2031JW20Q00067 RFQ.pdf
PDF 536 KB Posted
- Attached to
- Disabilitly STD/LTD Program Federal contract opportunity
- Solicitation number
- 2031JW20Q00067
About this file
This request for quotation solicits proposals for an experienced contractor to underwrite and administer a short-term and long-term disability insurance program. The contractor will provide integrated disability management services for employees of the Office of the Comptroller of the Currency and the Office of Financial Research. Eligible federal employees total approximately 3,479 for the OCC and 102 for the OFR. The contractor must administer the programs from an integrated approach to ease transitions between short-and long-term benefits. The base period of performance is January 1, 2021 through December 31, 2021, with four optional one-year extensions. Pricing is fixed for both short- and long-term disability coverage. The solicitation includes a performance work statement, deliverables list, and various contract clauses on security, accessibility, and evaluation. The closing date for proposals is June 15, 2020, with award anticipated by January 1, 2021.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 2031JW20Q00067 Disability RFQ.pdf | ||
| OCC DISABILITY QUESTIONS AND ANSWERS RESPONSES.pdf | ||
| Attachment9_Claims Data_2015.07.01 through 2020.05.31.xlsx | XLSX spreadsheet | |
| Attachment 4 - LTD_Certificate.pdf | ||
| Attachment 5 - STD_Certificate.pdf | ||
| Attachment 6 - STD_LTD_Prem_History.xlsx | XLSX spreadsheet | |
| Attachment 8 - Census.xlsx | XLSX spreadsheet | |
| Attachment 3 - Claim_Detail.xlsx | XLSX spreadsheet | |
| Attachment 2 - TechnicalQuestionnaire.docx | DOCX document | |
| Attachment 1 - Non-Disclosure Agreement.doc | DOC document | |
| Attachment 7 - VPAT.docx | DOCX document |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUMIS CHECKED
CODE 18a. PAYMENT WILL BE MADE BY
CODE
FACILITYCODE
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
OFFEROR
OCC
Washington DC 20219
400 7TH STREET SW
Acquisitions Management Comptroller of the Currency
CODE 16. ADMINISTERED BYCODE
X
X
SIZE STANDARD:
% FOR:SET ASIDE:UNRESTRICTED OROCC
RFPIFB
10. THIS ACQUISITION ISCODE
RFQ
14. METHOD OF SOLICITATION
13b. RATING
NAICS:
SMALL BUSINESS
07/13/2020 1000 ET
06/15/2020
CLIFTON GARDNER
(No collect calls)
INFORMATION CALL:
FOR SOLICITATION 8. OFFER DUE DATE/LOCAL TIMEb. TELEPHONE NUMBER a. NAME
4. ORDER NUMBER3. AWARD/ 6. SOLICITATION
2031JW20Q00067
5. SOLICITATION NUMBER
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS 1. REQUISITION NUMBER PAGE OF
1 66 OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
TELEPHONE NO.
17a. CONTRACTOR/
15. DELIVER TO
Washington DC 20219
400 7TH STREET SW
Acquisitions Management
9. ISSUED BY
7.
2. CONTRACT NO.
EFFECTIVE DATE
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW
ISSUE DATE
DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
11.
SEE SCHEDULE
12. DISCOUNT TERMS
THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13a.
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
8(A)
Comptroller of the Currency
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
24.
AMOUNT
23.
UNIT PRICE
22.
UNIT
21.
QUANTITY
20.
SCHEDULE OF SUPPLIES/SERVICES
19.
ITEM NO.
Inv Approver/COR: WILDER, ROSE Period of Performance: 01/01/2021 to 12/31/2021
(Use Reverse and/or Attach Additional Sheets as Necessary)
HEREIN, IS ACCEPTED AS TO ITEMS:
XX
DATED
ROMENA R. MOY
. YOUR OFFER ON SOLICITATION (BLOCK 5),
INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER
ARE
ARE
31c. DATE SIGNED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (Type or print)
ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL
SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
26. TOTAL AWARD AMOUNT (For Govt. Use Only)
OFFER
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
ARE NOT ATTACHED.
ARE NOT ATTACHED.
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
30b. NAME AND TITLE OF SIGNER (Type or print)
30a. SIGNATURE OF OFFEROR/CONTRACTOR
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
25. ACCOUNTING AND APPROPRIATION DATA
29. AWARD OF CONTRACT:
REF.
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE
32c. DATE 32b. SIGNATURE OF AUTHORIZED GOVERNMENT REPRESENTATIVE
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
40. PAID BY39. S/R VOUCHER NUMBER38. S/R ACCOUNT NUMBER
37. CHECK NUMBER
FINALPARTIAL
36. PAYMENT
FINALPARTIAL
35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER33. SHIP NUMBER
COMPLETE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
42d. TOTAL CONTAINERS42c. DATE REC'D (YY/MM/DD)
42b. RECEIVED AT (Location)
42a. RECEIVED BY (Print)
41c. DATE41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
STANDARD FORM 1449 (REV. 2/2012) BACK
24.
AMOUNT
23.
UNIT PRICE
22.
UNIT
21.
QUANTITY
20.
SCHEDULE OF SUPPLIES/SERVICES
19.
ITEM NO.
32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT REPRESENTATIVE
66 2 of
Disability Insurance Program STD/LTD Request for Quotation No. 2031JW20Q00067
PART I - SUPPLIES OR SERVICES AND PRICES/COSTS
1.0 General
The contractor shall provide the services specified in Section C, Performance Work Statement, of this Request for Quote. The NAICS for this requirement is 524113, Direct Life Insurance Carriers.
1.1 TYPE OF CONTRACT
A Firm Fixed Price Contract will be awarded pursuant to this solicitation at the rates specified in each Contract Line Item Number (CLIN) Description. These prices shall be in effect through the base period of the contract and option periods, if exercised.
1.2 Contract Line Item Number (CLIN) Description
The number of eligible employees enrolled in the Short-Term Disability (STD) and eligible employees covered by Long-Term Disability (LTD) plans is estimated and used for the purposes of establishing a funding amount for each performance period. The OCC employee population may fluctuate within each performance period resulting in an increase or decrease throughout the year (i.e., there may be a variation in quantity). The OCC will remit premium payment based on the actual benefit eligible employee population for that month for LTD at the performance period’s fixed unit rate.
Funds for LTD will be obligated at time of award for the base period (or at the time each option period is exercised, if the Government chooses to exercise an option). The contractor shall notify the CO when 75% of these funds have been invoiced to the OCC. The contractor shall provide an estimate of additional funds required for the remainder of the period of performance.
2.0 LTD Pricing
The total price for the base and option periods is anticipated to be $___________________ (based on covered payroll). This amount and the amount associated with the total price for each year (i.e., column 3 in the tables below) are estimates used to establish a contract value. Monthly premium payments are to be based on the actual number of benefit eligible employees and the monthly payroll at the time of payment. The unit rate(s) for this contract are “fixed” for each year as specified below. Rates shall not include commissions/fees to any selling agent.
0001 Base Year (January 1, 2021 through December 31, 2021) Type of Coverage Monthly Rate Per $100 of
Coverage Estimated Total Price for Base (based on covered payroll)
Long-Term Disability $________ $_____________________
0002 Option Year 1 (January 1, 2022 through December 31, 2022) Type of Coverage Monthly Rate Per $100 of
Coverage Estimated Total Price for Option Year 1 (based on covered payroll)
Long-Term Disability $________ $_____________________
0003 Option Year 2 (January 1, 2023 through December 31, 2023) Type of Coverage Monthly Rate Per $100 of
Coverage Estimated Total Price for Option Year 2 (based on covered payroll)
Long-Term Disability $________ $_____________________
0004 Option Year 3 (January 1, 2024 through December 31, 2024) Type of Coverage Monthly Rate Per $100 of
Coverage Estimated Total Price for Option Year 3 (based on covered payroll)
Long-Term Disability $________ $_____________________
0005 Option Year 4 (January 1, 2025 through December 31, 2025) Type of Coverage Monthly Rate Per $100 of
Coverage Estimated Total Price for Option Year 4 (based on covered payroll)
Long-Term Disability $________ $_____________________
2.1 STD PRICING
The total price for the base and option periods is anticipated to be $__________________ (based on covered payroll). The unit rates for this contract are fixed for each year as specified below. Bi-weekly premium payments are to be based on the actual number of employees enrolled and the bi-weekly payroll at the time of payment.
0007 Base Year (January 1, 2021 through December 31, 2021) Maximum Weekly Benefit
Age Brackets Biweekly Rate Per $10 of Weekly Coverage
Annual Cost Estimate (2317 employees)
$3,808 <35 35-39 40-44 45-49 50-54 55-59 60>
0008 Option Year 1 (January 1, 2022 through December 31, 2022) Maximum Weekly Benefit
Age Brackets Biweekly Rate Per $10 of Weekly Coverage
Annual Cost Estimate (2317 employees)
$3,808 <35 35-39 40-44 45-49 50-54 55-59 60>
0009 Option Year 2 (January 1, 2023 through December 31, 2023)
Benefit
Age Brackets Biweekly Rate Per $10 of Weekly Coverage
Annual Cost Estimate (2317 employees)
$3,808 <35 35-39 40-44 45-49 50-54 55-59 60>
0010 Option Year 3 (January 1, 2024 through December 31, 2024)
Benefit
Age Brackets Biweekly Rate Per $10 of Weekly Coverage
Annual Cost Estimate (2317 employees)
$3,808 <35 35-39 40-44 45-49 50-54 55-59 60>
0011 Option Year 4 (January 1, 2025 through December 31, 2025)
Benefit
Age Brackets Biweekly Rate Per $10 of Weekly Coverage
Annual Cost Estimate (2317 employees)
$3,808 <35 35-39 40-44 45-49 50-54 55-59 60>
PART II – PERFORMANCE WORK STATEMENT (PWS)
1.0 INTRODUCTION
The OCC is a non-appropriated federal financial regulatory bureau of the U. S. Department of the Treasury. The OCC charters, regulates, and supervises all national banks and federal savings associations. It also supervises the federal branches and agencies of foreign banks. The OCC is headquartered in Washington, DC. It also has primary locations in Chicago, Dallas, Denver and New York to supervise the international activities of national banks. The OCC employs approximately 3,479 employees in approximately 70 cities nationwide.
The OCC is a federal government agency that has authority to offer compensation and benefits programs outside of those offered by the federal government. The OCC sponsored benefit programs include, but are not limited to, dental, vision, life insurance, accidental death and dismemberment insurance, business travel accident insurance, flexible spending accounts, 401(k) plans, STD and LTD insurances.
The Office of Financial Research (OFR), which was established within Treasury as a result of Dodd-Frank, has a Memorandum of Understanding with the OCC for the provision of services related to some of the benefits that the OFR provides to its employees; therefore, the OFR became a participant in the OCC’s STD and LTD plans, in which its employees were able to enroll starting in July 2011. Currently, the OFR employs approximately 102 employees located in Washington, DC and New York.
Also due to Dodd-Frank, the Office of Thrift Supervision (OTS) merged into the OCC and effective August 2012; these employees were eligible to participate in the STD/LTD plans.
Hence, the premium history will show a spike in paid premiums.
Both the OCC and the OFR, as governmental plans, are specifically exempted from Title I of
ERISA.
2.0 SCOPE OF WORK
2.1 General
The OCC is seeking an experienced and qualified contractor to underwrite and administer its STD and LTD insurances program for its employees as well as the employees of the OFR. The contractor shall administer these programs from an integrated disability management approach to ease the transition from STD to LTD. This integrated approach should enhance employees’ overall experience that aids in the return to work efforts, vocational rehabilitation, claim filing process, and early social security notice. Federal employees are ineligible for state disability benefits. Both STD and LTD are fully insured plans.
The OCC and the OFR provide its employees leave that is consistent with all applicable laws and regulations. This includes sick leave, annual leave, leave without pay (LWOP), family and medical leave (FMLA), leave transfer and leave bank programs. The OCC’s policy is to administer the STD and LTD benefits in conjunction with the usage of sick leave, leave donated from the leave transfer or leave bank programs. Employees must be in a non-pay status/LWOP to receive STD/LTD benefits.
Additionally, in support of the OCC’s efforts to educate employees on healthy living and their benefit options, the successful contractor shall attend an onsite health benefits fair that is generally held in November of every year at OCC’s headquarters location at 400 7th Street, SW, Washington, DC. The contractor is to supply handouts and giveaways and be prepared to answer employee questions concerning the OCC disability insurance program.
2.2 Eligibility
For STD and LTD, the eligibility requirement is defined as a regular employee (full-time or part-time) or temporary employee with an appointment greater than one year who is actively at work at least 60 hours biweekly.
2.3 Enrollment and Effective Dates
Enrollment Employees have two opportunities to enroll in STD:
• New Hire – Employees who enroll within 31 days of hire.
• Late Enrollment – Employees who decide not to enroll as a new hire may enroll at any time but they will be subject to a late enrollment penalty.
Late Enrollment Penalty The late enrollment penalty is applicable in lieu of medical underwriting/pre-existing clauses.
The late enrollment penalty changes the benefit-waiting period from seven calendar days to 30 calendar days. During this period, employees are required to exhaust all accrued sick leave and the time is concurrent with the 30 calendar days. The penalty will apply if employees file a claim for an illness, pregnancy or a mental disorder during the first 12 months after the employees’ effective date of coverage. After the first 12 months of coverage, the benefit-waiting period reverts to the seven calendar days. The late enrollment penalty does not apply to a disability caused by accidental injury (injury to the body).
The OCC plan provides for a late enrollment penalty in lieu of medical underwriting.
Effective Dates For STD, enrollments are effective the first of the month following the receipt of a completed enrollment form by Human Resources.
For LTD, coverage is effective on the date employees meet the eligibility requirements.
Enrollment Data The OCC maintains the STD enrollment data for its employees and the employees of OFR. For LTD, eligible employees are covered as of the date of hire and no enrollment is necessary and the population data is maintained by the OCC.
2.4 Premium Cost
For STD, OCC and OFR employees pay 100 percent of the premium via payroll deductions on a bi-weekly basis. The premium is deducted on an after-tax basis and benefit payments are non-taxable. On a biweekly basis, STD premium payments will be remitted electronically via the payroll vendor, the National Finance Center (NFC). This is applicable for the OCC and the OFR employees.
For LTD, the OCC and the OFR pay 100 percent of the premium for its employees; therefore, 100 percent of the benefit payment is subject to taxation for employees. For STD/LTD, the contractor shall be responsible for all tasks related to tax reporting. This includes the preparation and distribution of appropriate tax filing documents, e.g., 1099 and W-2 for each claimant for paid benefits in accordance with the plan.
OCC will prepare separate self-billed invoices on a monthly basis for both the OCC and the OFR.
OCC will send the vendor a copy of the invoice electronically via email on a monthly basis.
2.5 Workload Requirements
The Contractor shall provide services in accordance with this PWS regardless of the actual amount of services or fluctuation in services. There is no guaranteed minimum amount of services to be covered. Any information in this PWS regarding estimated or historical services is intended to aid the Contractor in understanding the requirements associated with the services and in submitting an appropriate proposal.
Table 1: Estimated Annual Population Summary for the Proposed Term of the Contract
Employees with a leave balance less than the maximum benefit period could perhaps benefit from enrolling in the STD program. These employees have sick leave balances of 13 weeks or less, which is the maximum benefit period for STD (40 hours per week times 13 weeks = 520 hours).
Refer to Technical Attachment 8 (OCC Census Data – Labeled VSTD Potential) for additional.
For the OCC, the potential population is about 2,234, of which approximately 1,166 employees are enrolled in STD.
For the OFR, the potential population is about 83, of which approximately 39 employees are enrolled in STD.
Service Type Service Requirement Population Location
OCC Short-Term Disability Annually
2,234 Benefit Eligible Employees that could potentially enroll in benefit
Worldwide and Continental US
OCC Long-Term Disability Annually 3,448 Benefit Eligible
Employees Worldwide and Continental US
OFR Short-Term Disability Annually
83 Benefit Eligible Employees that could potentially enroll in benefit
Continental US
OFR Long-Term Disability Annually 102 Benefit Eligible
Employees Continental US
2.6 Plan Design
The STD and LTD plans shall be administered from an integrated disability management approach. The OCC’s intent is to increase the benefit maximum amount from $300,000 (60 percent $180,000) to ($330,000 maximum at 60 percent $198,000). The OCC’s policy is to administer the STD and LTD benefits in conjunction with the usage of sick leave, leave donated from the leave transfer or leave bank programs. Employees must be in a non-pay status/LWOP to receive STD/LTD benefits. Federal employees are ineligible for state disability benefits. The following tables summarize the plan design that the OCC plans to implement under this contract.
Plan Design STD LTD Benefit 60% weekly salary 60% monthly salary Benefit Max/Min* ($330,000 maximum at 60 percent $198,000)
$3,808/$25* $16,500/greater of $100 or 10% of monthly benefit*
Benefit Waiting Period 7 calendar days plus the use of all accrued sick leave and leave donated from the leave bank or leave transfer programs
90 calendar days plus the use of all accrued sick leave and leave donated from the leave bank or leave transfer programs
Late Enrollment Penalty 30 calendar days plus the use of all accrued sick leave and leave donated from the leave bank or leave transfer programs
Note: The Late Enrollment penalty does not apply to a disability caused by accidental injury (injury to the body)
N/A
Maximum Benefit Period 90 calendar days Varies (age at the time of disability) *Minimum Benefit is not applicable while in a paid status from the OCC or OFR.
3.0 PERSONNEL REQUIREMENTS
The contractor shall provide an account manager that will be a single point of contact and serve as a liaison to the OCC to address day-to-day matters. The individual must have a minimum of three years of account management experience in the insurance industry.
4.0 CLAIMS EXPERIENCE
Claims experience is provided for both STD/LTD plans. Refer to Technical Attachment 3 – STD/LTD Claims Data.
5.0 PLACE OF PERFORMANCE
The contractor shall perform all its duties relating to this contract at the contractor’s work location. The OCC will inspect the contractor’s place of performance prior to the award of this contract and annually at the OCC’s discretion.
6.0 PERFORMANCE REQUIREMENT SUMMARY
All services under this contract will be subject, at all times to inspection by the Government.
Although the Government retains the right to specifically enforce all clauses in the contract, the Performance Requirement Summary (PRS) identifies those contract requirements considered most important to acceptable contract performance and the Government’s intended quality assurance procedures. The PRS references the most applicable section of the PWS, the qualitative performance standards (objectives), the Government’s intended quality assurance procedures and frequency of inspection (measures), and what the Government believes is the minimum satisfactory rating (expectations) at this time. The Contracting Officer (CO) may unilaterally change the PRS provided the contractor is notified of the change at least 30 calendar days prior to the beginning of the evaluation period to which the changes apply. Please see Appendix A for the
PRS.
7.0 DELIVERABLES
See Appendix B for the list of deliverables and associated due dates.
8.0 PAYMENT OF POSTAGE AND FEES
All postage and fees related to submitting information, including forms, reports, etc., to the Contracting Officer (CO) or the Contracting Officer’s Representative (COR) shall be paid by the Contractor.
9.0 MARKING
All information submitted to the CO or the COR shall be clearly marked to show the following:
1. Name of the Contractor
2. Contract Number
3. Consignee’s name and address
4. Date of Submission
10.0 REPORT COVER SHEET
Each report submitted by the Contractor shall have a cover sheet containing the following information:
1. Title of report
2. Report number or type
3. Period covered by the report
4. Contract number
5. Name and address of the Contractor
6. Name of the COR
7. Date of Submission
11.0 Acceptance Criteria
The Contracting Officer’s Representative (COR) will review all draft and final deliverables to ensure accuracy, functionality, completeness, professional quality, and overall compliance with the guidelines/ requirements. The contractor shall ensure the accuracy and completeness of all deliverables. Errors, misleading or unclear statements, incomplete or irrelevant information, and/or excessive rhetoric, repetition, and/or “padding”, shall be considered deficiencies and shall be subject to correction by the contractor, at no additional cost to the Government. Unless otherwise indicated, the Government will require ten business days to review and comment on deliverables. If the deliverable does not meet the noted criteria, the Government will return it for correction.
12.0 Rejection Procedures
If the COR rejects any deliverable, that rejected document will be handled in the following manner:
12.1 After notification that the deliverable did not meet the acceptance criteria, the contractor shall re-submit an updated/corrected version within five business days after receipt of Government comments.
12.2 Upon re-submission by the Contractor, the Government will reapply the same acceptance criteria. If the deliverable does not meet the acceptance criteria a second time, the Government may consider the Contractor as having deficient performance with respect to the deliverable.
13.0 IT Accessibility
All electronic documents and proposed solution, such as a web-based automated enrollment system shall comply with Section 508 of the Rehabilitation Act of 1973 as amended. The OCC has identified the following applicable standards:
36 CFR 1194.22 – Internet and Intranet Information and Applications 36 CFR 1194.31 – Functional Performance Criteria 36 CFR 1194.41 – Information, Documentation, and Support
APPENDIX A
PERFORMANCE REQUIREMENTS SUMMARY
PWS Performance Requirement
Standard (Objective)
Method of Surveillance (Measurement)
Frequency Acceptable Quality Level (AQL)
Incentive/Disincentive
Adjudicate STD claims and all actions necessary in determining a claimant’s disability status in accordance with the plan.
Ensure that total claim process is handled within 10 days upon receipt of a completed claim.
Evaluation of the Activity Report or Claim Experience Report by the Contracting Officer’s Representative
(COR).
Quarterly 80% of STD claims for the month must be adjudicated within 10 days from receipt of a completed claim by the insurance company.
Incentive: If contractor meets or exceeds AQL, OCC will give favorable past performance.
Disincentive: If contractor fails to meet AQL, 0.5% of annual policy premium will be reimbursed directly to OCC. The insurance company will reimburse OCC via check on annual basis.
Adjudicate LTD claims and all actions necessary in determining a claimant’s disability status in accordance with the plan.
Ensure that total claim process is handled within 45 days upon receipt of a completed claim.
Evaluation of the Activity Report or Claim Experience Report by the
COR.
Quarterly 80% of LTD claims for the month must be adjudicated within 45 days of a completed claim by the insurance company.
Incentive: If contractor meets or exceeds AQL, OCC will give favorable past performance.
Disincentive: If contractor fails to meet AQL, 0.5% of annual policy premium will be reimbursed directly to OCC. The insurance company will
PWS Performance Requirement
Standard (Objective)
Method of Surveillance (Measurement)
Frequency Acceptable Quality Level (AQL)
Incentive/Disincentive reimburse OCC via check on annual basis.
For LTD - Prepare the appropriate tax filing documents, e.g. 1099 and W2, for each claimant for paid benefits in accordance with the plan.
Ensure timely issuance of tax filing documents annually
Evaluation of the Disability Income Report (1099 and W-2) by the COR.
Annually 100% of all 1099s and W2s will be issued in accordance with IRS deadline.
Incentive: If contractor meets or exceeds AQL, OCC will give favorable past performance.
Disincentive: If contractor fails to meet AQL, 0.5% of annual policy premium will be reimbursed directly to OCC. The insurance company will reimburse OCC via check on annual basis.
For STD and LTD – Provide staff to perform customer services duties in accordance with administering the plan.
Speed to answer calls within 30 seconds.
Call Intake Report.
Quarterly 90% of all calls are answered within 30 seconds.
Incentive: If contractor meets or exceeds AQL, OCC will give favorable past performance.
If contractor fails to meet AQL, 2% of annual policy premium will be reimbursed directly to OCC. The insurance company will reimburse OCC
PWS Performance Requirement
Standard (Objective)
Method of Surveillance (Measurement)
Frequency Acceptable Quality Level (AQL)
Incentive/Disincentive via check on annual basis.
1. Respond to COR and CO emails, phone calls, and faxes.
2. Coordinate attendance of a contractor’s representative at OCC’s annual benefits fair held at its headquarters location.
3. Coordinate site visit to the claim office and/or home office.
1. Response is within 24 hours.
2. Ensure availability of representative.
3. Ensure that the arrangements are made within 2 weeks of the request to meet by the COR.
1. Log maintained by
COR.
2. Monitored by COR day of the event.
3. Monitored by
COR.
1. Quarterly
2. Annually
3. Annually
1. 90% of all emails, phone calls, and faxes are responded to within 24 hours.
2. Standard is met 100%.
3. Standard is met 100%.
Incentive: If contractor meets or exceeds AQL, OCC will give favorable past performance.
Disincentive: If contractor fails to meet AQL, 0.5% of annual policy premium will be reimbursed directly to OCC. The insurance company will reimburse OCC via check on annual basis.
APPENDIX B
REQUIRED REPORTS/LETTERS/DOCUMENTS LISTING
Reports/ Letters/ Deliverables Submission Date
Insurance Policies and Certificates (Electronic) Six weeks after date of contract award
Forms and Brochures (Electronic) Six weeks after date of contract award
Implementation Project Plan As agreed upon between the OCC and the Contractor
Create Reporting Structures for the OCC and the OFR Six weeks after date of contract award
STD/LTD At-a-Glance As agreed upon between the OCC and the Contractor
Claim Filing Instructions (Electronic and Hardcopy) Six weeks after date of contract award
Disability Income Report (1099 and W-2) Annually
Call In-take Report Quarterly Experience Report – reflect paid claims, active claims, reserves IBNR, Employer FICA, commissions, premium taxes, other expense and risk charges
Annually
Activity Report – (includes receive date for a completed claim, date of claim decision, date of notification letter, date first payment issued, deductions, adjusted net benefits, benefits withheld, offsets etc.)
Monthly
Claims Experience Report (active and closed claims) As agreed upon between the OCC and the Contractor
Federal Market Security and Privacy Requirements
A. Compliance with Applicable Laws, Regulations, and Standards
1. Federal Laws. The contractor and all of its respective subcontractors shall follow and remain compliant at all times with the Federal Acquisition Regulation (FAR), Privacy Act of 1974 (5 U.S.C. 552a - the Act), and the Federal Information Security Modernization Act of 2014 (Public Law 107-347) (FISMA), as applicable.
2. Regulations and Standards. The contractor and all of its respective subcontractors shall comply with current federal regulations and guidance found in Executive Orders, Office of Management and Budget (OMB) circulars and memorandum, National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) publications and the 800-Series Special Publications (SP), Department of Homeland Security (DHS) Directives, and other relevant federal laws and regulations that apply to OCC data, including, but not limited to:
• FIPS 200
• FIPS 199
• OMB Circular A-130
• OMB M-03-22, M-06-19, M-06-19, M-07-16
• NIST Special Publications (SP) (current revisions) o 800-34 o 800-37 o 800-18 o 800-30 o 800-60 o 800-53 o 800-53A o 800-144
3. OCC Policy and Standards. The contractor and all of its respective subcontractors shall comply with all Office of the Comptroller of the Currency (OCC) security and privacy policies and standards in effect at the time of the award of the contract, as well as those requirements that may be added during the contract.
The contractor/service provider shall conform to OCC administrative regulations, policies, and procedures, as listed in section [cite corresponding location in contracting document], in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. The contractor shall work with OCC internal organizations as needed to ensure that policies, procedures, configuration control, and product life-cycle requirements are fulfilled to the satisfaction of OCC ITS.
The contractor shall support agency’s operational models and specific security rules throughout the duration of the contract. The contractor shall support adjustments based on threats identified by the TIC Portal SOC. For example, adjustments to the security policy could be made by the OCC's authorities after the SOC identifies changing trends in intrusion behavior.
4. Privacy Act. As prescribed in the FAR 24.104, if the contract involves the design, development, or operation of a system of records on individuals, the contractor must implement requirements in FAR clause 52.224-1, “Privacy Act Notification” and FAR clause 52.224-2, “Privacy Act.” In addition, the contractor is responsible for ensuring individuals supporting the OCC are trained in accordance with FAR clause 24.301, “Privacy Training.”
5. Section 508 Accessibility. The contractor’s products and services shall comply with all applicable provisions of the standards issued by the Architectural and Transportation Barriers Compliance Board (Access Board) (http://www.access-board.gov/sec508/guide/) to ensure the accessible use of federal electronic and information technology.
B. Solution Authorization before Operations
1. Authorization for External Service Providers. Per NIST Special Publication 800-53, as amended, Security and Privacy Controls for Federal Information Systems and Organizations:
FISMA and OMB policies require that federal agencies using external service providers to process, store, or transmit federal information or operate information systems on behalf of the federal government, assure that such use meets the same security requirements that federal agencies are required to meet. Security requirements for external service providers including the security controls for external information systems are expressed in contracts or other formal agreements. Organizations are responsible and accountable for the information security risk incurred by the use of information system services provided by external providers. Such risk is addressed by incorporating the Risk Management Framework (RMF) as part of the terms and conditions of the contracts with external providers.
Organizations can require external providers to implement all steps in the RMF except the security authorization step, which remains an inherent federal responsibility directly linked to managing the information security risk related to the use of external information system services.
Organizations can also require external providers to provide appropriate evidence to demonstrate that they have complied with the RMF in protecting federal information.
Prior to the implementation of the contractor’s system or services, the OCC will provide an Authority to Operate (ATO) or Authority to Use (ATU), based on the findings of the OCC’s analysis of the system or services IT security and privacy controls.
2. FedRAMP. FedRAMP is mandatory for federal agency cloud deployments and service models at the low, moderate, and high risk impact levels. Private cloud deployments intended for single organizations and implemented fully within federal facilities are the only exception.
3. FedRAMP. The Contracting Office may decide to prioritize specific security controls in which the contractor must perform ISCM to include AC-2, AU-6, CA-5, RA-5, SI-2, and SI-3. The contractor shall ensure that any system, application, or environment being operated on behalf of the OCC or being used to process any OCC information must meet these requirements, including services that are either fully or partially provided, such as other agency hosted, outsourced, and cloud computing solutions.
4. FIPS System Category. It is anticipated that the FIPS 199 baseline for the [name] system/application will be [low/moderate/high]. As a result, the OCC has determined that all Federal Information Security Modernization Act of 2014 (FISMA) security and privacy requirements for a [low/moderate/high] impact system apply to the contractor and the contractor systems supporting these services.
B. General Requirements
1. Location. The contractor shall not host any portion of the information, data, information system, infrastructure, or environment in facilities outside the contiguous United States, Alaska, Hawaii, and other U.S. Territories. Information collected, used, stored, maintained, or otherwise processed by the contractor in the performance of this contract shall be accessed, transferred, stored or processed only within the United States. In addition, the maintenance and support operations of the contractor’s technology and information must take place, and originate from, within the United States.
The primary locations shall be the primary and backup data centers located within the sole jurisdiction of the United States Federal Government. In addition, the maintenance and support operations of the contractor’s technology and information must take place, and originate from, within the United States.
2. FISMA Reporting Requirements. Contractors operating information systems on behalf of OCC must comply with FISMA reporting requirements. Annual and quarterly data collection will be coordinated by OCC. Contractors must provide OCC with the requested information based on the timeframes provided with each request. Contractor systems must comply with monthly data feed requirements as coordinated by OCC.
Reporting requirements are determined by OMB and may change each reporting period.
The contractor will provide OCC with all information to fully satisfy FISMA reporting requirements for the contractor system.
3. Authorization to Use, Store, or Share Sensitive Information. The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems, gathered or created under this contract shall be considered as [Controlled Unclassified Information] information. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.
4. Deliverables. The deliverables in this contract will be considered sensitive and shall not be shared with any other organization without prior approval from the OCC Contracting Officer.
5. Confidentiality. The contractor agrees to assume responsibility for protecting the confidentiality of Government records and data associated with this contract, which are not public information. Each contractor or employee of the contractor to whom information may be made available or disclosed shall be notified in writing by the contractor that such information may be disclosed only for a purpose and to the extent authorized herein.
6. Customer Design Specifications. The contractor shall provide detailed technical architecture specifications and design artifacts for any client-site (i.e., OCC-hosted) IT components related to the use of the [solution name], to include ports, protocols and services. A summary of these requirements shall be provided in the contractor’s proposal.
The contractor shall also detail any actions required by the OCC to enable installation, configuration, and use of the [solution name]. Final architecture specifications and design artifacts shall show any interconnections to the OCC and/or external components or system, as well as any supporting software used in the final OCC solution, and shall be provided within 60 days of contract award.
C. Security and Privacy Assessment and Monitoring
1. Assessment. The contractor shall be responsible for performing an initial IT security and privacy control assessment of all applicable controls for each IT component associated with the [solution name], to include facility controls and IT network infrastructure controls, with the exception of the organizational common controls inherited from the
OCC.
The contractor shall also be responsible for performing annual or more frequent IT security and privacy control assessments of all applicable controls for each IT component associated with the [solution name], to include facility controls and IT network infrastructure controls, with the exception of any organizational common controls inherited from the OCC.
The assessments shall be performed by a certified Third- Party Assessment Organization (3PAO) or a qualified independent assessor that meets the qualifications and independence requirements and guidelines specified in NIST SP 800-37 and NIST SP 800-53 (Current Revision).
As part of the SA&A package, the contractor shall be responsible for documenting a Security and Privacy Control Assessment (SPCA) Plan and a Security and Privacy Assessment Report (SAR) for each assessment, as well as a Plan of Action and Milestones (POA&M) for each deficiency identified during the initial and annual/ongoing IT security and privacy control assessments.
The contractor shall complete the SA&A process and provide the required documents to the OCC within 60 calendar days of contract award. The OCC may choose to issue a conditional ATO or ATU for the solution commensurate with identified risk, based on an independent assessment of applicable security and privacy controls.
2. Security Assessment & Authorization (SA&A) Package. A written ATO or ATU granted by the OCC Authorizing Official (AO) is required prior to processing operational data or connecting to any OCC network. The contractor shall provide access to all information and documentation needed to support the OCC’s determination of whether to authorize the solution for operation and the migration of production data to the solution, at no additional cost to the OCC.
The SA&A Package shall be developed in accordance with OMB A-130 and applicable NIST SPs, and shall contain the following, at a minimum:
1) Security and Privacy Assessment Report (SAR)
2) System Security Plan (SSP) and Privacy Plan
3) Contingency Plan
4) Contingency Plan Test Results
5) Configuration Management Plan
6) Continuous Monitoring Plan (must conform to the NIST SP 800-137 and be formally approved by the OCC CISO or designee)
7) Federal Information Processing Standards (FIPS) 199 Security Categorization
8) Privacy Threshold Analysis (PTA)
9) E-Authentication Risk Assessment / Digital Identity Risk Assessment (per NIST SP 800-
63-3)
10) Security and Privacy Assessment Plan (SAP)
11) Current ATO Letter if an ATO has been granted by another Federal Agency
12) Current/open POA&Ms
13) Ongoing Authorization Artifacts as required by the OCC Information Security
Continuous Monitoring Strategy and Privacy Continuous Monitoring Strategy (current version).
3. Plan of Action and Milestones (POA&M) Management. The contractor shall manage
POA&Ms identified through the assessment and monitoring processes in accordance with
(A) the OCC POA&M management procedures (available upon contract award); or (B) with POA&M management procedures established by the contractor for the purposes of this initiative, provided that the POA&M management procedures and mechanisms are established in accordance with all relevant Federal requirements, as determined by a 3PAO/independent assessment.
The POA&Ms shall be provided to the OCC COR following each assessment and made available to authorized OCC personnel within (7) calendar days upon request throughout the remediation process.
4. POA&M Remediation. The contractor shall remediate problems identified during security testing as needed to ensure the system/application meets applicable control requirements. The contractor shall document the resolution for each weakness in a Plan of Action and Milestones (POA&M) and provide supporting evidence of weakness remediation upon completion.
The contractor shall be responsible for remediating, and having an independent party validate the remediation of, identified IT security and privacy control deficiencies, per the POA&Ms, and bringing the solution into an acceptable level of risk and compliance to enable the OCC to issue an ATO for the solution.
The contractor shall schedule a weekly meeting with the COR and other relevant stakeholders to review POA&M status and resolutions until all deficiencies are addressed.
5. Ongoing Authorization. The contractor shall provide the OCC with access to all information and documentation needed to support the OCC's ongoing authorization for the solution and shall provide periodic status of risk updates including:
a. Annual Security and Privacy Assessment Report (SAR).
b. Quarterly Open POA&M report and, if any, actions taken to mitigate and/or remediate open POA&Ms.
c. Quarterly vulnerability and configuration compliance scans for components relevant to the [insert name] solution provided to the OCC.
d.
6. FedRAMP Solutions (ONLY). Should the vendor submit a proposal for a FedRAMP solution, items 1-5 above will not apply. The determination of whether to issue an authorization to operate (ATO) will be made by the OCC based on the identified risks to the OCC’s data/operations. These risks include: (1) the gaps identified in the IT security and privacy control assessments performed specific to FedRAMP ATO package customer responsibility implementation/deviations; (2) deficiencies noted in the POA&Ms that are open at the time of the ATO determination for each FedRAMP ATO package; and (3) IT control deficiencies identified in assessments of the IT components associated with the [solution name] that are not specifically incorporated within the boundary of a current FedRAMP package (if applicable).
The contractor shall be responsible for performing an initial IT security and privacy control assessment of (1) each FedRAMP ATO package customer responsibility implemented by the contractor and/or the OCC under the contract, and (2) each change to the FedRAMP ATO packages under the contract.
The contractor shall also be responsible for performing annual IT security and privacy control assessments of (1) each FedRAMP ATO package customer responsibility implemented by the contractor and/or the OCC under the contract, and (2) each change to the FedRAMP ATO packages under the contract.
The assessments shall be performed by a FedRAMP-certified Third-Party Assessment Organization (3PAO). Both the 3PAO and the assessments shall be furnished by the contractor as part of the proposed solution.
D. Configuration Management
1. Configuration Management. Hardware or software configuration changes shall be in accordance with the defined and OCC-approved Configuration Management Plan and associated change control procedures. The OCC Cyber Security Office (CSO) shall be informed of and involved in all configuration changes to the OCC IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The OCC CSO shall approve any request for change prior to any development activity occurring for that change and shall define the security requirements for the requested change.
2. Equipment Maintenance. The contractor shall ensure that the system, once operational, is properly maintained and monitored, to include immediate response to critical security patches, routine maintenance windows to allow for system updates, and compliance with the defined configuration management and change control processes. All patches and system updates shall be properly tested in a development environment before being implemented in the production environment.
E. Continuous Monitoring
1. Information Security and Privacy Continuous Monitoring. All contractor systems must participate in Information Security Continuous Monitoring (ISCM) and Privacy Continuous Monitoring and reporting. The contractor will be expected to perform automated scans and continuous monitoring activities which may include, but will not be limited to, authenticated and unauthenticated scans of networks, operating systems, applications, and databases and provide the results of the scans to the OCC CIO, or designee, or allow the OCC (or its designee) to run the scans directly.
2. Monthly Reports. The contractor shall submit monthly continuous monitoring reports to the OCC COR by the 5th of each month. At a minimum, the continuous monitoring reports shall detail vulnerabilities identified, secure configuration compliance status, status of open POA&Ms and accepted risks, and independent assessments planned/completed.
3. Compliance Reviews and Audits. The contractor shall permit compliance reviews and audits under applicable laws to allow OCC to meet legal and compliance obligations and shall implement processes that allow visibility into the privacy and security controls employed and their effectiveness. The contractor shall provide the OCC or authorized designated officials logical and physical access to the contractor’s facilities, installations, technical capabilities, operations, records, and databases pertinent to this contract within seven (7) calendar days upon request for these purposes.
F. Data Protection
1. Data Encryption. Where encryption is required, as specified by the OCC, the contractor shall ensure that encryption is established and maintained for data at rest and in transit for the duration of the contract. The encryption employed shall be equivalent to those approved in Federal Information Processing Standards (FIPS) Publication 140.
2. Data Separation. Unless otherwise directed by the OCC, any storage of data shall be contained within the resources allocated by the contractor to support the OCC and may not be on systems that are shared with other commercial or government clients.
3. Need to Know. Sensitive information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected.
4. Use of PII. The contractor shall not use any Personally Identifiable Information (PII), E-mail Groups, Lists, or contract information for any purpose other than those activities necessary to the performance of this contract.
G. Incident Response
1. Notification. The contractor must report all information security incidents that potentially or actually cause the compromise of OCC information, even if the contractor believes the security incident may be limited, small, or insignificant with respect to OCC data or systems. The OCC will determine when the contractor’s reported security incident requires additional focus and attention.
Within one hour from the time the contractor validates that an information security incident has occurred, the contractor must report the security incident information to the OCC Cyber Defense Center (CDC): Computer.Security@occ.treas.gov, (202) 649-7930, regardless of day or time.
The contractor must provide any supplementary information or reports related to a previously reported incident directly to the OCC CDC with the following text in the subject line of the email: “Supplementary Information/Report related to previously reported incident ## [insert number].”
Do NOT include any Sensitive Information in the subject or body of any e-mail. To transmit Sensitive Information, use FIPS 140-2 compliant encryption methods to protect Sensitive Information in attachments to email. Passwords must not be communicated in the same email as the attachment.
When notifying the OCC CDC, copy the Contracting Officer if possible or, if reporting by phone or Contracting Officer’s email is not immediately available, contact the Contracting Officer immediately after reporting the incident to the OCC CDC.
2. System, Tools, and Information Availability. The contractor shall make available system-related tools and information necessary for the OCC to respond to incidents in a manner consistent with NIST SP 800-61 (current version). In the case of a reported security incident, the contractor shall provide the OCC with access to the contractor’s system and/or facilities within 72 hours of the OCC’s request.
H. Information Ownership
1. Government Access. The government will retain unrestricted rights to government data.
The OCC retains ownership of any user created/loaded data and applications hosted on contractor’s infrastructure, as well as maintains the right to request full copies of these at any time.
2. Removal of OCC Data. The contractor acknowledges the OCC’s exclusive right of ownership of the information and is required to transfer or return (or delete) all agency data collected, processed, stored or maintained by the contractor on behalf of the OCC upon termination of services, and shall provide written certification and supporting documentation attesting to the return or deletion of agency data collected, processed, maintained, or stored by the contractor.
3. Documents and Deliverables. The preliminary and final deliverables and all associated working papers and other material deemed relevant by the OCC…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .