270-15-0459_Attach_1_SOW.docx
DOCX document 80 KB Posted
- Attached to
- Data Waiver and Processing Project Federal contract opportunity
- Solicitation number
- 270-15-0459
About this file
Attachment 1 - SOW
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP No. 270-15-0459 Buprenorphine Waiver Processing and Support Attachment I
Description/Specifications/Work Statement
I BACKGROUND
The Drug Addiction Treatment Act (DATA) of 2000 requires practitioners to notify the Secretary of Health and Human Services of the intent to begin dispensing approved partial opioid agonists in Schedules III, IV, or V, or combinations of such drugs, for maintenance or detoxification treatment of opioid addiction. With this notification, practitioners must also certify that they are qualified physicians under DATA and meet other requirements. The Food and Drug Administration approved two products containing a partial opioid agonist, buprenorphine, on October 8, 2002.
This contract will support training to enable physicians to meet the DATA waiver qualifications and to support the credentialing and waiver process which has been in operation since 2000 and is expected to end on August 31st, 2020. This Statement of Work is for a re-competition of a contract to support continued processing of physician waiver notifications, refining the Buprenorphine Waiver Notification System, and maintaining and improving the Buprenorphine Physician and Treatment Program Locator and Physician specific Web Board.
II OVERVIEW
A Scope
This contract will support SAMHSA’s efforts to implement its responsibilities under the DATA legislation. The Secretary of the Department of Health and Human Services (DHHS) is required to make determinations within 45 days of receipt of a physician waiver notification as to whether a practitioner meets the requirements for a waiver under DATA – the current processing time for a physician waiver averages between 15 – 20 days. SAMHSA has certified over 26,000 waivered physicians since 2002, with a historical average of approximately 3,000 per year. This number can be expected to increase as the need for more opiate treatment options are identified. Subsequently, SAMHSA must coordinate with the Justice Department/ Drug Enforcement Administration (DEA) in the assignment of a new unique identification registration number. The DEA reviews the contractor background checks, approves or denies, and after SAMHSA staff certify the physician to receive the waiver, the DEA will provide waivered physician with a unique identifier number. A physician may choose to be located on the SAMHSA locator or not. Currently approximately 44% have chosen the option to be listed on the locator. DATA also requires SAMHSA to establish and maintain records on trained and waived physicians, and it will require SAMHSA to advise the Secretary in making several determinations as to whether the program should be continued in the future, or whether there should be limitations or restrictions. This contract is essential to implementing the responsibilities delegated to SAMHSA pursuant to DATA.
B Introduction to Tasks
The major objectives of this contract are to continue processing physician waiver notifications, verifying physician credentials and that the required 8 hour buprenorphine training has been completed by the physician, while maintaining and enhancing the databases that enable this activity. These enhancements include: outreach activities to increase the numbers of physicians listed on the Buprenorphine Physician and Treatment Program Locator; enhancements to the Buprenorphine Physician and Treatment Program Locator to increase the accuracy of address listings for individual physicians; and the use of various available data sources to conduct analyses on buprenorphine waivers. For this contract, the Contractor shall meet objectives which are outlined below. Additionally, the government anticipates savings in tasks in option years 1-4, (if exercised) due to increased proficiency with the work and thus subsequent efficiencies, except for task 3 in which the government anticipates an increase in activities due to the expectation of an increase in physician waiver applicants. Expectations can be based on current political climate relative to opioid related overdoses. ” These are more fully explained regarding specific task requirements in Section III. B.
Track Practitioner Waiver Notifications and Registration Applications
A. Registration Applications and Waiver Notifications Processing and Data Bases Implementation and Enhancements.
(1) Maintain Data Bases
The Contractor shall maintain procedures and systems for physicians to inform SAMHSA of their intent to use buprenorphine or buprenorphine/naloxone, or to notify SAMHSA of their intent to treat up to 100 patients. These applications are required by statutory and/or regulatory requirements. These procedures and systems shall maintain waiver notification status information as well as verify Drug Enforcement Administration (DEA) registration status. Form SMA-167, entitled, “Notification of Intent to Use Schedule III, IV, or V Opioid Drugs for the Maintenance and Detoxification Treatment of Opiate Addiction under 21 USC § 823(g)(2),” (OMB Approval Number: 0930-0234; Expiration Date: 12/31/2015) - SAMHSA will provide clearance through OMB prior to expiration date of the form. Form SMA-167 is the primary form used for physicians to notify SAMHSA. The Contractor shall also maintain and upgrade the electronic means by which physicians are able, using the World Wide Web or Internet, to submit electronically, the required waiver notification with electronic signature compliance. The Contractor shall maintain and upgrade the database (currently an application in SQL language) containing data from all of the notifications. The database shall allow for electronic processing of these requests.
(2) Confirmation System
Refine the process to confirm waiver notification and registration applications, including credentialing status, registration status, and medical licensure, specialty status, and any license practice limitations. The system is currently capable of handling several thousand new waiver notifications/ registration applications a year and with the expectation of an increase in waivers the system should be utilizing the most current and efficient technologies available. The system should also facilitate independent verification of licensure and credentials with the appropriate State Medical Boards and professional certification or credentialing organizations.
(3) Support Services
Provide basic programming and database support services for the maintenance of the System software and enhancements as required, and development of Microsoft Windows based System software. The Contractor shall maintain and upgrade the System website, and provide a variety of technical assistance to users of the System - electronically (email) and by telephone (including a toll-free access number).
(4) Record Storage
Provide document storage, in paper format for original applications and pertinent documents, and in electronic format. Scanning of paper-formatted documents into electronic “pdf” files or their equivalent may be required for record keeping and storage.
(5) Training of SAMHSA/CSAT Staff
Develop a plan and implement training for up to 5 SAMHSA/CSAT staff who will have oversight for the related programs.
III SERVICES TO BE PERFORMED
A. General Requirements and Responsibilities
1. Independently, and not as an agent of the Government, the Contractor shall furnish the necessary personnel, labor, equipment, software, services, materials, and supplies, except as otherwise noted specifically herein to perform the work set forth below.
2. All work under this contract/task order will be monitored by the Contracting Officer’s Representative (COR).
3. SAMHSA/DIVISION OF TECHNOLOGY MANAGEMENT (DTM) GUIDELINES:
The Contractor shall use software that meets SAMHSA Guidelines. Specifically, the system(s) must be PC compatible; operate in a Windows environment; and use Microsoft Office Suite (Word, Excel, PowerPoint, and Access); .Net, Java or other software, Oracle or SQL server databases, as well as web applications services such as IIS and Oracle AS or other software consistent with SAMHSA/OMTO/DTM standards. Click here for the latest version of the Technology Standards. The Contractor shall at all times maintain compliance with current DTM standards, which may change over the duration of this contract/task order. Any deviation from the SAMHSA standards should be negotiated with SAMHSA prior to contract/task order award.
4. IT Plan: The Contractor shall prepare an IT Plan that addresses and describes the Design, Development, Implementation, and Maintenance for all IT Applications in the contract/task order. The IT Plan should include functional requirements (e.g., data, workloads, user interface, reliability, security, and maintenance), technical requirements (e.g., hardware, software, and telecommunications) and operational and other requirements. It should also include major IT milestones and implementation dates of the project. The draft and final IT Plan [i.e., “Electronic Version” and “Hard Copy”] shall be submitted as a deliverable to the COR and the DTM [through the COR] for review and approval. Full acceptance of the Contractor’s IT Plan is required and contingent upon the review and approval of DTM. The IT Plan must be reviewed on an annual basis, and updated as necessary if major modifications. The IT Plan review shall occur 90 calendar days after the start of the contract/task order year or 90 calendar days after a major modification. In the initial contract/task order year and if an IT Plan update is necessary in following contract/task order years, the Draft IT Plan shall be provided 90 calendar days after the start of the contract/task order year or 90 calendar days after a major modification; and the Final IT Plan shall be submitted 30 days after the draft is reviewed by the DTM and returned to the Contractor.
5. Security and Privacy Requirements for SAMHSA owned Contractor Managed Systems
(1) Adherence to security and privacy policy. The Contractor shall comply with all Federal and Department of Health and Human Services (HHS) security and privacy guidelines in effect at the time of the award of this contract/task order. A list of applicable United States (U.S.) laws, Office of Management and Budget (OMB) requirements, HHS policies, standards and guidance, and Federal Government Computer Security guidelines can be located on the Secure One HHS website at http://www.hhs.gov/ocio/securityprivacy/index.html. The Contractor shall perform periodic reviews to ensure compliance with existing information security and privacy requirements. The Contractor reviews should revalidate compliance with previous requirements as well as any new requirements since the last review. The Contractor shall make all system information and documentation produced in support of the contract/task order available to the agency and agency auditors upon request. All questions concerning IT security should be directed to the IT Security Team at infosecurity@samhsa.hhs.gov.
(2) Perimeter defense and notification. The Contractor shall ensure that the system and the information it contains are secured using appropriate perimeter defense technologies and that these technologies are monitored for anomalous traffic behavior. The Contractor shall immediately report any unauthorized system access to the agency COR and/or System Owner.
(3) Protection of sensitive information. The Contractor shall ensure that sensitive information is protected by information security and privacy controls commensurate with the risk associated with the potential loss or compromise of the information. For purposes of this contract/task order, information is sensitive if: the loss of confidentiality or integrity could be expected to have a serious, severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.[footnoteRef:1][1] Further, the loss of sensitive information confidentiality or integrity could: (i) cause a significant or severe degradation in mission capability to an extent and duration that the organization is unable to perform its primary functions or the effectiveness of the functions is significantly reduced; (ii) result in significant or major damage to organizational assets; (iii) result in significant or major financial loss; or (iv) result in significant, severe or catastrophic harm to individuals. [1: [1] Federal Information Processing Standard (FIPS) 1999, Standards for Security Categorization of Federal Information and Information Systems, February 2004.]
Personally identifiable information (PII) is a subset of sensitive information and is defined as data which can potentially be used to identify, locate, or contact an individual, or potentially reveal the activities, characteristics, or other details about a person.[footnoteRef:2][2] PII shall receive a level of protection commensurate with the risk associated with the loss or compromise of sensitive information. [2: [2] DHHS Rules of Behavior, February 12, 2008.]
(4) Sensitive information on public systems. The Contractor shall ensure that sensitive information is not stored, processed or transmitted on any system (via the Internet) without the appropriate controls in place and specific authorization from the SAMHSA Chief Information Officer (CIO) and/or Chief Information Security Officer (CISO).
(5) Privacy requirements. The Contractor shall conduct and maintain a Privacy Impact Assessment (PIA) as defined by Section 208 of the E-Government Act of 2002 and Federal Acquisition Regulation (FAR) Clause 52-239-1, and required by HHS policy. The PIA shall be completed in accordance with HHS PIA guidance at http://www.hhs.gov/ocio/securityprivacy/privacyresources/pias.html. Periodic reviews shall be conducted to determine if a major change to the system has occurred, and if a PIA update is subsequently required. If it is determined that an update is necessary, the Contractor shall make the necessary changes to the PIA. Questions or assistance required for PIA completion should be directed to PIA Support at info.privacy@samhsa.hhs.gov.
The Contractor shall abide by all requirements of the Privacy Act of 1974 and FAR Clause 52-239-1. Pursuant to those requirements, the Contractor shall create and publish a System of Records Notice (SORN) in the Federal Register when required and shall publish an updated SORN following a major change to the system, as directed by OMB Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002, or subsequent replacement guidance.
(6) Website Privacy Policy: The Contractor shall assure each page of the website, including the homepage, contains a link to SAMHSA's Website Privacy Policy (currently available at http://www.samhsa.gov/privacy). DHHS and SAMHSA policy does not allow for persistent cookies on any SAMHSA or SAMHSA-funded websites. In addition, any forms on the site which will ask users to enter personal information must first be approved through SAMHSA channels and DTM. Questions or assistance required for SAMHSA websites should be directed to the SAMHSA webmaster (webmaster@samhsa.hhs.gov).
(7) Information System Security Plan (ISSP): The Contractor shall develop, submit and maintain an information system security plan compliant with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-18 Revision 1, Guide for Developing Security Plans for Information Technology Systems, standards and must be consistent with the HHS and SAMHSA policy, as applicable to the contract’s/task order’s Statement of Work.
Draft and Final ISSP Plan: The Contractor’s draft information system security plan shall be submitted [no later than 90 calendar days after the contract/task order effective date (CED)] to the COR with the proposal for approval. The Final IT Plan shall be submitted 30 days after the draft is reviewed by DTM and returned to the Contractor. The draft and final IT Security Plan [i.e., “Electronic Versions” and “Hard Copies”] shall be submitted as a deliverable to the COR and DTM [through the COR]. Full acceptance of the Contractor’s ISSP [IT Security Plan] is required and contingent upon the review and approval of DTM.
Information System Security Plan requirements:
· Each of the 17 NIST security control families prescribed in NIST Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems, and the specific ways in which those controls are implemented must be addressed, if applicable, in the ISSP and pertinent to the function the system is designed to provide.
· The system security plan must be reviewed on at least an annual basis.
· The completion date of the ISSP should be revised to record when the plan has been reviewed and update completed.
· Version numbers must be employed and revised to record when changes are made to the document.
Updated ISSP Plan: Following approval of the draft ISSP, the Contractor shall update and resubmit its ISSP to the COR in contract/task order year 3 and when a major modification has been made, as determined by the contracting officer. The Contractor shall use the current ISSP template in Appendix A of NIST SP 800-18 Revision 1, http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf to complete the ISSP. The information contained in the Contractor’s IT Security Plan shall be commensurate with the System Categorization indicated by the IT Security Officer.
Subcontracts: The Contractor shall include information consistent with this contract/task order language in any subcontractor for performance under the SOW, whenever the submission of an IT Security Plan is required.
(8) System Authorization. The Contractor shall certify and accredit all systems developed for support of the contract/task order in conformance with the standards set forth by the Federal Information Security Management Act (FISMA) and NIST SP800-37 Revisions 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, prior to the system becoming operational, or within 90 days after system completion with approval from the SAMHSA CIO or CISO. This activity shall be performed in conjunction with the initial development of the system, updated when a major change occurs to the system, and renewed no less than every three years. All system authorization (S&A) packages shall be compliant with all Public Law (PL)-107-347, OMB mandates, FIPS, and additional applicable NIST guidance. This guidance includes, but is not limited to FIPS 199, FIPS 200, NIST SP 800-18, NIST SP 800-30, NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and NIST SP 800-60. All NIST and FIPS documentation can be found at the NIST website at http://csrc.nist.gov/.
SAMHSA has created an S&A checklist to facilitate compliance with the OMB-mandated S&A process. The SAMHSA S&A Checklist will be provided to the Contractor after contract/task order award and upon request to DTM through the SAMHSA COR.
Annual requirements. The Contractor shall be responsible for meeting ongoing information security and privacy system requirements. These include, but are not limited to, performing annual system testing, completing an annual system self-assessment, and supporting quarterly and annual SAMHSA FISMA reporting. Additionally, SAMHSA reserves the right to test or review the system security and privacy controls at any time. All annual requirements will be administered by SAMHSA IT security and privacy team.
(9) Security and privacy training. All Contractors shall receive general awareness training and role-based training, commensurate with the responsibilities required to perform the work articulated in the terms and conditions of the contract/task order.
The Contractor shall be responsible for ensuring each contractor employee has completed the SAMHSA Security Awareness Training as required by the agency prior to performing any contract/task order work or accessing any system, and on an annual basis thereafter, throughout the period of performance of the contract/task order. The Contractor shall maintain a list of all individuals who have completed this training and shall submit this list to the COR upon request. As a part of this training, the Contractor shall ensure that all staff read, agree to, and sign the DHHS Rules of Behavior at http://www.hhs.gov/ocio/policy/hhs-rob.html.
(10) Clearances. The Contractor shall ensure all staff has the required level of security clearance commensurate with the sensitivity of the information being stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract/task order. At the minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other HHS resources is granted.
(11) Non-Disclosure. The Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of sensitive information:
-18 U.S.C. 641 (Criminal Code: Public Money, Property or Records) -18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information)
- PL 96-511 (Paperwork Reduction Act)
(12) Mobile device encryption. The Contractor shall: (a) encrypt all laptop computers, mobile devices and portable media which store or process, or may store or process, sensitive information using FIPS 140-2 compliant encryption technology; (b) verify that encryption products have been validated under the Cryptographic Module Validation Program at http://csrc.nist.gov/groups/STM/cmvp/index.html to confirm compliance with FIPS 140-2; (c) establish key recovery mechanisms to ensure the ability to decrypt and recover sensitive information by authorized personnel; and (d) generate and manage encryption keys securely to prevent unauthorized decryption of information. For more information, reference the HHS Encryption Standard for Mobile Devices and Portable Media at http://intranet.hhs.gov/it/cybersecurity/docs/policies_guides/EPF/encrypt_plan_format_for_protect_of_sensitive_info.pdf.
(13) Maintenance. The Contractor shall ensure that the system, once operational, is properly maintained and monitored, to include immediate response to critical security patches, routine maintenance windows to allow for system updates, and compliance with a defined configuration management process. All patches and system updates shall be properly tested in a development environment before being implemented in the production environment.
References
1. Policy for Department-wide Information Security at http://www.hhs.gov/ocio/policy/hhs-ocio-2011-0003.html
1. HHS IRM Information Security Program Policy at http://www.hhs.gov/ocio/policy/index.html
1. HHS Personnel Security/Suitability Handbook at http://intranet.hhs.gov/it/cybersecurity/docs/policies_guides/PISSP/pol_for_info_sys_sec_and_priv_hndbk_20110707.pdf
1. NIST SP 800-18, Rev.1, Guide for Developing Security Plans for Information Technology Systems at http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf
1. NIST SP 800-37, Guide for Security Certification and Accreditation of Federal Information Systems: at http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf
1. NIST SP 800-53, Recommended Security Controls for a Federal Information System at http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
1. NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, Volume I at http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf
1. NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, Volume II at http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
1. NIST SP 800-64, Security Considerations in the Information System Development Life Cycle at http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-Revision2.pdf
1. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems at http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
1. Federal Information Processing Standards, Minimum Security, Requirements for a Federal Information System at http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf
1. Cryptographic Module Validation Program at http://csrc.nist.gov/groups/STM/cmvp/index.html
1. HHS Policy for Records Management: http://www.hhs.gov/ocio/policy/2007-0004.001.html.
1. Enterprise Performance Lifecycle: http://www.hhs.gov/ocio/eplc/index.html
6. SECTION 508 COMPLIANCE:
1. Section 508 of the Rehabilitation Act, requires agencies and their Contractors to buy Electronic and Information Technology (EIT) that makes information accessible to people with disabilities.
2. On June 25, 2001, accessibility requirements for Federal Electronic and Information Technology took effect under Section 508 of the Rehabilitation Act. This law requires that such technology be accessible according to standards developed by the Access Board, which are now part of the Federal government's procurement regulations (Refers to the Section 508 Federal Acquisition Regulations (FAR) Final Rule published on April, 2001 in the Federal Register).
3. These standards, as issued by the Board, cover a variety of products, including computer hardware and software, websites, phone systems, fax machines, copiers, and similar technologies. Provisions in the standards spell out what makes these products accessible to people with disabilities, including those with vision, hearing, and mobility impairments. The Board included both technical criteria specific to various types of technologies and performance-based requirements, which focus on a product's functional capabilities.
4. The law relies strongly on the procurement process to ensure compliance with the new standards. Compliance with the standards is required except where it would pose an "undue burden" (as defined in the standards) or where no complying product is commercially available.
5. To be considered eligible for award, Offerors must propose goods and/or services that meet the applicable provisions of the Access Board's standards as identified by the agency. Alternatively, Offerors may propose goods or services that provide equivalent facilitation. Such offers will be considered to have met the provisions of the Access Board's standards for the feature or component providing equivalent facilitation.
6. In instances when deliverables and other artifacts generated by the Contractor are intended for distribution via the Web, deliverables must comply with Section 508 requirements. Additional online resources, including the Section 508 compliance standards are available for reference (http://section508.gov/summary-section508-standards or http://www.hhs.gov/web/508/).
7. SAMHSA/OFFICE OF COMMUNICATIONS (OC) REQUIREMENTS
A. Branding – The Contractor shall adhere to the branding and trademarking guidelines outlined in the SAMHSA Identity Standards. SAMHSA is the only entity that shall be branded in content, services, and products (including, but not limited to publications, webpages, mobile applications, program descriptions) developed through this contract/task order. Communications products and promotion activities developed through this contract/task order shall position and brand SAMHSA as the leading source for behavioral health expertise and innovation in the Nation.
B. Communications Products – The COR shall not direct the Contractor to expend funds on the development of any specific communications product until the SAMHSA Office of Communications (OC) has issued a concept clearance or other commensurate approval for the product including specific law or description in SAMHSA’s Strategic Communications Plan. The COR working with the Contractor shall ensure that SAMHSA products reflect SAMHSA's Strategic Initiatives and priorities and are produced with appropriate participation from all SAMHSA Centers/Offices and other relevant external agencies. Recommendations from an annual communication product planning meeting and Executive Leadership Team decisions shall determine the final communication products to be produced. As a cost reimbursable contract/task order, SAMHSA maintains the right to stop work, cancel future work, or change the level of effort of work on any communications products within this contract/task order. This includes, but is not limited to, the revising, repurposing, producing, finalizing, or disseminating of products. Changes that incur a significant reduction or incretion of effort may require a contract/task order modification depending on the level of effort and cost implications. Any decision by SAMHSA to change the purpose, direction, production, completion, or dissemination of a product is not a reflection on the performance of the Contractor. The Contractor shall be reimbursed for any product development up to the date of request by the COR to end work on the product(s) or to change direction on the product(s). All products are the property of the Government and shall be turned over to the COR if the decision is made to stop work on the product(s).
Unless SAMHSA exercises the right to produce/print hard copies, products produced under this contract/task order shall be developed for electronic and web-based distribution only, in accordance with the Executive Order on Promoting Efficient Spending (EO 13589). The duplication of print copies/DVDs/CDs shall be the exception and shall require OC approval prior to duplication. Products developed under this contract/task order shall adhere to SAMHSA’s web governance policy for layout, file format and other technical specifications. The Contractor shall work with the COR to upload approved content into SAMHSA’s Web Content Management System (WCMS). Training on SAMHSA’s WCMS shall be provided to the Contractor and the COR. OC approval is required for final communication products to be produced in hard copy. The intent to produce hard copies shall be identified during the concept clearance approval process. In addition, all products prepared under this contract/task order shall follow the “Plain English” guidelines and shall strive to maintain the national level of suggested reading levels for the appropriate audiences. Products granted an exception to print hardcopies prepared under this contract/task order shall be written and edited in accordance with the Government Printing Office Style Manual and SAMHSA style guidelines. All materials granted an exception shall be printed by the Government Printing Office (GPO) or other approved entity, such as through SAMHSA’s Public Engagement Platform (PEP), that still meets GPO printing guidelines.
C. Public Engagement Platform (PEP) and Marketing Support - Use of and close collaboration with the COR and SAMHSA’s OC for the services provided by PEP and OC is a requirement of this contract/task order. This contract/task order shall not reproduce or budget for any of the services that are available through SAMHSA’s OC. See below for details on the distribution services and Marketing Support that SAMHSA already has available:
· Contact center – 1-877-SAMHSA-7 which responds to public inquiries.
· Warehouse – full warehouse functions of receiving, maintaining, shipping, and managing the entire SAMHSA print and audiovisual library.
· Communications Products Pages – provides online presence for products, including “shopping cart” functionality to order/download products, tagging with the SAMHSA taxonomy, and other related content.
· Reports – provides inventory management information, (e.g. remaining inventory, monthly distribution, and reprint recommendations) and data analytics on the electronic consumption of SAMHSA communications products. Analyzing the product inventory reports is a requirement of this task order. The Contractor shall work with the COR in obtaining these reports from the OC.
· Press releases, News bulletins – these are more traditional forms of information dissemination. They are typically distributed to other news outlets.
· Conference Exhibit Program – Provides a SAMHSA presence at meetings that are aligned with the Agency’s strategic initiatives. Provides publications, programmatic information, promotional materials, etc.
· eBlasts – Internet-based email marketing and current awareness tool that allows subscribers to create profiles and select to receive updates on topics of interest to them, including, but not limited to upcoming awareness campaigns, funding opportunities, and new publications.
· Social Media – SAMHSA utilizes various social media tools (Facebook, Twitter, Flickr, YouTube) with a strong presence and following.
· SAMHSA Newsletter – SAMHSA News, the Agency’s newsletter, disseminates information to behavioral health service providers, consumers, and the general public from all SAMHSA program divisions and offices.
D. Adherence to SAMHSA Technical Governance: The Contractor shall adhere to the SAMHSA Technical Governance. Any development, production and maintenance of Internet/Web applications, including Intranets and Extranets shall comply with SAMHSA policy and procedures.
The SAMHSA.gov website is the only authorized agency website. No new websites shall be created without prior written approval of the COR, in collaboration with OC and DTM and any appropriate agency website officials. Any new websites created by the Contractor shall be part of the SAMHSA.gov website. Websites or applications development may be accomplished on the Contractor's server(s). Production versions must reside on the SAMHSA/DTM infrastructure.
i. Content Development and Management Plan - Within sixty (60) days after the Contract Effective Date (CED), the Contractor shall submit electronic and hard copy versions of the Content Development and Management Plan through the COR to OC and DTM for review and approval. Full acceptance of the Contractor’s Content Development and Management Plan is required and contingent upon the review and approval of DTM—for IT Technical Issues; and OC—for Content and New Media Issues. This plan must include any information on the web content that is being prepared for the SAMHSA site. The plan must also include, but is not limited to:
· Social Media. Details on any channels of social media that are planned to be used, either external (e.g., Facebook, Twitter) or internal to the content, with justification for their use.
· E-mail. Details on mass e-mail distribution, or other Internet-based communication methods, with justification for their use.
· Processes. Descriptions of the processes for the review, approval, and clearance (if applicable) for the Web content (inclusive of social media, e-mail, etc.) for both initial posting and ongoing maintenance. Multiple/variable processes for different classes of content is suggested if applicable.
· Disposition. The management plan shall also include a plan for management or disposition of the content after the contract/task order ends.
· Hosting. If there is a plan to physically host the content outside of SAMHSA.gov, details and a justification shall be provided.
· Content Management System Standards. Details how the Contractor plans to provide updates compatible with or directly through SAMHSA’s Web Content Management System.
· Metrics Standards. Provides information on how the Contractor plans to place “code” on each page of web content to allow it to be discovered and counted by SAMHSA metrics tools.
· Data Standards. Details how all data that is produced or incorporated as part of this contract/task order and that is cleared for public distribution shall be made available in an open data format, compatible with Federal raw data and/or geo data standards at data.gov.
· Web Content Integration. If this contract/task order includes assuming responsibility for a legacy site or content, the management plan shall include a plan for integrating that legacy site or content into SAMHSA.gov. This plan shall be coordinated with the agency plans for SAMHSA.gov, and may require multiple phases or steps for integration.
The COR, OC and DTM shall have 30 days to review and provide comments.
ii. Digital Engagement – The preferred approach to digital engagement focuses on the empowerment of trained Federal staff as the agent of engagement. However, there shall be instances where Contractors are responsible for engagement activities. Digital engagement activities should be included as part of the Content Development and Management Plan and should, as closely as possible, adhere to the following principles:
· Transparency is essential to effective engagement
· Digital engagement should encourage building and sustaining communities and work to establish long-term relationships
· Engaging in a way that allows for timely responses should be the default
· Establishing an emergency mitigation strategy should be included as part of all planning activities
· Documenting where engagement activities have occurred is mandatory
· Measuring and reporting on mission-based outcomes is essential
iii. Web Content Approval - No later than three (3) weeks prior to the planned initial posting of a document, the Contractor shall submit the Content to the COR for review and approval. This document should be consistent with Federal policy and have all signatures obtained for any clearances (as needed) prior to submission. Depending on the document and the level of review necessary, SAMHSA shall review and post the Content onto the SAMHSA site or on the appropriately determined SAMHSA social media platform. Development of new social media accounts is limited on a case by case basis based on criteria set by the SAMHSA Communications Governance Council (CGC).
iv. Web Content Migration Plan – For existing websites or other Internet content, if not already completed, the Contractor shall in conjunction with the COR, Center Content Coordinator and OC, plan for, facilitate and expedite the migration of all production (as opposed to development) Web content from the current website to the SAMHSA website. The Contractor shall prepare a plan that includes Development, Implementation, Public Production and Maintenance. The Content Migration Plan should include functional requirements, technical requirements and other operational requirements. It should also include major milestones and implementation dates of the project, including the migration phase. The draft and final Content Migration Plan shall be submitted as a deliverable to the COR and the DTM [through the COR] for review and approval. Any new content proposed by the Contractor for the Internet shall become part of the SAMHSA website. It is not SAMHSA’s intent to have the Contractor house SAMHSA-funded content for this contract/task order unless evidence is presented that it is more efficient to do so and approval is received from OC and DTM. Any new Web development must be focused on content that is logically integrated into the SAMHSA.gov organization, design and existing content. Content shall be developed in a manner that provides smooth and efficient integration into the SAMHSA.gov website. Web content consists of any and all materials (HTML files, XML files, PDF files, video, audio, etc.) with an expectation of being distributed via the Web or similar Internet system.
v. Contractor shall submit quarterly reports of actual Web-related IT costs to the COR. It is the responsibility of the COR to submit the quarterly report to OC and DTM. A reporting template shall be provided to the Contractor upon award of contractor/task order.
vi. Staff members from both OC and DTM shall be included in the initial contractor/task order kick-off meeting at the start of the contract/task order as well as any required annual meetings.
E. HHS and SAMHSA Strategic Clearance Platforms are designed for the COR, their Contractors and field partners to create a consistent approach for planning communication activities for communications products or for ongoing operation of a program or organization as well as to determine the appropriate level of clearance required for the product. The HHS and SAMHSA platforms include the key elements in communications planning and execution:
· Field Analysis - identifying what the field needs, what is already available to meet these needs, and potential collaborators
· Goal - how meeting these needs shall support SAMHSA’s mission.
· Objectives - ways in which particular communications and marketing activities shall achieve this goal.
· Target Audiences - specific target audiences that need to be reached to achieve these objectives.
· Program, Product or Service - what shall be delivered to these target audiences in order to reach the identified objectives.
· Formatting - how messages about these deliverables shall be formatted to reach the identified objectives.
· Creative Mix of Tactics and Message Products -Advertising, Promotion, Events, Public Relations and Personal Communications approaches that shall be combined with electronic or print message products to help achieve the identified objectives, timed against a projected product life expectancy.
· Dissemination - implementation of this creative mix to reach identified objectives.
· Evaluation and Quality Improvement - data gathering needed to improve contract/task performance, and justify public investment in activities supporting SAMHSA’s mission.
Use of the HHS and/or SAMHSA clearance platforms is required for the creation, promotion, dissemination and evaluation of communications products developed through this contract/task
B Specific Task Requirements
Task 1: Transfer of Activities
Task 1A: Startup at Beginning of Contract (Base Year)
The Contractor shall coordinate an orderly transition of the project from the previous Contractor during the time between the Estimated Date of Contract (EDOC) September 4th, 2015 and expiration of the previous contract, for which the final performance period will end on September 14th, 2015. This transition should insure a smooth transition with no disruption in services. (Base year only) The contractor shall:
a. At the Contract Officer’s discretion, contractor shall participate in three or more virtual meetings, within first two (2) weeks of EDOC, with the previous contractor to effect a smooth transition and to receive detailed information on the operation of Buprenorphine Waiver Processing and Support contract;
b. Ensure receipt from the previous contractor or SAMHSA of all materials required to complete tasks and send confirmation to COR of receipt by September 14th, 2015; to include; complete documentation and all government furnished property, hardware, software, materials and data necessary to support continuation of full services, capabilities and outstanding technical and related work inherited from the previous contractor and promptly notify the Contract Officer of any omissions or deficiencies; and
c. Contractor’s personnel receive training from the previous Contractor’s senior personnel in all system operation and maintenance functions within 2 weeks of EDOC.
Task 1B: Turnover at End of Contract (final option year)
The Contractor shall provide, by no later than the first (1st) business day of the ninth (9th) month of the final performance period, one (1) electronic copy and one (1) hard copy, of the plan/process to transfer the project to the SAMHSA COR. The COR will provide comments on the plan within (10) business days of receipt. The contractor shall make edits to document within 3 business days of receipt and resubmit revised document to COR. If necessary, as directed by COR, the contractor shall initiate transition activities twenty-one (21) business days prior to the expiration of the contract while supporting contract activities. The contractor shall perform close-out activities of all project work. Contractor shall continue during transition (21 days before end of contract) and through to the end date of contract, (Option year 4 only) to perform the following:
a. Full service to the customers of CSAT;
b. At the COR’s discretion, participation in three or more meetings with the new contractor to effect a smooth transition and to receive detailed information on the operation of Buprenorphine Waiver Processing and Support system;
c. Provide complete documentation and all hardware, software, materials and data produced or acquired to with contract funds, or under the Contractor’s control to new contractor and COR: such as Government Furnished Property or Materials shall be turned over to SAMHSA or the new Contractor in good condition and, during a three week transition period, the Contractor’s senior personnel shall train the new personnel (contractor or government) in all system operation and maintenance functions; and
d. Perform appropriate closeout of all outstanding technical and related work by end date of incumbent’s contract.
If State data are used, the Federal government shall collaborate with the participating States in planning, carrying out and disseminating the results of such analyses. All information and materials including data developed under this contract are the property of the government and shall be delivered as part of the turnover at the end of the contract. Without the written permission of the government the Contractor shall release no information developed under this contract. Unless the underlying data used in the selected study analysis are leased or proprietary, analytic files (where source files are reduced in volume and tailored to specific analyses), data analytic programs and the results produced under the auspices of this project will be the property of the Federal government
Task 2: Establish and Maintain Work Plan
Task 2A: Meet with CSAT COR to Devise Preliminary Work Plan
Contractor shall meet with COR virtually to discuss elements of work plan, as well as the deliverables within two weeks of EDOC. The contractor shall participate in weekly (monthly) calls with the COR, Alt-COR or other identified individuals to discuss the status of contract deliverables, activities, and any issues, concerns and resolutions the with work plan. Within three (3) weeks following EDOC award, the Contractor shall confer with the CSAT COR to review the submitted preliminary draft of a comprehensive work plan. This work plan will define the process that the Contractor will utilize in hiring staff, scheduling tasks defined in the Statement of Work, and obtaining necessary resources to complete the objectives of this contract.
Task 2B: Finalize Work Plan
Modifications of this work plan shall be delivered as an integrated part of the final work plan described below. Once revise and finalized, (4 weeks after EDOC), (1 hard and 1 electronic) copy of the preliminary work plan are to be submitted to COR.
Task 2C: Meet or Confer Regularly with the CSAT COR
In a separate call than Task 2A the contractor will confer with COR no less than weekly for first three weeks after EDOC and shall participate in weekly/monthly calls as determined by COR thereafter to discuss progress to date, issues requiring clarification, problems and trends in the work and any other contract related issues not identified in Task 2A of the Contract.
Note to Offerors: Kick Off meeting to be held within first five (5) days of EDOC. This meeting is a one-time face to face meeting. Travel is included within RFP for Kick-off meeting. Travel will be airfare for two people (2), per diem and local travel for 3 days and two nights to SAMHSA’s Rockville location – all travel costs are inclusive in contract award amount. Travel arrangements and approval must be confirmed by COR.
Task 2D: Prepare and Implement Draft and Final for the IT Plan
Draft IT Plan shall be provided 90 calendar days after the EDOC. Final IT Plan shall be submitted 30 days after the draft is reviewed by the DTM and returned to the Contractor. Contractor shall identify areas where the process of receipt of and verification of physician qualifications may be improved within their plan. See General Requirements #4.
The draft and final IT Plan Deliverables (1electronic and 1 hard copy) shall be submitted as a deliverable to the COR and the Division of Technology Management (DTM) through the COR for review and approval.
Task 2E: Prepare and Implement Draft and Final IT Security Plan
The Contractor’s draft information system security plan shall be submitted [no later than 90 calendar days after the contract/task order effective date (CED)] to the COR with the proposal for approval. The Final IT Plan shall be submitted 30 days after the draft is reviewed by DTM and returned to the Contractor. The draft and final IT Security Plan Deliverables (electronic and 1 hard copy) shall be submitted as a deliverable to the COR and the Division of Technology Management (DTM) through the COR for review and approval. See General Requirements #5(7).
Task 3: Process and Track Practitioner Waiver Nominations and Registration Applications
Contractor shall train CSAT staff on how to access information from Data system. Contractor shall maintain the Buprenorphine Waiver Notification System that verifies physician qualifications and tracks the training and credentialing of practitioners who will be using Schedule III, IV, or V drugs in their treatment of opioid addicted patients. The form SMA-167 (“Notification of Intent to Use Schedule III, IV, or V Opioid Drugs for the Maintenance and Detoxification Treatment of Opiate Addiction under 21 USC § 823(g) (2);” OMB Approval Number: 0930-0234; Expiration Date: 12/31/2015) is the primary form used. This tracking system will be set up in accordance with the statutory and/or regulatory requirements.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .