36C10B18R2933-001.docx

DOCX document 109 KB Posted

Attached to
Genomic LIMS Phase II Modification to post Draft PWS Federal contract opportunity
Solicitation number
36C10B18R2933
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

36C10B18R2933 36C10B18R2933_1.docx

View the file

Other files for this federal contract opportunity

Other files attached to Genomic LIMS Phase II Modification to post Draft PWS, newest first.
File Type Posted
36C10B18R2933-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Genomic Laboratory Information Management System (LIMS) Phase II TAC Number: TAC-18-50695

FedBizOpps Modification to a Previous Notice

CLASSIFICATION CODE

SUBJECT

CONTRACTING OFFICE'S

ZIP-CODE

SOLICITATION NUMBER

BASE NOTICE TYPE

RESPONSE DATE (MM-DD-YYYY)

ARCHIVE

DAYS AFTER THE RESPONSE DATE

RECOVERY ACT FUNDS

SET-ASIDE

NAICS CODE

CONTRACTING OFFICE

ADDRESS

POINT OF CONTACT

(POC Information Automatically Filled from User Profile Unless Entered)

DESCRIPTION

See Attachment

AGENCY'S URL

URL DESCRIPTION

AGENCY CONTACT'S EMAIL

ADDRESS

EMAIL DESCRIPTION

ADDRESS

POSTAL CODE

COUNTRY

ADDITIONAL INFORMATION

GENERAL INFORMATION

PLACE OF PERFORMANCE

* = Required Field FedBizOpps Modification to a Previous Notice Rev. March 2010 D Genomic LIMS Phase II Modification to post Draft PWS 07724 36C10B18R2933 N 541519 Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Derek Maselli, Contract Specialist:

derek.maselli@va.gov

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Office of Information & Technology Office of Connected Care, Innovation Program

Genomic Laboratory Information Management System (LIMS) Phase II

Date: June 28, 2018

TAC-18-50695

PWS Version Number: 1.2

Contents

1.0BACKGROUND5
2.0APPLICABLE DOCUMENTS6
3.0SCOPE OF WORK9
4.0PERFORMANCE DETAILS9
4.1PERFORMANCE PERIOD9
4.2PLACE OF PERFORMANCE10
4.3TRAVEL10
5.0SPECIFIC TASKS AND DELIVERABLES10
5.1PROJECT MANAGEMENT10
5.1.1CONTRACTOR PROJECT MANAGEMENT PLAN10
5.1.2REPORTING REQUIREMENTS11
5.1.3TECHNICAL KICKOFF MEETING11
5.1.4PRIVACY TRAINING11
5.1.5WEEKLY STATUS MEETING12
5.2VAMC Analysis and Millenium Helix Implementation12
5.3CERNER TECHNOLOGY CENTER13
5.4Transfer Huntington Millennium Helix License to Tampa13
5.5VAMC Genomic Facilities configuration and testing13
5.6Reporting and Analytics14
5.6.1MEDICAL MANAGEMENT REPORTING14
5.6.2MILLENNIUM HELIX FOR MOLECULAR DIAGNOSTICS15
5.6.3FOR MILLENNIUM HELIX FOR INFECTIOUS DISEASE16
5.6.4MILLENNIUM HELIX FOR CYTOGENETICS18
5.6.5PROVISION OF DEVICE WORKS FLAT FILES19
5.6.6CAREAWARE IBUS MULTIPLEXOR MEDICAL DEVICE INTERFACE (MDI) SERVICES (CTS-IBUS-MULTI)20
5.7CareAware Maintenance Training21
5.8TRAINING FOR MILLENNIUM HELIX21
5.9End User Training22
5.10Optional TAsk one - Additional Genomic facility22
5.10.1CONFIGURATION AND TEST22
5.10.2REPORTING AND ANALYTICS AT ADDED GENOMIC FACILITY23
6.0GENERAL REQUIREMENTS23
6.1ENTERPRISE AND IT FRAMEWORK23
6.1.1ONE-VA TECHNICAL REFERENCE MODEL23
6.1.2FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)23
6.1.3INTERNET PROTOCOL VERSION 6 (IPV6)25
6.1.4TRUSTED INTERNET CONNECTION (TIC)25
6.1.5STANDARD COMPUTER CONFIGURATION25
6.1.6VETERAN FOCUSED INTEGRATION PROCESS (VIP)26
6.1.7PROCESS ASSETT LIBRARY (PAL)26
6.2SECURITY AND PRIVACY REQUIREMENTS26
6.2.1POSITION/TASK RISK DESIGNATION LEVEL(S)26
6.2.2CONTRACTOR PERSONNEL SECURITY REQUIREMENTS27
6.3METHOD AND DISTRIBUTION OF DELIVERABLES29
6.4PERFORMANCE METRICS29
6.5FACILITY/RESOURCE PROVISIONS30
6.6GOVERNMENT FURNISHED PROPERTY31
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED32
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE38

BACKGROUND

The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OI&T), Veterans Health Administration (VHA) Innovation Program (10P8) is to provide benefits and services to Veterans of the United States. In meeting these goals, OI&T strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.

In Fiscal Year (FY) 2016, the VA Innovation Project identified the VA Laboratory Systems Re-engineering Project’s (LSRP) Cerner Millennium Helix module and Reference Lab Network (RLN) as solutions that could provide genomics order/results workflow management, genomics instrument connectivity and commercial reference laboratory connectivity that the Veterans Information Systems and Technology Architecture (VistA) is incapable of processing and managing today.

Current VistA laboratory functionality is incapable of handling the pre-analytical data generated by molecular instrumentation currently in operation at VA genomic testing laboratories. These molecular analyzers have limited storage, access and transport capacity requiring VA genomic laboratories to purge data to function properly. LSRP’s Cerner’s Helix module provides the required molecular instrument connectivity to interface with these analyzers, store the data sent by the analyzers, manage and data mine the patient’s historical data as well as receive and process molecular orders and results required by VA genomic laboratories. The Cerner RLN will manage the connection to the seven VA genomic laboratories and the Mobile Applications Environment (MAE) (via Vitria – not direct connection) enabling orders and specimen results to pass to and from VistA. Clinicians will use VistA to view genomic data, manage data reporting analysis and test results.

Genomics LIMS Phase I was completed in December 2017. There were three tasks completed in this phase:

1.Develop, setup, install, configure and implement Cerner RLN interfaces, specifically to deploy connections to Associated Regional and University Pathologists, Inc. Labs, Quest and LabCorp between one VA Medical Center (VAMC) genomic performing laboratory (Tampa), seven VAMC genomic laboratories (Huntington, WV; Washington D.C.; West Haven, CT; Little Rock, AR; New Orleans, LA; San Antonio, TX; Los Angeles, CA), the MAE and VistA.
2.Setup, install and implement three test protocol workflows and integrate with three molecular analyzers for the Millennium Helix Genomic proof of concept.
3.Deliver three example cases (cytogenetics, infectious disease, and molecular diagnostics) going through the different disciplines of molecular testing.

The Cerner RLN connection was established, to allow the VA genomic labs to send reference lab procedure order HL7 messages to ARUP, Quest and LabCorp and receive test result HL7 messages. The Helix proof of concept at VAMC Tampa, FL demonstrated the capability for automating select molecular test workflows and interfacing to select molecular instrumentation utilizing the Millennium Helix software deployed on a temporary non-production Cerner Remote Hosted database. The Helix proof of concept allows for communication protocols and enhanced workflows to be implemented.

Phase II will develop the full Millennium Helix solution, based on the prototype, and deploy it to the all the genomic labs. The Millennium Helix prototype is hosted in an external cloud environment to validate the proof of concept in a production environment. Phase II involves the transfer of the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa production environment, configuring all the genomic labs to operate in a Millennium Helix single domain with the transferred license from Huntington, WV and implementation of Cerner Millennium Helix and the RLN. Phase II implementation is to configure and integrate the RLN connection and instrument interfaces to all labs into a single domain.

APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”

4. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004

5. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, March 2016

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

9. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

10. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters

11. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

12. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

13. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

14. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003

16. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008

19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998

20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

21. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012

22. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015

23. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

24. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, July 28, 2016

25. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014

26. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010

27. VA Handbook 6500.6, “Contract Security,” March 12, 2010

28. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

29. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

30. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

31. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

32. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

33. VA Handbook 6510, “VA Identity and Access Management”, January 15, 2016

34. VA Directive 6300, Records and Information Management, February 26, 2009

35. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

36. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach, June 10, 2014

37. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015

38. OMB Memorandum, “Transition to IPv6”, September 28, 2010

39. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015

40. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014

41. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006

42. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003

43. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

44. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011

45. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

46. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

47. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008

48. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

49. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017

50. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014

51. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012

52. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

53. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

54. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

55. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

56. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

57. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

58. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

61. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

63. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

64. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

65. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

66. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

67. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

68. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ #7823189)”, September, 15, 2017, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

69. Attachment A - Genomic Molecular Lab Equipment

70. Attachment B – Cerner LSRP End User License Agreement

SCOPE OF WORK

The Contractor shall transfer the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa, FL VAMC production environment and validate the Tampa VAMC genomic laboratory is capable of Millennium Helix operation and access.

After solution is tested and accepted at the Tampa location the Contractor shall deploy the Cerner Millennium Helix capabilities and services to the other six VA genomic laboratories; Washington D.C., West Haven, Little Rock, New Orleans, San Antonio, and Los Angeles. The Contractor shall configure the Tampa, FL facility and the other VAMC genomic facilities to operate in a Millennium Helix single domain with the transferred license from Huntington, WV.

The deployment and implementation to the genomic facilities shall include an Enterprise Standard Design to allow for reuse to other laboratories. The Tampa build shall be leveraged for roll out of the remaining laboratories. Additional build, design and localization, as appropriate, shall be performed for those laboratories that differ in their instrumentation inventory. The Contractor shall provide and maintain monthly progress and on-boarding requirement reports, remote hosting, technical support, system security, network connectivity, application support, testing, capacity planning and operations and maintenance as well as setup and installation of the solution.

PERFORMANCE DETAILS

1.1 PERFORMANCE PERIOD

The Period of Performance (POP) shall be 12 months from date of award with one optional task.

The POP for the Genomic Facility Configuration and Testing optional task shall be 60 days from exercise and can be exercised up to three times.

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).

There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's DayJanuary 1
Independence DayJuly 4
Veterans DayNovember 11
Christmas DayDecember 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's BirthdayThird Monday in January
Washington's BirthdayThird Monday in February
Memorial DayLast Monday in May
Labor DayFirst Monday in September
Columbus DaySecond Monday in October
ThanksgivingFourth Thursday in November

1.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed, predominately, at Contractor facilities. The Contractor shall identify the Contractor’s place of performance in their Task Execution Plan submission.

Software installation, configuration, implementation, change management, and training, under this PWS shall be performed in VA facilities located in:

1. Tampa, FL

2. Washington D.C.

3. West Haven, CT

4. Little Rock, AR

5. New Orleans, LA

6. San Antonio, TX

7. Los Angeles, CA

1.3 TRAVEL

The Government does not anticipate additional travel to perform the tasks associated with this effort.

SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the following:

1.4 PROJECT MANAGEMENT

1.4.1 CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The Contractor shall also address any Memorandum of Understanding (MOU), Enterprise Systems Change Control Board (ESCCB) processing and/or other VA approvals processes that are needed, in the CPMP. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA Program Manager (VAPM) approved CPMP throughout the POP.

Deliverable:

A. Contractor Project Management Plan

1.4.2 REPORTING REQUIREMENTS

The Contractor shall provide the Contracting Officer’s Representative (COR) with Monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

Deliverable:

A. Monthly Progress Reports

1.4.3 TECHNICAL KICKOFF MEETING

The Contractor shall hold a technical kickoff meeting within 10 days after contract award. The Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort. The Contractor shall initiate pre-project start up discussions with VA to establish tasks, durations, assignments and key milestones to include MOU, ESCCB processing and/or other VA approvals processes. The Contractor shall specify dates, locations (can be virtual), agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the CO, Contract Specialist (CS), COR, and the VAPM.

1.4.4 PRIVACY TRAINING

The Contractor shall submit VA Talent Management System training certificates of completion for VA Privacy and Information Security Awareness and Rules of Behavior training, and provide signed copies of the Contractor Rules of Behavior in accordance with Section 9, Training, from Appendix C of the VA Handbook 6500.6, “Contract Security”.

The Contractor shall submit status of VA Privacy and Information Security Awareness and Rules of Behavior training for all individuals engaged on the task. The status reporting shall identify; a single Contractor Security Point of Contact, the names of all personnel engaged on the task, their initial training date for VA Privacy and Information Security and Rules of Behavior training, and their next required training date. The training referenced above is required to be renewed annually.

This training information shall be submitted as part of the Monthly Progress Report.

Deliverables:

A. VA Privacy and Information Security Awareness Training Certificates B. Rules of Behavior Training Certificates

1.4.5 WEEKLY STATUS MEETING

The Contractor shall support a one hour (approximate) weekly status meeting (virtual) to review the work that has completed the previous week, outline the work that will be performed in the coming week and discuss any potential issues that need resolution and the plan to resolve those issues.

1.5 VAMC Analysis and Millenium Helix Implementation

The Contractor shall provide an analysis on the VAMC genomic facilities, listed in Section 4.2 Place of Performance, capabilities to host and access the Millennium Helix client application. The Contractor shall capture the results of each analysis in the Monthly Progress Reports. The Contractor shall for each VAMC genomic facility:

a. Provide an on-site visit

b. Perform an analysis of current state hardware and licensing on both the non-production and production environments and the environments’ ability to support the Millennium Helix system. The Contractor shall notify the COR and document any potential issues or deficiencies, with recommended resolution steps needed to correct the deficiency, in the Monthly Progress Reports

c. Provide system improvement recommendations to support future state XR platforms, in the Monthly Progress Reports

The Contractor shall install, configure and test Millennium Helix at the VAMC genomic facilities, listed in Section 4.2 Place of Performance. The Contractor shall for each VAMC genomic facility:

a. Build into one non-production environment to include the following:

1. All templates shall be built to replace Win32 chart formats

2. Build all distributions and expedites

3. Purge jobs, privileges, and preferences as they relate to Clinical Reporting XR

b. Rebuild entire solution into the production environment

c. Configure the XR archive to utilize CareAware Multimedia Archive or a network file location

1.6 CERNER TECHNOLOGY CENTER

The Contractor shall provide the designated VAMC genomic facilities listed in Section 4.2, Place of Performance, access to the Cerner Technology Center(s) (CTC). The CTC shall provide uninterrupted power and service for Cerner-hosted solutions. The Contractor shall ensure the CTC infrastructure reduces downtime and operates under supervision 24 hours per day, seven days per week, 365 days per year (24x7x365).

1.7 Transfer Huntington Millennium Helix License to Tampa

The Contractor shall transfer the Millennium Helix license from the Huntington, WV VAMC non-production environment to the Tampa, FL VAMC production environment. The Contractor shall configure the Tampa, FL facility to operate in a Millennium Helix single domain with the transferred license from Huntington, WV. The Contractor shall configure the Tampa facility to provide all the VAMC genomic facilities access to the Millennium Helix. The Contractor shall validate the operational capabilities of the Tampa, FL VAMC genomic facility to include the following:

a. Non-production environment maintains prior operational capabilities

b. Access to the Millennium Helix

c. RLN access

d. Operational Reporting capabilities in Section 5.5

e. Medical Device Interfaces maintain prior operational capabilities

The Contractor shall provide a demonstration of the Tampa VAMC genomic facility validating the operational capabilities with the transferred Millennium Helix license.

The Contractor shall document the results of the license transfer and any testing performed in the Monthly Progress Reports.

1.8 VAMC Genomic Facilities configuration and testing

The Contractor shall provide a Rollout Plan, for government approval, detailing the deployment of Millennium Helix to the VAMC genomic facilities.

The Contractor shall configure the VAMC genomic facilities listed in Section 4.2 Place of Performance to operate in a Millennium Helix single domain with the Tampa domain.

The Contractor shall setup, install, implement, interface and test Millennium Helix with the VAMC genomic facilities. The Contractor shall validate the operational capabilities of the VAMC genomic facilities to include the following:

a. Non-production environment maintains prior operational capabilities

b. Access to the Millennium Helix

c. RLN access

d. Operational Reporting capabilities in Section 5.6

e. Medical Device Interfaces maintain prior operational capabilities

The Contractor shall provide a demonstration for each VAMC genomic facility, validating the operational capabilities.

The Contractor shall document test results in the Monthly Progress Reports.

Deliverable:

A. Rollout Plan

1.9 Reporting and Analytics

The Contractor shall provide the following reporting capabilities for all the VAMC genomic facilities. In addition, the Contractor shall provide an operation demonstration validating the reporting capabilities for all the VAMC genomic facilities.

1.9.1 MEDICAL MANAGEMENT REPORTING

The Contractor shall provide the capability to create customizable Lab Management Reporting with Personalized Reports (Discern Analytics). The Contractor shall provide technical support to VA on the use of tools to create appropriate reports. Laboratory Management reporting shall include the following reports within Discern Analytics:

Service Management Reports:

a. Order level turnaround time (TAT) log report

b. Order level TAT analysis report

c. Order level missed volume analysis

Utilization Management:

a. Order level volume analysis report

b. Activity level volume analysis report template

c. Current procedural terminology (CPT)4 Volume Analysis template (CPT4 codes must be associated to orderables)

d. Cancellation analysis report template

e. Charge level volume analysis report template

Additional reports templates available include:

a. Activity level TAT log report templates

b. Activity level TAT analysis reports templates

c. Activity level missed volume analysis templates

1.9.2 MILLENNIUM HELIX FOR MOLECULAR DIAGNOSTICS

The Contractor shall provide the capability to order, at a minimum, 27 individual case types (e.g. Cystic Fibrosis, BCR/ABL, BRAF, EGFR, Factor II, Factor V, HER-2/neu, Huntington’s).

The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:

a. Ability to print labels with accession specimen numbers that are linked to the specimen

b. The accession specimen number is reflected in management reports

c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA

d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack

The Contractor shall provide the capability to create, at a minimum, 30 unique, custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.

The Contractor shall provide access to automated lab results that are provided by Millennium Helix to include the following:

a. Capability to associate Interpretive Data to performing instruments or benches

b. Interpretation text can be flexed based on specific alpha responses

c. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports

d. Electronic Signature can be included in Case Integration Reports to capture verifying personnel

e. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification

f. Clinical Bioinformatics Ontology (CBO) provides the capability to associate a concept name that corresponds to the mutation or concept defined in the CBO for an assay

g. The Controlled Medical Terminology (CMT) tool allows for the creation of custom CBO terms to be included into assays

h. The Contractor shall perform an assessment of VA molecular testing procedures to identify any gaps in Cerner’s reference database. Gaps identified will be submitted for inclusion in an upcoming CMT

i. Capability to build Case Integration Reports by utilizing the Layout Builder tool to create custom Unified Case Reporting templates

j. Up to 50 Unified Case Reporting templates shall be created

The Contractor shall provide access to the following Standard Reports:

a. Daily Activity Report

b. Exception Report

c. Correction Report

d. Assay Analysis Report

e. Case Analysis Report

f. Unified Case Integration Report (UCR)

g. Case Integration TAT Analysis Report

h. Pending Sign-out Report

i. Protocol Activity Analysis Report

j. Protocol Order Analysis Report

The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1). The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.

The Contractor shall provide the capability to create, at a minimum three rules. The Contractor shall provide technical support to VA on rules development.

1.9.3 FOR MILLENNIUM HELIX FOR INFECTIOUS DISEASE

The Contractor shall provide the capability to order, at a minimum, 19 individual case types (e.g. CMV, HPV, GC, Chlamydia).

The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:

a. Ability to print labels with accession specimen numbers that are linked to the specimen

b. The accession specimen number is reflected in management reports

c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA

d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack

The Contractor shall provide the capability to create, at a minimum, 20 unique custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.

The Contractor shall provide access to automated lab results that are provided by Millennium Helix to include the following:

a. Capability to associate Interpretive Data to performing instruments or benches

b. Interpretation text can be flexed based on specific alpha responses

c. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports

d. Electronic Signature can be included in Case Integration Reports to capture verifying personnel

e. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification

f. Clinical Bioinformatics Ontology provides the capability to associate a concept name that corresponds to the mutation or concept defined in the CBO for an assay

g. The CMT tool allows for the creation of custom CBO terms to be included into assays

h. The Contractor shall perform an assessment of VA’s infectious disease testing procedures to identify any gaps in the Cerner’s reference database. Gaps identified will be submitted for inclusion in an upcoming CMT

The Contractor shall provide access to the following Standard Reports:

a. Daily Activity Report

b. Exception Report

c. Correction Report

d. Assay Analysis Report

a. Case Analysis Report

b. UCR

c. Case Integration TAT Analysis Report

d. Pending Sign-out Report

e. Protocol Activity Analysis Report

f. Protocol Order Analysis Report

The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1) – The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.

The Contractor shall provide the capability to create, at a minimum, three rules. The Contractor shall provide technical support to VA on rules development.

1.9.4 MILLENNIUM HELIX FOR CYTOGENETICS

The Contractor shall provide the capability to order, at a minimum, 19 individual cases types (e.g. Chromosome Analysis).

The Contractor shall configure Millennium Helix to provide the following Specimen Management data capabilities:

a. Ability to print labels with accession specimen numbers that are linked to the specimen

b. The accession specimen number is reflected in management reports

c. Capability to create, discard, and modify aliquots from parent specimens, such as DNA

d. PathNet Storage Tracking is utilized to digitally document the specimen’s location from the freezer or refrigerator unit to the position within a rack

The Contractor shall provide the capability to create, at a minimum, 50 unique custom Protocol Documents with the Worksheet Builder tool. The Contractor shall validate the Worksheet Builder tool allows Protocol Documentation to capture data, such as numeric values, free text, calculations, personnel, date/time, specimen information, and create specimen aliquots.

The Contractor shall provide access to UCR templates to include, at a minimum, 20 of the following types:

a. Word Processing Templates can be created to allow for canned text to import into Case Integration Reports

b. Karyotype Templates

c. Electronic Signature can be included in Case Integration Reports to capture verifying personnel

d. Clinical Validation can allow for results to queue in the Review Queue application before final verification and the Assign Responsible Personnel function allows for directly assigning cases for final verification

The Contractor shall provide access to the following Standard Reports:

a. Daily Activity Report

b. Exception Report

c. Correction Report

d. Assay Analysis Report

e. Case Analysis Report

f. UCR

g. Case Integration TAT Analysis Report

h. Pending Sign-out Report

i. Protocol Activity Analysis Report

j. Protocol Order Analysis Report

The Contractor shall provide the capability to create customizable Personalized Reports (Reference Discern Analytics reports types in 5.6.1) – The Contractor shall provide technical support to VA on the use of tools to create appropriate reports.

The Contractor shall provide the capability to create, at a minimum, three rules. The Contractor shall provide technical support on rules development

1.9.5 PROVISION OF DEVICE WORKS FLAT FILES

The Contractor shall provide and validate one initial set of Device Works Flat Files for the Millennium Helix Molecular Diagnostics, Infectious Disease and Cytogenetics modules and provide the capability to create DeviceWorks Flat Files using the File Definition Builder tool, in Millennium Helix. The Contractor shall provide and validate the File Definition Builder tool that can automate export of a delimited file or the import of data by a delimited file. The Contractor shall provide one of the following for each site:

a. One flat file script for a single worksheet and single instrument

b. The training necessary for the VA team to develop their own flat file scripts. This requires at least one individual with programming experience (preferably VBScript or JScript) and an understanding of file structures used by the laboratory instruments to attend a course lead by the Contractor

The Contractor shall document the Flat file testing results in the Monthly Progress Reports.

1.9.6 CAREAWARE IBUS MULTIPLEXOR MEDICAL DEVICE INTERFACE (MDI) SERVICES (CTS-IBUS-MULTI) CareAware iBus was created to facilitate communication of information between bedside medical devices (i.e. physiologic monitors) and the electronic medical record (EMR).

CareAware iBus has the ability to distinguish the make, model, and type of a particular device, load the associated device connectivity driver, and govern communication between the device and the appropriate EMR (i.e. patient record).

The Contractor shall configure, integrate and test the Medical Devices, referenced in Attachment A, at the facilities listed in Section 4.2, Place of Performance, using the CareAware iBus Multiplexor MDI service.

The Contractor shall provide the following CareAware iBus configuration support:

a. Configure the CareAware iBus for connected devices

b. Configure the Cerner Olympus and Microsoft Active Directory Application Mode (ADAM) repository

c. Test the core CareAware iBus functionality

The Contractor shall provide the following Medical Device Integration support:

a. Define the data elements of the medical device

b. Build the interface solution

c. Work with VA technical teams to establish connectivity to the medical device

d. Provide knowledge transfer for process workflow and troubleshooting

The Contractor shall test the medical device connectivity to the CareAware iBus to include the following:

a. Test basic medical device connectivity and data flow

b. Ensure that standard communication with the medical device is successful and that results can be viewed

c. Troubleshoot and resolve issues that arise from VA medical device connectivity testing

d. Document the test results in the Monthly Progress Reports

The Contractor shall provide the Medical Device to CareAware iBus Solution and deliver Cerner Commercial Maintenance, Configuration, and Operational Procedures Documentation for the devices listed in Attachment A. The Contractor shall validate the operation of the Medical Devices with the CareAware iBus and document the test results in a Medical Device to CareAware iBus Solution Report.

Deliverables:

A. Medical Device to CareAware iBus Solution Report B. Cerner Commercial Maintenance, Configuration, and Operational Procedures Documentation

1.10 CareAware Maintenance Training

The Contractor shall provide live instructor-led training for CareAware maintenance and configuration. The Contractor shall provide a “train-the-trainer” approach to the training of VAMC personnel. The Contractor shall provide a Training Plan for review and approval detailing the approach for delivering training to appropriate VA personnel at each VAMC genomic facility. The Contractor shall provide CareAware Training Materials to include training manuals (for both the Trainers and end users), user guides and notes for the training, as needed. The training shall include the following:

a. Maintenance of the CareAware interface

b. Configuring the CareAware interface

c. Using CareAware iBus process workflow and troubleshooting techniques

d. Configuring and Integrating additional Medical Devices via the CareAware iBus

Deliverables:

A. Training Plan

1.11 TRAINING FOR MILLENNIUM HELIX

The Contractor shall provide and deliver Train-the-Trainer courses to the VA Training Management System (TMS) for up to four TMS courses based on job roles and responsibilities. The Contractor shall detail the approach to delivering this training in the Training Plan. The Contractor shall provide Train-the-Trainer courses to include the following subject matter:

a. Creating customizable Personalized Reports (Discern Analytics)

b. Retrieving Specimen Management data

c. Creating Protocol Documentation

d. Retrieving automated lab results

e. Retrieving Standard Reports

f. Retrieving UCR templates

g. Creating rules sets

h. Developing DeviceWorks flat file scripts

i. Using CareAware iBus process workflow and troubleshooting techniques

j. Configuring and Integrating additional Medical Devices via the CareAware iBus

1.12 End User Training

The Contractor shall provide four hours of user training (can be virtual), for 20 trainees, on Millennium Helix. The Contractor shall detail the approach to delivering this training in the Training Plan. The Contractor shall provide End User Training Materials to include Millennium Helix training manuals, user guides and notes for the training. The training shall include the following:

a. Creating customizable Personalized Reports (Discern Analytics)

b. Retrieving Specimen Management data

c. Creating Protocol Documentation

d. Retrieving automated lab results

e. Retrieving Standard Reports

f. Retrieving UCR templates

g. Creating rules sets

h. Developing DeviceWorks flat file scripts

i. Using CareAware iBus process workflow and troubleshooting techniques

j. Configuring and Integrating additional Medical Devices via the CareAware iBus

1.13 Optional TAsk one - Additional Genomic facility

If this Optional Task is exercised by VA, the Contractor shall perform the following for an additional genomic facility:

1.13.1 CONFIGURATION AND TEST

The Contractor shall configure the genomic facility to operate in a Millennium Helix single domain with the Tampa domain.

The Contractor shall setup, install, implement, interface and test Millennium Helix with the genomic facility. The Contractor shall validate the operational capabilities of the genomic facility to include the following:

a. Non-production environment maintains prior operational capabilities

b. Access to the Millennium Helix

c. RLN access

d. Operational Reporting capabilities in Section 5.6

e. Medical Device Interfaces maintain prior operational capabilities

The Contractor shall provide a demonstration for the genomic facility, validating the operational capabilities.

The Contractor shall document test results in the Monthly Progress Reports.

1.13.2 REPORTING AND ANALYTICS AT ADDED GENOMIC FACILITY

The Contractor shall perform all tasks in the Section 5.6 and it’s sub-sections for the added genomic facility.

GENERAL REQUIREMENTS

1.14 ENTERPRISE AND IT FRAMEWORK

1.14.1 ONE-VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (One-VA TRM). One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and Design (ASD) has overall responsibility for the One-VA TRM.

1.14.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the OMB Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at: https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems. https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

1.14.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance (http://csrc.nist.gov/publications/PubsSPs.html) shall be included…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.