PWS_HIPAA_05.04.15.pdf
PDF 590 KB Posted
- Attached to
- HIPAA Privacy and Security Policy Services Federal contract opportunity
- Solicitation number
- 2015-Q-17159
About this file
PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions.pdf | ||
| Past-Present_Performance_Questionnaire.docx | DOCX document | |
| ACH-Vendor.pdf | ||
| Relevant_Contracts_Reference_Sheet.docx | DOCX document | |
| Solicitation_2015-Q-17159.pdf | ||
| HHSA_Security_Compliance.docx | DOCX document | |
| Supplemental_Instructions.pdf | ||
| QASP.pdf | ||
| Client_Authorization_Letter.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HIPAA Privacy and Security Policy Services
PWS
Performance Work Statement
HIPAA Privacy and Security
Policy Services
World Trade Center Health Program (WTCHP)
Table of Contents
1. DESCRIPTION OF SERVICES
1.1 Background
1.2 Scope
1.3 Non-personal Services
1.4 Definitions
1.5 Acronyms
2. SUMMARY OF REQUIREMENTS
2.1 Specific Requirements
2.1.1 Privacy Support
2.1.2 Complaint Resolution
2.1.3 Reporting Requirements Coordination
2.1.4 Policy Consultancy
2.1.5 Point of Contact
2.1.6 Policy Change Recommendations
2.1.7 Information Privacy Management
2.1.8 HIPAA Training
2.1.9 Meeting Attendance
2.1.10 General Communications Requirements
2.2 Contractor Experience and Credentials
2.3 General Requirements
2.3.1 Continuation of Services
2.3.2 Vacancies
2.3.3 Professionalism
2.4 Deliverables/Reporting Requirements
2.4.1 Quarterly Report
2.4.2 Monthly Status Report (MSR)
2.4.3 Quality Control Plan
2.4.4 General Guidance for Deliverables
2.4.5 COR Review of Contractor Deliverables
2.5 Services Summary and Method of Surveillance
2.6 Government Furnished Property/Information (GFP/GFI)
2.6.1 Documents
2.6.2 Local Area Network (LAN)
2.6.3 Workspace
2.7 Security Procedures
2.7.1 Security Provisions
2.7.2 Appointment with CDC Security Office…………
2.7.3 SF-85P (Public Trust)
2.8 Travel
2.8.1 Travel Reimbursement
2.8.2 Travel Guidance
2.8.3 Trip Report
2.9 Place of Performance
2.10 Work Schedule
2.10.1 Period of Performance
2.10.2 Hours
2.10.3 Scheduled Holidays
2.10.4 Facility Closures
2.11 Privacy of Information
2.11.1 Privacy Act of 1974
2.11.2 Need to Know
3.0 Applicable Publications
3.1 WTC Health Program Policies
APPENDIX A: Business Associate Agreement
1. DESCRIPTION OF SERVICES
1.1 Background
On November 13, 2012, the Department of Health and Human Services (HHS) designated the Centers for
Disease Control and Prevention (CDC) National Institute for Occupational Safety and Health (NIOSH), Office of the Director (OD), to the extent that it performs activities related to the World Trade Center Health Program
(WTCHP), a Health Care component of HHS pursuant to the Health Insurance Portability and Accountability
Act (HIPAA) of 1996. The WTC Health Program was established by Title I of the James Zadroga 9/11 Health and Compensation Act of 2010 (Zadroga Act), P.L. 111-347, to provide and pay for medical, monitoring, and treatment for eligible responders and survivors of September 11, 2001 terrorist attacks.
In accordance with its designation as a “Health Care component” the WTCHP must comply with the requirements of HIPAA regulations (45 C.F.R. 160, 162, and 164). The HIPAA regulations P.L. 104-191 (as amended), and its implementing regulations, 45 C.F.R. , Parts 160, 162, and 164 set parameters for the use and disclosure of protected health information by certain entities, referred to as “covered entities” and their business associates. To implement the HIPAA Rules, the WTCHP executed legal agreements (Business
Associate Agreement) with its WTCHP components (Contractors) that creates, receives, maintains, or transmits PHI on behalf of the Covered Entity (WTCHP) or in providing a service for the WTCHP that involves the use or disclosure of PHI. The Business Associate Agreements outlines responsibilities and obligations for compliance with HIPAA and the handling of PHI. Also, the WTCHP generated the “Notice of
Privacy Practices (NPP) document that describes how an individual’s PHI may be used/disclosed and outlines individual privacy rights, describes Covered Entity obligations under the HIPAA Privacy Rule, and outlines the process for filing a complaint. The WTCHP NPP is located at:
http://www.cdc.gov/wtc/pdfs/NPP%20_%20Full%20Page_%20WTC%20Health%20Program.pdf
For more information about the World Trade Center Health Program (WTCHP), see the NIOSH website:
http://www.cdc.gov/wtc
In an effort to fully comply with the HIPAA regulations and meet the increased demands of HIPAA, the
WTCHP, administered by the NIOSH, created a HIPAA Privacy and Security Risk Assessment Team (RAT).
The primary focus of the team is to serve as the focal point for HIPAA compliance issues, in support of the
WTC Health Program and all WTCHP Contractors. The team coordinates efforts through the HHS Office of
General Counsel (OGC). This interface includes Privacy Act issues/concerns, as well as HIPAA Privacy and security issues/concerns, to include breach notifications.
1.2 Scope
The objective of this requirement is for a single Contractor to assist the WTCHP with its HIPAA compliance goals and with the development of a WTCHP health information privacy and security training manual pursuant to HIPAA regulations for the following rules:
a. The Privacy Rule at 45 CFR Part 160 and Sub part A and E of Part 164.
b. The Security Rule at 45 CFR Part 160, 162 and Subparts A and C of Part 164.
c. The Breach Notification Rule at 45 CFR §§ 164.400-414.
http://www.cdc.gov/wtc/pdfs/NPP%20_%20Full%20Page_%20WTC%20Health%20Program.pdf http://www.cdc.gov/wtc
In support of this scope objective, the Contractor is expected to:
a. Conduct a comprehensive HIPAA risk analysis of the WTCHP.
b. Review and update HIPAA policies for the WTCHP.
c. Develop and conduct WTCHP Health Information Privacy and Security training (including the development of a training manual).
d. Investigate and address WTCHP HIPAA breaches (to include breach incident procedures).
e. Review and update the HIPAA Privacy web page.
f. Serve as a consultant to the WTCHP Privacy and Security Officers on HIPAA issues.
1.3 Non-personal Services
The Government will neither supervise the Contractor nor control the method by which the
Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for the Contractor. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are personal services, or give the perception of personal services. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s responsibility to notify the CO, immediately. These services shall not be used to perform work of a policy/decision making or management nature, i.e., inherently Governmental functions.
All decisions relative to programs supported by the Contractor shall be the sole responsibility of the
Government.
1.4 Definitions
“Accurately developed”: This term defines products and deliverables developed by the Contractor that need no corrections or further editing by either the Contracting Officer (CO) or the Contracting Officer’s
Representative (COR).
“Advisory and assistance services”: Services provided under contract by non-governmental sources to support or improve organizational policy development, decision-making; management and administration, program and/or project management and administration, or Research and Development activities. It can also be defined as professional advice or assistance rendered to improve the effectiveness of federal management processes or procedures (including those of an engineering and technical nature). In rendering the foregoing services, deliverables may take the form of information, advice, opinions, alternatives, analyses, evaluations, recommendations, training, and the day-to-day aid of support personnel needed for the successful performance of ongoing federal operations.
“Business Day”: Dates listed as business days are government working days (Monday through Friday except government holidays). All days referenced in this PWS that are not prefaced by “business” are considered to be calendar days.
“Contracting Officer’s Representative (COR)”: The individual(s) designated to perform quality assessment functions. They serve as on-site technical managers assessing the Contractor’s performance against contract performance standards.
“Contractor”: The Contractor is an independent entity and responsible for its own liability.
Contractor, when the word is capitalized, is a company and not an individual.
“National Agency Check with Inquires”: NACI is the type of personnel security investigation that the
Government conducts for the FTE performing under this contract. The Contractor performing the requirements under this contract is in a public trust position and requires a suitability determination and not an investigation for a security clearance higher than Unclassified.
“On Site”: On-site means at a Government’s facility (CDC NIOSH locations).
“Performance Threshold”: The minimum level of acceptable performance that the Contractor must meet in order to be considered satisfactory.
“Performance Work Statement (PWS)”: A statement of work for performance-based acquisitions that describes the required results in clear, specific, and objective terms with measurable outcomes.
“Services Summary”: A summary of the performance objectives and the performance thresholds required by the Government in evaluating the Contractor’s performance.
“Supported Entities”: Includes but is not limited to: HHS, CDC, NIOSH, and WTC Health
Program.
1.5 Acronyms
Acronym Definition
AQL Acceptable Quality Level
BAA Business Associate Agreement
CCE Clinical Centers of Excellence
CDC Centers for Disease Control and Prevention
CDD Certificate of Data Disposition
CFR Code of Federal Regulations
CHP Certification in Healthcare Privacy
CHPS Certification in Healthcare Privacy and Security
CO Contracting Officer
COB Close of Business
COR Contracting Officer’s Representative
DOB Date of Birth
DOJ U.S. Department of Justice
DSA Data Sharing Agreement
DUA Data Use Agreement e-QIP Electronic Questionnaires for Investigations Processing
FAR Federal Acquisition Regulation
FDNY Fire Department of New York City
FOIA Freedom of Information Act
FSS Federal Supply Schedule
FTC Federal Trade Commission
GAO Government Accountability Office
GFI Government Furnished Information
GFP Government Furnished Property
GSA General Services Administration
HHC NYC Health and Hospitals Corp. (Survivor Program)
HHS Department of Health and Human Services
HIPAA Health Insurance Portability and Accountability Act
ID/IQ Indefinite Delivery/Indefinite Quantity
LAN Local Area Network
Acronym Definition
LIJ/Q Long Island Jewish/Queens
MSR Monthly Status Report
MSSM Mount Sinai School of Medicine
NIOSH National Institute for Occupational Safety and Health
NACI National Agency Check and Inquiries
NDA Non-Disclosure Agreement
NPP Notice of Privacy Practices
NPN Nationwide Provider Network
NYU New York University, Bellevue Hospital
OCR HHS Office of Civil Rights
OGC Office of General Counsel, HHS
OMB Office of Management and Budget
PGI Procedures, Guidance, and Information
PM&A Program Management and Administration
PHI Protected Health Information
PIA Privacy Impact Assessment
PII Personally Identifiable Information
PoP Period of Performance
PWS Performance Work Statement
RAT Risk Assessment Team
RU Rutgers University (New Jersey)
SORN System of Record Notice
SSN Social Security Number
SUNY State University of New York
TR Trip Report
VCF The DOJ’s‘ September 11th Victims Compensation Fund
WTCHP World Trade Center Health Program
2. SUMMARY OF REQUIREMENTS
2.1 Specific Requirements
The Contractor shall provide HIPAA Privacy and Security Policy services while performing the requirements of this contract. The Contractor shall perform the following tasks.
2.1.1 Privacy and Security Support
The Contractor shall develop a Health Information Privacy and Security training manual pursuant to 45
C.F.F. § 164.308 (a covered entity or business associate must implement policies and procedure to prevent, detect, contain, and correct security violations; including implementing a security awareness and training program for all members of its workforce (including management).
● Ensure WTCHP policies and business practices comply with federal laws, regulations, and guidelines governing the privacy and security of PII/PHI, and in the development and in the development of
HIPAA regulations, instructions, policies and procedures.
● Provide guidance on the management and evaluation of potential risks and threats to the privacy and security of WTCHP members’ health information by performing a comprehensive review through:
- Evaluation of the privacy and security posture of the WTCHP by conducting the conducting a
HIPAA required Security Risk Assessment
- Conduct a performance of Compliance Risk Assessment throughout the WTCHP to evaluate Privacy and HIPAA compliance
- Establish an organization performance metrics to identify and measure potential compliance risks
- Evaluate the WTCHP data sharing processes between business associates and the
Interagency Agreement between the HHS/CDC/NIOSH/WTCHP and the U.S.
Department of Justice September 11th Victims Compensation Fund (VCF)
- Engage WTCHP workforce, including contractors, by developing and delivering education and awareness materials and annual Privacy and HIPAA training
- Provide recommendation on fully implementing applicable provisions of Privacy
Act, and the E-Government Act
The training and awareness materials should contain key privacy and security information pursuant to
HIPAA privacy, security and breach notification rules that will help the WTCHP workforce, stakeholders, and Contractors to understand the complex HIPAA privacy and security requirements.
2.1.2 Key elements of risk analysis: The Contractor risk analysis shall include the following:
● Identify and document reasonably anticipated and potential threats specific to the WTCHP HIPAA operating environment
● Identify vulnerabilities, which, if exploited by a threat, would create a risk of an inappropriate use or disclosure of ePHI
● Determine and document the potential impact and risk of potential risks to the confidentiality, integrity, and availability of ePHI
● Assess existing security measures
● Evaluate if the WTCHP and Business Associates are complying with HIPAA Privacy and Security
Rules and Breach Notification standards, in accordance with the Business Associate Agreements
(BAAs).
2.1.3 Reporting Requirements
Any HIPAA reporting requirements mandated from HHS OCR shall be included in the training manual.
This may include notifications of actual or potential breaches of information or other high visibility issues due to the HIPAA Privacy and Security requirements.
2.1.4 Policy Consultancy
The Contractor shall perform as a HIPAA Privacy and Security policy consultant to the NIOSH/WTC Health
Program/RAT
2.1.5 Point of Contact
The Contractor shall perform as the WTC Health Program HIPAA Subject Matter Expert (SME)/ point of contact for the WTCHP HIPAA Privacy and Security Officers. As a Contractor, the Contractor does not establish or make policy, guidance or direction on behalf of any government entity
2.1.6 Policy Change Recommendations
The Contractor shall make recommendations for change and assist the Government with the development of
WTC Health Program HIPAA Privacy and Security policies and procedures to ensure compliance with the
HIPAA laws and regulations. The Contractor shall maintain current HIPAA Privacy knowledge and expertise with respect to applicable federal laws, accreditation standards, and service regulations and where necessary, make recommendations to the Government for change to existing policies, procedures, and instructions.
2.1.7 Information Privacy Management
The Contractor shall recognize and recommend best practices relative to the management of the privacy and security of health information. The Contractor shall understand the content of health information and privacy protection of such information in its clinical, research and business contexts. The Contractor shall recommend activities to foster information privacy and security awareness within the WTC Health
Program. The Contractor shall assist with the implementation of his or her recommendations, as approved by the Government.
2.1.8 HIPAA Training
The Contractor, in collaboration with NIOSH/WTC Health Program RAT, will create Privacy and Security
HIPAA training for WTC Health Program workforce, stakeholders, and Contractors, as required. The
Contractor shall develop training modules to support HIPAA Privacy and Security initiatives. Training modules shall be updated within 60 days of changes in law and/or policy changes. The Contractor shall also include a training module for newcomers to the WTC Health Program. The training/briefings module should be designed so that the training can be completed by a newcomer within 30 days of the newcomer’s employment by the WTC Health Program, or one of its Business Associates, if directed by the Program.
2.1.9 Meeting Attendance
The Contractor shall be required to attend various staff meetings and conference calls.
a. The Contractor may be asked to attend monthly WTCHP HIPAA RAT and HIPAA Privacy and
Security conference calls, which may include Privacy Act issues. The Contractor shall not chair or be a voting member while attending such meetings.
b. The Contractor shall work with the WTC Health Program HIPAA RAT in coordinating and conducting HIPAA conference calls with WTC Health Program Contractors.
2.1.10 General Communications Requirements
The Contractor shall reply to and respond to all forms of communications received (phone, email, etc.) with customers and supporting agencies by close of business (COB) the following business day the communication was received. The Contractor shall be able to read, understand, speak, and write English in order to maintain open and professional communication with members of the Government.
2.2 Contractor Experience and Credentials
The service is performance-based and the Government requires that the Contractor have the required relevant experience, and credentials throughout the contract’s period of performance.
As such, the Contractor shall have, at a minimum, the following experience and credentials.
a. Certification in Healthcare Privacy (CHP) or in Healthcare Privacy and Security (CHPS)for at least 5 years.
b. More than 2 years of experience working on HIPAA Privacy and Security issues within the healthcare environment.
c. Experience with other relevant federal rules and standards, e.g., the Privacy Rule, FISMA, etc.
d. Experience with the HIPAA Privacy and Security Program or Policy for at least 10 years.
e. Experience with strategic planning, workflow analysis, business process reengineering, problem resolution, and training and development in medical administration from an agency-level, or a strategic-level, or corporate-level operation.
f. Experience training/communicating/briefing at the corporate/senior leadership level.
g. Subject matter expertise in HIPAA Privacy practices and HIPAA security practices.
h. Comprehensive knowledge of the Privacy Act, HIPAA, and HHS OCR HIPAA guidelines.
i. Comprehensive knowledge of civilian healthcare accreditation standards relevant to HIPAA industry requirements and standards for healthcare plans.
2.3 General Requirements
2.3.1 Continuation of Services
The Contractor shall ensure continuation of services during personnel absences due to sickness, leave, and voluntary or involuntary termination from employment such that impact to the Government is minimal and position vacancies do not exceed 30 days.
2.3.2 Vacancies
The Contractor shall provide follow-up documentation within 72 hours after notification, stating the date and time the position will be vacant, and the reason for vacating the position, the anticipated replacement date of personnel, and what management corrective action will be taken to ensure contract mission completion.
2.3.3 Professionalism
When in Government facilities, the Contractor shall wear a company picture identification badge to distinguish him or herself from government employees. When conversing with Government personnel during business meetings, over the telephone or via electronic mail, the Contractor shall identify themselves as such. The Contractor shall identify him or herself as a Contractor on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation. The Contractor shall be required to observe all facility parking, safety and traffic regulations that apply to all government and facility employees.
2.4 Deliverables/Reporting Requirements
Deliverables associated with this contract are specified below. All deliverables shall be submitted to and agreed upon by the Government.
Title
Para
Delivery Date/Description
Comprehensive HIPAA Risk
Analysis Report
1.2 Draft – 90 days after contract award
Final – 150 days after contract award
WTCHP HIPAA Policies
Report
1.2 Draft – 120 days after contract award
Final – 180 days after contract award
Training Module(s)
Development and
Deployment Updates and
Implementation
2.1.8 Define the deployment plan and process involved with
implementing and beginning HIPAA web base training. The intended audience is the WTCHP workforce, stakeholders, and contractors---Draft – 90 days after contract award.
Production simulation testing of training module—150 days after contract award.
Initial implementation of training module –270 days after contract award.
Final implementation of HIPAA training modules, manual including CDs with detailed presentation on HIPAA Privacy and
Security rules—due 360 days after contract award
HIPAA privacy and security awareness training plan/training
Provide HIPAA privacy and security awareness training to
WTCHP staff members, stakeholders, and other NIOSH staff as applicable to achieve HIPAA privacy and security training requirements. Develop a HIPAA privacy and security training plan. An effective plan should include:
•Access, use, and disclosure of PII/PHI
•Safeguarding PII/PHI
•Breach reporting and complaint filing processes
•Comprehensive documentation (communications request, findings)
•Design poster(s) to promote awareness consistently to prevent violations and breaches.
•Develop retraining materials as part of mitigation strategy
Draft plan ---60 days after contract award
90 days after contract award--- Deliver HIPAA privacy and security training to WTCHP staff
120 days after contract award--- Deliver assessment of HIPAA training to WTCHP Risk Assessment Team.
Deliver training every 12 months.
Quarterly Reports 2.4.1 By the 10 th business day of the month following the quarter being reported. Content shall include the status of completion of the following: 1)Comprehensive HIPAA Risk Analysis Report, 2)
HIPAA Policies Report, 3) HIPAA Privacy and Security training modules, 4) HIPAA Privacy and Security support (2.1.1), 5) Key elements of risk analysis assessment (2.1.2), 6) Evaluation of
WTCHP breach reporting, 7) and the status of other ongoing tasks.
Monthly Status
Reports (MSR)
2.4.2 By the 5
th business day of the month being reported. Monthly status reports shall provide brief updates on status of tasks identified under Quarterly Reports.
Quality Control Plan
(QCP)
2.4.3 By the 5
th business day after contract award. Contents are in accordance with the requirements detailed in paragraph 2.4.3.
Trip Reports (TR) 2.8.3 By the 5 th business day after the last day of travel. At a minimum, content shall include items listed in para 2.83.
2.4.1 Quarterly Report
The Contractor shall be responsible for the production of quarterly reports, which will illustrate the status and completion of deliverables. The Contractor shall present the information included in the quarterly reports to the RAT, as required.
2.4.2 Monthly Status Report (MSR)
The Contractor shall ensure that a MSR is submitted outlining progress, status, risks and problems/issues encountered with recommended solutions, schedule changes, and identify any
Government dependencies that are overdue which are impacting schedule and/or performance of this contract. The report shall be presented at monthly In-Progress Reviews. It is expected that the report will include at a minimum:
A description of activities of the past month (summary of work accomplished during the reporting period and percent complete).
Schedule of activities planned and estimated date/time of completion.
A summary of the status of work initiatives and documentation updates.
A summary analysis of databases/spreadsheets used by the Contractor to track training/briefings performed, complaints received and resolved, consultancy services delivered, and other assistance provided to the WTCHP.
2.4.3 Quality Control Plan
The Contractor is responsible for contract management and quality control, not the Government. The
Contractor’s Quality Control Plan (QCP) is the means by which the Contractor assures itself that its work complies with the requirements of the contract. The Contractor shall develop and maintain an effective
QCP to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. Contractor shall submit a QCP no later than five (5) business days after contract award. The COR will provide a written notice of acceptance to the Contractor.
2.4.4 General Guidance for Deliverables
All deliverables shall be submitted to the COR. Unless otherwise stipulated, written deliverables will be phrased in layperson language. Statistical and other technical terminology will not be used without providing a glossary of terms. The Contractor shall be responsible for providing the deliverable in the media required by the COR for each submittal.
a. Delivery Written deliverables shall be submitted in paper copies (one copy) and in electronic format using the most current version of MS Office suite of applications (2013 as of the writing of this PWS).
Additionally, each final deliverable may need to be supplied in .pdf format, if directed by the
COR. It is the responsibility of the Contractor to ensure that all data transmitted via diskette or e-mail is virus-free and the data is protected.
b. Documentation The Contractor shall prepare all documentation to meet established standards of WTC Health
Program RAT: timeliness, legibility, and accuracy of content. Only WTC Health Program
RAT approved abbreviations may be used in documentation. All electronic and manual documentation shall be maintained by the Contractor. Documentation includes results of analysis and work plan designs.
2.4.5 COR Review of Contractor Deliverables
The COR will inspect, accept or reject deliverables. The COR will notify the Contractor of any required changes. Unless otherwise stipulated, the Contractor shall have five (5) business days to make adjustments and re-submit a deliverable.
2.5 Services Summary and Method of Surveillance
The Government shall use the following standards to determine Contractor performance and shall compare Contractor performance to the Acceptable Quality Level (AQL).
Requirement
Paras
AQL/Performance Threshold
(Performance is acceptable if…)
Surveillance/
Monitoring Method
Assist the WTC Health
Program HIPAA RAT with HIPAA compliance.
2.1.1 There are no more than five (5) HIPAA
deficiencies, to include late, missed, unaccomplished responses or suspenses, as substantiated by the COR, in any six
(6) consecutive- month period.
Deficiencies will be tracked using a spreadsheet.
WTCHP Concerns
Policy Consultancy 2.1.4 The Contractor provides policy consultant services via recommendations and analysis with no more than five (5) deficiencies, to include late, missed, unaccomplished responses or suspenses, as substantiated by the COR, in any six (6) consecutive-month period. Deficiencies will be tracked using a spreadsheet.
Task deliverables
Development and
Updates of Training
Manual
2.1.8 Training manual is updated within
60 days of changes in law, and accurately developed 90% of the time. Deliveries will be tracked using a spreadsheet.
100% Inspection by the
COR
HIPAA Privacy and
Security Annual
Refresher Training
2.1.8 The Contractor delivers the annual
refresher training 100% of the time.
Training accomplishment will be tracked using a spreadsheet.
100% Inspection by the
COR
Monthly Newcomer’s
HIPAA Orientation briefing
2.1.8 The Contractor shall include in the training
manual a monthly “Newcomers” HIPAA briefing/training. The training shall include the notification of an absence, if any, for any “Newcomers” not completing the training within the first 30 days of employment. The “Newcomers” training will be tracked using a spreadsheet.
100% Inspection by the
COR
Communication 2.1.10 The Contractor returns all forms of
HIPAA-related communications (phone, email, etc.) with supported agencies, Contractors, and WTCHP personnel by
COB of the following business day every day that the communication was received 90% of the time.
WTCHP workforce, Stakeholders, and
Business Associates
Complaints
Requirement
Paras
AQL/Performance Threshold
(Performance is acceptable if…)
Surveillance/
Monitoring Method
Quarterly Reports 2.4.1 Due by the 10 th business day of the month following the quarter being reported no less than 3 quarters per annual PoP. All deliverables delivered to the COR will be tracked by the COR.
100% Inspection by the
COR
Monthly Status
Reports (MSR)
2.4.2 Due by the 5th business day of the
month being reported 11 out of every
12 months. All deliverables delivered to the COR will be tracked by the COR.
100% Inspection by the
COR
Comprehensive HIPAA Risk Analysis Report 1.2
Draft – 90 days after contract award
Final – 150 days after contract award
100% Inspection by the
COR
WTCHP HIPAA Policies Report
1.2 Draft – 120 days after contract award
Final – 180 days after contract award
COR
Training Module(s)
Development and
Deployment Updates and
Implementation
2.1.8 Define the deployment plan and process
involved with implementing and beginning
HIPAA web base training. The intended audience is the WTCHP workforce, stakeholders, and contractors---Draft – 90 days after contract award.
Production simulation testing of training module—150 days after contract award.
Initial implementation of training module
–270 days after contract award.
Final implementation of HIPAA training modules, manual including CDs with detailed presentation on HIPAA Privacy and Security rules—due 360 days after contract award.
HIPAA privacy and security awareness training plan/training
Provide HIPAA privacy and security awareness training to WTCHP staff members, stakeholders, and other NIOSH staff as applicable to achieve HIPAA privacy and security training requirements. Develop a HIPAA privacy and security training plan. An effective plan should include:
•Access, use, and disclosure of PII/PHI
•Safeguarding PII/PHI
•Breach reporting and complaint filing processes
•Comprehensive documentation
(communications request, findings)
•Design poster(s) to promote awareness consistently to prevent violations and breaches.
•Develop retraining materials as part of mitigation strategy
Draft plan ---60 days after contract award
90 days after contract award--- Deliver
HIPAA privacy and security training to
WTCHP staff
120 days after contract award--- Deliver assessment of HIPAA training to WTCHP
Risk Assessment Team.
Deliver training every 12 months.
Trip Reports (TR) 2.8.3 Due by the 5 th business day after the last day of travel 90% of the time. All deliverables delivered to the COR will be tracked by the COR.
2.6 Government Furnished Property/Information (GFP/GFI)
The Contractor shall ensure accurate control and accountability of all GFP/GFI in accordance with the Government property clauses incorporated into the basic contract. The following
GFP/GFI will be provided to the Contractor, on-site.
2.6.1 Documents
The Government will furnish or make available to the Contractor any documentation/material deemed necessary to accomplish requirements of this contract. Documents include access to databases, reference materials, and policy documents.
2.6.2 Local Area Network (LAN)
Contractor with a valid National Agency Check and Inquiries (NACI) verified through the Contractor’s security manager will be provided access to the CDC computer network and its inherent capabilities including, but not limited to: internet access, electronic mail, file and print services, and dial-in network access. The Contractor shall be aware of and abide with all government regulations concerning the authorized use of the Government’s computer network. Time spent by the Contractor obtaining LAN access and attending government required network security training is properly chargeable under this contract.
2.6.3 Workspace
The Federal Government does not require a particular place of performance for accomplishment of the requirement. The intended acquisition is for provision of services which will not be performed on a
Government site. D u r i n g s i t e v i s i t s , the Government shall provide the Contractor with workspace amenities for the handicapped in accordance with Section 508 laws.
2.7 Security Procedures
Minimum facility and personnel clearance level required under this contract is Unclassified
(UNCLAS). No foreign national candidates shall be utilized within the scope of this contract without prior approval of the Government. In addition to the below and due to the nature of the work that the
Contractor will likely be exposed to, the Contractor shall sign and comply with all security requirements.
2.7.1 Security Provisions
The Contractor shall fully adhere to the provisions of the referenced publications by having each of their on-site employee submit the appropriate forms and maintain a favorable suitability determination to continue performing under this contract. Within five (5) days after the Period of Performance (PoP) start date, the Contractor shall submit on-site employee name, and contract number, required/prospective start date, and telephone contact number to the Contracting Officer (CO) and the Security Officer identified in the contract.
2.7.2 Appointment with CDC Security Office
The Contractor shall schedule an appointment with the CDC Security Office, if required.
2.7.3 SF-85P (Public Trust)
The Contractor shall ensure contractor personnel completes the SF-85P (Public Trust) in the Electronic
Questionnaires for Investigations Processing (e-QIP) after the Unit Security Manager contacts the contract personnel to establish an account in e-QIP Direct.
2.8 Travel
Travel shall comply with the basic contract. The Contractor shall be required to perform travel within the Continental United States (CONUS). The Contractor shall obtain authorization for travel from the COR, within two (2) days of planned travel. The Contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence.
2.8.1 Travel Reimbursement
All Contractor travel shall be in accordance with the Federal Travel Regulations, per Federal Acquisition
Regulation (FAR) 31.205-46. The Contractor must notify the Government when expenditures are 75% expended of travel costs. The Contractor shall travel using the lowest cost mode of transportation commensurate with the mission requirements. The estimated amount for cost reimbursable travel for this contract shall be reimbursed to the Contractor provided that all trips taken in the performance of this contract must have the written consent of the COR. Written consent may be provided through email.
Travel shall be reimbursed on a cost reimbursable basis; no profit or fee shall be paid. Reimbursement will be for actual cost.
2.8.2 Travel Guidance
When necessary to use air travel, the Contractor shall use economy class. If the Contractor elects to travel by another method other than air, the reimbursed costs shall be either those of the actual travel used or the cost for the most economical air fare, whichever is less.
a. Email the following information to the COR when seeking approval for travel:
o destination o dates o purpose o estimated cost of the trip broken down by airfare, lodging, car rental, taxi/parking, and other miscellaneous costs approved by the COR.
b. On site visits to the WTCHP Business Associates are not an immediate requirement during the performance period of this contract. The Contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence. Travel will be in accordance with HHS Travel
Regulations.
2.8.3 Trip Report
Trip Reports (TRs) shall be submitted within five (5) business days after trip completion. TR contents shall include:
o Supporting documents for each traveler (e.g., airline ticket/receipt, hotel invoice, per diem expenses) o Inclusive Dates of Travel o Destination o Purpose o Individuals Contacted o Brief Synopsis o Issues & Challenges o Recommendations o Signature Block
2.9 Place of Performance
The work to be performed under this contract will be primarily performed in Washington, DC Metropolitan
Area, and Atlanta, GA. All federal buildings are smoke-free facilities.
2.10 Work Schedule
2.10.1 Period of Performance
The anticipated period of this order shall be 18 months from July 1, 2015 through December 31, 2016.
2.10.2 Hours
Weekly hours shall not exceed a forty (40) hour work week and a typical work day will be eight (8) hours between 7:30am to 4:30pm local time, Monday through Friday. The Government reserves the right to change hours of operation. Work outside these daily hours is prohibited without CO approval.
2.10.2 Scheduled Holidays
New Year’s Day, Dr. Martin Luther King, Jr. Birthday, President’s Day, Memorial Day, Independence
Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.
2.10.3 Facility Closures
The Government will notify the Contractor of anticipated closure of the facility, (i.e., training, holidays, administrative leave granted to the entire staff, or other closure including down days) five (5) business days in advance or as soon as possible. In the event of unplanned closure of the facility due to natural disasters, emergency or severe weather, the Government will notify Contractor in the same manner as the
Government notifies its workforce.
2.11 Privacy of Information
The Contractor shall not release any personnel or medical/patient information during the course of this contract. The Contractor shall comply with information privacy guidance in Appendix A.
2.11.1 Privacy Act of 1974
The Privacy Act of 1974 (5 U.S.C. § 552a), which includes Public Law 100-503, must be treated as FOR
OFFICIAL USE ONLY.
2.11.2 Need to Know
Contractor shall provide patient information only to Government employees, Government
Contractor, and Subcontractors having a need-to-know such information in the performance of their duties for this contract.
3. Applicable Publications Publications and forms are available electronically through the internet. Publications and forms applicable to this PWS are coded as mandatory. The Contractor shall comply with mandatory publications and forms to the extent specified in this PWS. The Contractor shall be responsible for all updates, supplements, and amendments to mandatory documents through the life of this contract. Publications applicable to the PWS, include, but are not limited to, those listed below. The Contractor is obligated to follow all applicable publications. These publications are available online and are maintained by the
Government. Supplements or amendments to listed publications from any organizational level may be issued during the life of the contract.
3.1 WTC Health Program Policies
WTC Health Program policies can be found at http://www.cdc.gov/wtc/index.html. Consult this site for the latest changes.
http://www.cdc.gov/wtc/index.html
APPENDIX A
World T r a d e Center Health Program Business Associate Agreement
This Business Associate Agreement ("Agreement") is incorporated as an exhibit into the contracts entered into between the Centers for Disease Control and Prevention (CDC) on behalf of its component, the National Institute for Occupational Safety and Health (NIOSH), and X X X X X for the purposes of carrying out functions, services, and responsibilities related to the World Trade Center (WTC) Health
Program ("Contract"). This Agreement describes legal obligations and requirements of the Business
Associate and Covered Entity, including permitted and required uses and disclosures of protected health information by the Business Associate; it is executed pursuant to the requirements of 45 C.F.R. §§
164.502(e)(2) and 164.504(c)(l)-(2) and Contract term C.3.4.5. The scope of this Agreement includes all functions, services, and responsibilities included in the Contract which require the Business Associate to perform functions or activities on behalf of the Covered Entity where the Business Associate creates, receives, maintains, or transmit protected health information or where the Business Associate provides certain services to or for the Covered Entity which require the disclosure of protected health information to the Business Associate by the Covered Entity.
A. Definitions
All terms used herein and not otherwise defined shall have the same meaning as in the Health Insurance
Po1tability and Accountability Act of 1996 ("HIPAA") (Pub. L. 104-191; 42 U.S.C. § 1320d), as modified, and the corresponding implementing regulations, including the Privacy, Security, Breach
Notification, and Enforcement Rules (45 C.F.R. Pm1s 160, 162, and 164). Non-HIPAA related
Provisions governing the duties and obligations of the Contractor, XXXX such as those under the Privacy
Act and any applicable data use agreements, are covered elsewhere in the Contract between the parties governing the provision of WTC Health Program services and other Contract-related documents. The parties acknowledge that Business Associate provides direct and substantial hea l th care services to WTC
Health Program applicants and e n r o l l e e s . For the purposes of this agreement "treatment" is defined as the
"provision, coordination, or management of health care and related services" by a health care provider, including "coordination or management of health care with a third party; consultation b e t wee n health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another." (45 C.F.R. § 164.501). Fo r treatment related services that fall within the above referenced definition, "protected health information" (PHI) is expressly excluded from this agreement. All other work under the contract involving PHI not fitting this definition shall be included under this agreement.
‘Business Associate', shall generally have the same meaning as the term "business associate" at 45
C.F.R. § 160.103 and, for the purpose of this Agreement and the Contract, shall mean XXXX.
"Covered Entity" shall generally have the same meaning as the term "covered entity" at 45 C.F.R. §
160.103 and, for the purpose of this Agreement and the Contract, shall mean the WTC Health Program and any other NIOSH, CDC, or HHS components to the extent that they assist in administering the
WTC Health Program where protected health information is involved.
"Protected Health Information" (PH I) shall generally have the same meaning as the term "protected health infom1ation" at 45 C.F.R. § 160.103. The HIPA A regulations define PHI as individually identifiable health information (health information, including demographic information, collected from an individual and created or received by a health care provider, health plan, employer, or health care clearinghouse that relates to the individual's past, present, or future mental or physical health condition, provision of health care, or payment for care and which identifies the individual or is reasonably believed to make the individual identifiable) that is transmitted by electronic media, maintained in electronic media, or transmit1ed or maintained in any other form or medium. PHI excludes individually identifiable health information in certain education records, certain student medical records, employment records held by a covered entity in its role as employer, and records regarding a person who has been deceased for more than 50 years. The definition of PHI throughout this Agreement shall be limited to PHI relating to Business Associate functions, and shall exclude PHI relating to treatment services.
"Secretary" shall mean the Secretary of the Department of Health and Human Services or the Secretary's designee.
"Treatment' as defined by HIPAA is the provision, coordination, or management of health care and related services for an individual by one or more health care providers, including consultation between providers regarding a patient and referral of a patient by one provider to another.
B. Obligations and Activities of Business Associate
Business Associate, as well as its agents and subcontractors, shall meet all applicable HIPAA obligations. Furthermore, it shall document in writing the policies and procedures that will be used to meet such obligations. These obligations include the following:
l. Business Associate agrees to not use or disclose PHI other than as permitted or required by the
Contract or as required by Law.
2. Business Associate agrees to prevent use or disclosure of PHI other than as provided for by this
Agreement through use of appropriate safeguards and complying with Subpart C of 45 C.F.R.
The term "covered entity'' is used in this section for case of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:
HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates "health care components" in accordance with 45 C.F.R. §
164.105(a)(2)(iii)(D). 45 C.F.R. § 161.103. As a hybrid entity, H HS must designate any component that would "meet the definition of a covered entity or business associate if it were a separate legal entity" as a health care component; a health care component also may include a component only to the extent that it perfom1s covered functions. 45 C.F.R.§ 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a "health care component" of the covered entity, H H S a s are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions.
Part 164 with respect to electronic PHI. In accordance with 45 C.F.R. §§ 164.306 and 164.316, Business Associate shall implement written policies and procedures to:
a. Prevent, detect, contain, and correct security violations2 through the use of:
i. Risk analyses (including periodic technical and nontechnical evaluations);
ii. Appropriate risk management strategies (including information system activity review);
iii. Inf01mation access procedures for approving individual's access rights to PHI
(including the implementation of workforce security measures to ensure continued appropriate role-based access to PHI over time), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and emergency access procedures);
and
1v. The imposit ion of appropriate sanctions of workforce members of Business
Associate for violations.
b. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.
c. Limit access to PHI through workstations and other devices, including access through mobile devices.8
d. Employ media controls covering the movement of devices containing PHI within or outside of the BA's facility as well as the disposal and reuse of media containing PH1.
3. Business Associate agrees to report, to the extent required by law, the Contract, and this
Agreement, to Covered Entity any use or disclosure of PHI not provided for by this Agreement which it discovers, including breaches of unsecured PHI as required at 45 C.F.R. § 164.410, and any security incident of which it becomes aware, including those of its agents and subcontractors. The Business Associate shall report, to the extent required by law, the Contract, and this Agreement, any violation in use or disclosure involving PHI, any security incidents, and any breaches involving unsecured Pl II to Covered Entity (designated WTC Health Program point of contact for HIPAA concerns) within ten (10) business days of discovery. Notification must be made in writing by email to the NIOSH HIPAA Privacy Officer. Upon reporting of a potential breach by Business Associate, Covered Ent ity may engage B u s in es s Associate in coordinating notification actions.
a. Notice of unsuccessful security incidents. Covered Entity acknowledges and agrees that this section constitutes notice by Business Associate of the ongoing existence and occurrence of attempted but unsuccessful security incidents. No addition<1l notice to
2 See 45 C.F.R. § 164.30!!(a)(l)(i).
) See 45 C.F.R. § 164.308(a)( I )(ii)(A) and (B).
4 See 45 C.F.R § 164.308(a)(l)(ii)(D) and (a)(8).
s See 45 C.F.R. § 164.308(a)(3) and (4); 45 C.F.R. § 164.312(a)(2).
6 See 45 C.F.R. § 164.308(a)(l)(ii)(C).
'See 45 C.F.R. § 164.310(a)(J).
See 45 C.F.R. § 164.310(b), (c), and (d).
See 45 C.F.R. § 16'1.31 O(d).
10 "Security incident" is defined as the "attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system." 45 C.F.R. § 164.304.
1/10/2014 (revision 0)
Covered Entity shall be required with respect to such unsuccessful security incidents, which include, but are not be limited to, pings and other broadcast attacks on Business
Associate's firewall, port scans, unsuccessful log-on attempts, denials of service and any combination of the above, so long as no such incident results in unauthorized acquisition, access, use or disclosure of PHI.
4. Business Associate agrees to ensure, in accordance with 45 C.F.R. § 164.502(e)(l)(ii) and, if applicable, 45 C.F.R. § 164.308(b)(2), that any agents or subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree through a written contract or other arrangement to the same restrictions, conditions, and requirements that apply to Business
Associate with respect to such information.
5. Business Associate agrees to provide access, at the request of Covered Entity, to PHI in a designated record set to Covered Entity or, as…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .