S06 - Conformed 36C10A24R0006 per A00001.pdf
PDF 1 MB Posted
- Attached to
- Cancer Registry Modernization (CRM) Federal contract opportunity
- Solicitation number
- 36C10A24R0006
About this file
This document appears to be the conformed version of Solicitation 36C10A24R0006 for the Cancer Registry Modernization (CRM) project. The solicitation is issued by the Department of Veterans Affairs Technology Acquisition Center in Austin for the VA's Office of Information & Technology, Software Product Management, and Population Health. The CRM software is required to modernize the VA's cancer registry. Questions and answers are due by May 29, 2024 at 3:00 PM EST. The solicitation provides details on the required products and services, response dates, and federal agencies involved, but does not include information on pricing terms, set asides, incumbents, or a Performance Work Statement or Statement of Objectives.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| S06 - 36C10A24R0006 A00001 Questions and Answers.pdf | ||
| S06 - Amendement 36C10A24R0006 A00001 6.4.24.pdf | ||
| S02 - 36C10A24R0006 - Final 5.14.24.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1081. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
TAC
36C10A24R0006 5/14/2024
Shakiya Harris; shakiya.harris@va.gov 512-981-4021 6/4/2024
15:00 PM EST
Department Technology Acquisition Center
23 Christopher Way Eatontown NJ 07724
X 100
X
513210
$47 Million
N/A
X
See Schedule
Y
Department of Veterans Affairs Technology Acquisition Center
23 Christopher Way Eatontown NJ 07724
Y
Department of Veteran Affairs Financial Services Center P.O. Box 149971
Austin TX 78714-8971
(877) 353-9791
See CONTINUATION Page
Cancer Registry Modernization (CRM) Software
See section B.1 Schedule of Supplies and Services and B.6 Product Description
See CONTINUATION Page
X X
Mary Accomando
36C10A24Q0007
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 SUPPLIES OR SERVICES PRICE SCHEDULE
Period of performance: 12 months with four (4) 12-month options and optional items that can be exercised at any time during the contract.
Line Item Description QTY
Unit of
Issue
Unit Price
Extended Price
Base Period June 1, 2024 through May 31, 2025 Product Service (PSC) Code: DA01
0001 Project Management
LT
0001A Contractor Project Management Plan
NSP
0001B Reporting Requirements
0001C Technical Kickoff
0001D Onboarding and Offboarding
0002 Cancer Registry Software
0003 Deployment
0004 Training and Support 1
Optional Tasks
Optional CLINs IAW FAR 52.217-7, OPTION FOR INCREASED QUANTITY- Separately Priced Line Items. Optional CLINs may be exercised multiple times, but total amounts exercised shall note exceed the quantities listed below. Optional CLINs 0005 & 0006 may only be exercised June 1, 2024 through May 31, 2025.
0005 FedRAMP Deployment 1
LT $ $
0006 FedRAMP Hosting 1 LT $ $ Total Base Period $
Option Period One: Option for an additional 12 months of services IAW FAR 52.217-9 Option to Extend the Term of the Contract (MAR 2000)
June 1, 2025 through May 31, 2026.
PSC Code: DC10
Issue
Unit Price Extended Price
1001 Project Management 1 LT $ $
1002 Enterprise License – Cancer Registry Software 1
1003 Training and Support 1 LT $ $ Optional Task times, but total amounts exercised shall note exceed the quantities listed below. Optional CLIN 1001 may only be exercised June 1, 2025 through
May 31, 2026.
1004 Optional Task 2: FedRAMP Hosting 1 LT $ $
Total Option Period One $ Option Period Two
Option Period Three: Option for an additional 12 months of services IAW
June 1, 2026 through May 31, 2027.
PSC Code: DA01
Issue
Unit Price Extended Price
2001 Project Management 1 LT $ $
2002 Enterprise License – Cancer Registry Software 1 LT $ $
2003 Training and Support 1 LT $ $ times, but total amounts exercised shall note exceed the quantities listed below. Optional CLIN may only be exercised June 1, 2026 through May 31, 2027.
2004 Optional Task 2: FedRAMP Hosting 1 LT $ $
Total Option Period Two $ Option Period Three
Option Period Three: Option for an additional 12 months of services IAW
June 1, 2027 through May 31, 2028.
PSC Code: DC10
Issue
Unit Price Extended Price
3001 Project Management 1 LT $ $
3002 Enterprise License – Cancer Registry Software 1
3003 Training and Support 1 LT $ $ times, but total amounts exercised shall note exceed the quantities listed below. Optional CLIN 3004 may only be exercised June 1, 2027 through
May 31, 2028.
3004 Optional Task 2: FedRAMP
Total Option Period Three $ Option Period Four
Option Period Three: Option for an additional 12 months of services IAW
June 1, 2028 through May 31, 2029.
PSC Code: DA01
Issue
Unit Price Extended Price
4001 Project Management 1 LT $ $
4002 Enterprise License –Cancer Registry Software 1
4003 Training and Support 1 LT $ $ times, but total amounts exercised shall note exceed the quantities listed below. Optional CLIN 4004 may only be exercised June 1, 2028 through
May 31, 2029.
4004 Optional Task 2: FedRAMP
Total Option Period Four $ Total Base and all Option Years Including Optional
Tasks
B.2 GOVERNING LAW (CONTINUATION OF SCHEDULE OF SUPPLIES AND
SERVICES ABOVE):
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. §3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S.
Department of Justice (DOJ in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by contract/order modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
B.3 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:
(1) Definitions.
a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”
b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired.
The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.
c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.
d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.
e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.
f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.
g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).
(2) Software License.
a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.
b) The Government may use the software in a networked environment.
c) Any dispute regarding the license grant or usag e limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).
d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.
(3) Software Maintenance and Technical Support.
a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.
b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.
c) Any telephone support provided by Contractor shall be at no additional cost.
d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).
e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.
(4) Disabling Software Code.
The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.
http://www.cpars.gov/
(5) Manuals and Publications.
Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.
B.4 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR: See Block 17a
b. GOVERNMENT: Contracting Officer 36C10A See Block 31b Department of Veterans Affairs Technology Acquisition Center – Division G 23 Christopher Way Eatontown, New Jersey 07724
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] Upon Acceptance
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
See website at:
http://www.fsc.va.gov/einvoice.asp
5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
http://www.fsc.va.gov/einvoice.asp
B.5 ACCOUNTING AND APPROPRIATION DATA
Funds in the following amounts are obligated on the following obligation references for the identified CLINs:
Action CLINs Obligation
Reference Amount Cumulative
Award Amount Base Award TBD TBD TBD TBD
The contractor shall reference the obligation Number on each invoice submitted for payment.
B.6 Performance Work Statement
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology Software Product Management
Population Health
Cancer Registry Modernization (CRM)
Date: 5/1/2024
VA-24-00020603
PWS Version Number: 1.4
1. BACKGROUND
The Department of Veterans Affairs (VA), Office of Information & Technology (OIT), Software Product Management, Population Health strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to Veterans throughout all points of VA’s Veterans health care system in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
The current VA Central Cancer Registry (VACCR) System uses VistA – OncoTraX to provide care to Veterans through all points of VA’s Veterans health care systems.
VACCR receives and stores information compiled by local cancer registry staff from each of the 131 separate Veterans Health Information Systems and Technology Architecture (VistA) instances. VistA – OncoTraX was written in Mumps prior to 1980 and supporting it has been burdensome to the VA. The information is obtained from a wide variety of medical record documents at the local medical center pertaining to each veteran cancer patient. Details collected include extensive demographics, cancer identification, extent of disease and staging, first course of treatment, and outcomes. The current fielded solution has not been able to keep up with the increasing requirements for complex oncology standards and the Commission on Cancer standard for accredited cancer programs. VA’s existing solution is not compliant with current technological requirements set by other national cancer registry standards organizations such as the North American Association of Central Cancer Registries (NAACCR), the American College of Surgeons' Commission on Cancer, and the American Joint Commission on Cancer, among others.
2. APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and
Information Systems,” March 2006
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and
Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
9. Public Law 109-461, Veterans Benefits, Health Care, and Information
Technology Act of 2006, Title IX, Information Security Matters
10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm https://www.va.gov/vapubs/index.cfm
12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm
13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5,
14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017
15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008
18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017
19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021
21. VA Handbook 6500, “Risk Management Framework for VA Information
Systems VA Information Security Program,” February 24, 2021
22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019
23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010
24. VA Handbook 6500.6, “Contract Security,” March 12, 2010
25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6,
26. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017
27. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference
Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
30. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
31. VA Handbook 6510, “VA Identity and Access Management,” January 15,
32. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017
33. VA Directive 6300, “Records and Information Management,” September 21,
34. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010
35. NIST SP 800-37 Rev 2, “Risk Management Framework for Information
Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018 https://www.va.gov/vapubs/index.cfm http://www.va.gov/vapubs http://www.va.gov/vapubs https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx
36. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)
37. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015
38. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-
12) Program,” March 24, 2014
39. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
40. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019
41. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008
42. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)
43. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018
44. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020
45. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014
46. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile
Devices (Draft),” October 2012
47. Draft National Institute of Standards and Technology Interagency Report
(NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014
48. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland
Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
49. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
50. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
51. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents
52. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
53. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008
54. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
55. S
56. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018 https://arch.idmanagement.gov/#what-is-the-ficam-architecture https://arch.idmanagement.gov/#what-is-the-ficam-architecture https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.cisa.gov/publication/tic-30-core-guidance-documents
57. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
58. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
59. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
60. VA Memorandum “Proper Use of Email and Other Messaging Services,”
January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
61. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
62. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020
63. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol
Version 6 (IPv6),” November 19, 2020
64. Social Security Number (SSN) Fraud Prevention Act of 2017
65. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23,
3. SCOPE OF WORK
VA, OIT, Software Product Management, Population Health requires a Cancer Registry product with integration between the new EHR Cerner product, Millennium EHR, and the Cancer Registry’s vendor applications. The Contractor shall provide a new cancer registry framework maintaining a comprehensive database of the VA Cancer Registry, regardless of Electronic Health Record (EHR) tool. The Contractor shall comply with current technological requirements and meet the demands of the Commission on Cancer standards for accredited cancer programs. To meet these requirements, the Contractor shall provide a new cancer registry framework maintaining a comprehensive database of the VA Cancer Registry, regardless of Electronic Health Record (EHR) tool.
To facilitate the consolidation of and transfer of Cancer Registry data from each of the 131 VistA sites, VA intends to use the Veterans Data Integration and Federation Enterprise Platform (VDIF-EP). This platform will allow the new Cancer Registry solution to have a single connection to one source, instead of requiring connections to each of the VistA sites for data.
The Contractor shall be responsible for the transfer of data to the Corporate Data Warehouse (CDW) for analytical functionality. This transfer will be done through a phased implementation to resolve any issues before full deployment across the enterprise.
The Contractor shall provide support for both linked and unlinked abstracts; case finding through various mechanisms such as case management view, case finding notes, imported notes, and case find module; custom fields; edits and data validation; activity and audit logs; definitions for user roles; transfer of reports into dashboards, pivots, and aggregated reports; export of data to Excel.
https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
4. PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The period of performance (PoP) shall be for one 12-month base period with four 12-month option periods and two optional tasks. The total period of performance for the task order shall not exceed 60 months.
Installation, maintenance, and disconnection of services shall take place between 8:00 AM to 4:30 PM (Local Time), Monday through Friday, excluding Federal holidays. Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO). If required, the CO may designate the Contractor to work during holidays and weekends.
There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
New Year's Day January 1 Juneteenth June 19 Independence Day July 4 Veterans Day November 11 Christmas Day December 25
If any of the above falls on a Saturday, then Friday shall be observed as a holiday.
Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November
4.2 PLACE OF PERFORMANCE
Tasks under this PWS shall be performed at Contractor facilities. The Contractor shall identify the Contractor’s place of performance in their proposal submission.
4.3 TRAVEL
The Government anticipates that no travel will be required to perform the tasks required under this effort.
5. SPECIFIC TASKS AND DELIVERABLES
The Contractor shall perform the following:
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of this effort.
The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate, execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The Contractor shall update and maintain the VA Program Management approved CPMP throughout the period of performance (PoP)
Deliverable:
A. Contractor Project Management Plan
5.1.2 REPORTING REQUIREMENTS
The Contractor shall provide a Monthly Progress Report in electronic form per mutually agreed upon format and media. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month.
The Monthly Progress Report shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
Status Report shall include the following data elements for each product supported:
1. Product Name.
2. Overview and description of the project.
3. Overall high-level assessment of project progress.
4. All Work In-Progress (WIP) vs work in-progress limit and completed during the reporting period.
5. Identification of any project related issues uncovered during the reporting period and especially highlight those areas with a high probability of impacting schedule or performance goals and their likely impact on schedule or performance goals.
6. Explanations for any unresolved issues, including workable solutions and any actions required of the Government and/or Contractor to resolve or mitigate any identified issue, including a plan and timeframe for resolution.
7. Status on previously identified issues, actions taken to mitigate the situation and/or progress made in rectifying the situation.
8. Work planned for the subsequent 3 reporting periods, when applicable Current project schedule overlaid on original project schedule showing any delays or advancement in schedule.
9. Workforce staffing data showing all Contractor personnel performing on the effort during the current reporting period. After the initial labor baseline is provided, each report shall identify any changes in staffing identifying each person who was added to the project or removed from the project.
10. Training Certificates, after initial and updated certificates are provided, each report shall identify any changes for all Contractor personnel including the dates of expiration and the due date for the next time due.
11. A Government Furnished Equipment (GFE) Report for all equipment issued to Contractor personnel performing on the effort during the current reporting period including a record of transfer.
12. Original schedule of deliverables and the corresponding deliverables made during the current reporting period.
Deliverables:
A. Monthly Status Report
5.1.3 TECHNICAL KICKOFF MEETING
A technical kickoff meeting shall be held within ten (10) days after award. The Contractor shall coordinate the date, time and meeting platform (teleconference, MS Teams, WebEx, etc.) with the Contracting Officer (CO), as the Post-Award Conference Chairperson, the VA PM, as the Co-Chairperson, the Contract Specialist (CS), and the COR. The Contractor shall provide a draft agenda to the CO and VA PM at least three
(3) calendar days prior to the meeting. Upon Government approval of a final agenda, the Contractor shall distribute to all meeting attendees. During the kickoff-meeting, the Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort via a Microsoft Office PowerPoint presentation. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report” which shall include notes on any major issues, agreements, or disagreements discussed during the kickoff meeting and the following statement “As the Post-Award Conference Chairperson, I have reviewed the entirety of this presentation and assert that it is an accurate representation and summary of the discussions held during the Technical Kickoff Meeting for the Cancer Registry Modernization program. The Contractor shall submit the final updated presentation to the CO for review and signature within three (3) calendar days after the meeting. The Contractor shall also work with the CS, the Government’s designated note taker, to prepare and distribute the meeting minutes of the kickoff meeting to the CO, COR and all attendees within three (3) calendar days after the meeting. The Contractor shall obtain concurrence from the CS on the content of the meeting minutes prior to distribution of the document.
A. Technical Kickoff Meeting Summary Report
5.1.4 MANDATORY TRAINING
The Contractor shall submit Talent Management System (TMS) Training Certificates of completion for VA Privacy and Information Security Awareness and Rules of Behavior and Health Insurance Portability and Accountability Act (HIPAA) training and provide signed copies of the Contractor Rules of Behavior in accordance with Section 9, Training, Appendix C of the VA Handbook 6500.6, “Contract Security”. The Contractor shall provide newly obtained certificates as part of the Monthly Status Report.
Contractor employees may be required to complete VA training courses before receiving access to the Data Repository. Contractor employees who have completed these VA training courses within a specified time and have furnished certificates will not be required to re-take the training courses. The Contractor shall collect and store copies of Training Certificates as evidence of completion for each individual. The Contractor shall provide a copy of the Training Roster and certificates to indicate the staff that have completed training in the Monthly Status Report.
A. Annual Training Certifications
5.1.5 ONBOARDING AND OFFBOARDING
The Contractor shall manage the onboarding of its staff on this project. Onboarding includes steps to obtain a VA Personal Identity Verification (PIV) card, network and email account, complete VA mandatory trainings for Contractors, initiate background investigations, and gain physical and logical access. In addition, the Contractor shall identify individuals which may require elevated privileges to the necessary development and test environments for the Product Lines. After review between the Contractor and VA COR(s), a decision will be made as to the necessity of obtaining GFE for the onboarding staff. If approved, Contractor shall follow the appropriate steps to obtain the equipment.
A single Contractor Onboarding Point of Contact (POC) shall be designated by the Contractor that tracks the onboarding status of all Contractor personnel. The Contractor Onboarding POC shall be responsible for accurate and timely submission of all required VA onboarding paperwork to the VA COR(s). All VA onboarding paperwork shall be stored on the deliverables folder in the COR designated VA SharePoint site or equivalent tool. The Contractor Onboarding POC shall be responsible for tracking the status of all their staff’s onboarding activities to include the names of all personnel engaged on the task, their initial training date for VA Privacy and Information Security training, and their next required training date. The Contractor Onboarding POC shall also report the status of the staff level in the Monthly Status Report.
The Contractor shall manage the offboarding process for VA access and to individual system/environment access for all Contractor staff. The Contractor shall prepare all forms necessary for termination of access to VA information systems, in accordance with VA guidance. The Contractor shall assist in confirming whether the GFE equipment, associated documentation, and PIV card has been returned to the proper receiving authorities in accordance with VA policy.
5.2 CANCER REGISTRY SOFTWARE
The Contractor shall provide an enterprise cancer registry to be used by each VA medical facility (or partnered facilities) to identify and collect data on patients diagnosed with cancer and transmit the data to a single database. This single database will have capabilities for reporting to the VA Central Cancer Registry (VACCR), as well as to state central cancer registries, and to a national database such as National Cancer Database (NCDB) where required, as part of the Veterans Health Administrations National Cancer Strategy.
The cancer registry software, at a minimum, shall include the following functionality:
5.2.1 The user shall have the ability to run a case ascertainment report within the System to understand the potential cancer cases needed for review. The user shall have the ability to view the source of information from the patient’s electronic health record, which identified the patient for case ascertainment, to determine if the case should be accessioned into the System. The user shall have the ability to perform case abstraction and data curation within the System to use the data for patient care tracking, reporting, and analytics.
5.2.2 The System will document follow up activities so the user can track patients with cancer from diagnosis until death.
5.2.3 The user shall have the ability to select new cancer cases from a case ascertainment report for accession into the cancer registry for cases to be abstracted.
5.2.4 The user shall have the ability to perform case abstraction in the cancer registry application for required data to be collected.
5.2.5 The System shall require a record to be locked when another user is editing to avoid two users editing the record at the same time. The System shall include a timeout function that limits the user’s time editing a record.
5.2.6 The user shall be notified the record has been locked when another user is editing the same case to avoid multiple users from editing at the same time.
5.2.7 The user shall have access to edit all information curated from a patient’s electronic health record to ensure patient data contained in the System is accurate.
5.2.8 The system shall protect all data from permanent deletion. An authorized user may flag data as deleted so it does not show up in standard reports.
5.2.9 The system shall allow an authorized power user to undelete data that has been flagged as deleted.
5.2.10 To ensure the accuracy of the cancer data, the System shall have the ability to flag cancer cases as not reportable when a determination is made.
5.2.11 The System shall include an audit trail regarding the information entered into specific data fields, including the old values, new values, who entered the data and a timestamp of the change.
5.2.12 The user shall have the ability view audit trail reports on the System at various levels of the VA enterprise to have an independent accounting of the various transactions.
5.2.13 The system shall provide the ability to manage user roles to determine levels of access and read write permissions at the facility, VISN and national level.
5.2.14 The system shall provide the ability to define user roles to ensure the staff has the level of access they need to perform their duties.
5.2.15 The System shall provide the ability to assign one or more user roles to each user of the System to ensure the staff has the level of access they need to perform their duties.
5.2.16 The system shall provide the ability to create standardized reusable content to use in letters to patients for follow-up management or other communication, to reuse the standardized content without having to recreate the content for each letter.
5.2.17 The system shall provide the ability to run standard reports from the application to contain audit information, and to understand which cases were reported and to which entity, date reported, and who reported them.
5.2.18 The system shall provide the ability to manage the data application for reporting, surveillance, and analytics, to use the data at any level throughout the enterprise such as by individual patient, facility, state, VISN, Region, enterprise, etc.
5.2.19 The system shall provide the ability to save customized reports of data at any level (cancer, patient, single, aggregated) throughout the enterprise (medical center, VISN, Enterprise) to store this information for reporting purposes.
5.2.20 The System shall provide the ability to export the report information in various formats, to further manipulate the data. These formats shall include Excel (xlsx), NAACR v23/v24 XML and CSV.
5.2.21 The system shall provide the ability to share customized views (reports) of data for others to have these views without having to create it themselves.
5.2.22 The System shall provide the ability to create standard export files for submission to state registries and national databases that will comply with VA privacy and security standards.
5.2.23 The System shall include the ability to select standard edits and edits sets to be implemented in the System software to ensure data quality.
5.2.24 The System shall include the ability to define VA specific fields (to be implemented across the enterprise) and for VA specific data fields to be collected.
5.2.25 The System shall include the ability to define edits for VA defined fields added to the System (to be implemented across the enterprise) for VA specific data fields to be verified for quality. Edits for VA specific fields should have a base format of NAACCR v23/v24 SMF metafiles with VA specific field edits written to the metafile.
5.2.26 The system shall provide access to a comprehensive System user guide within the primary work module or workflow to avoid breaking cognition to go into another application.
5.2.27 The system shall provide the user with a comprehensive user guide of the System to self-resolve and decrease reliance of the helpdesk.
5.2.28 The user guide shall have a table of contents with direct links to each section. The user will need to search in a comprehensive System user guide using key words to promptly locate content.
5.2.29 The system application shall include user prompts-context sensitive help to guide the use of the application to reduce the need for technical support by the user. Errors or other deficiencies in input data which could cause a business process to fail may be highlighted to users through a dialog box indicating the deficiency.
The following cancer registry software requirements if available are desired:
5.2.30 The user will need to place selected cases on a tickler list within the System to review the selection at a future date.
5.2.31 The user will need to send specific patient information from the System to a patient’s electronic health record for other authorized user access to view information in the EHR
5.2.32 The System shall include the ability to define fields for System specific data items from local medical center (hospital) to avoid collecting data items not required at the national level.
5.2.33 The System shall display instructional text when a user hovers the mouse over a data field.
5.2.34 The system will be able to leverage interoperability regulatory standards including but not limited to HL7 v2, HL7 v3 and HL7 FHIR R4/R5.
5.2.35 The system will have the ability to integrate with Cerner through HL7 FHIR R4.
5.2.36 The system will provide option for ETL process with a modern data migration framework to migrate both standard files such as NAACCR XMLs as well as custom data files such as an SQL database back up file.
Deliverables:
A. Annual Enterprise License for Cancer Registry Software B. User Guide for Cancer Registry Software
5.3 DEPLOYMENT
5.3.1 The solution shall be hosted in a cloud. The Contractor shall setup and supporting the solution on the VA’s enterprise cloud (VAEC). The solution must pass a VA approved Assessment and Authorization (A&A) process appropriate for a solution with data sensitivity of FISMA.
5.3.2 The system shall have an annual uptime of 99.5% or better.
5.3.3 The system application shall accommodate unlimited users. The VA anticipates a high water mark of unlimited users across all time zones.
5.3.4 The System shall be interoperable with both the legacy and modernized EHR (VistA and CERNER). Access to VistA will be through the VA’s Corporate Data Warehouse and future access to CERNER will be through VDIF.
5.3.5 The Contractor shall deliver a post deployment report that includes system and network diagrams, documentation to support the VA ATO (Authority to Operate) process and any other notes relevant to VA system administrators.
Deliverables:
A. Deployment Final Report
5.4 HISTORICAL DATA IMPORT
5.4.1 The System shall include the ability to import external datasets (e.g.
Surveillance, Epidemiology, & End Results (SEER) / Comprehensive Cancer Information (NCI), state registry records) in order to match to individual patients and/or cancer records, and devise algorithms to perform the following functions:
a) identify patients and/or cases which match cases in the System and display discrepancies,
b) identify unmatched cases and queue these to be reviewed/ accessioned
The Contractor shall document the above details in a data import report.
5.4.2 The contractor shall devise and execute algorithms to update existing records with missing information (such as treatment, stage, outcome information). Algorithms shall be documented in an electronic deliverable.
A. Data Import Report B. Electronic copy of algorithms
5.5 TRAINING AND SUPPORT
5.5.1 Training
The Contractor shall conduct initial system training. Training will be given prior to go-live with the System application. The Contractor shall provide training as follows:
1. Provide virtual training sessions to train VA staff. Staff may include users, program managers, IT specialists, and others directly involved in the Cancer Registry Modernization initiative.
2. Provide virtual Train-the-Trainer support. Training shall be designed to educate a select amount of staff (approximately 1,500) by providing essential, professional training skills and knowledge to train other VA staff.
3. Provide pre-recorded training on system use for on-going VA staff training.
4. Provide training for new and updated software modules as released.
5. The Contractor shall provide a Cancer Registry Modernization Training Plan, Cancer Registry Modernization User Training Material and Cancer Registry Modernization Train the Trainer Training Material. Training shall occur whenever crucial updates are made to the System software. Crucial updates shall refer to any update that changes the operability of the Solution.
A. Cancer Registry Modernization Training Plans B. Cancer Registry Modernization User Training Material (in electronic
PDF/PowerPoint format) C. Cancer Registry Modernization Train the Trainer Training Materials (in electronic
PDF/PowerPoint format) D. As Completed Recordings of virtual trainings
The Contractor shall provide operations support and systems maintenance support 11 hours a day, 5 days per week (Monday-Friday during the hours of 8am-7pm ET) for the solution for the life of the contract as follows:
1. The Contractor shall ensure the application is maintained to the most recent ly approved software baseline.
2. The Contractor shall perform software maintenance activities that may include version and release upgrades, security updates or patches, performance enhancements, data cleansing/archiving, and application modifications.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .