36C10B18R2933-001.docx
DOCX document 109 KB Posted
- Attached to
- Genomic LIMS Phase II Modification to post Draft PWS Federal contract opportunity
- Solicitation number
- 36C10B18R2933
About this file
36C10B18R2933 36C10B18R2933_1.docx
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10B18R2933-000.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Genomic Laboratory Information Management System (LIMS) Phase II TAC Number: TAC-18-50695
FedBizOpps Modification to a Previous Notice
CLASSIFICATION CODE
SUBJECT
CONTRACTING OFFICE'S
ZIP-CODE
SOLICITATION NUMBER
BASE NOTICE TYPE
RESPONSE DATE (MM-DD-YYYY)
ARCHIVE
DAYS AFTER THE RESPONSE DATE
RECOVERY ACT FUNDS
SET-ASIDE
NAICS CODE
CONTRACTING OFFICE
ADDRESS
POINT OF CONTACT
(POC Information Automatically Filled from User Profile Unless Entered)
DESCRIPTION
See Attachment
AGENCY'S URL
URL DESCRIPTION
AGENCY CONTACT'S EMAIL
ADDRESS
EMAIL DESCRIPTION
ADDRESS
POSTAL CODE
COUNTRY
ADDITIONAL INFORMATION
GENERAL INFORMATION
PLACE OF PERFORMANCE
* = Required Field FedBizOpps Modification to a Previous Notice Rev. March 2010 D Genomic LIMS Phase II Modification to post Draft PWS 07724 36C10B18R2933 N 541519 Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Derek Maselli, Contract Specialist:
derek.maselli@va.gov
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology Office of Connected Care, Innovation Program
Genomic Laboratory Information Management System (LIMS) Phase II
Date: June 28, 2018
TAC-18-50695
PWS Version Number: 1.2
Contents
| 1.0 | BACKGROUND | 5 |
| 2.0 | APPLICABLE DOCUMENTS | 6 |
| 3.0 | SCOPE OF WORK | 9 |
| 4.0 | PERFORMANCE DETAILS | 9 |
| 4.1 | PERFORMANCE PERIOD | 9 |
| 4.2 | PLACE OF PERFORMANCE | 10 |
| 4.3 | TRAVEL | 10 |
| 5.0 | SPECIFIC TASKS AND DELIVERABLES | 10 |
| 5.1 | PROJECT MANAGEMENT | 10 |
| 5.1.1 | CONTRACTOR PROJECT MANAGEMENT PLAN | 10 |
| 5.1.2 | REPORTING REQUIREMENTS | 11 |
| 5.1.3 | TECHNICAL KICKOFF MEETING | 11 |
| 5.1.4 | PRIVACY TRAINING | 11 |
| 5.1.5 | WEEKLY STATUS MEETING | 12 |
| 5.2 | VAMC Analysis and Millenium Helix Implementation | 12 |
| 5.3 | CERNER TECHNOLOGY CENTER | 13 |
| 5.4 | Transfer Huntington Millennium Helix License to Tampa | 13 |
| 5.5 | VAMC Genomic Facilities configuration and testing | 13 |
| 5.6 | Reporting and Analytics | 14 |
| 5.6.1 | MEDICAL MANAGEMENT REPORTING | 14 |
| 5.6.2 | MILLENNIUM HELIX FOR MOLECULAR DIAGNOSTICS | 15 |
| 5.6.3 | FOR MILLENNIUM HELIX FOR INFECTIOUS DISEASE | 16 |
| 5.6.4 | MILLENNIUM HELIX FOR CYTOGENETICS | 18 |
| 5.6.5 | PROVISION OF DEVICE WORKS FLAT FILES | 19 |
| 5.6.6 | CAREAWARE IBUS MULTIPLEXOR MEDICAL DEVICE INTERFACE (MDI) SERVICES (CTS-IBUS-MULTI) | 20 |
| 5.7 | CareAware Maintenance Training | 21 |
| 5.8 | TRAINING FOR MILLENNIUM HELIX | 21 |
| 5.9 | End User Training | 22 |
| 5.10 | Optional TAsk one - Additional Genomic facility | 22 |
| 5.10.1 | CONFIGURATION AND TEST | 22 |
| 5.10.2 | REPORTING AND ANALYTICS AT ADDED GENOMIC FACILITY | 23 |
| 6.0 | GENERAL REQUIREMENTS | 23 |
| 6.1 | ENTERPRISE AND IT FRAMEWORK | 23 |
| 6.1.1 | ONE-VA TECHNICAL REFERENCE MODEL | 23 |
| 6.1.2 | FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM) | 23 |
| 6.1.3 | INTERNET PROTOCOL VERSION 6 (IPV6) | 25 |
| 6.1.4 | TRUSTED INTERNET CONNECTION (TIC) | 25 |
| 6.1.5 | STANDARD COMPUTER CONFIGURATION | 25 |
| 6.1.6 | VETERAN FOCUSED INTEGRATION PROCESS (VIP) | 26 |
| 6.1.7 | PROCESS ASSETT LIBRARY (PAL) | 26 |
| 6.2 | SECURITY AND PRIVACY REQUIREMENTS | 26 |
| 6.2.1 | POSITION/TASK RISK DESIGNATION LEVEL(S) | 26 |
| 6.2.2 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 27 |
| 6.3 | METHOD AND DISTRIBUTION OF DELIVERABLES | 29 |
| 6.4 | PERFORMANCE METRICS | 29 |
| 6.5 | FACILITY/RESOURCE PROVISIONS | 30 |
| 6.6 | GOVERNMENT FURNISHED PROPERTY | 31 |
| ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 32 | |
| ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE | 38 |
BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OI&T), Veterans Health Administration (VHA) Innovation Program (10P8) is to provide benefits and services to Veterans of the United States. In meeting these goals, OI&T strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
In Fiscal Year (FY) 2016, the VA Innovation Project identified the VA Laboratory Systems Re-engineering Project’s (LSRP) Cerner Millennium Helix module and Reference Lab Network (RLN) as solutions that could provide genomics order/results workflow management, genomics instrument connectivity and commercial reference laboratory connectivity that the Veterans Information Systems and Technology Architecture (VistA) is incapable of processing and managing today.
Current VistA laboratory functionality is incapable of handling the pre-analytical data generated by molecular instrumentation currently in operation at VA genomic testing laboratories. These molecular analyzers have limited storage, access and transport capacity requiring VA genomic laboratories to purge data to function properly. LSRP’s Cerner’s Helix module provides the required molecular instrument connectivity to interface with these analyzers, store the data sent by the analyzers, manage and data mine the patient’s historical data as well as receive and process molecular orders and results required by VA genomic laboratories. The Cerner RLN will manage the connection to the seven VA genomic laboratories and the Mobile Applications Environment (MAE) (via Vitria – not direct connection) enabling orders and specimen results to pass to and from VistA. Clinicians will use VistA to view genomic data, manage data reporting analysis and test results.
Genomics LIMS Phase I was completed in December 2017. There were three tasks completed in this phase:
| 1. | Develop, setup, install, configure and implement Cerner RLN interfaces, specifically to deploy connections to Associated Regional and University Pathologists, Inc. Labs, Quest and LabCorp between one VA Medical Center (VAMC) genomic performing laboratory (Tampa), seven VAMC genomic laboratories (Huntington, WV; Washington D.C.; West Haven, CT; Little Rock, AR; New Orleans, LA; San Antonio, TX; Los Angeles, CA), the MAE and VistA. |
| 2. | Setup, install and implement three test protocol workflows and integrate with three molecular analyzers for the Millennium Helix Genomic proof of concept. |
| 3. | Deliver three example cases (cytogenetics, infectious disease, and molecular diagnostics) going through the different disciplines of molecular testing. |
The Cerner RLN connection was established, to allow the VA genomic labs to send reference lab procedure order HL7 messages to ARUP, Quest and LabCorp and receive test result HL7 messages. The Helix proof of concept at VAMC Tampa, FL demonstrated the capability for automating select molecular test workflows and interfacing to select molecular instrumentation utilizing the Millennium Helix software deployed on a temporary non-production Cerner Remote Hosted database. The Helix proof of concept allows for communication protocols and enhanced workflows to be implemented.
Phase II will develop the full Millennium Helix solution, based on the prototype, and deploy it to the all the genomic labs. The Millennium Helix prototype is hosted in an external cloud environment to validate the proof of concept in a production environment. Phase II involves the transfer of the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa production environment, configuring all the genomic labs to operate in a Millennium Helix single domain with the transferred license from Huntington, WV and implementation of Cerner Millennium Helix and the RLN. Phase II implementation is to configure and integrate the RLN connection and instrument interfaces to all labs into a single domain.
APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004
5. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, March 2016
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
7. 10 U.S.C. § 2224, "Defense Information Assurance Program"
8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters
11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/
13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs
14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998
20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
21. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
22. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015
23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, July 28, 2016
25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014
26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010
27. VA Handbook 6500.6, “Contract Security,” March 12, 2010
28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
29. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016
34. VA Directive 6300, Records and Information Management, February 26, 2009
35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
36. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach, June 10, 2014
37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015
38. OMB Memorandum, “Transition to IPv6”, September 28, 2010
39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015
40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014
41. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003
43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011
45. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
47. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008
48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017
50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014
51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
52. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
61. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
62. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
63. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
64. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
65. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
66. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
67. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
68. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ #7823189)”, September, 15, 2017, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
69. Attachment A - Genomic Molecular Lab Equipment
70. Attachment B – Cerner LSRP End User License Agreement
SCOPE OF WORK
The Contractor shall transfer the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa, FL VAMC production environment and validate the Tampa VAMC genomic laboratory is capable of Millennium Helix operation and access.
After solution is tested and accepted at the Tampa location the Contractor shall deploy the Cerner Millennium Helix capabilities and services to the other six VA genomic laboratories; Washington D.C., West Haven, Little Rock, New Orleans, San Antonio, and Los Angeles. The Contractor shall configure the Tampa, FL facility and the other VAMC genomic facilities to operate in a Millennium Helix single domain with the transferred license from Huntington, WV.
The deployment and implementation to the genomic facilities shall include an Enterprise Standard Design to allow for reuse to other laboratories. The Tampa build shall be leveraged for roll out of the remaining laboratories. Additional build, design and localization, as appropriate, shall be performed for those laboratories that differ in their instrumentation inventory. The Contractor shall provide and maintain monthly progress and on-boarding requirement reports, remote hosting, technical support, system security, network connectivity, application support, testing, capacity planning and operations and maintenance as well as setup and installation of the solution.
PERFORMANCE DETAILS
1.1 PERFORMANCE PERIOD
The Period of Performance (POP) shall be 12 months from date of award with one optional task.
The POP for the Genomic Facility Configuration and Testing optional task shall be 60 days from exercise and can be exercised up to three times.
Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 | |
| Independence Day | July 4 | |
| Veterans Day | November 11 | |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January | |
| Washington's Birthday | Third Monday in February | |
| Memorial Day | Last Monday in May | |
| Labor Day | First Monday in September | |
| Columbus Day | Second Monday in October | |
| Thanksgiving | Fourth Thursday in November |
1.2 PLACE OF PERFORMANCE
Tasks under this PWS shall be performed, predominately, at Contractor facilities. The Contractor shall identify the Contractor’s place of performance in their Task Execution Plan submission.
Software installation, configuration, implementation, change management, and training, under this PWS shall be performed in VA facilities located in:
1. Tampa, FL
2. Washington D.C.
3. West Haven, CT
4. Little Rock, AR
5. New Orleans, LA
6. San Antonio, TX
7. Los Angeles, CA
1.3 TRAVEL
The Government does not anticipate additional travel to perform the tasks associated with this effort.
SPECIFIC TASKS AND DELIVERABLES
The Contractor shall perform the following:
1.4 PROJECT MANAGEMENT
1.4.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The Contractor shall also address any Memorandum of Understanding (MOU), Enterprise Systems Change Control Board (ESCCB) processing and/or other VA approvals processes that are needed, in the CPMP. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA Program Manager (VAPM) approved CPMP throughout the POP.
Deliverable:
A. Contractor Project Management Plan
1.4.2 REPORTING REQUIREMENTS
The Contractor shall provide the Contracting Officer’s Representative (COR) with Monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.
The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
Deliverable:
A. Monthly Progress Reports
1.4.3 TECHNICAL KICKOFF MEETING
The Contractor shall hold a technical kickoff meeting within 10 days after contract award. The Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort. The Contractor shall initiate pre-project start up discussions with VA to establish tasks, durations, assignments and key milestones to include MOU, ESCCB processing and/or other VA approvals processes. The Contractor shall specify dates, locations (can be virtual), agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the CO, Contract Specialist (CS), COR, and the VAPM.
1.4.4 PRIVACY TRAINING
The Contractor shall submit VA Talent Management System training certificates of completion for VA Privacy and Information Security Awareness and Rules of Behavior training, and provide signed copies of the Contractor Rules of Behavior in accordance with Section 9, Training, from Appendix C of the VA Handbook 6500.6, “Contract Security”.
The Contractor shall submit status of VA Privacy and Information Security Awareness and Rules of Behavior training for all individuals engaged on the task. The status reporting shall identify; a single Contractor Security Point of Contact, the names of all personnel engaged on the task, their initial training date for VA Privacy and Information Security and Rules of Behavior training, and their next required training date. The training referenced above is required to be renewed annually.
This training information shall be submitted as part of the Monthly Progress Report.
Deliverables:
A. VA Privacy and Information Security Awareness Training Certificates B. Rules of Behavior Training Certificates
1.4.5 WEEKLY STATUS MEETING
The Contractor shall support a one hour (approximate) weekly status meeting (virtual) to review the work that has completed the previous week, outline the work that will be performed in the coming week and discuss any potential issues that need resolution and the plan to resolve those issues.
1.5 VAMC Analysis and Millenium Helix Implementation
The Contractor shall provide an analysis on the VAMC genomic facilities, listed in Section 4.2 Place of Performance, capabilities to host and access the Millennium Helix client application. The Contractor shall capture the results of each analysis in the Monthly Progress Reports. The Contractor shall for each VAMC genomic facility:
a. Provide an on-site visit
b. Perform an analysis of current state hardware and licensing on both the non-production and production environments and the environments’ ability to support the Millennium Helix system. The Contractor shall notify the COR and document any potential issues or deficiencies, with recommended resolution steps needed to correct the deficiency, in the Monthly Progress Reports
c. Provide system improvement recommendations to support future state XR platforms, in the Monthly Progress Reports
The Contractor shall install, configure and test Millennium Helix at the VAMC genomic facilities, listed in Section 4.2 Place of Performance. The Contractor shall for each VAMC genomic facility:
a. Build into one non-production environment to include the following:
1. All templates shall be built to replace Win32 chart formats
2. Build all distributions and expedites
3. Purge jobs, privileges, and preferences as they relate to Clinical Reporting XR
b. Rebuild entire solution into the production environment
c. Configure the XR archive to utilize CareAware Multimedia Archive or a network file location
1.6 CERNER TECHNOLOGY CENTER
The Contractor shall provide the designated VAMC genomic facilities listed in Section 4.2, Place of Performance, access to the Cerner Technology Center(s) (CTC). The CTC shall provide uninterrupted power and service for Cerner-hosted solutions. The Contractor shall ensure the CTC infrastructure reduces downtime and operates under supervision 24 hours per day, seven days per week, 365 days per year (24x7x365).
1.7 Transfer Huntington Millennium Helix License to Tampa
The Contractor shall transfer the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa, FL VAMC production environment. The Contractor shall configure the Tampa, FL facility to operate in a Millennium Helix single domain with the transferred license from Huntington, WV. The Contractor shall configure the Tampa facility to provide all the VAMC genomic facilities access to the Millennium Helix. The Contractor shall validate the operational capabilities of the Tampa, FL VAMC genomic facility to include the following:
a. Non-production environment maintains prior operational capabilities
b. Access to the Millennium Helix
c. RLN access
d. Operational Reporting capabilities in Section 5.5
e. Medical Device Interfaces maintain prior operational capabilities
The Contractor shall provide a demonstration of the Tampa VAMC genomic facility validating the operational capabilities with the transferred Millennium Helix license.
The Contractor shall document the results of the license transfer and any testing performed in the Monthly Progress Reports.
1.8 VAMC Genomic Facilities configuration and testing
The Contractor shall provide a Rollout Plan, for government approval, detailing the deployment of Millennium Helix to the VAMC genomic facilities.
The Contractor shall configure the VAMC genomic facilities listed in Section 4.2 Place of Performance to operate in a Millennium Helix single domain with the Tampa domain.
The Contractor shall setup, install, implement, interface and test Millennium Helix with the VAMC genomic facilities. The Contractor shall validate the operational capabilities of the VAMC genomic facilities to include the following:
a. Non-production environment maintains prior operational capabilities
b. Access to the Millennium Helix
c. RLN access
d. Operational Reporting capabilities in Section 5.6
e. Medical Device Interfaces maintain prior operational capabilities
The Contractor shall provide a demonstration for each VAMC genomic facility, validating the operational capabilities.
The Contractor shall document test results in the Monthly Progress Reports.
Deliverable:
A. Rollout Plan
1.9 Reporting and Analytics
The Contractor shall provide the following reporting capabilities for all the VAMC genomic facilities. In addition, the Contractor shall provide an operation demonstration validating the reporting capabilities for all the VAMC genomic facilities.
1.9.1 MEDICAL MANAGEMENT REPORTING
The Contractor shall provide the capability to create customizable Lab Management Reporting with Personalized Reports (Discern Analytics). The Contractor shall provide technical support to VA on the use of tools to create appropriate reports. Laboratory Management reporting shall include the following reports within Discern Analytics:
Service Management Reports:
a. Order level turnaround time (TAT) log report
b. Order level TAT analysis report
c. Order level missed volume analysis
Utilization Management:
a. Order level volume analysis report
b. Activity level volume analysis report template
c. Current procedural terminology (CPT)4 Volume Analysis template (CPT4 codes must be associated to orderables)
d. Cancellation analysis report template
e. Charge level volume analysis report template
Additional reports templates available include:
a. Activity level TAT log report templates
b. Activity level TAT analysis reports templates
c. Activity level missed volume analysis templates
1.9.2 MILLENNIUM HELIX FOR MOLECULAR DIAGNOSTICS
The Contractor shall provide the capability to order, at a minimum, 27 individual case types (e.g. Cystic Fibrosis, BCR/ABL, BRAF, EGFR, Factor II, Factor V, HER-2/neu, Huntington’s).
The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:
a. Ability to print labels with accession specimen numbers that are linked to the specimen
b. The accession specimen number is reflected in management reports
c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA
d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack
The Contractor shall provide the capability to create, at a minimum, 30 unique, custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.
The Contractor shall provide access to automated lab results that are provided by Millennium Helix to include the following:
a. Capability to associate Interpretive Data to performing instruments or benches
b. Interpretation text can be flexed based on specific alpha responses
c. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports
d. Electronic Signature can be included in Case Integration Reports to capture verifying personnel
e. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification
f. Clinical Bioinformatics Ontology (CBO) provides the capability to associate a concept name that corresponds to the mutation or concept defined in the CBO for an assay
g. The Controlled Medical Terminology (CMT) tool allows for the creation of custom CBO terms to be included into assays
h. The Contractor shall perform an assessment of VA molecular testing procedures to identify any gaps in Cerner’s reference database. Gaps identified will be submitted for inclusion in an upcoming CMT
i. Capability to build Case Integration Reports by utilizing the Layout Builder tool to create custom Unified Case Reporting templates
j. Up to 50 Unified Case Reporting templates shall be created
The Contractor shall provide access to the following Standard Reports:
a. Daily Activity Report
b. Exception Report
c. Correction Report
d. Assay Analysis Report
e. Case Analysis Report
f. Unified Case Integration Report (UCR)
g. Case Integration TAT Analysis Report
h. Pending Sign-out Report
i. Protocol Activity Analysis Report
j. Protocol Order Analysis Report
The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1). The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.
The Contractor shall provide the capability to create, at a minimum three rules. The Contractor shall provide technical support to VA on rules development.
1.9.3 FOR MILLENNIUM HELIX FOR INFECTIOUS DISEASE
The Contractor shall provide the capability to order, at a minimum, 19 individual case types (e.g. CMV, HPV, GC, Chlamydia).
The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:
a. Ability to print labels with accession specimen numbers that are linked to the specimen
b. The accession specimen number is reflected in management reports
c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA
d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack
The Contractor shall provide the capability to create, at a minimum, 20 unique custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.
The Contractor shall provide access to automated lab results that are provided by Millennium Helix to include the following:
a. Capability to associate Interpretive Data to performing instruments or benches
b. Interpretation text can be flexed based on specific alpha responses
c. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports
d. Electronic Signature can be included in Case Integration Reports to capture verifying personnel
e. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification
f. Clinical Bioinformatics Ontology provides the capability to associate a concept name that corresponds to the mutation or concept defined in the CBO for an assay
g. The CMT tool allows for the creation of custom CBO terms to be included into assays
h. The Contractor shall perform an assessment of VA’s infectious disease testing procedures to identify any gaps in the Cerner’s reference database. Gaps identified will be submitted for inclusion in an upcoming CMT
The Contractor shall provide access to the following Standard Reports:
a. Daily Activity Report
b. Exception Report
c. Correction Report
d. Assay Analysis Report
a. Case Analysis Report
b. UCR
c. Case Integration TAT Analysis Report
d. Pending Sign-out Report
e. Protocol Activity Analysis Report
f. Protocol Order Analysis Report
The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1) – The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.
The Contractor shall provide the capability to create, at a minimum, three rules. The Contractor shall provide technical support to VA on rules development.
1.9.4 MILLENNIUM HELIX FOR CYTOGENETICS
The Contractor shall provide the capability to order, at a minimum, 19 individual cases types (e.g. Chromosome Analysis).
The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:
a. Ability to print labels with accession specimen numbers that are linked to the specimen
b. The accession specimen number is reflected in management reports
c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA
d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack
The Contractor shall provide the capability to create, at a minimum, 50 unique custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.
The Contractor shall provide access to UCR templates to include, at a minimum, 20 of the following types:
a. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports
b. Karyotype Templates
c. Electronic Signature can be included in Case Integration Reports to capture verifying personnel
d. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification
The Contractor shall provide access to the following Standard Reports:
a. Daily Activity Report
b. Exception Report
c. Correction Report
d. Assay Analysis Report
e. Case Analysis Report
f. UCR
g. Case Integration TAT Analysis Report
h. Pending Sign-out Report
i. Protocol Activity Analysis Report
j. Protocol Order Analysis Report
The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1) – The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.
The Contractor shall provide the capability to create, at a minimum, three rules. The Contractor shall provide technical support on rules development
1.9.5 PROVISION OF DEVICE WORKS FLAT FILES
The Contractor shall provide and validate one initial set of Device Works Flat Files for the Millennium Helix Molecular Diagnostics, Infectious Disease and Cytogenetics modules and provide the capability to create DeviceWorks Flat Files using the File Definition Builder tool, in Millennium Helix. The Contractor shall provide and validate the File Definition Builder tool that can automate export of a delimited file or the import of data by a delimited file. The Contractor shall provide one of the following for each site:
a. One flat file script for a single worksheet and single instrument
b. The training necessary for the VA team to develop their own flat file scripts. This requires at least one individual with programming experience (preferably VBScript or JScript) and an understanding of file structures used by the laboratory instruments to attend a course lead by the Contractor
The Contractor shall document the Flat file testing results in the Monthly Progress Reports.
1.9.6 CAREAWARE IBUS MULTIPLEXOR MEDICAL DEVICE INTERFACE (MDI) SERVICES (CTS-IBUS-MULTI) CareAware iBus was created to facilitate communication of information between bedside medical devices (i.e. physiologic monitors) and the electronic medical record (EMR).
CareAware iBus has the ability to distinguish the make, model, and type of a particular device, load the associated device connectivity driver, and govern communication between the device and the appropriate EMR (i.e. patient record).
The Contractor shall configure, integrate and test the Medical Devices, referenced in Attachment A, at the facilities listed in Section 4.2, Place of Performance, using the CareAware iBus Multiplexor MDI service.
The Contractor shall provide the following CareAware iBus configuration support:
a. Configure the CareAware iBus for connected devices
b. Configure the Cerner Olympus and Microsoft Active Directory Application Mode (ADAM) repository
c. Test the core CareAware iBus functionality
The Contractor shall provide the following Medical Device Integration support:
a. Define the data elements of the medical device
b. Build the interface solution
c. Work with VA technical teams to establish connectivity to the medical device
d. Provide knowledge transfer for process workflow and troubleshooting
The Contractor shall test the medical device connectivity to the CareAware iBus to include the following:
a. Test basic medical device connectivity and data flow
b. Ensure that standard communication with the medical device is successful and that results can be viewed
c. Troubleshoot and resolve issues that arise from VA medical device connectivity testing
d. Document the test results in the Monthly Progress Reports
The Contractor shall provide the Medical Device to CareAware iBus Solution and deliver Cerner Commercial Maintenance, Configuration, and Operational Procedures Documentation for the devices listed in Attachment A. The Contractor shall validate the operation of the Medical Devices with the CareAware iBus and document the test results in a Medical Device to CareAware iBus Solution Report.
Deliverables:
A. Medical Device to CareAware iBus Solution Report B. Cerner Commercial Maintenance, Configuration, and Operational Procedures Documentation
1.10 CareAware Maintenance Training
The Contractor shall provide live instructor-led training for CareAware maintenance and configuration. The Contractor shall provide a “train-the-trainer” approach to the training of VAMC personnel. The Contractor shall provide a Training Plan for review and approval detailing the approach for delivering training to appropriate VA personnel at each VAMC genomic facility. The Contractor shall provide CareAware Training Materials to include training manuals (for both the Trainers and end users), user guides and notes for the training, as needed. The training shall include the following:
a. Maintenance of the CareAware interface
b. Configuring the CareAware interface
c. Using CareAware iBus process workflow and troubleshooting techniques
d. Configuring and Integrating additional Medical Devices via the CareAware iBus
Deliverables:
A. Training Plan
1.11 TRAINING FOR MILLENNIUM HELIX
The Contractor shall provide and deliver Train-the-Trainer courses to the VA Training Management System (TMS) for up to four TMS courses based on job roles and responsibilities. The Contractor shall detail the approach to delivering this training in the Training Plan. The Contractor shall provide Train-the-Trainer courses to include the following subject matter:
a. Creating customizable Personalized Reports (Discern Analytics)
b. Retrieving Specimen Management data
c. Creating Protocol Documentation
d. Retrieving automated lab results
e. Retrieving Standard Reports
f. Retrieving UCR templates
g. Creating rules sets
h. Developing DeviceWorks flat file scripts
i. Using CareAware iBus process workflow and troubleshooting techniques
j. Configuring and Integrating additional Medical Devices via the CareAware iBus
1.12 End User Training
The Contractor shall provide four hours of user training (can be virtual), for 20 trainees, on Millennium Helix. The Contractor shall detail the approach to delivering this training in the Training Plan. The Contractor shall provide End User Training Materials to include Millennium Helix training manuals, user guides and notes for the training. The training shall include the following:
a. Creating customizable Personalized Reports (Discern Analytics)
b. Retrieving Specimen Management data
c. Creating Protocol Documentation
d. Retrieving automated lab results
e. Retrieving Standard Reports
f. Retrieving UCR templates
g. Creating rules sets
h. Developing DeviceWorks flat file scripts
i. Using CareAware iBus process workflow and troubleshooting techniques
j. Configuring and Integrating additional Medical Devices via the CareAware iBus
1.13 Optional TAsk one - Additional Genomic facility
If this Optional Task is exercised by VA, the Contractor shall perform the following for an additional genomic facility:
1.13.1 CONFIGURATION AND TEST
The Contractor shall configure the genomic facility to operate in a Millennium Helix single domain with the Tampa domain.
The Contractor shall setup, install, implement, interface and test Millennium Helix with the genomic facility. The Contractor shall validate the operational capabilities of the genomic facility to include the following:
a. Non-production environment maintains prior operational capabilities
b. Access to the Millennium Helix
c. RLN access
d. Operational Reporting capabilities in Section 5.6
e. Medical Device Interfaces maintain prior operational capabilities
The Contractor shall provide a demonstration for the genomic facility, validating the operational capabilities.
The Contractor shall document test results in the Monthly Progress Reports.
1.13.2 REPORTING AND ANALYTICS AT ADDED GENOMIC FACILITY
The Contractor shall perform all tasks in the Section 5.6 and it’s sub-sections for the added genomic facility.
GENERAL REQUIREMENTS
1.14 ENTERPRISE AND IT FRAMEWORK
1.14.1 ONE-VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (One-VA TRM). One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and Design (ASD) has overall responsibility for the One-VA TRM.
1.14.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the OMB Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at: https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
1.14.3 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance (http://csrc.nist.gov/publications/PubsSPs.html) shall be included…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.