36C10B25Q0155_CrestPoint EMS Dashboard_Final.docx

DOCX document 359 KB Posted

Attached to
DA01--VISN 8 EMS Operations Efficiency Dashboard (VA-25-00024839) Federal contract opportunity
Solicitation number
36C10B25Q0155
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document is a Request for Quote (RFQ) for the Department of Veterans Affairs Technology Acquisition Center, solicitation number 36C10B25Q0155, seeking renewal of the CrestPoint Solutions Environmental Management Operations Efficiency Dashboard for VISN 8. The procurement covers 80 software licenses across 8 facilities, focusing on managing and monitoring Environmental Management Services (EMS) operations, including areas such as sanitation, textile management, groundskeeping, waste management, pest control, inspections, and budget management.

The contract is structured as a firm-fixed-price, 12-month base period with two 12-month option periods, with a total potential duration of 3 years. The system must provide 99.0% availability, comprehensive technical support, and comply with FedRAMP Moderate Authorization requirements. Key deliverables include a System Security Plan, implementation diagram, third-party security assessments, and user training. The solicitation is set aside for Service-Disabled Veteran-Owned Small Businesses (SDVOSB), with a total value not explicitly stated but encompassing software licenses, maintenance, technical support, and training across VISN 8's healthcare facilities.

View the file

Other files for this federal contract opportunity

Other files attached to DA01--VISN 8 EMS Operations Efficiency Dashboard (VA-25-00024839), newest first.
File Type Posted
JA_VISN 8 EMS Dashboard_Redacted.pdf PDF
36C10B25Q0155.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

VISN 8 EMS Dashboard 36C10B25Q0155

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

VA-25-00024839

05-14-2025 Amanda Anderson, Contract Specialist 848-377-5329 05-21-2025 10:00

EDT

Department of Veterans Affairs Technology Acquisition Center

23 Christopher Way Eatontown NJ 07724

X

541519 150 Employees

N/A

See Delivery Schedule

Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724

Department of Veterans Affairs Technology Acquisition Center Financial Services Center PO Box 149971 Austin TX 78714-8971

CrestPoint EMS Software Maintenance and Technical Support

See B.1 Schedule of Supplies/Services

Points of Contact:

Amanda Anderson/amanda.anderson12@va.gov

Contract Specialist

Kathryn Pantages/Kathryn.pantages@va.gov Contracting Officer

Kathryn Pantages Contracting Officer

Table of Contents

SECTION A……………………………………………………………………………………………….1

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES…………………………………………...………………….1

SECTION B - CONTINUATION OF SF 1449 BLOCKS4
B.1 GOVERNING LAW4
B.2 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT4
B.3 CONTRACT ADMINISTRATION DATA7
B.4 PRICE SCHEDULE8
B.5 PRODUCT DESCRIPTION13
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE26
SECTION C - CONTRACT CLAUSES35
C.1 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)35
C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (JAN 2025)35
C.3 52.217-7 OPTION FOR INCREASED QUANTITY-SEPARATELY PRICED LINE ITEM (MAR 1989)44
C.4 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)44
C.5 52.227-19 COMMERCIAL COMPUTER SOFTWARE LICENSE (DEC 2007)44
C.6 VAAR 852.219-74 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED VETERAN-OWNED SMALL BUSINESSES (JAN 2023) (DEVIATION)45
C.7 VAAR 852.219-75 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—CERTIFICATE OF COMPLIANCE FOR SERVICES AND CONSTRUCTION (JAN 2023) (DEVIATION)48
C.8 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV 2018)50
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS52
SECTION E - SOLICITATION PROVISIONS53
E.1 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)53
E.2 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)53
E.3 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018)56
E.4 52.216-1 TYPE OF CONTRACT (APR 1984)57
E.5 52.233-2 SERVICE OF PROTEST (SEP 2006)57
E.6 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)58
E.7 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)58
E.8 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (MAY 2024)59
E.9 VETCERT VERIFICATION REQUIREMENT FOR SERVICE-DISABLED VETERAN OWNED SMALL BUSINESSES (SDVOSBs)77
E.10 QUOTE SUBMISSION INSTRUCTIONS77

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.2 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT

(1). Definitions.

a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

(2). Software License.

a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b) The Government may use the software in a networked environment.

c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.

(3). Software Maintenance and Technical Support.

a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers so as to cause the software to perform according to its specifications, documentation or demonstrated claims.

c) Any telephone support provided by Contractor shall be at no additional cost.

d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.ppirs.gov).

e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

(4). Disabling Software Code. The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

(5). Manuals and Publications. Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

B.3 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C10B

Department of Veterans Affairs
Technology Acquisition Center
23 Christopher Way
Eatontown NJ 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] Upon acceptance of deliverables in accordance with B.4 Price Schedule

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

B.4 PRICE SCHEDULE

NOTE: All days are calendar unless otherwise noted.

FOB: Destination

BASE PERIOD

The Period of Performance shall be up to 12 months.

Any resulting contract will be awarded on a firm-fixed-price basis as defined by Federal Acquisition Regulation Subpart 16.202. Accordingly, the Contractor shall ensure that any and all costs associated with the Contractor’s proposed application(s), software products, software solution, and/or system, shall be included in the Contractor’s proposed firm-fixed price, and shall serve as the Contractor’s firm-fixed price for the life of any resulting contract. No additional costs or fees relative to the Contractor’s proposed application(s), software products, software solution, and/or system including, but not limited to, licensing costs and any associated licensing maintenance required for the development, delivery, integration, operation, and/or maintenance of the Contractor’s proposed solution will be allowed, accepted, and/or paid by the Government. Software shall be delivered within five business day of award.

Contract Line Item Number (CLIN)
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
0001
FedRAMP approval for CrestPoint EMS Operation Efficiency Dashboard System

PSC: DA01

LO
1
Not Separately Priced (NSP)
NSP
0001AA
FedRAMP System Security Plan (SSP) and supporting documentation.

Due 75 calendar days after contract award.

PSC: DA01

*10% of the FedRAMP Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.

LO
1
*$
*$
0001AB
VA Implementation Diagram:

VA specific architecture diagram demonstrating proposed implementation of the system at VA.

Due 10 calendar days after contract award.

PSC: DA01

LO
1
NSP
NSP
0001AC
Third Party Assessment Organization (3PAO) Security Assessment Plan (SAP)

Due 90 calendar days after the SSP is accepted by VA.

PSC: DA01

*10% of the FedRAMP Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.

LO
1
*$
*$
0001AD
3PAO Security Assessment Report (SAR)

Due 90 calendar days after contract award.

PSC: DA01

*10% of the FedRAMP Approved Solution value. VA does not pay for FedRAMP Authorization fees and/or vendor acquired costs.

LO
1
*$
*$
BASE PERIOD TOTAL
$

BASE PERIOD OPTIONAL TASK ONE

In accordance with FAR 52.217-7, “Option for Increased Quantity-Separately Priced Line Item,” Optional Tasks may be exercised one time during the base period of performance once solution is FedRAMP Authorized and VA FedRAMP Authorized. If exercised, the Period of Performance shall be 12 months. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

CLIN
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
0004
FedRAMP Moderate Approved EMS Operation Efficiency Dashboard System Service and Maintenance Support for 8 sites within VISN 8 in accordance with (IAW) the Product Description sections 1.0 and 2.1 through 2.5.

PSC: DA01

*70% of FedRAMP Moderate approved solution

Period of Performance: 12 months

EA
80
*$
*$
0005
Training shall be IAW PD section 2.6.

PSC: DA01

EA
8
$
$

BASE PERIOD OPTIONAL TASK TWO

Optional Tasks may be exercised at any time and from time to time during the base period of performance in accordance with FAR 52.217-7 Option for Increased Quantity-Separately Priced Line Item. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

0006
Site Visits (1 per site) shall be IAW PD section 2.7.

PSC: DA01

EA
8
$
$

OPTION PERIOD ONE

This 12-month option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term on the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, Option Period One shall begin immediately after expiration of the Base Period.

CLIN
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
1001
EMS Operation Efficiency Dashboard System Service and Maintenance Support for 8 sites within VISN 8 in accordance with (IAW) the Product Description sections 1.0 and 2.1 through 2.5.

Period of Performance: 12 months

EA
80
$
$
1001AA
Plan of Action and Milestones Monthly Reports IAW PD Section 2.8.

Due monthly

PSC: DA01

LO
1
NSP
NSP
1002
Training shall be IAW PD section 2.6.

PSC: DA01

EA
8
$
$
OPTION PERIOD ONE TOTAL
$

OPTION PERIOD ONE OPTIONAL TASK

Optional Tasks may be exercised at any time and from time to time during the base period of performance in accordance with FAR 52.217-7 Option for Increased Quantity-Separately Priced Line Item. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

CLIN
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
1003
Site Visits (1 per site) shall be IAW PD section 2.7.

PSC: DA01

EA
8
$
$

OPTION PERIOD TWO

This 12-month option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term on the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, Option Period Two shall begin immediately after expiration of Option Period One.

CLIN
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
2001
EMS Operation Efficiency Dashboard System Service and Maintenance Support for 8 sites within VISN 8 in accordance with (IAW) the Product Description sections 1.0 and 2.1 through 2.5.

Period of Performance: 12 months

PSC: DA01

EA
80
$
$
2001AA
Plan of Action and Milestones Monthly Reports IAW PD Section 2.8.

Due monthly

PSC: DA01

LO
1
NSP
NSP
2002
Training shall be IAW PD section 2.6.

PSC: DA01

EA
8
$
$
OPTION PERIOD TWO TOTAL
$

OPTION PERIOD TWO OPTIONAL TASK

Optional Tasks may be exercised at any time and from time to time during the base period of performance in accordance with FAR 52.217-7 Option for Increased Quantity-Separately Priced Line Item. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

CLIN
DESCRIPTION OF SERVICES
UNIT
QTY
UNIT PRICE
TOTAL PRICE
2003
Site Visits (1 per site) shall be IAW PD section 2.7.

PSC: DA01

EA
8
$
$

B.5 PRODUCT DESCRIPTION

PRODUCT DESCRIPTION (PD)

DEPARTMENT OF VETERANS AFFAIRS

Bay Pines Veterans Affairs Medical Center

VISN 8

Maintenance and Support for VISN 8 EMS Dashboard Operations System

Date: 27 March 2025

VA-25-00024839

Version Number: 1.0

1.0 PRODUCT REQUIREMENTS

The Department of Veterans Affairs (VA), Veterans Health Administration (VHA), Sunshine Healthcare Veteran Integrated Service Network 8 (VISN 8) requires renewal of CrestPoint Solutions Environmental Management Operations Efficiency Dashboard to allow VA employees oversight necessary to manage and monitor Environmental Management Services (EMS) operations in a consolidated approach for the following EMS Scopes of Service:

Description
Part Number
Quantity
Sanitation
CrestPoint
10
Linen/Laundry
CrestPoint
10
Groundskeeping
CrestPoint
10
Waste Management
CrestPoint
10
Pest Control
CrestPoint
10
Inspections
CrestPoint
10
Cost/Budget Management
CrestPoint
10
Bed Turnover Solutions
CrestPoint
10

The required CrestPoint Solutions Environmental Management Operations Efficiency Dashboard shall comply with FedRAMP and VA Authorizations in accordance with section 2.8 prior to use by VA.

2.0 SCOPE OF WORK

2.1 SYSTEM ADMINISTRATION

a. The Contractor shall provide all maintenance and support services to ensure the EMS Dashboard Operations system has availability at least 99.0% of the time 24 hours per day, 365 days per year. “System availability” shall not include any minutes of downtime resulting from:

i. Scheduled maintenance pre-approved by the VA

ii. Events of force

iii. Malicious attacks on the system

iv. Issues associated with VA’s computing devices, local area networks, or internet service provider connections.

v. Contractor’s inability to delivery services because of VA’s acts or omissions.

b. All new software versions shall be covered in the maintenance services, including all subsequent versions designed to replace the version installed under this contract.

c. Maintenance and systems support (Tier II Help Desk) shall be provided during the entire period of performance, including options, if exercised.

d. The Contractor shall distribute maintenance notification updates or releases by using an electronic or printed media to the POC.

e. Sixty (60) days prior to the expiration of each contract period, Contractor shall validate that the system’s user information for inspectors and users is accurate as of that date. Contractor shall:

i. Compile a list of valid users and delete users that no longer have a valid email address

ii. Coordinate the list with the POC

iii. Update the coordinated list and that number is used to true-up the number of users utilized for computation of any license for the upcoming option year of the contract.

2.2 EMERGENCY OPERATIONS

The Contractor shall possess, keep current, test disaster recovery and failover capabilities to mitigate the occurrence of hardware and software failure, power outages, and disruptions that may be caused by natural occurrence (such as hurricanes, tornadoes, earthquakes, etc.). Contractor shall provide remote location system rollover function of the system and backup of all software and data.

2.3 HELP DESK SUPPORT

The Contractor shall provide Tier II (Advanced) Help Desk support to government uses, of all aspects of the service purchased under this contract. Contractor shall provide Tier II Help Desk support via phone, email and/or chat accessible for government users from Monday through Friday between the hours of 8:00 AM Eastern Time and 8:00 PM Eastern Time, excluding federal holidays. Help Desk support shall be available 24/7 during times of National Crisis either man-made or natural to support the National Response Framework Plan.

2.4 LICENSES

The Contractor shall provide licenses to 10 users per department per medical center in VISN 8 to access the system. The Contractor shall include unlimited, non-exclusive software and interface site licenses for all products/services to include license and training for individual facilities defined by the Government.

2.5 UPGRADES AND ENHANCEMENTS TO SOFTWARE

The Contractor shall update all software and supporting electronic literature and software updates as implemented, limited the days and times the system is not available for use by scheduling updates during non-working days and hours as feasible.

Within 30 days after release, the Contractor shall provide the latest upgrades/version changes/updates, enhancements, and corrections to the system. Updates/version changes are defined as software improvements to the already existing software. The Contractor shall provide updates that are:

a. Initiated by the software publisher to improve functionality of the EMS Dashboard Operations system.

b. Required to maintain the EMS Dashboard Operations system compliant with new regulatory requirements.

2.6 USER TRAINING

The Contractor shall provide in-person and on-line web-based technical, end-user training on the use and operations of the software. Final dates and times for all training for each location shall be agreed upon between the Contractor and the Point of Contact (POC).

a. New User and Refresher Training

i. In-person training. The Contractor shall provide new user training once per year per facility. Classes shall each be approximately one (1) day in length or a portion thereof. Breaks shall be scheduled every two (2) hours and a lunch break must be incorporated into the schedule. Government will provide the final number of personnel to be trained to the Contractor a month before scheduled training.

ii. Online based training. The Contractor shall provide a minimum of one (1) instructor to provide training to users, for each facility. Classes shall each be approximately one (1) day in length or a portion thereof. Breaks shall be scheduled every two (2) hours and a lunch break must be incorporated into the schedule. Total number of users to be retrained is determined by how many licenses are acquired. Government will provide the final number of personnel to be trained to the Contractor a month before scheduled training.

iii. Objectives for user training. The following are minimum topics to be covered during training. Contractor shall provide training sufficient for users to utilize the system in the performance of their jobs. As a minimum, after training users shall be able to demonstrate proficiency in:

1. Completion of relevant unit level forms.

2. Entering inspection findings.

3. Generating different reports.

4. Managing unit level spending and budget controls.

iv. The Contractor shall evaluate the proficiency of students by requiring each student to demonstrate standard practical system functions. Students identified as requiring remedial instruction shall be provided one-on-one instruction in areas where a weakness was demonstrated. At Contractor’s option the instruction may be face-to-face, via the web or other method to address the weakness.

Each location will provide a training room for students with computers capable of accessing the web. To not delay training, the Contractor shall coordinate with the POC to test each training center’s computer access to the EMS Software System before class begins.

2.7 SITE VISIT (OPTIONAL TASK)

If exercised, the Contractor shall conduct one in-person site-visit training at each location per year. The Contractor shall provide a certified CrestPoint EMS Software Specialist to visit each site and collaborate with current users to address any areas of concern or training needs they have. To ensure all CrestPoint EMS Software users in VISN 8 are efficient and in compliance with VA regulations.

2.8 FedRAMP Authorization and VA Authorization:

1. The information system solution selected by the Contractor shall comply with the Federal Information Security Management Act (FISMA).

2. The Contractor shall comply with FedRAMP requirements Moderate as mandated by Federal laws and policies, including making available any documentation, physical access, and logical access needed to support this requirement.

3. The Contractor shall provide a SaaS product as defined by the following criteria: Software as a Service (SaaS) is an application delivery model in which the application is hosted on a cloud infrastructure outside the security boundary of VA and is provided to the Cloud Service Customer (CSC) over the internet. The CSC uses the SaaS offering via a thin-client interface, such as a web-browser or a program interface. The CSC subscribes to the SaaS offering and is only responsible for minor in-app customizations. The Cloud Service Provider (CSP) offering the application is responsible for management of the application, safeguarding of data stored or processed by the application, and all elements of the underlying infrastructure. Additionally, the CSP is responsible for all on-going compliance.

In order to qualify as SaaS for use at VA, and to align with Federal Risk and Authorization Management Program (FedRAMP) requirements, the hosting for the offering must conform to the NIST 800-145 definition of Cloud Computing and thus contain following key characteristics:

• On-Demand Self-Service: The CSP fully automates the provisioning of both the customer interface and the underlying cloud components of the SaaS offering. In some cases, to the CSP may provision internal resources manually, while providing the CSC an automated interface to request and track the service.

• Broad Network Access: The SaaS capabilities are available over the internet or over a network that is available from all access points the CSC requires. The SaaS offering is accessible through common platforms (e.g., mobile phones, tablets, laptops, and workstations).

• Resource Pooling: The computing infrastructure supporting the SaaS offering is shared among more than one CSC using a multi-tenant model, and resources are dynamically assigned depending on customer demand.

• Rapid Elasticity: Computing capabilities are automatically provisioned and released in a manner that scales with customer demand. In some cases, the scaling of resources may not be fully automated, but it should be fast enough to support the needs of the CSC, which the CSC would have to define.

• Measured Service: Resource usage, such as storage, processing, bandwidth, and user activity are measured and reported on in a manner that is relevant to the SaaS offering.

4. Following guidance from the Federal CIO, VA will utilize existing JAB ATO or agency ATO issued by another agency as a starting point for FedRAMP requirements. If neither of those exist, VA will sponsor The Cloud Service Provider for a FedRAMP Authorization. VA will be using the FedRAMP baselines as a starting point, since they are specifically tailored for cloud services.

5. The Contractor shall, where applicable, assist with the VA ATO Process to help achieve agency authorization of the cloud service or migrated application at the impact level required by VA to utilize the product. For this solution the required impact level is: Moderate

6. The Contractor shall comply with FedRAMP requirements surrounding data location within the Continental United States. FedRAMP specifies data location requirements in the High Baseline as part of control SA-9 (5); however, FedRAMP does not provide or specify data location requirements for other baselines.

7. The Contractor shall complete a FedRAMP System Security Plan (SSP) and supporting documentation including required attachments within 75 calendar days after contract award.

8. The Contractor shall work with a VA Subject Matter Expert to develop a specific system boundary diagram including any integration and connectivity components for VA use. This will be known as the VA Implementation Diagram (VAID) and will demonstrate the proposed implementation of this system at VA. The Contractor shall complete this deliverable with VA within 10 calendar days of contract award.

9. The Contractor shall complete a Third-Party Assessment Organization (3PAO) Security Assessment Plan (SAP) within 90 calendar days after contract award.

10. The Contractor shall complete a 3PAO Security Assessment Report (SAR) within 90 calendar days after the SSP is accepted by VA.

11. The Contractor shall work with VA Subject Matter Experts to test the validity of the Incident Response Plan (IRP) and ensure proper troubleshooting of issues that may arise. This should be completed within 30 calendar days of the SSP being delivered.

12. The Contractor shall afford VA access to the Contractor’s and Cloud Service Provider’s (CSP) facilities, installations, technical capabilities, operations, documentation, records, and databases.

13. If new or unanticipated vulnerabilities are discovered by either VA or the Contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party in accordance with Addendum B, VA Information, and Information System Security/Privacy Language.

14. The Contractor shall comply with data management requirements.

15. Successful issuance of a VA ATO will be required before live VA data can be used in the system.

16. The Contractor shall participate in FedRAMP Continuous Monitoring activities as outlined by FedRAMP’s Continuous Monitoring Strategy Guide found on the FedRAMP website.

17. The Contractor shall participate in monthly Agency and FedRAMP Sustainment meetings following the granting of a VA ATO.

18. The Contractor shall provide continuous monitoring activities including, but not limited to scans, security artifacts, and monthly Plan of Action and Milestones (POAM) reports as outlined by VA and FedRAMP requirements.

Deliverables:

A. FedRAMP System Security Plan (SSP) and required Attachments B. VA Implementation Diagram C. 3PAO Security Assessment Plan (SAP) D. 3PAO Security Assessment Report (SAR) E. Plan of Action and Milestones Monthly Reports.

2.9 PERFORMANCE PERIOD

The Period of Performance (PoP) shall be a 12-month base period with two 12-month option periods, if exercised.

2.10 PLACE OF PERFORMANCE

1. Bay Pines VA Healthcare System 10,000 Bay Pines Blvd Bay Pines, FL 33744

2. Miami VA Healthcare System 1201 N.W. 16th Street Miami, FL 33125

3. James A. Haley Veterans Hospital/Tampa VAMC 13000 Bruce B. Downs Blvd Tampa, FL 33612

4. North Florida/South Georgia VA Healthcare System (2 sites) 1601 SW Archer Road Gainesville, FL 32608

5. Orlando VAMC 13800 Veterans Way Orlando, FL 32827

6. VA Caribbean Healthcare System 10 Casia Street San Juan, PR 00921-32

7. West Palm Beach VA Healthcare System 7305 North Military Trail West Palm Beach, FL 33410

3.0 NOTICE OF THE FEDERAL ACCESSIBILITY LAW AFFECTING ALL INFORMATION AND COMMUNICATION TECHNOLOGY (ICT) PROCUREMENTS (SECTION 508)

On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.

3.1 SECTION 508 – INFORMATION AND COMMUNICATION TECHNOLOGY (ICT) STANDARDS

The Section 508 standards established by the Access Board are incorporated into, and made part of all VA orders, solicitations and purchase orders developed to procure ICT. These standards are found in their entirety at: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. A printed copy of the standards will be supplied upon request.

Federal agencies must comply with the updated Section 508 Standards beginning on January 18, 2018. The Final Rule as published in the Federal Register is available from the Access Board: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule.

The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:

☒ E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines) ☒ E204 Functional Performance Criteria ☐ E206 Hardware Requirements ☒ E207 Software Requirements ☒ E208 Support Documentation and Services Requirements

3.2 COMPATABILITY WITH ASSISTIVE TECHNOLOGY

The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.

3.3 ACCEPTANCE AND ACCEPTANCE TESTING

Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.

The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.

The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.

4.0 INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS

The Contractor shall comply with Sections 524 and Sections 525 of the Energy Independence and Security Act of 2007; Section 104 of the Energy Policy Act of 2005; Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018; Executive Order 13221, “Energy-Efficient Standby Power Devices,” dated August 2, 2001; and the Federal Acquisition Regulation (FAR) to provide ENERGY STAR®, Federal Energy Management Program (FEMP) designated, low standby power, and Electronic Product Environmental Assessment Tool (EPEAT) registered products in providing information technology products and/or services.

4.1 EPEAT

EPEAT product compliance is not required in this acquisition.

4.2 ENERGY STAR

Energy Star compliance is not required in this acquisition.

4.3 FEMP

FEMP or FEMP low standby power product compliance is not required in this acquisition.

5.0 GENERAL REQUIREMENTS

5.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

5.2 SOCIAL SECURITY NUMBER (SSN) REDUCTION

The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the Integrated Control Number (ICN) in all VA information systems for all individuals. The Contractor shall ensure that all Contractor delivered applications and systems integrate with the VA Master Person Index (MPI) for identity traits to include the use of the ICN as the Primary Identifier. The Contractor solution may only use a Social Security Number to identify an individual in an information system if and only if the use of such number is required to obtain information VA requires from an information system that is not under the jurisdiction of VA.

5.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

5.4 SOFTWARE AND LICENSING REQUIREMENTS

The Contractor shall be responsible for the provision of all software licenses and any associated licensing maintenance required for any development, delivery, integration, operation, and/or maintenance associated with its proposed application(s), software products, software solution, and/or system including, but not limited to, any and all application(s), software and/or software products that comprise, are a part of, or integrate with the Contractor’s proposed application(s), software products, software solution, and/or system for the life of any resulting contract.

6.0 POINTS OF CONTACT

VA Program Manager:

Name:Abdoulie Jammeh
Address:10000 Bay Pines Blvd
Bay Pines, FL 33744
Voice:727-398-6661 EXT 14531
Email:Abdoulie.jammeh@va.gov

Contracting Officer:

Name:Kathryn Pantages
Address:23 Christopher Way
Eatontown, NJ 00724
Voice:848-377-5039
Email:Kathryn.pantages@va.gov

Contract Specialist:

Name:Amanda Anderson
Address:23 Christopher Way
Eatontown, NJ 00724
Voice:848-377-5329
Email:Amanda.anderson12@va.gov

7.0 INFORMATION SECURITY CONSIDERATIONS

The Assessment and Authorization (A&A) requirements do not apply and a Security Accreditation Package is not required.

All VA sensitive information shall be protected at all times in accordance with local security field office System Security Plans (SSP’s) and Authority to Operate (ATO)’s for all systems/LAN’s accessed while performing the tasks detailed in this Product Description.

a. A prohibition on unauthorized disclosure: “Information made available to the Contractor or Subcontractor by VA for the performance or administration of this contract or information developed by the Contractor/Subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA.”

b. A requirement for data breach notification: Upon discovery of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the Contractor/Subcontractor has access, the Contractor/Subcontractor shall immediately notify the COR and simultaneously, the designated ISO, and Privacy Officer for the contract. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. See VA Handbook 6500.6, Appendix C, paragraph 6.a.

c. A requirement to pay liquidated damages in the event of a data breach: “In the event of a data breach or privacy incident involving SPI the contractor processes or maintains under this contract, the contractor shall be liable to VA for liquidated damages for a specified amount per affected individual to cover the cost of providing credit protection services to those individuals.” However, it is the policy of VA to forgo collection of liquidated damages in the event the Contractor provides payment of actual damages in an amount determined to be adequate by the agency.

Based on the determinations of the independent risk analysis, the Contractor shall be responsible for paying to VA liquidated damages in the amount of $37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

1) Notification;

2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

3) Data breach analysis;

4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs

d. A requirement for annual security/privacy awareness training: “Before being granted access to VA information or information systems, all Contractor employees and Subcontractor employees requiring such access shall complete on an annual basis either: (i) the VA security/privacy awareness training (contains VA security/privacy requirements) within 1 week of the initiation of the contract, or (ii) security awareness training provided or arranged by the contractor that conforms to VA’s security/privacy requirements as delineated in the hard copy of the VA security awareness training provided to the Contractor. If the Contractor provides their own training that conforms to VA’s requirements, they will provide the COR or CO, a yearly report (due annually on the date of the contract initiation) stating that all applicable employees involved in VA’s contract have received their annual security/privacy training that meets VA’s requirements and the total number of employees trained. See VA Handbook 6500.6, Appendix C, paragraph 9.

e. A requirement to sign VA’s Rules of Behavior: “Before being granted access to VA information or information systems, all Contractor employees and Subcontractor employees requiring such access shall sign on annual basis an acknowledgement that they have read, understand, and agree to abide by VA’s Contractor Rules of Behavior which is attached to this contract.” See VA Handbook 6500.6, Appendix C, paragraph 9, and Appendix D. Note: If a medical device vendor anticipates that the services under the contract will be performed by 10 or more individuals, the Contractor Rules of Behavior may be signed by the vendor’s designated representative. The contract must reflect by signing the Rules of Behavior on behalf of the vendor that the designated representative agrees to ensure that all such individuals review and understand the Contractor Rules of Behavior when accessing VA’s information and information systems.

ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE

B1. GENERAL

Contractors, Contractor personnel, Subcontractors, and Subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

B2. VA INFORMATION CUSTODIAL LANGUAGE

1. Information made available to the Contractor or Subcontractor by VA for the performance or administration of this contract or information developed by the Contractor/Subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of VA.

2. VA information should not be co-mingled, if possible, with any other data on the Contractors/Subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the Contractor must ensure that VA information is returned to VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of Contractor and Subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

3. Prior to termination or completion of this contract, Contractor/Subcontractor shall not destroy information received from VA,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .