RFP_updated.pdf
PDF 980 KB Posted
- Attached to
- Data Coordinating Center for the Centers for Disease Control and Prevention Federal contract opportunity
- Solicitation number
- 2016N17778
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RESPONSES_TO_QUESTIONS_RECEIVED_FOR_REQUEST_FOR_PROPOSAL_2016N17778.pdf | ||
| RFP.pdf | ||
| RFP_Part_1_of_2.pdf | ||
| RFP_Part_2_of_2.pdf | ||
| 2016N17778Attachments.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGES
15A. NAME
AND
ADDRESS
OF
OFFEROR
SEC. PAGE(S) SEC. PAGE(S)
(Date) (Hour)
CALENDAR DAYS
14. ACKNOWLEDGMENT OF AMENDMENTS
(The offeror acknowledges receipt of amend-ments to the SOLICITATION for offerors and related documents numbered and dated:
(Type or Print)
SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 700)
RATING
PAGE OF
1 72
2. CONTRACT NO.
3. SOLICITATION NO.
2016-N-17778
4. TYPE OF SOLICITATION
SEALED BID (IFB)
X NEGOTIATED (RFP)
5. DATE ISSUED
6. REQUISITION/PURCHASE
NO.
HCVJC5X2-2016-93540
7. ISSUED BY CODE 2536 8. ADDRESS OFFER TO (If other than Item 7)
Centers for Disease Control and Prevention
Acquisition and Assistance Branch 1
2920 Brandywine Road, MS E-15
Atlanta, GA 30341-5539
Approved as to Form and Legality: _____________________________
NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”
SOLICITATION
9. Sealed offers in original and copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in until 10AM local time
CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR INFORMATION
CALL:
A. NAME
Germaine Mullins
B. TELEPHONE (NO COLLECT CALLS)
AREA CODE NUMBER: EXT:
(770) 488-1938
C. E-MAIL ADDRESS
gmullins@cdc.gov
11. TABLE OF CONTENTS
(x) DESCRIPTION (x) DESCRIPTION
PART I – THE SCHEDULE PART II – CONTRACT CLAUSES
X A SOLICITATION/CONTRACT FORM 1 X I CONTRACT CLAUSES 48
X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X C DESCRIPTION/SPECS./WORK STATEMENT 4 X J LIST OF ATTACHMENTS 55
X D PACKAGING AND MARKING 28 PART IV – REPRESENTATIONS AND INSTRUCTIONS
X E INSPECTION AND ACCEPTANCE 29 REPRESENTATIONS, CERTIFICATIONS, AND
X F DELIVERIES OR PERFORMANCE 30 X K OTHER STATEMENTS OF OFFERORS 56
X G CONTRACT ADMINISTRATION DATA 35 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 62
X H SPECIAL CONTRACT REQUIREMENTS 39 X M EVALUATION FACTORS FOR AWARD 68
OFFER (Must be fully completed by offeror)
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52-232-8)
10 CALENDAR DAYS
20 CALENDAR DAYS
30 CALENDAR DAYS
AMENDMENT NO. DATE AMENDMENT NO. DATE
CODE FACILITY 16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER
15B. TELEPHONE NO.
AREA CODE NUMBER EXT.
15C. CHECK IF REMITTANCE ADDRESS
IS DIFFERENT FROM ABOVE - ENTER
SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE
18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
21. ACCOUNTING AND APPROPRIATION
10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( )
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
24. ADMINISTERED BY (If other than Item 7) CODE 2536 25. PAYMENT WILL BE MADE BY CODE 434
Centers for Disease Control and Prevention
Acquisition and Assistance Branch 1
2920 Brandywine Road, MS E-15
Atlanta, GA 30341-5539
Centers for Disease Control and Prevention (FMO)
PO Box 15580 404-718-8100
Atlanta, GA 30333-0080
26. NAME OF CONTRACTING OFFICER (Type or print)
27. UNITED STATES OF AMERICA
(Signature of Contracting Officer)
28. AWARD DATE
IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)
PREVIOUS EDITION IS UNUSABLE Prescribed by GSA
FAR (48 CFR) 53.214©
K
Section B - Supplies Or Services And Prices/Costs
Transition Period: July 1, 2016 through August 31, 2016
ITEM SUPPLIES / SERVICES QTY /
UNIT
UNIT
PRICE
EXTENDED
PRICE
0001 Base Period
The Contractor shall provide services in accordance with the attached Statement of Work
2 Months
Base Period: September 1, 2016 through June 30, 2017
ITEM SUPPLIES / SERVICES QTY /
UNIT
UNIT
PRICE
EXTENDED
PRICE
1001 Base Period
The Contractor shall provide services in accordance with
10 Months
Option Period 1: July 1, 2017 through June 30, 2018
UNIT
PRICE
EXTENDED
PRICE
2001 Option Period 1
The Contractor shall provide services in accordance with
12 Months
Option Period 2: July 1, 2018 through June 30, 2019
UNIT
PRICE
EXTENDED
PRICE
3001 Option Period 2
The Contractor shall provide services in accordance with
Option Period 3: July 1, 2019 through June 30, 2020
UNIT
PRICE
EXTENDED
PRICE
4001 Option Period 3
The Contractor shall provide services in accordance with
Option Period 4: July 1, 2020 through June 30, 2021
UNIT
PRICE
EXTENDED
PRICE
5001 Option Period 4
The Contractor shall provide services in accordance with
0001 Transition Period $________________
1001 Base Period $________________
2001 Option Period 1 $________________
3001 Option Period 2 $________________
4001 Option Period 3 $________________
5001 Option Period 4 $________________
Total Estimated Value for the Base Period and Option Periods 1 through 4 $________________
This is a Firm Fixed price requirement for the Data Coordinating Center.
Section C - Description/Specification/Work Statement
Statement of Work
Title: Data Coordinating Center (DCC) for the
Centers for Disease Control and Prevention (CDC)
SECTION 1 – BACKGROUND
HIV causes a chronic infection that leads to a progressive disease. Without treatment, most HIV-infected persons develop life threatening illnesses within 10 years of infection, which results in substantial morbidity and premature death. CDC reports that at the end of 2012 an estimated 1.2 million persons aged 13 years and older were living with HIV infection in the U.S. (CDC, 2014), with over 45,000 diagnosed HIV infections occurring each year (CDC, 2015). In response to the growing epidemic, the National HIV/AIDS Strategy for the United States (NHAS) was first released by executive order in 2010. The NHAS has four goals: 1) reduce new HIV infections; 2) increase access to care and improve health outcomes for people living with HIV; 3) reduce HIV-related health disparities;
and 4) achieve a more coordinated national response to the HIV epidemic.
The Division of HIV/AIDS Prevention (DHAP) oversees a comprehensive multi-component surveillance system to measure and characterize the scope and magnitude of disease and to monitor progress toward achieving the NHAS goals. Surveillance for HIV/AIDS includes the National HIV Surveillance System (NHSS), the Medical Monitoring
Project (MMP) and the National HIV Behavioral Surveillance System (NHBS). The first component, NHSS, includes all 50 states, the District of Columbia, and 6 U.S. dependent areas and uses confidential name-based HIV infection reports that are collected and de-identified at local health jurisdictions and then submitted to CDC. The
Medical Monitoring Project (MMP) and the National HIV Behavioral Surveillance (NHBS) System complement
NHSS with in-depth clinical and behavioral risk information collected on a sample population using personal interviews and information collected from in-depth medical records reviews. These two additional surveillance systems provide key data that are used to evaluate and inform public health prevention efforts and policy development, and monitor progress toward reaching the objectives of the NHAS. Data collected through these national systems are complex and robust and must be managed properly for timely dissemination and appropriate use.
The Medical Monitoring Project (OMB No. 0920-0740)
MMP is an ongoing, nationally representative surveillance system that collects data annually on a probability sample of about 10,000 HIV-diagnosed adults in 23 project sites including 6 U.S. cities, 16 states, and Puerto Rico with plans to function in no more than 26 project sites in the future. MMP monitors sociodemographic variables, behavioral and clinical characteristics, supportive service needs, use of healthcare and prevention services, and adherence to clinical care guidelines among HIV-diagnosed adults. The data from MMP are used to help inform and guide local and national HIV prevention, care, and treatment efforts.
MMP employs a two-stage sample design. The sampling frame at the first stage consists of all 50 states plus the
District of Columbia and Puerto Rico. At the second stage, within each project site, the sampling frame includes persons reported to NHSS.
Current MMP project sites
1. California 13. New York
2. Chicago, Il 14. New York City, NY
3. Delaware 15. North Carolina
4. Florida 16. Oregon
5. Georgia 17. Pennsylvania
6. Houston, TX 18. Philadelphia, PA
7. Illinois 19. Puerto Rico
8. Indiana 20. San Francisco, CA
9. Los Angeles, CA 21. Texas
10. Michigan 22. Virginia
11. Mississippi 23. Washington
12. New Jersey Intentionally Left Blank
Additional sites that may be included in future years include Maryland, Massachusetts, and South Carolina.
MMP data include the following:
1. Interview
2. Medical record abstraction (MRA)
3. Minimum data set (MDS) from NHSS
4. Sampling and recruitment data
The National HIV Behavioral Surveillance System (OMB No: 0920-0770)
NHBS is an ongoing bio-behavioral surveillance activity that monitors the HIV epidemic, to detect changes over time in HIV-risk behaviors and HIV prevalence among populations at high risk for HIV infection and to inform and evaluate HIV prevention activities. NHBS collects data on approximately 14,000 surveys annually conducted in 20-
23 health jurisdictions that include large metropolitan areas with high HIV prevalence. Data from NHBS are used to improve HIV prevention, testing and treatment services (by identifying sub-groups with sub-optimal treatment utilization) and to reduce HIV incidence among populations at high risk for HIV infection.
The implementation strategy for NHBS is to conduct at least one cycle of data collection annually among three different populations at high risk for HIV: men who have sex with men (MSM), people who inject drugs (IDU), and heterosexuals at increased risk of HIV infection (HET). An additional survey may be conducted along with these three populations to reach either young men who have sex with men (YMSM) or transgender persons (TG).
Sampling methods to reach these groups include venue-based, time-space sampling and respondent driven sampling;
thus the number and type of data collected, processed, and maintained for NHBS differ each year although the sample size for each project site is approximately 500 – 900 each cycle.
Projected NHBS project sites
1. Atlanta, GA
2. Baltimore, MD
3. Boston, MA
4. Chicago, IL
5. Dallas, TX
6. Denver, CO
7. Detroit, MI
8. Houston, TX
9. Los Angeles, CA
10. Miami, FL
11. Memphis, TN
12. Nassau, NY
13. Norfolk, VA
14. New Orleans. LA
15. New York, NY
16. Newark, NJ
17. Philadelphia, PA
18. Portland, OR
19. San Diego, CA
20. San Francisco, CA
21. San Juan, PR
22. Seattle, WA
23. Washington, DC
NHBS data collected include the following:
1. In-person interviews
2. Sampling and recruitment data
3. Local test results data
4. CDC laboratory test results
5. Additional data from optional surveillance activities provided by the project sites
6. Community level data (Census and similar community statistics)
The Data Coordinating Center (DCC)
Given the size and complexity of MMP and NHBS operations, an estimated annual investment of over $20 million in federal funding to state and local health departments, and the critical need for data-driven HIV prevention programs and policy, data management support for these national systems must meet or exceed standards for best practices.
Attempts at managing these data in-house from 2004 to 2007 failed to produce data sets within an acceptable time frame. In response, CDC awarded a contract in 2007 to evaluate operations and recommend best practices for MMP and NHBS data management. Following those recommendations, a new data management contract was developed and awarded at the end of fiscal year 2008. This award established the Data Portal, a secure electronic data management system that became fully functional in March 2009. The Data Portal marked a change from the manual, disjointed data management processes of the past and instead operated as a highly coordinated data management life cycle system producing higher quality data sets in less time and at less cost than previous MMP and NHBS data management processes. In 2011, the 2nd DCC contract was awarded widening the scope of the Data
Portal to include sampling and weighting processes, developing software applications to track and manage samples, developing weighted data sets with accompanying documentation, and performing non-response analysis. See
Attachment A for screen shots of the Data Portal. However, given advancements in technology and years of MMP and NHBS data processing experience, Portal updates in systems and processes are expected in this 3rd acquisition process, which include: an updated MMP Tracking Module (Attachment B), site level automated data upload, automated data import and reports generation and the facilitation of the bi-directional secure exchange of data -among CDC, the project sites, DCC, and the medical records abstraction (MRA) contractor. These updates and others proposed by the selected Contractor will streamline current MMP and NHBS processes and enhance efficiency thereby reducing operational costs in the long run.
The Data Portal is an integral part of MMP and NHBS surveillance operations (see Attachments C, D). The Data
Portal serves as a platform for CDC, project sites, CDC’s medical record abstraction software application (MRA) contractor, and the DCC Contractor to conduct routine data management activities and to exchange information among each other using a secure environment. Specifically, the MMP and NHBS project sites use CDC’s DCC
Portal to submit timely, data submissions, acquire submission-related information, enter and edit data, obtain technical assistance on data management related tasks, perform tracking functions, monitor recruitment, data collection, and data quality, construct and manage sampling frames (NHBS), obtain software for managing recruitment coupons (NHBS), view project related documents, enter project operation related information, download data sets, and exchange information with the DCC and CDC. CDC uses the Data Portal to monitor progress of recruitment, data collection, and submission activities with a focus on quality assurance. The MRA contractor uses the Data Portal to submit medical records data. The DCC contractor uses the Data Portal to coordinate functions across all users and process data received, merge data and update reports, upload datasets for project sites and CDC, track changes made to data, provide technical assistance via a helpdesk, manage the secured environment and post documents. The process flow of the Data Portal for data input, processing, output, and storage is represented in the figure below:
Data Security and Confidentiality
MMP and NHBS operate in a confidential and secure environment. The first layer of security is provided by a federal assurance of confidentiality (See Attachment E, Assurance of Confidentiality for NHSS and Surveillance-related Data). The Assurance requires that information collected by CDC as part of the HIV surveillance system that would permit direct or indirect identification of any individual or institution on whom a record is maintained, and any identifiable information collected during the course of an investigation on either persons supplying the information or persons described in it, is collected with a guarantee that it will be held in confidence, will be used only for the purposes stated in this Assurance, and will not otherwise be disclosed or released without the consent of the individual or institution. During the routine course of MMP and NHBS operations, no personally identifiable data is permitted to be transferred to CDC.
Next, CDC and its public health partners developed the Data Security and Confidentiality Guidelines for HIV, Viral
Hepatitis, Sexually Transmitted Disease, and Tuberculosis Programs: Standards to Facilitate Sharing and Use of
Surveillance Data for Public Health Action (See Attachment F). These Guidelines recommend standards regarding the secure collection, storage, and use of data while maintaining confidentiality. The standards are based on 10 guiding principles that provide the foundation for the collection, storage, and use of these public health data. They address five areas: program policies and responsibilities, data collection and use, data sharing and release, physical security, and electronic data security. They are intended for use by state and local health department disease programs to inform the development of policies and procedures. DCC operations must successfully function within the security standards as applied by each participating MMP and NHBS health jurisdiction.
The successful DCC Contractor must also be “certified” and have the ability to host and maintain a system for data collection, management, use, and reporting to support activities funded by the federal government. Information to assist in the preparation of documents necessary for the Certification and Accreditation (C&A) of an Information
System are found in Attachment G. Under the C&A requirements, contractors must be granted an “Authority to
Operate.” Without this, the DCC shall not function. The EGovernment Act of 2002, (Federal Information
Management Act) and the federal policies described in Attachment G dictate the framework for assuring information security for data systems operated by or on behalf of the Federal government.
Additional protections for HIV/AIDS surveillance data include the Privacy Act of 1974 and exemptions from the
Freedom of Information Act of 1966 (specifically U.S.C. 552(b) [6]). The DCC Contractor shall be responsible for complying with above guidelines and regulations and any updates and new regulations related to MMP and NHBS data.
Need
The acquisition is needed to support DCC operations including the Data Portal system. The DCC provides secure, efficient, technically sound, and timely data management services for MMP and NHBS. Without the DCC, HIV surveillance goals and objectives would not be met.
SECTION 2 – PURPOSE
The purpose of this requirement is to:
1. Improve and update an existing DCC Portal thereby creating greater efficiencies in the collection and management of National HIV Behavioral Surveillance (NHBS) and Medical Monitoring Project (MMP) data, and
2. Produce high quality, timely data sets ready for analyses and public health action.
SECTION 3 – SCOPE OF WORK
As an independent organization, and not as an agent of the government, the Contractor shall furnish the necessary services through all tasks and activities contained within this Statement of Work. The Contractor shall provide all labor, equipment, materials, supplies (including SAS Licenses), facilities to maintain and administer the Data
Coordinating Center (DCC) within a secured environment as an integral part of the Medical Monitoring Project
(MMP) and the National HIV Behavioral Surveillance (NHBS) systems to achieve high quality, timely data that is ready for analysis and dissemination. The Contractor shall use “Best Practice” approaches for reproducible data – processes that include supporting documentation and shall achieve greater automation of services over time. The
DCC Portal and all data associated with the Data Portal are the property of CDC.
SECTION 4 – TASKS TO BE PERFORMED
The Contractor shall provide the following tasks:
Task 1.0 – The Data Portal IT Systems
The Data Portal serves as a platform for CDC, CDC’s MRA application contractor, and the DCC Contractor to conduct routine data management activities and to exchange information among each other using a secure environment. The Data Portal operates as an integral part of the MMP and NHBS surveillance systems. Each year, CDC will update the MMP and NHBS protocols for the next annual data-collection cycle. The Contractor shall review these documents and make adjustments to DCC Portal processes to maintain operational systems that optimally support MMP and NHBS objectives and goals relative to data management. On an annual basis, the
Contractor shall update the Data Portal to meet annual MMP and NHBS objectives and improve efficiency while maintaining security for all Data Portal operations and related processes.
Task 1.1 – Update and test the Data Portal systems on an annual basis.
The update and test the Data Portal systems on an annual basis. Testing for the annual updates to the Data
Portal shall include the full range of data processing and reconciliation starting with the project sites and ending with a run-through of data-close out procedures. Testing processes are consistent with the DCC
Operational Plan. Test procedures ensure shall ensure high quality performance. Upgrades to servers
(including cloud, virtual, or other approved technology) occur no less than every 3 years. In addition, the setup of the servers shall include development, test and/or stage, and production environments to accommodate enhanced Portal features. The site shall include a CDC “acceptance test environment” to document CDC concurrence with the test results. The Data Portal shall have the capacity to accept and host data and related information for MMP and NHBS data processes as required in the protocols
(Attachments C, D) and annual updates to the protocols.
The Data Portal supports a Secure File Transfer Protocol (SFTP) to facilitate the exchange of information and data between CDC and the project sites. In addition the updated Portal shall include automatic data import and report generation. Imported data are consistent with the MMP and NHBS protocols
(Attachments C, D). Automated data import is particularly important for QDS survey data.
The Contractor shall submit a Portal System Report on an annual basis. The Data Portal System Report describes the Data Portal system architect design and documents all the functional and technical specifications to perform required activities. The Data Portal System Report also outlines business processes used for data management, monitoring (including Portal Reports), and quality control procedures for the upcoming MMP and NHBS data collection cycles and recommendations for improved processes that shall result in more timely final annual data sets. Annually by November 1, the Data Portal System
Report is submitted. The Report is 10 pages long not including the following attachments:
1. System architect diagram (including server locations)
2. Data flow and continual quality improvement diagram
3. Automatic data import feature
4. SFTP diagram
5. Roles and privileges of administrators
6. Test reports demonstrating that system requirements are met
7. Tracking systems updates including Coupon Manager, VDTS, and MMP tracking
8. Updates to portal data reports used for monitoring recruitment and data collection
9. Back-end Portal system documentation
10. Updates planned for the upcoming year that improve data timeliness
In 2016 and 2019, the Data Portal shall incorporate updated hardware or updated systems that meet technology standards of the times. Software and relevant licenses-- including SAS are updated as needed for optimum support. The table below may be used as a suggested guide as the equipment supports current
The Data Portal processes. All equipment should meet updated standards for memory and speed, and all software versions should be updated for optimal system performance. Note that SAS licenses will not be provided as direct assistance by the government; the Contractor shall make arrangements for these licenses using internal company processes.
Name Manufacturer
/Model Processor
Memory at least
Operatin g System Software
CDC-DCC-
ROCWEB
190.168.100.
Dell 2950 Intel Xeon
E5420
2.50 GHz
16G MS
Windows
Server
Standard
SP1
Microsoft Internet Information
Services 7, McAfee Virus Scan 8.5, Symantec Backup Exec Remote
Agent Utility, Microsoft .NET
Framework Version 2.0 Service
Pack 1, Microsoft .NET Framework
Version 3.5 Service Pack 1
CDC-DCC-
ROCSQL
190.168.100.
Dell 2950 Intel Xeon
E5420
3.00 GHz
16G MS
Windows
Server
Standard
SP1
Microsoft SQL Server 2008 (build
10.0.1600), Check Point Smart
Console R65, Symantec Backup Exec for
Window Server 12.5
CDC-DCC-
ROCSAS
190.168.100.
Dell 2950 Intel Xeon
E5420
3.33 GHz
16G MS
Windows
Server
Standard
SP1
SAS Version 9.1.3 (Base , SAS/STAT, SAS/GRAPH, SAS/ETS, SAS/FSP, SAS/OR, SAS/QC, SAS/SHARE, SAS/CONNECT, SAS Integration
Technologies, SAS/ACCESS
Interface to
ORACLE, SAS/ACCESS Interface to PC Files, SAS/ACCESS
Interface to ODBC , SAS/ACCESS
Interface to OLE DB, SAS
Management Console, SAS
Information Map Studio), QDS
Warehouse Manager 2.4, QDS
Warehouse Manager, CAPI, HAPI
2.5
CDC-DCC-
ATLWEB
190.168.200.
Dell 2950 Intel Xeon
E5420
2.50 GHz
8G MS
Windows
Server
Standard
SP1
Microsoft Internet Information
Services 7, McAfee Virus Scan 8.5, Symantec Backup Exec Remote
Agent Utility, Microsoft .NET
Framework Version 2.0 Service
Pack 1, Microsoft .NET Framework
Version 3.5 Service Pack 1
CDC-DCC-
ATLSQL
190.168.200.
Dell 2950 Intel Xeon
E5420
3.00 GHz
16G MS
Windows
Server
Standard
SP1
Microsoft SQL Server 2008 (build
10.0.1600), Check Point Smart
Console R65, Symantec Backup Exec for
Window Server 12.5, Task 1.2 – Annual Data Portal User Acceptance Testing
Annually by April 15th, the Contractor shall submit the Data Portal Final User Testing Report. The Report is an Excel spreadsheet documenting identified issues and dates of corrected action and final testing procedures for the Data Portal. The spreadsheet is an exhaustive list enumerating problems identified during the Contractor, project site, and CDC review of the Data Portal functionalities. The Contractor shall lead this final testing process after all other testing procedures as described in Task 1.1 are finished and the
Data Portal certified by the Contractor as fully functional. Minimal errors are expected to be identified during this last testing procedure. The Contractor provides the templates and testing scenarios to use during the final testing process. CDC will provide one testing scenario for inclusion in the testing plan.
Task 1.3 – Certification and Accreditation
The Data Portal system shall continue to incorporate functionalities that support the full range of operational requirements as described in the MMP/NHBS protocols (Attachments C, D) while meeting all security requirements. The Data Portal uses systems and processes consistent with Certification and
Accreditation (C&A) requirements as specified in Attachment G. The Contractor shall obtain the
“Authority to Operate” (ATO) by October 15, 2016. All requirements for the ATO must be met as described in Attachment G. The requirement for C&A is annual and the Contractor shall be responsible for any updates or changes in requirements as proscribed by Federal and HHS Information Security Program
Policies. In addition, the Contractor shall operate in accordance with the Data Security and Confidentiality
Guidelines for HIV, Viral Hepatitis, Sexually Transmitted Disease, and Tuberculosis Programs: Standards to Facilitate Sharing and Use of Surveillance Data for Public Health Action (See Attachment F). These
Guidelines recommend standards regarding the secure collection, storage, and use of data while maintaining confidentiality at the state and local health department level. All MMP and NHBS project sites shall collect and submit data to the Data Portal in accordance to these guidelines.
On-site consultative or data analysis services may be necessary to support DCC functions on a temporary basis. When access to data are necessary to any temporary contractor who has not had the annual security training, the temporary contractor must state that they will comply with the rules of behavior set forth by
CDC to protect NHBS and MMP data. This shall include signing a data security agreement prior to accessing any data. Attachment E includes an example of an approved data security agreement that may be used for temporary contractors, as well as permanent contractors. If a different agreement is used, it must have CDC approval in advance of data access.
Task 2.0 – Secure File Transfer Mechanism
An enhanced secure file transfer mechanism will increase the Data Portal’s efficiency in data access and transfer among the DCC stakeholders while maintaining security requirements.
Task 2.1
The Contractor shall update the Data Portal to include PGP keys for CDC staff on the Data Portal’s encrypted data files. CDC staff, as designated by the COR, must see files on the Data Portal and will need a key in order to decrypt them. Providing this key or a similar feature as described in the Operational Plan, designated CDC staff will be able to review data as needed without having to request it from the
Contractor. This feature will save a step in data processing and allows viewing by CDC “on-demand.”
The Contractor shall provide this feature by January 1, 2017.
Task 2.2
In addition to the data management and associated data receipt and transfer processes, the Contractor shall facilitate the efficient bidirectional exchange of confidential information and data between CDC and the project sites. This allows CDC technical monitors to address questions or challenges related to data quality specific to one or more sites or to the sample as it builds. Current data transfer processes require the Data
Portal to provide project sites with the ability to transfer double encrypted participant level data (non-PII) to DCC only and then they are transferred to CDC via the Data Portal. The Contractor shall provide a
Secure File Transfer Protocol (SFTP) mechanism to better facilitate the exchange of data sets and associated files among CDC, the project sites, the MRA contractor, and the DCC.
The SFTP incorporates the following:
a. Each project site shall have a site specific file folder for uploading data packages directly to CDC
b. Each project site shall have a site specific file folder for uploading participant level (non-PII) data for DCC and CDC
c. Each project site shall have access only to their own file folders
d. CDC shall have the rights to access all project site folders and the ability to upload data to all folders
e. DCC shall have the rights to access all project site folders specific for DCC and the ability to upload data to those folders
f. All SFTP accounts shall have ability to upload and download files in the secure folder
The diagram below illustrates the requirements described above.
The Contractor shall do the following:
a. Ensure the SFTP site is operational and available to all approved users 24/7
b. Develop a protocol for archiving and managing historical files transferred via SFTP; the protocol is no greater than 10 pages long and is posted on the Data Portal
c. Develop a brief user guide (two-pager) on how to use SFTP to transfer data; the user guide is posted on the
Data Portal
d. Log all access with user name, action, and date and time stamps
e. Maintain and manage user accounts and has ability to add or remove users at any time
f. Set up and manage cryptography for all pre-approved users that is compliant with FIPS 14-2 certification
The Contractor shall setup and implement the SFTP site no later than January 31, 2017. The User Guide and the
Protocol are posted on the Data Portal by January 31, 2017.
Task 3.0 – MMP Tracking Portal Module
The Contractor shall develop web-based functionality for the MMP project sites to use as a tool to facilitate and enhance management and tracking of recruitment of sampled persons. This functionality is currently in an Access database called Contact Attempt Tracking (CAT) that operates locally from the other Data Portal tracking functions causing duplicative data entry for the MMP project sites. The Contractor shall integrate CAT functionalities into the
Data Portal. These functionalities are linked to the other MMP tracking data that is currently held in the Data Portal.
The current CAT works to manage information associated with MMP recruitment efforts. At the beginning of each cycle, project sites use a SAS program provided by CDC to pull into CAT the names, addresses, facility and lab information and various other personally identifying information (PII) that will allow project sites to find and recruit sampled persons. All PII remains at the local site and does not “touch” the Data Portal. The CAT then displays this information in an organized format for users. Additionally, project sites enter and view information about phone numbers, addresses, or other “leads” that they find while searching other databases, as well as information about attempts to contact sampled persons using these leads. The CAT stores information about recruitment dispositions, interviews, and medical record abstractions; some of this information necessary for data management is duplicative of what is managed in the Data Portal, but the CAT allows additional free text fields for entry of PII necessary for recruitment but that is not permitted in the Data Portal. See Attachment A for screen shots of the current CAT software system.
Integrating the CAT tracking functionalities in the Data Portal will facilitate and enhance recruitment tracking and better support recruitment. It will also address the double data entry burden currently necessary for the project sites.
In addition, the offline session requirements for the new functionality is aimed at keeping the PII and related comments at the project site (and not accessible through the Data Portal.) Data shall not be physically deleted from the Data Portal and the tracking databases, and could be marked as “deleted” for data management purpose. SQL server audit trial function is enabled to capture changes made to record at when and by whom. The Contractor shall develop a web-based tracking module that will automatically log data received, run validations, flag variables that fail validation, import eligible data into the database, and park the data that did not pass the validation to the designated tables in the database.
Task 3.1 – MMP Tracking Module Strategy Paper
The Contractor shall provide a Strategy Paper for MMP tracking, development, and deployment. The
Paper shall include the functions currently supported by CAT. The Strategy Paper shall outline proposed technical and security requirements that include a plan and timeline for C&A and subsequent deployment.
The Paper shall include a testing component to ensure that the enhanced DCC tracking functions operate as proposed. Testing shall include selected project sites. The Paper is no greater than 35 pages not including attachments. Attached to the Paper is a data dictionary and data flow diagram based on the existing CAT
Access database and existing Data Portal MMP tracking databases. The Paper shall be provided to CDC for review and approval before development begins and is due as proposed in the Operational Plan or by
June 30, 2017 at the latest. The enhanced MMP tracking module shall provide all functionalities as the current CAT and current MMP tracking while adding efficiency to MMP recruitment efforts.
Task 3.2 – MMP Tracking Module Implementation
The Contractor shall update the Data Portal tracking functions with those currently associated with CAT.
The MMP Tracking Portal Module shall be fully functional by January 1, 2018. This module in the Data
Portal shall include the following overarching functionalities and features. All changes shall comply with
Certification and Authentication requirements as described in Attachment G.
1. PII is protected behind a local firewall; only local project site staff have access to PII
2. The Data Portal is the authentication point for approved user access to the tracking module;
Privileges are role-based
3. De-identified CAT data are linked to associated MMP data (e.g., MMP Interview and MRA) currently stored in the Data Portal
4. User ability to edit and view imported sampled records
5. User ability to add/delete contact attempt records
6. User ability to view for record submission statuses, e.g., submitted (passed all validation rules), in progress.
The Contractor shall:
1. Allow data entry when there is no cellular network or Wi-Fi connection
2. Run validation on variable, page, and record levels
3. Use standardized formats throughout the form
4. Build re-useable functions (e.g., save, next, ignore, print) in all forms development
5. Store selected data locally
6. Standardize navigation schema that allows user to move to a different section directly
7. Secure local specific variables at local sessions and provide ability for local users to transfer data to a local server
8. Automate extract features for datasets created and uploaded by the project site
9. Automate validation and import features for uploading data
See Attachment B for high-level requirements for MMP Tracking Module.
Task 4.0 – Automated Data Import and Reports Update to the Data Portal
The automated import aims at enhancing the current semi-automatic data import process and improving data quality by preventing problematic data from importing into the DCC data bases. The updated Portal automated feature shall automate log data received and processed. Additional automated features include running a validation program, importing eligible data into the database, and parking the data that did not pass the validation rules to the designated tables in the database.
Task 4.1 – Data Portal Automated Data Import and Report Generation Module -- Plan
The Contractor shall develop a Plan to update the Data Portal with automated features and shall submit the
Plan to the COR by August 15, 2017 via electronic mail. The Plan shall be no greater than 20 pages in length and shall include the specifications for the automated features, a testing plan, and a timeline for implementation.
Task 4.2 - Data Portal Automated Data Import and Report Generation Module --Implementation
The Contractor shall update the Data Portal according to the Plan described above in Task 4.1. Updates include a feature that generates automatic case-based and batch-based import status reports. The case based reports describe import status that lists source of the data, form name and version, sections and variables that did not pass the validation and reasons. The feature shall support auto-email notification with a web link to the report to appropriate individuals at CDC and project sites. The report generated describes the number of records received, date received, date processed, list of record IDs, number of records that pass the validation, and number that failed. The report shall be posted to the Data Portal and be available to
CDC and project sites. The Data Portal’s updated features shall be fully functional by December 31, 2017.
Task 5.0 – Issues Management Tool - Update and Maintenance
The Contractor shall update the “TIMS” function in the Data Portal to an improved system called the Issues
Management Tool. The Tool is used to track issues in the data that are often solved using an iterative process that includes many steps. The Tool documents a final agreed upon resolution along with additional action steps if indicated. See Attachment A for screen shots of the current management system used for this purpose. The
Contractor shall review the existing system and revise it to better facilitate MMP and NHBS tracking activities.
Issues that require investigation are those that are associated with changes in requirements, data submission challenges, protocol violations, and other issues that impact data quality or production of final unweighted or weighted datasets. As data are submitted and processed, the Contractor shall identify issues for resolution and open a “ticket” in the Tool. The revised Tool incorporates these functions:
1. Display MMP and NHBS specific items based on user login information
2. Capture date and time stamps when the item is created
3. Allow sorting for all variables
4. Allow user to enter and update information
The Contractor shall maintain the Issues Management Tool as specified in the Operational Plan. Revisions to the
Issues Management Tool shall be incorporated and fully functional by March 1, 2017. The Contractor shall provide a final Issues Management Testing Report by April 1, 2017. The Report is no greater than 10 pages long and documents that the Tool is working to standards set in the Operational Plan.
Task 6.0 - Data Receipt
Using the Data Portal, the Contractor shall begin data receipt from project sites no later than
November 1, 2016. MMP and NHBS operate continuously and adhere to strict data collection timelines that begin annually on June 1. Data are submitted and processed monthly for MMP and NHBS and submitted weekly for NHBS reporting purposes. All data receipt, data processing, and technical assistance tasks as described below are repeated annually on established timelines for each respective surveillance system.
Core NHBS data collection systems operate on rotating annual cycles targeting three core populations for data collection as follows:
In addition to Core NHBS, optional populations may be targeted for data collection. These populations include either young men who have sex with men (YMSM) or transgender persons
(TG). Data are collected for optional populations and received by the DCC from no more than 10
NHBS project sites and data collection cycles for each optional populations is time limited to one year or less and is not on-going or cyclical. For more information about optional population data collection see Attachment D.
MMP and NHBS project sites use the following electronic instruments to collect data to send to the Data Portal for receipt and processing:
1. Questionnaire Development System (QDS)
2. Medical Record Abstraction application (MRA)
3. Coupon Manager Application
4. Respondent Driven Sampling Analysis Tool
5. Venue-Based Day Time Sampling Application
6. MMP tracking data (contact attempt tracking)
7. Microsoft Excel
The Contractor shall begin receiving MMP data from the project sites for data management no later than November 1st for Year 1 of the contract and as described in the DCC Operational Plan.
Subsequently, the Data Portal is fully functional on a continual basis. Data are received from 23
MMP project sites on a 12 month annual data collection cycle. Using the Data Portal, the
Contractor shall receive the following types of MMP data:
1. Interview data (200-500 surveys per site per year)
Contract Year Calendar
Year
NHBS Cycle
YEAR 1 2016 NHBS-HET
YEAR 2 2017 NHBS-MSM
YEAR 3 2018 NHBS-IDU
YEAR 4 2019 NHBS-HET
YEAR 5 2020 NHBS-MSM
2. MMP tracking data
3. Minimum Data Set (MDS) data
Data are also received from a CDC contractor that supports web-based data collection from medical records. The DCC Contractor shall merge medical records data with the survey data collected from the project sites.
4. Medical Record Abstraction (MRA) data (200-500 MRAs per site per year)
The Contractor shall begin receiving NHBS data for data management no later than November 1st for Year 1 of the contract or as indicated in the Operational Plan. The Plan must include a strategy to address a new DCC contract, related startup processes and the availability of the Data Portal when data collection starts on June 1 for a short 6 month data collection process. Plans to “catch up” on processing NHBS data in Year 1 shall be included in the Operational Plan. After Year 1, the Portal is fully functional on a continual basis. Data are received from no more than 23 NHBS project sites on an annual data collection cycle from June to December. Using the Data Portal, the
Contractor shall receive the following types of data:
1. Interview data (approximately 500 surveys per site per cycle)
2. Coupon manager data (YMSM, TG, HET, IDU cycles) or venue based data
(YMSM, TG, and MSM cycle)
3. Local HIV, STD, and hepatitis test data
The CDC laboratory, project sites, and the US Census provide additional data for NHBS.
Available census data, such as American Community Survey Data, are downloaded at no cost from the census website. Other community level statistics provided to the Contractor may include data on local HIV services. In addition, the project sites may submit a SAS dataset containing up to 30 variables related to optional surveillance activities. Contractor shall receive data from these sources and prepare it for use by the project sites. Data from these sources shall be merged with the NHBS survey data collected by the project sites.
1. CDC laboratory data
2. Additional data from optional surveillance activities provided by the project sites
6. Community Level Data (Census data or other community statistics)
For more detailed information about the approximate numbers and types of electronic records received per project cycle, the various sampling and tracking methods, and the data collection instruments, the Contractor may refer to the attached MMP and NHBS protocols and resource documents (Attachments C, D).
Task 7.0 – MMP and NHBS Data Reconciliation
The reconciliation process contains four phases:
Phase I. Documenting standard operating procedures (SOPs)
Phase II. Processing monthly data submissions, Phase III. Reconciling end-of-cycle data, and
Phase IV. Finalizing unweighted data.
Task 7.1 - Reconciliation SOP (Phase I)
Annually, the Contractor shall generate the “Reconciliation SOP” two months prior to the data management training. The SOP shall be no more than 25 pages for MMP and 25 pages for NHBS not including attachments. The SOP shall address the following items:
A. Data packages required for each Phase
B. Data checks
C. Data error log
D. Data management reports
E. Variable formats and labels
F. Data Closeout
Phase I- A. Data Packages
The SOP shall include itemized descriptions of “data packages” for each phase of the reconciliation process. A data package consists of a processed dataset and a set of supporting documentation. Each phase of the data reconciliation process produces a data package (a data set and supporting documentation) that is returned to the project site. A data package will include the dataset containing the interview data merged with other data sources as outlined in the MMP and NHBS protocols. The dataset has been
“processed” or checked for errors and inconsistencies. The specific content of the data package’s documentation depends on the phase of reconciliation and is described in the
SOP. At a minimum, the documentation in the data package shall include a data management report that identifies records with data inconsistencies for project sites to review and resolve prior to submitting the following month’s data to the Data Portal.
Project sites shall only receive their respective datasets in their data packages (i.e., project site dataset). CDC shall receive data for all MMP and NHBS sites contributing data for that cycle (i.e., CDC aggregate dataset). For MMP, the State health departments in
California, Illinois, New York, Pennsylvania, and Texas shall receive final unweighted datasets containing the data of cities within the State’s jurisdiction (i.e., State aggregate dataset) after the CDC aggregate dataset is reviewed and approved.
Phase I- B. Data Checks
The Contractor shall perform data checks to identify inconsistencies in the data. Some examples of checks include inconsistencies due to mis-merged data, mis-entered identifying variable values, and inconsistencies in data entered (e.g., lab test results and final interpretation are inconsistent, eligibility does not correspond with underlying eligibility criteria, data in medical abstraction record is inconsistent with similar data in interview, etc.). The Contractor shall include other checks in addition to these examples as part of the SOP. The SOP shall describe data checks that will provide the highest quality data possible.
The Reconciliation SOP includes schedules for the data management checks that are consistent with the MMP and NHBS protocols, the logic used for programming each of the data management checks, and the guidance provided to project sites for reviewing the data check and the data management reports.
Data management checks should be conducted monthly during reconciliation and at the end-of-cycle. The Contractor shall phase in data management checks during the processing of monthly data submissions. The Contractor shall consider work-load at the project site when phasing-in monthly data checks over time. Using a phased in approach, the number of reports shall increase about mid-way through the data collection cycle.
Phase I- C. Data Error Log
When data checks are performed, inconsistencies are identified. Project sites may also report data inconsistencies to the DCC after data submission. These inconsistencies in the data may require further investigation or an action before a final determination is made. The Reconciliation SOP includes the use of a “Data Error Log.” The Data Error
Log is part of the Data Portal and is an online database of changes project sites propose making to the interview data. There are separate data logs for most data sources.
Information from the Data Error Log template is managed using a searchable database.
Phase I- D. Data Management Reports
As data are processed, the Contractor shall identify errors and inconsistencies in the data through detailed data management reports. The SOP shall detail how these items are tracked and resolutions documented. The Contractor shall provide data management reports to the project sites when datasets are returned to them during reconciliation.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .