment

● Identify vulnerabilities, which, if exploited by a threat, would create a risk of an inappropriate use or disclosure of ePHI

● Determine and document the potential impact and risk of potential risks to the confidentiality, integrity, and availability of ePHI

● Assess existing security measures

● Evaluate if the WTCHP and Business Associates are complying with HIPAA Privacy and Security

Rules and Breach Notification standards, in accordance with the Business Associate Agreements

(BAAs).

2.1.3 Reporting Requirements

Any HIPAA reporting requirements mandated from HHS OCR shall be included in the training manual.

This may include notifications of actual or potential breaches of information or other high visibility issues due to the HIPAA Privacy and Security requirements.

2.1.4 Policy Consultancy

The Contractor shall perform as a HIPAA Privacy and Security policy consultant to the NIOSH/WTC Health

Program/RAT

2.1.5 Point of Contact

The Contractor shall perform as the WTC Health Program HIPAA Subject Matter Expert (SME)/ point of contact for the WTCHP HIPAA Privacy and Security Officers. As a Contractor, the Contractor does not establish or make policy, guidance or direction on behalf of any government entity

2.1.6 Policy Change Recommendations

The Contractor shall make recommendations for change and assist the Government with the development of

WTC Health Program HIPAA Privacy and Security policies and procedures to ensure compliance with the

HIPAA laws and regulations. The Contractor shall maintain current HIPAA Privacy knowledge and expertise with respect to applicable federal laws, accreditation standards, and service regulations and where necessary, make recommendations to the Government for change to existing policies, procedures, and instructions.

2.1.7 Information Privacy Management

The Contractor shall recognize and recommend best practices relative to the management of the privacy and security of health information. The Contractor shall understand the content of health information and privacy protection of such information in its clinical, research and business contexts. The Contractor shall recommend activities to foster information privacy and security awareness within the WTC Health

Program. The Contractor shall assist with the implementation of his or her recommendations, as approved by the Government.

2.1.8 HIPAA Training

The Contractor, in collaboration with NIOSH/WTC Health Program RAT, will create Privacy and Security

HIPAA training for WTC Health Program workforce, stakeholders, and Contractors, as required. The

Contractor shall develop training modules to support HIPAA Privacy and Security initiatives. Training modules shall be updated within 60 days of changes in law and/or policy changes. The Contractor shall also include a training module for newcomers to the WTC Health Program. The training/briefings module should be designed so that the training can be completed by a newcomer within 30 days of the newcomer’s employment by the WTC Health Program, or one of its Business Associates, if directed by the Program.

2.1.9 Meeting Attendance

The Contractor shall be required to attend various staff meetings and conference calls.

a. The Contractor may be asked to attend monthly WTCHP HIPAA RAT and HIPAA Privacy and

Security conference calls, which may include Privacy Act issues. The Contractor shall not chair or be a voting member while attending such meetings.

b. The Contractor shall work with the WTC Health Program HIPAA RAT in coordinating and conducting HIPAA conference calls with WTC Health Program Contractors.

2.1.10 General Communications Requirements

The Contractor shall reply to and respond to all forms of communications received (phone, email, etc.) with customers and supporting agencies by close of business (COB) the following business day the communication was received. The Contractor shall be able to read, understand, speak, and write English in order to maintain open and professional communication with members of the Government.

2.2 Contractor Experience and Credentials

The service is performance-based and the Government requires that the Contractor have the required relevant experience, and credentials throughout the contract’s period of performance.

As such, the Contractor shall have, at a minimum, the following experience and credentials.

a. Certification in Healthcare Privacy (CHP) or in Healthcare Privacy and Security (CHPS)for at least 5 years.

b. More than 2 years of experience working on HIPAA Privacy and Security issues within the healthcare environment.

c. Experience with other relevant federal rules and standards, e.g., the Privacy Rule, FISMA, etc.

d. Experience with the HIPAA Privacy and Security Program or Policy for at least 10 years.

e. Experience with strategic planning, workflow analysis, business process reengineering, problem resolution, and training and development in medical administration from an agency-level, or a strategic-level, or corporate-level operation.

f. Experience training/communicating/briefing at the corporate/senior leadership level.

g. Subject matter expertise in HIPAA Privacy practices and HIPAA security practices.

h. Comprehensive knowledge of the Privacy Act, HIPAA, and HHS OCR HIPAA guidelines.

i. Comprehensive knowledge of civilian healthcare accreditation standards relevant to HIPAA industry requirements and standards for healthcare plans.

2.3 General Requirements

2.3.1 Continuation of Services

The Contractor shall ensure continuation of services during personnel absences due to sickness, leave, and voluntary or involuntary termination from employment such that impact to the Government is minimal and position vacancies do not exceed 30 days.

2.3.2 Vacancies

The Contractor shall provide follow-up documentation within 72 hours after notification, stating the date and time the position will be vacant, and the reason for vacating the position, the anticipated replacement date of personnel, and what management corrective action will be taken to ensure contract mission completion.

2.3.3 Professionalism

When in Government facilities, the Contractor shall wear a company picture identification badge to distinguish him or herself from government employees. When conversing with Government personnel during business meetings, over the telephone or via electronic mail, the Contractor shall identify themselves as such. The Contractor shall identify him or herself as a Contractor on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation. The Contractor shall be required to observe all facility parking, safety and traffic regulations that apply to all government and facility employees.

2.4 Deliverables/Reporting Requirements

Deliverables associated with this contract are specified below. All deliverables shall be submitted to and agreed upon by the Government.

Title

Para

Delivery Date/Description

Comprehensive HIPAA Risk

Analysis Report

1.2 Draft – 90 days after contract award

Final – 150 days after contract award

WTCHP HIPAA Policies

Report

1.2 Draft – 120 days after contract award

Final – 180 days after contract award

Training Module(s)

Development and

Deployment Updates and

Implementation

2.1.8 Define the deployment plan and process involved with

implementing and beginning HIPAA web base training. The intended audience is the WTCHP workforce, stakeholders, and contractors---Draft – 90 days after contract award.

Production simulation testing of training module—150 days after contract award.

Initial implementation of training module –270 days after contract award.

Final implementation of HIPAA training modules, manual including CDs with detailed presentation on HIPAA Privacy and

Security rules—due 360 days after contract award

HIPAA privacy and security awareness training plan/training

Provide HIPAA privacy and security awareness training to

WTCHP staff members, stakeholders, and other NIOSH staff as applicable to achieve HIPAA privacy and security training requirements. Develop a HIPAA privacy and security training plan. An effective plan should include:

•Access, use, and disclosure of PII/PHI

•Safeguarding PII/PHI

•Breach reporting and complaint filing processes

•Comprehensive documentation (communications request, findings)

•Design poster(s) to promote awareness consistently to prevent violations and breaches.

•Develop retraining materials as part of mitigation strategy

Draft plan ---60 days after contract award

90 days after contract award--- Deliver HIPAA privacy and security training to WTCHP staff

120 days after contract award--- Deliver assessment of HIPAA training to WTCHP Risk Assessment Team.

Deliver training every 12 months.

Quarterly Reports 2.4.1 By the 10 th business day of the month following the quarter being reported. Content shall include the status of completion of the following: 1)Comprehensive HIPAA Risk Analysis Report, 2)

HIPAA Policies Report, 3) HIPAA Privacy and Security training modules, 4) HIPAA Privacy and Security support (2.1.1), 5) Key elements of risk analysis assessment (2.1.2), 6) Evaluation of

WTCHP breach reporting, 7) and the status of other ongoing tasks.

Monthly Status

Reports (MSR)

2.4.2 By the 5

th business day of the month being reported. Monthly status reports shall provide brief updates on status of tasks identified under Quarterly Reports.

Quality Control Plan

(QCP)

2.4.3 By the 5

th business day after contract award. Contents are in accordance with the requirements detailed in paragraph 2.4.3.

Trip Reports (TR) 2.8.3 By the 5 th business day after the last day of travel. At a minimum, content shall include items listed in para 2.83.

2.4.1 Quarterly Report

The Contractor shall be responsible for the production of quarterly reports, which will illustrate the status and completion of deliverables. The Contractor shall present the information included in the quarterly reports to the RAT, as required.

2.4.2 Monthly Status Report (MSR)

The Contractor shall ensure that a MSR is submitted outlining progress, status, risks and problems/issues encountered with recommended solutions, schedule changes, and identify any

Government dependencies that are overdue which are impacting schedule and/or performance of this contract. The report shall be presented at monthly In-Progress Reviews. It is expected that the report will include at a minimum:

A description of activities of the past month (summary of work accomplished during the reporting period and percent complete).

Schedule of activities planned and estimated date/time of completion.

A summary of the status of work initiatives and documentation updates.

A summary analysis of databases/spreadsheets used by the Contractor to track training/briefings performed, complaints received and resolved, consultancy services delivered, and other assistance provided to the WTCHP.

2.4.3 Quality Control Plan

The Contractor is responsible for contract management and quality control, not the Government. The

Contractor’s Quality Control Plan (QCP) is the means by which the Contractor assures itself that its work complies with the requirements of the contract. The Contractor shall develop and maintain an effective

QCP to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. Contractor shall submit a QCP no later than five (5) business days after contract award. The COR will provide a written notice of acceptance to the Contractor.

2.4.4 General Guidance for Deliverables

All deliverables shall be submitted to the COR. Unless otherwise stipulated, written deliverables will be phrased in layperson language. Statistical and other technical terminology will not be used without providing a glossary of terms. The Contractor shall be responsible for providing the deliverable in the media required by the COR for each submittal.

a. Delivery Written deliverables shall be submitted in paper copies (one copy) and in electronic format using the most current version of MS Office suite of applications (2013 as of the writing of this PWS).

Additionally, each final deliverable may need to be supplied in .pdf format, if directed by the

COR. It is the responsibility of the Contractor to ensure that all data transmitted via diskette or e-mail is virus-free and the data is protected.

b. Documentation The Contractor shall prepare all documentation to meet established standards of WTC Health

Program RAT: timeliness, legibility, and accuracy of content. Only WTC Health Program

RAT approved abbreviations may be used in documentation. All electronic and manual documentation shall be maintained by the Contractor. Documentation includes results of analysis and work plan designs.

2.4.5 COR Review of Contractor Deliverables

The COR will inspect, accept or reject deliverables. The COR will notify the Contractor of any required changes. Unless otherwise stipulated, the Contractor shall have five (5) business days to make adjustments and re-submit a deliverable.

2.5 Services Summary and Method of Surveillance

The Government shall use the following standards to determine Contractor performance and shall compare Contractor performance to the Acceptable Quality Level (AQL).

Requirement

Paras

AQL/Performance Threshold

(Performance is acceptable if…)

Surveillance/

Monitoring Method

Assist the WTC Health

Program HIPAA RAT with HIPAA compliance.

2.1.1 There are no more than five (5) HIPAA

deficiencies, to include late, missed, unaccomplished responses or suspenses, as substantiated by the COR, in any six

(6) consecutive- month period.

Deficiencies will be tracked using a spreadsheet.

WTCHP Concerns

Policy Consultancy 2.1.4 The Contractor provides policy consultant services via recommendations and analysis with no more than five (5) deficiencies, to include late, missed, unaccomplished responses or suspenses, as substantiated by the COR, in any six (6) consecutive-month period. Deficiencies will be tracked using a spreadsheet.

Task deliverables

Development and

Updates of Training

Manual

2.1.8 Training manual is updated within

60 days of changes in law, and accurately developed 90% of the time. Deliveries will be tracked using a spreadsheet.

100% Inspection by the

COR

HIPAA Privacy and

Security Annual

Refresher Training

2.1.8 The Contractor delivers the annual

refresher training 100% of the time.

Training accomplishment will be tracked using a spreadsheet.

100% Inspection by the

COR

Monthly Newcomer’s

HIPAA Orientation briefing

2.1.8 The Contractor shall include in the training

manual a monthly “Newcomers” HIPAA briefing/training. The training shall include the notification of an absence, if any, for any “Newcomers” not completing the training within the first 30 days of employment. The “Newcomers” training will be tracked using a spreadsheet.

100% Inspection by the

COR

Communication 2.1.10 The Contractor returns all forms of

HIPAA-related communications (phone, email, etc.) with supported agencies, Contractors, and WTCHP personnel by

COB of the following business day every day that the communication was received 90% of the time.

WTCHP workforce, Stakeholders, and

Business Associates

Complaints

Requirement

Paras

AQL/Performance Threshold

(Performance is acceptable if…)

Surveillance/

Monitoring Method

Quarterly Reports 2.4.1 Due by the 10 th business day of the month following the quarter being reported no less than 3 quarters per annual PoP. All deliverables delivered to the COR will be tracked by the COR.

100% Inspection by the

COR

Monthly Status

Reports (MSR)

2.4.2 Due by the 5th business day of the

month being reported 11 out of every

12 months. All deliverables delivered to the COR will be tracked by the COR.

100% Inspection by the

COR

Comprehensive HIPAA Risk Analysis Report 1.2

Draft – 90 days after contract award

Final – 150 days after contract award

100% Inspection by the

COR

WTCHP HIPAA Policies Report

1.2 Draft – 120 days after contract award

Final – 180 days after contract award

COR

Training Module(s)

Development and

Deployment Updates and

Implementation

2.1.8 Define the deployment plan and process

involved with implementing and beginning

HIPAA web base training. The intended audience is the WTCHP workforce, stakeholders, and contractors---Draft – 90 days after contract award.

Production simulation testing of training module—150 days after contract award.

Initial implementation of training module

–270 days after contract award.

Final implementation of HIPAA training modules, manual including CDs with detailed presentation on HIPAA Privacy and Security rules—due 360 days after contract award.

HIPAA privacy and security awareness training plan/training

Provide HIPAA privacy and security awareness training to WTCHP staff members, stakeholders, and other NIOSH staff as applicable to achieve HIPAA privacy and security training requirements. Develop a HIPAA privacy and security training plan. An effective plan should include:

•Access, use, and disclosure of PII/PHI

•Safeguarding PII/PHI

•Breach reporting and complaint filing processes

•Comprehensive documentation

(communications request, findings)

•Design poster(s) to promote awareness consistently to prevent violations and breaches.

•Develop retraining materials as part of mitigation strategy

Draft plan ---60 days after contract award

90 days after contract award--- Deliver

HIPAA privacy and security training to

WTCHP staff

120 days after contract award--- Deliver assessment of HIPAA training to WTCHP

Risk Assessment Team.

Deliver training every 12 months.

Trip Reports (TR) 2.8.3 Due by the 5 th business day after the last day of travel 90% of the time. All deliverables delivered to the COR will be tracked by the COR.

2.6 Government Furnished Property/Information (GFP/GFI)

The Contractor shall ensure accurate control and accountability of all GFP/GFI in accordance with the Government property clauses incorporated into the basic contract. The following

GFP/GFI will be provided to the Contractor, on-site.

2.6.1 Documents

The Government will furnish or make available to the Contractor any documentation/material deemed necessary to accomplish requirements of this contract. Documents include access to databases, reference materials, and policy documents.

2.6.2 Local Area Network (LAN)

Contractor with a valid National Agency Check and Inquiries (NACI) verified through the Contractor’s security manager will be provided access to the CDC computer network and its inherent capabilities including, but not limited to: internet access, electronic mail, file and print services, and dial-in network access. The Contractor shall be aware of and abide with all government regulations concerning the authorized use of the Government’s computer network. Time spent by the Contractor obtaining LAN access and attending government required network security training is properly chargeable under this contract.

2.6.3 Workspace

The Federal Government does not require a particular place of performance for accomplishment of the requirement. The intended acquisition is for provision of services which will not be performed on a

Government site. D u r i n g s i t e v i s i t s , the Government shall provide the Contractor with workspace amenities for the handicapped in accordance with Section 508 laws.

2.7 Security Procedures

Minimum facility and personnel clearance level required under this contract is Unclassified

(UNCLAS). No foreign national candidates shall be utilized within the scope of this contract without prior approval of the Government. In addition to the below and due to the nature of the work that the

Contractor will likely be exposed to, the Contractor shall sign and comply with all security requirements.

2.7.1 Security Provisions

The Contractor shall fully adhere to the provisions of the referenced publications by having each of their on-site employee submit the appropriate forms and maintain a favorable suitability determination to continue performing under this contract. Within five (5) days after the Period of Performance (PoP) start date, the Contractor shall submit on-site employee name, and contract number, required/prospective start date, and telephone contact number to the Contracting Officer (CO) and the Security Officer identified in the contract.

2.7.2 Appointment with CDC Security Office

The Contractor shall schedule an appointment with the CDC Security Office, if required.

2.7.3 SF-85P (Public Trust)

The Contractor shall ensure contractor personnel completes the SF-85P (Public Trust) in the Electronic

Questionnaires for Investigations Processing (e-QIP) after the Unit Security Manager contacts the contract personnel to establish an account in e-QIP Direct.

2.8 Travel

Travel shall comply with the basic contract. The Contractor shall be required to perform travel within the Continental United States (CONUS). The Contractor shall obtain authorization for travel from the COR, within two (2) days of planned travel. The Contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence.

2.8.1 Travel Reimbursement

All Contractor travel shall be in accordance with the Federal Travel Regulations, per Federal Acquisition

Regulation (FAR) 31.205-46. The Contractor must notify the Government when expenditures are 75% expended of travel costs. The Contractor shall travel using the lowest cost mode of transportation commensurate with the mission requirements. The estimated amount for cost reimbursable travel for this contract shall be reimbursed to the Contractor provided that all trips taken in the performance of this contract must have the written consent of the COR. Written consent may be provided through email.

Travel shall be reimbursed on a cost reimbursable basis; no profit or fee shall be paid. Reimbursement will be for actual cost.

2.8.2 Travel Guidance

When necessary to use air travel, the Contractor shall use economy class. If the Contractor elects to travel by another method other than air, the reimbursed costs shall be either those of the actual travel used or the cost for the most economical air fare, whichever is less.

a. Email the following information to the COR when seeking approval for travel:

o destination o dates o purpose o estimated cost of the trip broken down by airfare, lodging, car rental, taxi/parking, and other miscellaneous costs approved by the COR.

b. On site visits to the WTCHP Business Associates are not an immediate requirement during the performance period of this contract. The Contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence. Travel will be in accordance with HHS Travel

Regulations.

2.8.3 Trip Report

Trip Reports (TRs) shall be submitted within five (5) business days after trip completion. TR contents shall include:

o Supporting documents for each traveler (e.g., airline ticket/receipt, hotel invoice, per diem expenses) o Inclusive Dates of Travel o Destination o Purpose o Individuals Contacted o Brief Synopsis o Issues & Challenges o Recommendations o Signature Block

2.9 Place of Performance

The work to be performed under this contract will be primarily performed in Washington, DC Metropolitan

Area, and Atlanta, GA. All federal buildings are smoke-free facilities.

2.10 Work Schedule

2.10.1 Period of Performance

The anticipated period of this order shall be 18 months from July 1, 2015 through December 31, 2016.

2.10.2 Hours

Weekly hours shall not exceed a forty (40) hour work week and a typical work day will be eight (8) hours between 7:30am to 4:30pm local time, Monday through Friday. The Government reserves the right to change hours of operation. Work outside these daily hours is prohibited without CO approval.

2.10.2 Scheduled Holidays

New Year’s Day, Dr. Martin Luther King, Jr. Birthday, President’s Day, Memorial Day, Independence

Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.

2.10.3 Facility Closures

The Government will notify the Contractor of anticipated closure of the facility, (i.e., training, holidays, administrative leave granted to the entire staff, or other closure including down days) five (5) business days in advance or as soon as possible. In the event of unplanned closure of the facility due to natural disasters, emergency or severe weather, the Government will notify Contractor in the same manner as the

Government notifies its workforce.

2.11 Privacy of Information

The Contractor shall not release any personnel or medical/patient information during the course of this contract. The Contractor shall comply with information privacy guidance in Appendix A.

2.11.1 Privacy Act of 1974

The Privacy Act of 1974 (5 U.S.C. § 552a), which includes Public Law 100-503, must be treated as FOR

OFFICIAL USE ONLY.

2.11.2 Need to Know

Contractor shall provide patient information only to Government employees, Government

Contractor, and Subcontractors having a need-to-know such information in the performance of their duties for this contract.

3. Applicable Publications Publications and forms are available electronically through the internet. Publications and forms applicable to this PWS are coded as mandatory. The Contractor shall comply with mandatory publications and forms to the extent specified in this PWS. The Contractor shall be responsible for all updates, supplements, and amendments to mandatory documents through the life of this contract. Publications applicable to the PWS, include, but are not limited to, those listed below. The Contractor is obligated to follow all applicable publications. These publications are available online and are maintained by the

Government. Supplements or amendments to listed publications from any organizational level may be issued during the life of the contract.

3.1 WTC Health Program Policies

WTC Health Program policies can be found at http://www.cdc.gov/wtc/index.html. Consult this site for the latest changes.

http://www.cdc.gov/wtc/index.html

APPENDIX A

World T r a d e Center Health Program Business Associate Agreement

This Business Associate Agreement ("Agreement") is incorporated as an exhibit into the contracts entered into between the Centers for Disease Control and Prevention (CDC) on behalf of its component, the National Institute for Occupational Safety and Health (NIOSH), and X X X X X for the purposes of carrying out functions, services, and responsibilities related to the World Trade Center (WTC) Health

Program ("Contract"). This Agreement describes legal obligations and requirements of the Business

Associate and Covered Entity, including permitted and required uses and disclosures of protected health information by the Business Associate; it is executed pursuant to the requirements of 45 C.F.R. §§

164.502(e)(2) and 164.504(c)(l)-(2) and Contract term C.3.4.5. The scope of this Agreement includes all functions, services, and responsibilities included in the Contract which require the Business Associate to perform functions or activities on behalf of the Covered Entity where the Business Associate creates, receives, maintains, or transmit protected health information or where the Business Associate provides certain services to or for the Covered Entity which require the disclosure of protected health information to the Business Associate by the Covered Entity.

A. Definitions

All terms used herein and not otherwise defined shall have the same meaning as in the Health Insurance

Po1tability and Accountability Act of 1996 ("HIPAA") (Pub. L. 104-191; 42 U.S.C. § 1320d), as modified, and the corresponding implementing regulations, including the Privacy, Security, Breach

Notification, and Enforcement Rules (45 C.F.R. Pm1s 160, 162, and 164). Non-HIPAA related

Provisions governing the duties and obligations of the Contractor, XXXX such as those under the Privacy

Act and any applicable data use agreements, are covered elsewhere in the Contract between the parties governing the provision of WTC Health Program services and other Contract-related documents. The parties acknowledge that Business Associate provides direct and substantial hea l th care services to WTC

Health Program applicants and e n r o l l e e s . For the purposes of this agreement "treatment" is defined as the

"provision, coordination, or management of health care and related services" by a health care provider, including "coordination or management of health care with a third party; consultation b e t wee n health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another." (45 C.F.R. § 164.501). Fo r treatment related services that fall within the above referenced definition, "protected health information" (PHI) is expressly excluded from this agreement. All other work under the contract involving PHI not fitting this definition shall be included under this agreement.

‘Business Associate', shall generally have the same meaning as the term "business associate" at 45

C.F.R. § 160.103 and, for the purpose of this Agreement and the Contract, shall mean XXXX.

"Covered Entity" shall generally have the same meaning as the term "covered entity" at 45 C.F.R. §

160.103 and, for the purpose of this Agreement and the Contract, shall mean the WTC Health Program and any other NIOSH, CDC, or HHS components to the extent that they assist in administering the

WTC Health Program where protected health information is involved.

"Protected Health Information" (PH I) shall generally have the same meaning as the term "protected health infom1ation" at 45 C.F.R. § 160.103. The HIPA A regulations define PHI as individually identifiable health information (health information, including demographic information, collected from an individual and created or received by a health care provider, health plan, employer, or health care clearinghouse that relates to the individual's past, present, or future mental or physical health condition, provision of health care, or payment for care and which identifies the individual or is reasonably believed to make the individual identifiable) that is transmitted by electronic media, maintained in electronic media, or transmit1ed or maintained in any other form or medium. PHI excludes individually identifiable health information in certain education records, certain student medical records, employment records held by a covered entity in its role as employer, and records regarding a person who has been deceased for more than 50 years. The definition of PHI throughout this Agreement shall be limited to PHI relating to Business Associate functions, and shall exclude PHI relating to treatment services.

"Secretary" shall mean the Secretary of the Department of Health and Human Services or the Secretary's designee.

"Treatment' as defined by HIPAA is the provision, coordination, or management of health care and related services for an individual by one or more health care providers, including consultation between providers regarding a patient and referral of a patient by one provider to another.

B. Obligations and Activities of Business Associate

Business Associate, as well as its agents and subcontractors, shall meet all applicable HIPAA obligations. Furthermore, it shall document in writing the policies and procedures that will be used to meet such obligations. These obligations include the following:

l. Business Associate agrees to not use or disclose PHI other than as permitted or required by the

Contract or as required by Law.

2. Business Associate agrees to prevent use or disclosure of PHI other than as provided for by this

Agreement through use of appropriate safeguards and complying with Subpart C of 45 C.F.R.

The term "covered entity'' is used in this section for case of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:

HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates "health care components" in accordance with 45 C.F.R. §

164.105(a)(2)(iii)(D). 45 C.F.R. § 161.103. As a hybrid entity, H HS must designate any component that would "meet the definition of a covered entity or business associate if it were a separate legal entity" as a health care component; a health care component also may include a component only to the extent that it perfom1s covered functions. 45 C.F.R.§ 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a "health care component" of the covered entity, H H S a s are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions.

Part 164 with respect to electronic PHI. In accordance with 45 C.F.R. §§ 164.306 and 164.316, Business Associate shall implement written policies and procedures to:

a. Prevent, detect, contain, and correct security violations2 through the use of:

i. Risk analyses (including periodic technical and nontechnical evaluations);

ii. Appropriate risk management strategies (including information system activity review);

iii. Inf01mation access procedures for approving individual's access rights to PHI

(including the implementation of workforce security measures to ensure continued appropriate role-based access to PHI over time), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and emergency access procedures);

and

1v. The imposit ion of appropriate sanctions of workforce members of Business

Associate for violations.

b. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.

c. Limit access to PHI through workstations and other devices, including access through mobile devices.8

d. Employ media controls covering the movement of devices containing PHI within or outside of the BA's facility as well as the disposal and reuse of media containing PH1.

3. Business Associate agrees to report, to the extent required by law, the Contract, and this

Agreement, to Covered Entity any use or disclosure of PHI not provided for by this Agreement which it discovers, including breaches of unsecured PHI as required at 45 C.F.R. § 164.410, and any security incident of which it becomes aware, including those of its agents and subcontractors. The Business Associate shall report, to the extent required by law, the Contract, and this Agreement, any violation in use or disclosure involving PHI, any security incidents, and any breaches involving unsecured Pl II to Covered Entity (designated WTC Health Program point of contact for HIPAA concerns) within ten (10) business days of discovery. Notification must be made in writing by email to the NIOSH HIPAA Privacy Officer. Upon reporting of a potential breach by Business Associate, Covered Ent ity may engage B u s in es s Associate in coordinating notification actions.

a. Notice of unsuccessful security incidents. Covered Entity acknowledges and agrees that this section constitutes notice by Business Associate of the ongoing existence and occurrence of attempted but unsuccessful security incidents. No addition<1l notice to

2 See 45 C.F.R. § 164.30!!(a)(l)(i).

) See 45 C.F.R. § 164.308(a)( I )(ii)(A) and (B).

4 See 45 C.F.R § 164.308(a)(l)(ii)(D) and (a)(8).

s See 45 C.F.R. § 164.308(a)(3) and (4); 45 C.F.R. § 164.312(a)(2).

6 See 45 C.F.R. § 164.308(a)(l)(ii)(C).

'See 45 C.F.R. § 164.310(a)(J).

See 45 C.F.R. § 164.310(b), (c), and (d).

See 45 C.F.R. § 16'1.31 O(d).

10 "Security incident" is defined as the "attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system." 45 C.F.R. § 164.304.

1/10/2014 (revision 0)

Covered Entity shall be required with respect to such unsuccessful security incidents, which include, but are not be limited to, pings and other broadcast attacks on Business

Associate's firewall, port scans, unsuccessful log-on attempts, denials of service and any combination of the above, so long as no such incident results in unauthorized acquisition, access, use or disclosure of PHI.

4. Business Associate agrees to ensure, in accordance with 45 C.F.R. § 164.502(e)(l)(ii) and, if applicable, 45 C.F.R. § 164.308(b)(2), that any agents or subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree through a written contract or other arrangement to the same restrictions, conditions, and requirements that apply to Business

Associate with respect to such information.

5. Business Associate agrees to provide access, at the request of Covered Entity, to PHI in a designated record set to Covered Entity or, as…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .