Draft_SOW.docx

DOCX document 50 KB Posted

Attached to
Medical Record Abstraction for MMP Federal contract opportunity
Solicitation number
2017-N-66809
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

Medical Record Abstraction Application for Medical Monitoring Program

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

2017-N-66809 DRAFT STATEMENT OF WORK

MEDICAL RECORD ABSTRACTION (MRA) APPLICATION

FOR MEDICAL MONITORING PROJECT (MMP)

1. BACKGROUND

The current MRA application for MMP is an “off-the-shelf” product called Discovere®, a web-based research platform that has streamlined MMP’s data collection activities. MMP is a supplemental surveil lance program designed to produce local l y and nationally representative data on people living with H IV/AI DS. The MMP data collection operates under OMB approval #0920-0740 which is up for renewal on May 31, 2018. CDC, in collaboration with state and local health departments, conducts MMP in the following 23 project areas (PA):

1. California Department of Health Services

2. Chicago Department of Public Health

3. County of Los Angeles Department of Health Services

4. Delaware Division of Public Health

5. Florida Department of Health

6. Georgia Department of Public Health

7. Houston Department of Health and Human Services

8. Illinois Department of Public Health

9. Indiana State Department of Health

10. Michigan Department of Community Health

11. Mississippi State Department of Health

12. New Jersey Department of Health and Senior Services

13. New York State Department of Health

14. New York City Department of Health & Mental Hygiene

15. North Carolina Department of Health and Human Services

16. Oregon Department of Human Services

17. Philadelphia Department of Public Health

18. Pennsylvania Department of Health

19. Puerto Rico Department of Health

20. San Francisco Department of Public Health

21. Texas Department of Health

22. Virginia Department of Health

23. Washington State Department of Health

MMP aims to gain a deeper understanding of health-related experiences and needs of people living with HIV. MMP uses a probability sample of people living with HIV in the United States to make nationally and locally representative estimates of clinical outcomes; health -related behaviors; and accessibility and use of prevention and support services. This information increases knowledge of care and treatment and is used to examine associations between clinical outcomes and patient characteristics.

People living with H I V, HIV prevent ion community planning groups, Ryan White CARE Act planning councils and consortia, providers of HIV care, and other stakeholders use MMP data to inform HI V pol icy decisions and planning activities. M MP provides valuable state and national estimates of health care utilization, quality of care, scope and level of need, and effectiveness of prevent ion messages. MMP data help estimate resource needs for treatment and services for people living with HIV/AIDS. To be effective, programs must meet the current needs of the population. MMP data provide contextual information on prevention, care-seeking, treatment, and risk behaviors which can aid in the design and improvement of H IV programs.

From 2005-2014, MMP sampled persons from HIV care facilities, so only people receiving HIV medical care were included in the project. Starting in 2015, MMP introduced a new sampling method to include all adults diagnosed with HIV in the United States. This is accomplished using a two stage sampling strategy. The first stage is state level. All 50 states, the District of Columbia and Puerto Rico were eligible for inclusion in MMP. A sample of states was based on the number of AIDS cases within each area. A total of 16 states and 1 U.S. territory were selected. The next stage is person level.

A sample of about 400 HIV infected individuals from each area is selected each year from the National HIV Surveillance System. These individuals must be at least 18 years old and diagnosed with HIV. People who are selected are asked to participate in an interview during which they answer questions about their behavior and HIV medical care. They also give the MMP project staff permission to review their medical chart. While data from the interview focuses on behavioral issues, the M RA focuses on clinical care, treatment, and outcomes of HIV patients who are in care. MRA data will serve as a source of information for national indicators on HIV quality of care, as well as on the spectrum and burden of comorbid conditions among HI V patients.

The complexity of the MRA application design and development procedures can create problems for data collection, processing, updating elements, and analysis. From 2004-2012, MMP struggled with using various data collection systems and tools to capture MMP’s complex medical record abstraction data. There were multiple application system failures, leading to missed timelines and data collected on paper which then led to additional resources needed for data entry and verification. Data were inconsistent, errors were unable to be fixed, and many records were deemed unusable. Beginning in 2012, MMP has successfully used Discovere®, a web-based medical record abstraction application to collect medical record abstraction data. The data collected have been accurate, timely, and have allowed for the analyses needed to reach the objectives of MMP.

The importance of the medical record data and the annual multi-million dollar investment in this surveillance system requires that the application is reliable and free of errors. Using Discovere® as the MRA application for MMP has met this requirement and provided a high-quality, consistent data collection tool. Continuing to procure highly specialized and consistent services in collecting medical record data will help to protect CDC's investment in MMP.

2. PURPOSE

The contractor shall continue to utilize Discovere® or use a comparable product for timely, consistent MMP data collection. MMP data collection begins June 1 each year and Discovere® or a comparable product must be in place and able to collect data through May 31 of each year without interruption in data collection activities. The current MMP data elements are attached. Discovere® or comparable product shall include the data elements and shall meet the following objectives in order to enable continued, uninterrupted, updated functioning for MMP’s ongoing data collection activities: analysis, programming, security assessment and authorization, testing, deployment, end-user training and technical support, data management, and quality assurance.

3. SCOPE OF WORK

Independently, and not as an agent of the government, the Contractor shall furnish all the necessary personnel, facilities, supplies (including software licenses), and equipment required to provide support in the following areas:

Programming and modifications. Development and delivery of a high quality web-based medical record abstraction application that complies with CDC security requirements to meet specifications, functionality, and timelines provided by CDC. Programming and modifications are completed prior to deployment each year and also are conducted “live” to address changes or errors encountered during each data collection year.

Testing. Testing is composed of two phases: 1) the Contractor shall conduct internal testing of the deliverables and 2) the CDC shall conduct User Acceptance Testing to inspect and accept the deliverables.

Deployment of an MRA application each year. After testing is complete, a web-based MRA application is deployed June 1 of each year.

Training and technical support. An annual web-based training shall be conducted by the Contractor and distance-learning trainings shall be provided via webinar for field and local field supervisors across the United States and Puerto Rico to aid in their ability to effectively use Discovere® or the comparable product. In addition, training shall be conducted for CDC epidemiologists to increase technical knowledge and skills. Ongoing technical support shall be provided to those entering data into the web application.

Data Management and quality assurance. The contractor shall manage all data collected by the application, assure completeness and accuracy of the data, and securely transfer that data to a data coordinating center.

4. TASKS TO BE PERFORMED

Task 1.0. Transition Plan. The Contractor shall submit a plan outlining the following plans for a seamless transition of data collection from Discovere® to a system that:

a) Is able to comply with all of CDC’s security requirements

b) Incorporates all data elements (see attached)

c) Does not result in loss of data collection time for MMP

d) Does not result in loss of data quality for MMP

Task 2.0. Kick-off Meeting. The Contractor shall arrange for a one-hour meeting via conference call to confirm points of contact. The kick-off meeting shall occur no later than 2 weeks after the contract award. The Contractor will provide meeting notes summarizing the call in a bulleted format not to exceed (NTE) one page no later than one week after the call.

Task 3.0. Modifications to Discovere®. The Contractor shall conduct an analysis of the technical feasibility and impact on functionality of any modifications to Discovere® or the comparable product requested by CDC, and report their findings to CDC. The Contractor shall review their product for 508 compliance and incorporate any 508 improvements to the product at this time. See “Special Considerations Section” for a detailed description of 508 requirements.

Task 3.1. Program Discovere® or the comparable product to accomplish modifications requested by CDC that are technically feasible and deemed to have acceptable impact on functionality. Modifications may include, but are not limited to, moving items from one location to another on case report forms, adding or deleting data elements or sections, adding or deleting items from lists of medications, diagnoses, etc., and incorporation of searchable databases, e.g. a comprehensive pharmacopeia or ICD-10 database into Discovere® or the comparable product if feasible. Any modifications should be approved by the COR prior to the change via conference call.

Task 3.2. The contractor shall provide an updated MMP MRA application data dictionary with any changes highlighted on an annual basis.

Task 4.0. Compliance with CDC security requirements.

The Contractor will consult with CDC security officers and provide all needed documentation and access to all associated databases and systems for security testing. This includes, but is not limited to, completing a full or amended SA&A process and providing information on collection, transfer, and storage of MMP MRA data. No "Personally Identifiable Data" shall be collected by Discovere® or the comparable product (See Special Considerations Section for a comprehensive description of required activities).

Task 5.0. Testing. The contractor shall use an industry standard for testing methodology to test Discovere® or comparable product functionality and user acceptability. The testing phase shall begin no later than October 15th in the base year of the contract and April 15 in each of the following years of the contract.

Task 5.1. The contractor shall provide a test plan to be provided to the CDC for approval before modifications begin.

Task 5.2. A testing report will accompany each delivered version to CDC at the beginning of user acceptance testing.

Task 6.0. Deployment. The contractor shall deploy an updated MMP MRA application annually that is web-based and hosted on the contractor’s servers.

Task 6.1. Upon annual deployment of Discovere® or the comparable product, the contractor shall provide an annually updated operating manual that includes, at minimum, information about: login/logout; general navigation, security measures; browser support and configuration; account management; Discovere® message system; participants list; general rules of data collection, validations and error messages, auto query; freezing, locking, and unlocking; printing a casebook; reabstraction; and reports.

Task 7.0. Training. The Contractor shall develop and implement a 4-hour abstractor training session once per year via the Web. Training curriculum shall be developed by the Contractor and approved by CDC. The curriculum shall include elements necessary for proper use of Discovere® or the comparable product. The Contractor shall provide an instructor and supporting training tools (handouts), equipment, and/or PowerPoint presentations one four-hour training session that will include approximately 50 state and local health department participants. The Contractor shall coordinate all logistics for this training, including the training agenda, invitations, and training evaluation. One month prior to the training, the Contractor shall present the draft agenda and training materials to the COR for review and approval.

Task 7.1. Distance-learning training shall be provided via webinar for field staff across the United States and Puerto Rico to aid in their ability to effectively use Discovere® or the comparable product not more than 6 times per year with one annual comprehensive training.

Task 7.2. The contractor shall conduct training for CDC epidemiologists to increase technical knowledge and skills in using survey support tools including training in new Discovere® or comparable product features not more than once per year.

Task 7.3. The contractor shall provide technical support for and be available to participate in 2-hour monthly data collector webinars. The Contractor will record the monthly webinars and deliver a file of the recording to CDC within 10 days of the event.

Task 8.0. Technical Support. The contractor shall provide technical support for Discovere® or the comparable product to all users for the hardware and software required for data entry and use. Requests for support from PAs and CDC shall be addressed no later than 48 hours after the request is made. It is anticipated that the Contractor will receive most requests for technical support via email. It is estimated that email requests for technical support from users will not exceed 50 requests per month.

Task 9.0. Data Management. The contractor shall receive, download, merge, manage, and clean all data collected with the Discovere® or the comparable product from each PA and store at a centralized location. The contractor shall assure completeness and accuracy of data collected by using industry standard data management techniques. The contractor shall consolidate data into person-level and relational data tables and will take measures to remove potential personally identifying information (PII) from free text fields prior to data transfer to the data coordinating center. The contractor shall encrypt and securely transfer datasets to the Data Coordinating Center (DCC) (see Special Considerations section for detailed description of required encryption processes) according to the following schedule:

Task 9.1. A copy of one national processed Demographics table on a monthly basis, commencing September 30, 2017.

Task 9.2. A copy of the data structure file on a monthly basis, commencing September 30, 2017.

Task 9.3. A copy of the full processed dataset, including one national and 23 PA-specific subsets on a quarterly basis commencing on or before October 30, 2017 followed by January 30, April 30 of each cycle.

Task 9.4. A copy of the preliminary full national raw dataset at the end of the third quarter of each data cycle commencing on or before April 30, 2018.

Task 9.5. A copy of the full national raw dataset at the end of each data cycle, commencing July 15, 2018.

Task 9.6. Reabstraction reports, including one national and 23 PA-specific subsets on a quarterly basis commencing on or before October 30, 2017 followed by January 30, April 30 of each cycle.

Task 9.7. Reabstraction dataset, including one national and 23 PA-specific subsets at the end of the first quarter commencing on or before October 30, 2017 and at the end of each cycle commencing July 15, 2018.

Task 9.8. A final fully processed dataset, including one national and 23 PA-specific subsets each cycle commencing July 15, 2018.

Task 10.0. Automated Programming. On at least a monthly basis, the Contractor shall also maintain and execute automated programming to identify errors and gaps in data collection.

Task 10.1. The contractor shall deliver monthly quality assurance reports enumerating these errors and gaps with the SAS dataset(s) via secure portal and will include both national and PA-specific listings. PA-specific reports will be delivered only if they contain data. Data in these reports will be divided into 23 PA-specific folders. Within each folder, data will be combined into a single SAS file. All data will be securely transferred on a monthly basis to the DCC commencing September 30, 2017. Quality assurance reports shall include the following information:

a) Deleted participant IDs (demographic forms) from one data transfer to next (CDC only)

b) Missing demographic forms (CDC and PAs)

c) Duplicate demographics forms (CDC only)

d) Number (%) of reabstractions and total abstractions performed by PA (CDC only)

e) Open auto queries by PA (CDC only)

f) Out-of-range laboratory data as compared to the upper and lower limit validation assigned in Discovere® (CDC only)

g) Lab dates outside of observation period (CDC only)

h) Facility ID errors where last 4 digits of facility ID = cycle year (CDC and PAs

i) Demographics records with facilities having missing or inconsistent Ryan White funding status (CDC and PAs)

j) Abstractions with observation period not equal to 2 years (CDC only)

k) Any PII included in text fields (CDC only)

Task 11.0. Biweekly Status Calls The contractor shall arrange biweekly status calls with the COR. Calls shall be approximately one hour in length. Meeting notes shall be provided by the contractor no later than one week after each biweekly call. The notes shall be no longer than 2 pages.

5. GOVERNMENT FURNISHED MATERIALS

List and specifications for MMP data elements

6. PERIOD OF PERFORMANCE

The contract under consideration shall be performed in one (1) 12-month base period and four 12-month option periods, if exercised by the Government.

Base period: This includes the initiation of Discovere® (or comparable application) and completion of tasks as outlined i n the Statement of Work.

Four option periods: Ongoing Discovere® (or comparable application) support and completion of tasks as outlined in the Statement of Work.

7. DELIVERABLES/REPORTING SCHEDULE

Task Number
Deliverable
Delivery Date
Deliver To
Task 1.0
Transition Plan
1 week after contract award
COR
Task 2.0
Kick-Off Meeting Notes
3 weeks after contract award
COR
Task 3.0
Report of findings
4 weeks after request submitted
COR
Task 3.1
Report and demonstration of modifications
12 weeks after request submitted
COR
Task 3.2
Data Dictionary
June 15 of each year
COR
Task 4.0
Written verification of complete SA&A process as specified by CDC Security Officer
November 15, 2017 with recertification as indicated
COR
Task 5.0
E-mail confirmation of beginning of testing phase
October 15 of base year and April 15 of each year after
COR
Task 5.1
Test plan
October 1 of base year and February 1 of each year after
COR
Task 5.2
Testing report
Report due with each updated version of Discovere® or the comparable product
COR
Task 6.0
MMP Discovere® or comparable product deployment verification
November 15 of base year and June 15 of each year after
COR
Task 6.1
MMP Discovere® or comparable product Operating manual
November 15 of base year and June 15 of each year after
COR
Task 7.0
Completion of 4-hour web training session
November 30 of base year and June 30 of each year after
COR
Task 7.1
Distance learning web training
6 web trainings completed by September 30 of each year
COR
Task 7.2
Annual CDC web training
Web training completed by September 30 of each year
COR
Task 7.3
Monthly webinar support
Recording of webinar due monthly, 10 days after webinar
COR
Task 8.0
Technical support
Ongoing, addressed 48 hours after request submitted
COR
Task 9.0
Data Management plan submitted and approved
May 1 of each year
COR
Task 9.1
Demographics table
Monthly
DCC and COR
Task 9.2
Data structure file
Monthly
DCC and COR
Task 9.3
Full processed national dataset and 23 project areas subsets
Quarterly
DCC and COR
Task 9.4
Full national raw dataset
April 30 of each year
DCC and COR
Task 9.5
Final full national raw dataset
July 15 of each year
DCC and COR
Task 9.6
National reabstraction report and 23 project area subsets
Quarterly
DCC and COR
Task 9.7
National reabstraction dataset and 23 project areas subsets
Quarterly
DCC and COR
Task 9.8
Final fully processed national dataset and 23 project area subsets
July 15 of each year
DCC and COR
Task 10.0
List of automated programming quality assurance checks
November 1 of base year and May 1 of each year after and updated on an ongoing basis
COR
Task 10.1
National quality assurance reports and project area specific reports
Monthly
DCC and COR
Task 11.0
Status calls notes
Biweekly
COR

8. SPECIAL CONSIDRERATIONS

Security Requirements and Section 508

The below information complies with HHSA Security compliance requirements for the EGovernment Act of 2002 (FISMA)

Security Compliance

The contractor must have the ability to host and maintain a system for data collection, management, use, and reporting to support activities funded by the federal government. We provide the following information to assist in the preparation of documents necessary for the Security Assessment and Authorization (SA&A) of an Information System. The EGovernment Act of 2002, (Federal Information Management Act) and the below federal policies dictate the framework for assuring information security for data systems operated by or on behalf of the Federal government. These are summarized below.

OMB Circular A-130 (http://www.whitehouse.gov/omb/Circulars_a130_a130trans4/) establishes policy for the management of Federal information resources, pursuant to a number of laws and regulations, including the Paperwork Reduction Act of 1980 (amended in 1995), the Computer Security Act of 1987, and other laws. Circular A-130 requires all federal information systems to have security plans, emergency response capabilities, designated individuals who are responsible for security, security awareness training, and regular review of the system. Appendix III of Circular A-130, entitled “Security of Federal Automated Information Resources,” establishes a minimum set of controls to be included in Federal automated information security programs; assigns Federal agency responsibilities for the security of automated information; and links agency automated information security programs (such as the DHHS AISSP) with OMB Circular No. A-123 The Federal Information Security Management Act of 2002 (P.L. 107-347) (FISMA) http://csrc.nist.gov/drivers/documents/FISMA-final.pdf requires each agency to develop, document, and implement an agency-wide information security program to safeguard information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor (including sub-contractor), or other source. The National Institute of Standards and Technology (NIST) has issued a number of publications that provide guidance in the establishment of minimum security controls for management, operational, and technical safeguards needed to protect the confidentiality, integrity, and availability of a Federal information system and its information.

Pursuant to Federal and HHS Information Security Program Policies the following standards and guidelines apply:

1. FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf),

1. FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf)

1. NIST Special Publication 800-18, Guide to Developing Security Plans for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf

1. NIST Special Publication 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories Vol. 1 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf and Vol. 2 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v2r1.pdf

1. NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

1. NIST Special Publication 800-63, Electronic Authentication Guideline http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-2.pdf

The System Security Plan (SSP) is part of the Security Assessment and Authorization (SA&A) process required by the EGovernment Act of 2002 and NIST Special Publication 800-18, 800-37, and will include selected mandatory controls required by NIST Special Publication 800-53, and NIST Special Publication 800-60 Volume I & II. The successful contractor in conjunction with the NCHHSTP Information System Security Officer (ISSO) will submit SA&A documentation to the CDC Chief Information Security Officer (CISO). The successful completion of the SA&A documents will result in an award of an Authority To Operate. Based on guidance in FIPS 199 and NIST SP 800-60 the system will be assigned an overall security category (SC) of LOW or MODERATE based on (confidentiality, LOW/MODERATE), (integrity, LOW/MODERATE), and (availability, LOW/MODERATE) impact levels. These impact levels will be initially determined by the NCHHSTP ISSO and confirmed by the CDC OCISO Certifying Authority as part of the Certification and Accreditation process.

The successful contractor is responsible for providing pertinent security information to the NCHHSTP ISSO and Security Staff and assisting in completing the below CDC Certification and Accreditation documents to include Annual Assessments, Annual Business Continuity Plan, Re-Certifications and applicable significant/non-significant change requests. Appropriate security templates will be provided to the successful Contractor by the NCHHSTP Security Staff. Completed documents will be sent to the CDC Chief Information Security Office (CISO) for review, approval and subsequent issuance of an Authority To Operate (ATO).

1. Baseline System Information (BSI)

1. Privacy Impact Assessment (PIA)

1. System Security Plan (SSP)

1. Business Continuity Plan (BCP)

1. Risk Assessment Report (RAR)

Deliverable Table

BSI, PIA, SSP, BCP, RAR (SA&A)
Completed Documents due to NCHHSTP ISSO 75 days prior to desired System Production date
Completed Documents Due to CDC Chief Information Security Office 60 days prior to desired System production date
Recertification (required every 3 years or when significant change occurs
Completed Documents due to NCHHSTP ISSO 75 days prior to current ATO expiration date
Completed Documents Due to CDC Chief Information Security Office 60 days prior to current ATO expiration date
Annual Assessment/Business Continuity Plan (BCP)
Completed Documents due to NCHHSTP ISSO 15 days prior to date of annual renewal
Completed Documents Due to CDC Chief Information Security Office 1 day prior to date of annual renewal
Non-Significant Change Requests (OS or application version change, change in data variables)
Completed documentation due to ISSO for signature prior to change implementation
Completed documentation due to OCISO for approval prior to change implementation

The Contractor shall respond to the following seven security–associated requirements in the application:

(1) Position Sensitivity Designations

CDC requires a Public Trust Level 5 for the following

The following position sensitivity designations and associated clearance and investigation requirements apply under this licensing contract:

Level 5: Public Trust - Moderate Risk (Requires Suitability Determination with NACIC, MBI or LBI). Licensor employees assigned to a Level 5 position with no previous investigation and approval shall undergo a National Agency Check and Inquiry Investigation plus a Credit Check (NACIC), a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

Upon award, the Licensor will be required to submit a roster of all staff (including sub-contractor staff) working under the contract that will have the ability to access sensitive NCHHSTP information from the system. The roster shall be submitted to the Project Officer/technical monitor, with a copy to the Contracting Officer, within 14 calendar days of the effective date of the contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer shall notify the licensor of the appropriate level of suitability investigations to be performed, but Licensor employees and subcontractors who have met investigative requirements within the last five years may only require an updated or upgraded investigation. An electronic template, “Roster of Employees Requiring Suitability Investigations,” is available for contractor use at: http://ais.nci.nih.gov/forms/Suitability-roster.xls. Upon receipt of the Government’s notification of applicable suitability investigations required, the Licensor shall complete and submit the required forms within 30 days of the notification.

Non-Disclosure Agreements

The Contractor and any sub-Contractors or employees are forbidden from sharing any technical or logistical information they may gain in conjunction with matters related to this task order that could jeopardize the physical or information security of CDC or its employees, projects, or information systems.

The following apply to Licensor employees and their subcontractors associated with the project:

1. Personnel may not begin work under the contract until the contractor has submitted the employee roster and non-disclosure agreements as described above.

1. Personnel without necessary background investigations will not have access to sensitive project data.

1. Violation of these conditions may lead to termination of the contract.

It is the Contractor's responsibility to ensure that all employees have met CDC and federal requirements, such as, for example, completion of background checks, before gaining or utilizing access to CDC information technology resources.

(2) Privacy Compliance

Licensor in conjunction with CDC Center ISSO shall conduct and maintain an initial Privacy Impact Assessment (PIA) as defined by Section 208 of the E-Government Act of 2002. Periodic reviews shall be conducted by the system owner, with assistance from the CDC Center ISSO and contractor, to determine if a major change to the system has occurred, and if a PIA update is needed.

(3) Contractor’s Official Responsible for Information Security

The contractor shall include in the “Information Security” part of the Technical Proposal the name and title of its official who will be responsible for all information security requirements should the contractor be selected for an award.

(4) Rules of Behavior

The contractor’s employees and subcontractors shall comply with the HHS Information Technology General Rules of Behavior.

(5) Information Security Training

HHS policy requires that contractors and subcontractors shall receive security training commensurate with their responsibilities for performing work under the terms and conditions of their contractual agreements. The successful contractor shall be responsible for assuring that each employee, including subcontractors, has completed the HHS Computer Security Awareness Training course (or another course designated by CDC) prior to performing any contract work, and thereafter completing the HHS-specified annual refresher course during the period of performance of the contract. This would be provided at the Contractor's expense and would be the Contractor's responsibility to plan and arrange.

The successful contractor shall maintain a listing of all individuals who have completed this training and shall submit this listing to the project officer.

(6) HSPD-12 Compliance

Federal Information Processing Standard 201 (FIPS-201) (vii) compliant, Homeland Security Presidential Directive 12 (HSPD-12) card readers shall: (a) be included with the purchase of servers, desktops, and laptops; and (b) comply with FAR Subpart 4.13, Personal Identity Verification.

(7) Encryption

All sensitive CDC-funded data stored on desktop computers used on behalf of HHS shall be secured either through a FIPS 140-2 compliant encryption solution or through adequate physical security and operational controls at the desktop’s residing location.

All mobile devices, portable media and transfer data files that contain sensitive CDC- data shall be encrypted using FIPS 140-2 compliant algorithms.

Section 508 of the Rehabilitation Act of 1973

This section ensures compliance by the Centers for Disease Control and Prevention (CDC) with Section 508 of the Rehabilitation Act of 1973 (Title 29, United States Code [U.S.C.] § 794 (d)), as amended by the Workforce Investment Act of 1998 (Public Law [P.L.] 105-220), August 7, 1998. The policy will be implemented by all CDC employees, contractors, and organizations subject to partner agreements while performing CDC business.

HHSAR Provision, 352.239-73: Electronic and Information Technology Accessibility Notice

(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.

(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at http://www.hhs.gov/web/508. The complete text of the Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.

(c) The Section 508 accessibility standards applicable to this contract are: 1194.21, .22, .31, and .41.

In order to facilitate the Government's determination whether proposed EIT supplies meet applicable Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and documentation detail - whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS Section 508 Evaluation Template are available under Section 508 policy on the HHS Web site http://hhs.gov/web/508.

In order to facilitate the Government's determination whether proposed EIT services meet applicable Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.

(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the described accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.

(End of provision)

File details come from the government source that posted it. Updated .