Questions.pdf

PDF 167 KB Posted

Attached to
HIPAA Privacy and Security Policy Services Federal contract opportunity
Solicitation number
2015-Q-17159
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Pittsburgh

About this file

Responses to Questions.

View the file

Other files for this federal contract opportunity

Other files attached to HIPAA Privacy and Security Policy Services, newest first.
File Type Posted
Relevant_Contracts_Reference_Sheet.docx DOCX document
Solicitation_2015-Q-17159.pdf PDF
HHSA_Security_Compliance.docx DOCX document
Supplemental_Instructions.pdf PDF
QASP.pdf PDF
Client_Authorization_Letter.docx DOCX document
Past-Present_Performance_Questionnaire.docx DOCX document
ACH-Vendor.pdf PDF
PWS_HIPAA_05.04.15.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Questions & Answers:

Q1: Will the World Trade Center Health Program accept equivalent experience and relevant certifications in lieu of the CHP and CHPS credentials?

A1: No. Per the Performance Work Statement (2.2) certification in CHP or CHPS for at least 5 years is required.

Q2: Can a company with less than 2 years of experience submit a proposal?

A2: Per the Performance Work Statement (2.2) certification in CHP or CHPS for at least 5 years is required.

Q3: Is this a follow-on requirement?

A3: No.

Q4: Is this a new requirement?

A4: Yes.

Q5: Is there an incumbent for this work?

A5: No.

Q6: The document HHS Security Compliance indicates that the contract involves hosting and maintaining a system for data collection and that all responses would require a draft System Security Plan (SSP). Is this applicable to this solicitation? If so, please provide information about the specifications for the information system.

A6: All data collected will be stored and maintain by the government.

Q7: The PWS, Section 1.2- Scope, indicates that the work will include support investigating and addressing

HIPAA breaches (to include breach incident procedures).” In order to estimate the LOE for this task, will the government please share the number of reported breaches (to include incidents that were determined not to be breaches) by WTCHP in the last two years?

A7: In 2014 7 incidents were reported. Of the 7, 4 incidents were determined not to be a breach. Information is not available before January 1, 2014.

Q8: The PWS, Section 2.2.1- Privacy and Security Support, indicates that the contractor will develop and deliver education and awareness materials to support the annual Privacy and HIPAA training. In order to estimate the LOE for this task, will the government advise on the timing (i.e., month of the year) for this annual training?

A8: It is the expectation of the Program to have the annual HIPAA Privacy and Security training delivered before

December 31, 2015.

Q9: The PWS, Section 2.2- Contractor Experience and Credentials, states that the Contractor have the required relevant experience and credentials…” for this requirement, does “contractor” refer to an individual or company?

Assuming a teaming arrangement, may the sub-contractor hold these credentials or must the credentials be held by the prime?

A9: The experience requirement refers to a Subject Matter Expert (individual position), which can be held by either the prime or a subcontractor.

Q10: The PWS, Section 2.2- Contractor Experience and Credentials, (d) requires “experience with HIPAA Privacy and Security Program or Policy for at least 10 years.” Will the government confirm that the labor category requirements are accurate? The HIPAA Privacy and Security Program is barely 10 years old.

A10: The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security and breach notification rules have been in place more than 10 years.

Q11: Per our industry research, there is no Certification in Healthcare Privacy (CHP). Instead, there is Certified

HIPAA Professional (CPA) and Certified HIPAA Administrator (CHA).

A11: CHPS is the acronym for “Certified in Healthcare Privacy and Security” and the CHPS credential: Denotes competence in designing, implementing, and administering comprehensive privacy and security protection programs in all types of healthcare organizations; Demonstrates a choice to focus and advance by specializing in the privacy and security dimensions of Health Information Management (HIM); and Shows a commitment to advancing privacy and security management practices and lifelong learning and professional development.

Q12: Will the government accept any substitute certifications for this requirement?

A12: No, Per PWS (2.2), certification in CHP or CHPS for at least five years required.

Q13: How many FTEs does the Government require to meet these HIPAA and Privacy Act Policy requirements?

A13: The number of FTEs proposed is at the discretion of the offeror.

Q14: Does the agency have current HIPAA policies and procedures, a risk assessment framework/template, and forms/documentation for breach reporting, or will the Contractor be responsible for developing these initial documents?

A14: The WTCHP HIPAA Risk Assessment Team has in place WTCHP HIPAA policies and procedures, which includes a risk assessment framework/template, etc.

Q15: Why is this effort 18 months in duration? How does the agency anticipate meeting these requirements thereafter?

A15: The requirement for continued HIPAA support services will be reevaluated at the end of 18 months.

Q16: Is the Contractor expected to only assist with breach notification, or does the agency intend the Contractor to be responsible for all aspects and related expenses associates with any and all breaches? Will the contractor be legally liable for any breaches? Is the Contractor responsible for establishing a call center? Notification by letter, phone, mass media? Providing credit monitoring services? Providing forensic investigations?

A16: The offeror will be expected to deliver the activities as listed in the PWS.

Q17: Does the Prime have to meet all the requirements or can they be met through a subcontractor.

A17: The PWS requirements can be met either through a prime or subcontractor.

Q18: Would the Government please confirm that the experience and credential requirements listed in the PWS are for proposed contractor staff and not the company itself (i.e., a company cannot be CHPS certified)?

A18: The experience requirement refers to a Subject Matter Expert (individual position).

Q19: Approximately how many employees/others will receive training through this program? Approximately how many beneficiaries will require their PHI and PII to be safeguarded by this program?

A19: The WTCHP and selected HHS offices ( to the extent that they perform activities related to the WTCHP, have been designated as health care components of the Department of Health and Human Services (HHS). As health care components under the HHS HIPAA designation, the listed offices (8), to the extent that they perform activities related to the WTC Health Program, will need to comply with applicable provisions in the HIPAA regulations (45 C.F.R. Parts 160, 162, and 164) and take steps to prevent the occurrence of HIPAA violations. They will also be required to participate in trainings on HIPAA conducted by WTC Health Program staff. The designation of these offices as HHS health care components will prevent a potential disruption in the day-to-day operations of the WTC Health Program and the Department by allowing the WTC Health Program and the listed offices to share relevant PHI without the need for obtaining special authorizations from individual members of the Program.

Q20: What location in Washington, DC and Atlanta, GA does the Government anticipate having the Contractor work? How will it be determined which location the Contractor will be required to report to? May Contractor staff work off site, or will they be required on the Government site at all times? Will GFE be provided?

A20: The National Institute for Occupational Safety and Health (NIOSH) has offices located in several states. Members of the WTCHP HIPAA risk assessment team are primarily located in Washington D.C. and Atlanta, GA. The offeror will be required to work off site to perform the PWS requirements. At the discretion of the Government, face-to-face meetings may be required on a Government work site.

Q21: How many HIPAA, Privacy Act, E-Government Act, and FISMA inquiries does the Government anticipate

Contractor handling per day?

A21: In 2014 7 incidents were reported. Of the 7, 4 incidents were determined not to be a breach. Information is not available before January 1, 2014.

Q22: How many systems of record does the Government have? Does each SOR currently have a published SORN? Will the Contractor assist with initial SORNs and renewals/amendments?

A22: This question is not applicable to this requirement.

Q23: Will the contractor be limited to the options available for delivering the training (e.g., written documentation, video, particular LMS, game, class room)? Will Contractor be expected to provide the training platform (e.g. LMS), content, and administration?

A23: The offeror will be expected to deliver both class room style training and web based training. It is the expectation of the Program to have the annual HIPAA Privacy and Security training delivered before December

31, 2015.

Q24: Will the Government provide an estimated man-years Level of Effort (LoE) to assist in competitive staffing and pricing?

A24: The LoE proposed is at the discretion of the offeror.

Q25: Will the Government consider a response extension as response to these questions would significantly impact response?

A25: Yes.

Q26: Will the contractor be provided administrative support of any kind in connection with this contract (e.g., clerical, etc.)?

A26: No.

Q27: Should training modules involve video/graphic art production? Will governmental resources be available?

Will those services be expected of the contractor?

A27: It is the discretion of the offeror how art production is incorporated to the training modules. Additional

Government resources will not be available.

Q28: How many electronic information collections (e.g. IT systems) does the Government have? Does each system currently have a published PIA?

A28: This question is not applicable to this requirement.

Q29: Will Contractor assist with initial PIAs and renewals?

A29: This question is not applicable to this requirement.

Q30: Is the Contractor required to maintain documentation of training administered? Will the Contractor be required to directly advise personnel when they are due recurring training or will this function be performed by the Government?

A30: A designated Government official will communicate training requirements. All data collected will be stored and maintain by the government.

Q31: Is the Contractor responsible for supporting research initiatives and the related privacy and security implications?

A31: No.

Q32: Please describe the extent and purpose of any anticipated travel requirements.

A32: The National Institute for Occupational Safety and Health (NIOSH) has offices located in several states. Members of the WTCHP HIPAA risk assessment team are primarily located in Washington D.C. and

Atlanta, GA. The offeror will be required to work off site to perform the PWS requirements. At the discretion of the Government, face-to-face meetings may be required on a Government work site.

Q33: Are other healthcare-related security and privacy certifications besides CHP and CHPS acceptable (such as a Juris Doctorate, CIPP, or CISSP)?

A33: Per PWS (2.2), certification in CHP or CHPS for at least five years required.

Q34: What is the scope of the program's data sharing needs (e.g., numerous hospitals, insurance companies, Business Associates, researchers, other Agencies, etc)?

A34: HHS and CDC offices and WTCHP Business Associates

Q35: Is there currently a HIPAA policy solution and HIPAA training solution that we would adapt or are you looking for innovation, and/or design development?

A35: It is the discretion of the offeror.

Q36: Will Contractor support any external reporting requirements related to the 9/11 Commission, Section 803, FISMA, SORNs, Complaints, or other SAOP reports?

A36: No.

Q37: Can we offer alternatives on how to complete this work?

A37: It is the discretion of the offeror.

Q38: Request list of items, schedule of requirements, scope of work, terms of reference, bill of materials required.

A38: Please review the Performance Work Statement as well as all Questions & Answers.

Q39: Request soft copy of documents through email.

A39: All necessary documents are available for download via FBO.

Q40: Names of countries eligible to participate.

A40: This is a total small business set-aside, US domestic.

Q41: Information about the procedure and guidelines.

A41: This requirement is being solicited utilizing FAR Part 13.5, Simplified Acquisition Procedures, Test Program for Certain Commercial Items.

Q42: Request estimated budget.

A42: It is the discretion of the offeror as to what budget to propose.

Q43: Request addendum or pre bid meeting minutes.

A43: All documents are available on FBO. The Questions & Answers document is the only additional addendum item. There was no pre bid meeting.

Q44: How many locations (outside of DC and Atlanta) will be assessed under this engagement? Where are they located?

A44: The National Institute for Occupational Safety and Health (NIOSH) has offices located in several states. Members of the WTCHP HIPAA risk assessment team are primarily located in Washington D.C. and

Atlanta, GA.

Q45: Do you have an estimated number of systems and applications which create, receive, process or transmit ePHI?

A45: The WTCHP and selected HHS offices ( to the extent that they perform activities related to the WTCHP, have been designated as a health care components of the Department of Health and Human Services (HHS). As health care components under the HHS HIPAA designation, the listed offices (8), to the extent that they perform activities related to the WTC Health Program, will need to comply with applicable provisions in the HIPAA regulations (45 C.F.R. Parts 160, 162, and 164) and take steps to prevent the occurrence of HIPAA violations. They will also be required to participate in trainings on HIPAA conducted by WTC Health Program staff. The designation of these offices as HHS health care components will prevent a potential disruption in the day-to-day operations of the WTC Health Program and the Department by allowing the WTC Health Program and the listed offices to share relevant PHI without the need for obtaining special authorizations from individual members of the Program. The Computer Sciences Corporation (CSC) creates, receives, processes and transmits medical claims data on behalf of the WTCHP. The National Government Services, contractor for the Center for

Medicare and Medicaid Services (CMS), process medical and pharmacy payments to WTCHP providers.

Q46: Is it expected that the Contractor is going to create and document a comprehensive listing of the systems and applications which create, receive, process or transmit ePHI? If so, is this high level in nature or is the

Contractor expected to use automated tools in the discovery of ePHI?

A46: The offeror is not expected to perform a comprehensive listing of the systems and applications that create, receive, process or transmit ePHI.

Q47: Is there a central IT department for WTCHP?

A47: WTCHP has an IT team but relies on the centralized CDC IT department for most IT related services.

Q48: Is there a unified set of Information Security policies and procedures, including physical security policies and procedures, which are implemented across the WTCHP departments?

A48: Yes. Across the WTCHP we comply with FISMA. We are currently using NIST special publication 800-53

Revision 3. We are upgrading to Revision 4 currently and should be finished in the next couple of months.

Q49: Have any other privacy or security policies or procedures been created to support HIPAA compliance to date? Or will the Contractor be developing all policies?

A49: Yes. The offeror will review policies.

Q50: What will be the WTCHP’s process for reviewing and approving the policies drafted by Contractor during the course of the engagement?

A50: The WTCHP risk assessment team will review and approved proposed polices.

Q51: Are there any budget or time constraints for this project that the Contractor should be aware of?

A51: Relevant information is included in the solicitation.

Q52: Will there be a single project manager or point of contact for all departments/divisions to provide requested documentation and assist with interview scheduling?

A52: Yes. The Contracting Officer Representative (COR)/ Project Officer.

Q53: Will the WTCHP HIPAA RAT team serve as the primary point of contact as a team?

A53: The WTCHP HIPAA RAT will respond to requests from the COR.

Q54: How many individuals serve on the WTCHP HIPAA RAT team.

A54: Eight to ten members make up the WTCHP HIPAA RAT. All WTCHP HIPAA RAT members directly support the WTCHP.

Q55: Is vendor/subcontractor management centrally managed?

A55: The WTCHP has contractual relationships with 7-Clinical Centers of Excellence (CCEs), 3-Data Centers, and

1-Nationwide Provider Network (NPN).

Q56: Does the WTCHP HIPAA RAT team manage the business associate process and maintain an inventory of business associates?

A56: Copies of Business Associate Agreements are on file with the WTCHP HIPAA RAT team.

Q57: Has WTCHP experienced any unauthorized disclosures to date?

A57: Yes.

Q58: If so, does a standardized process for receiving and investigating reports of unauthorized disclosures, and reporting breaches when necessary, exist?

A58: Yes.

Q59: Do these processes vary by department/division, or are they centralized?

A59: No.

Q60: Will the Contractor be using WTCHP’s online training platform in the development of HIPAA web based training?

A60: No.

Q61: How many employees and business associates will be expected to take the web-based training?

A61: See Q19 & A19.

Q62: Will any training be provided in-person to employees at the WTCHP sites in Washington, DC or Atlanta, GA, or to business associates at their offices elsewhere?

A62: Yes, the exact number of in-person training sessions has not yet been determined. However, the number of in-person training sessions will be less than 10 in the first year of the contract.

Q63: Who is expected to own the hardware and software that hosts the online training both initially and ongoing?

A63: All hardware and software that hosts the online training will be owned and hosted by CDC\NIOSH initially and ongoing.

Q64: The PWS, Section 2.1.2- Key Elements of Risk Analysis, “Evaluate if the WTCHP and Business Associates are complying with HIPAA Privacy and Security Rules and Breach Notification standards, in accordance with the Business Associate Agreements (BAAs).” Does this statement mean that all business associates must be assessed

(onsite or remote) by the contractor when completing the HIPAA Privacy and Security Risk Assessment for WTCHP? Or would you prefer a sampling approach?

A64: All Business Associates will not be assessed on site or remotely by the contractor. The offeror will receive information from the WTCHP HIPAA RAT.

Q65: The PWS, Section 1.2- Scope “Investigate and address WTCHP HIPAA breaches (to include breach incident procedures).” Is the intent of this to review the process by which WTCHP conducted its breach notification risk assessments for past incidents?

A65: Yes.

Q66: Will the Contractor be investigating and assessing past incidents as well as incidents that arise during the engagement period?

A66: The Offeror will be expected to review past incidents as part of the risk analysis report.

Q67: Will a Privacy Risk Assessment be included within the “Risk Analysis Report”?

A67: Yes.

Q68: Will the government consider extending the deadline for submissions to allow for bidders to receive and review the responses to these questions?

A68: Yes.

File details come from the government source that posted it. Updated .