FY25 HITC Presort Services PWS Performance Work Statement.draft.pdf
PDF 277 KB Posted
- Attached to
- HITC Presort Mail Services Federal contract opportunity
- Solicitation number
- 36C10X24Q0294
About this file
This document is a Performance Work Statement (PWS) for Presort Mail Services to be provided to the Department of Veterans Affairs (VA) Hines Information Technology Center (HITC) located in Hines, Illinois.
The PWS outlines the contractor responsibilities for picking up, barcoding, presorting, and delivering first-class mail generated by the HITC to the U.S. Postal Service. The contractor must use the HITC's Electronic Payment System account to pay postage and provide reports on daily and weekly mail processing activities. The contractor will also handle special projects involving large mail volumes around certain events. The contract will be for a one-year base period with four one-year option periods. All services must be provided at the HITC facility, and the contractor must comply with VA security and privacy requirements. The PWS includes specific performance standards and metrics that will be used to evaluate the contractor's performance.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Source Sought Notice_HITC Mail Presort Services.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
DEPARTMENT OF VETERANS AFFAIRS
OFFICE OF INFORMATION TECHNOLOGY
HINES INFORMATION TECHNOLOGY CENTER (HITC)
PRESORT MAIL SERVICES
1.0 BACKGROUND
The Department of Veterans Affairs, Information Technology Center (ITC), Hines, Illinois currently generates an estimated ten (10) million pieces of computer generated, first-class mail each year. These letters (domestic and international) are printed, folded, and inserted into Government permit imprinted envelopes and mailed worldwide. Outgoing mail is inserted into mail trays at the Hines ITC.
2.0 SCOPE OF WORK
The Contractor shall pick up, store, and deliver letters to a United States Post Office (USPS) facility. The Contractor is responsible to presort all first-class mail to achieve the best postage discount possible. Additionally, the Contractor will provide Hines ITC with services for completing the required permit report (PS 3600-R), barcoding each letter with the appropriate Zip+4+2, and presorting Hines ITC mail. Contractor must be able to use a Postal Service Enterprise Payment System (EPS) account to pay postage for domestic mail. An EPS account will be set up with appropriate Post Office to deduct daily postage. Hines will provide postage funds directly to the contractor within CLIN 2 “Postage for Letters with no Permit Indicia.”
3.0 SPECIFIC TASKS / REQUIREMENTS
The Contractor shall comply with all automation compatible mail requirements contained in Chapter 5 of the domestic Mail Manual (available through USPS). The Contractor shall be subject to all governing regulations and other requirements of the USPS and laws affecting the processing of official Government mail. New rules, regulations, directives, and requirements issued during this contract’s terms shall apply to the Contractor as they are issued, and the PWS will be amended as this occurs.
Computer generated output is processed in daily, weekly, monthly, and yearly cycles. As a result, the volume of output on a daily, weekly, monthly and yearly basis varies. Output is released to the Contractor the same day it is to be released to the USPS. The estimated average mail processed daily varies from a low of 10,000 letters to a high of more than 50,000 letters.
During peak workload periods, i.e. November through February (3.4 Special Projects), the
Hines ITC may process more than 100,000 letters daily.
3.1 PICKUP
3.1.1 The Hines ITC normally processes computer generated letters 24 hours a day, five (5) days per week, Monday through Friday. The Contractor shall pick up letters in mail trays a minimum of once per day for barcoding, presorting, and delivery to the USPS. The Contractor shall be responsible for shrink-wrapping the pallets of trays at the time of pickup. The daily pickup shall be no earlier than 10:00 AM Monday through Friday and on Saturday as requested and scheduled 24 hours in advance by VA. This schedule may require a maximum of one (1) additional daily pickup. This additional daily pickup on Saturday will be done on an as needed basis as requested by Hines ITC 24 hours in advance. The maximum allowable pick-up on Saturday is one.
3.1.2 Pickups will be made at the staging area in the mailroom, Room 132, Building 215, located at First Avenue North of Cermak Road (22nd Street), Hines, Illinois 60141.
3.1.3 The Hines ITC designated Contracting Officer’s Representative (COR) will be provided with the schedule for pickup. Changes to the regularly scheduled pickup time will be coordinated and agreed upon by both the COR and Contractor. The Contractor will be notified in advance of any peak workload periods. Additionally, at the request of the Hines ITC, the Contractor shall provide special pickups of mail, in varying amounts, in addition to scheduled pickups.
3.2 SORTING
3.2.1 All mail will be separated into two categories of weight1 (mail up to two ounce and mail over two ounce) and into two categories of destination2 (domestic and foreign) and given to the Contractor as it is processed. The Contractor will release the mail in accordance with the date, destination (domestic/foreign) and weight specified and separated by the Hines ITC. Hines ITC mail shall be commingled with mail from other customers of the Contractor to ensure that Hines ITC mail receives the highest postage discounts possible.
3.2.2 Contractor must presort and meter flats (large envelopes and small cartons).
3.3 BARCODING
3.3.1 All mail shall be processed and sprayed with a barcode representing the 'Zip+4+2' zip code.
Presorted and released to the US Post Office on the same day released from Hines ITC. The bar coded 'Zip+4+2' zip code is to be correct for the street, city and state add ress. The Contractor shall ensure that the final barcoded and presorted mail product will be in accordance with the most recent USPS requirements in effect.
3.3.2 Contractor must provide National Change of Address (NCOA) address correction to comply with USPS "move update" requirements.
3.3.3 As is required when permit imprinted envelopes are used for mailing, the Contractor will provide the USPS with the Statement of Mailing with Permit Imprint First-Class Mail PS 3600-R report. The required report for permit mailing (Statement of Mailing with Permit Imprint First- Class Mail, PS 3600-R) must be prepared and submitted to the USPS with the mail.
3.4 INTERNATIONAL
3.4.1 Mail with delivery addresses in Philippines is produced daily. The Contractor is required to handle this mail, pay postage, and invoice VA separately from the EPS account.
1 Less than 5% of this Center's mail is over two ounces in weight.
2 Less than 1% of this Center's mail is foreign.
3.4.2 Mail with delivery addresses in Canada and International delivery addresses is to be handled by the Contractor daily. It is expected that this mail will be presorted and commingled with other customers’ mail to achieve the best postage discount available.
3.5 SPECIAL PROJECTS
In addition to the recurring daily/weekly/monthly scheduled letters processing, the Hines ITC also processes numerous computer-generated "special projects" that are released monthly. The volumes and times for these special projects are sometimes unknown until two (2) weeks prior to the processing date. Some special projects of this type which are currently known include:
3.5.1 Once a year - Cost of Living Adjustment (COLA) - Approximately 700,000 (approximately 6,000 of these are foreign) letters are generally released in December
3.5.2 Once or twice a year - Basic Allowance Housing (BAH) - Estimated volume 400,000
3.5.3 Once or twice a year – First Class Certificate of Bulk Mailing receipt
3.6 STORAGE
3.6.1 Letters processed are generally not stored prior to release for mailing. Occasionally a project may be prepared one to three days ahead of the scheduled release date and must be temporarily stored in a controlled area until the scheduled release date. Access to this area must be restricted in a lock up space with full floor to ceiling walls per VA 0730 physical security manual.
The site should be inspected by VA physical security specialist prior to them storing any PII.
Contractor will be notified in the event of a deferred schedule release and mail trays will be labeled with the required mail date.
3.6.2 When necessary, the Contractor will be responsible for the secure storage of all mail prior to its release date, unless otherwise specified.
3.7 GOVERNMENT RESPONSIBILITY
3.7.1 Currently the Hines ITC has an Electronic Payment System (EPS) account to pay postage with the Palatine Post Office for permit mail. This EPS account will be used to pay postage with the awardee’s designated Post Office for permit mail.
3.8 CONTRACTOR RESPONSIBILITY
3.8.1 The Contractor will be responsible for all coordination necessary with USPS.
3.8.2 The Contractor shall return all letters mutilated by their equipment or employees within 24 hours of mutilation. Anything damaged that cannot be mailed should be returned in its entirety .
Additionally, the Contractor will notify the COR and identify any letters that are mutilated .
Damaged packages being returned to VA should be repackaged to ensure no PII is lost or disclosed further. The Contractor must return this damaged mail unopened to the COR on the next pickup of mail from the Hines ITC for reprocessing without additional co st to the VA.
Final destruction for damaged mail items will be carried out by VA employees.
3.8.6 On occasion the Hines ITC has experienced blank envelopes or letters without the address showing through the window being sent to the Contractor for barcoding and presorting. These envelopes will reject since an address will not be readable. The Contractor must return this rejected mail unopened to the COR on the next pickup of mail from the Hines ITC for reprocessing without additional cost to the VA.
3.8.7 Hines ITC mail contains personal Identifiable Information that must be protected from unauthorized disclosure. Contractor site must be secure to prevent unauthorized individuals from access to the Hines ITC mail. Any lost or stolen mail must be reported to the COR as soon as it is known. The number of letters missing must be reported , as well as a full investigative summary of the circumstances surrounding the loss and a plan for corrective action for prevention.
3.6 CONTRACTOR PERSONNEL
3.6.1 Contractors, Contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
3.6.2 The Contractor will be responsible for ensuring compliance by its employees with the security regulations of VA, VACO and other Government installations or Contractor facilities where work is performed under this Contract. This includes the safekeeping and display of a
Government-provided photo ID badge for employees of the Contractor and any subcontractors while these employees are in federally owned or leased property as described in Section 21, Place of Performance. The Contractor will ensure the security of all VA and VHA property, building ID badges, key cards and standard keys issued to Contractor staff. For employees leaving the project permanently or for an extended period, the Contractor will return all badges, property, key cards, parking placards, and keys, etc. the same day the employees leave the project.
3.6.3 The Contractor's employees shall always wear visible identification while on the premises of the Hines ITC. It is the responsibility of the Contractor to park in the appropriate designated parking areas. Information on parking is available from the ITC Security staff at (708) 483- 5911. The Hines ITC will not invalidate or make reimbursement for parking violations of the Contractor under any conditions. Smoking is prohibited outside of the designated areas on the
Hines ITC campus. Possession of weapons is prohibited. Enclosed containers, including tool kits, shall be subject to search. Violations of VA regulations may result in citation answerable in the United States (Federal) District Court. Not a local district, state, or municipal court.
3.6.4 KEY PERSONNEL
3.6.4.1 These are skilled and experienced professional personnel that are essential for successful Contractor accomplishment of the work to be performed for this requirement. The Contractor shall identify individuals such as the Program Manager, Executive Assistant, Supervisor, and others who have access to unsealed, opened, and damaged mail.
3.6.4.2 The Contractor shall provide a primary Point of Contact (POC) who shall be responsible for the performance of the work. The POC, or alternate, shall have full authority to act for the
Contractor on all contract matters relating to daily operation of the anticipated task order. The POC, or alternate, shall be available between 8:00 a.m. to 4:30p.m., Monday through Friday.
except Federal holidays or when the Government facility is closed for administrative reasons.
The POC will be notified 24 hours in advanced if they will be needed on Saturday for special deliveries. This person and the alternate shall, always, report directly to the Contract Officer’s Representative throughout the performance period.
3.6.5 NON-KEY PERSONNEL
3.6.5.1 The non-key personnel, such as the driver for pickups of sealed mail, are interchangeable;
however, for security purposes the VA will require proof of identification for access to Government facilities.
3.6.5.2 Non-key personnel do not require the NACI background investigation. However, non-key personnel must be accompanied by key personnel when accessing VA facilities and handling Government property. Non-key personnel shall complete all required training and provide copies of certificates to the COR.
3.7 DELIVERABLES
3.7.1 On a weekly basis, the Contractor will provide the COR with a typed report to include the following information for the previous week's processing: a count of envelopes released, number of returned mutilated mail, cost and count of qualified and residual pieces and copies of PS 3600-R for each day within the period of the invoice.
3.7.2 The Contractor shall provide a daily Postage Report on the next business day after mail is delivered to the Post Office. This report will include a breakdown by postage cost and number of pieces for both under two ounce and over two ounce mail.
3.8 INSPECTION AND ACCEPTANCE
Final inspection and acceptance of all work performed will occur at the place of performance by the COR. Final approval and acceptance of documentation by the COR shall constitute acceptance.
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The period of performance for this requirement shall be one (1) 12-month base year and four (4) 12-month option years that may be exercised.
4.2 PLACE OF PERFORMANCE
All services shall be provided at the following:
Department of Veterans Affairs Hines Information Technology Center (HITC) 5000 South 5th Avenue Building 215
Hines, IL 60141-7001
4.3 HOURS OF OPERATION
The Contractor is responsible for conducting business, between the hours of 8:00 AM and 4:30
PM, CT Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. There may also be special pickups on Saturday as requested and scheduled 24 hours in advance by VA.
4.4 TRAVEL
The Government anticipates local travel in performance of the tasks associated with the effort.
These costs will not be reimbursed by the Government.
4.5 KICK-OFF MEETING
The Contractor may be required to attend a Kick-Off Meeting with the Contracting Officer (CO) and the COR no later than (NLT) 5 (five) business days after the date of award. The purpose of the Kick-Off Meeting is to discuss technical and contracting objectives of this purchase order. If required, the Kick-Off Meeting will be held via phone.
4.6 CONTRACTOR FURNISHED PROPERTY
The Contractor shall furnish all facilities, equipment, materials and labor required to meet the requirements of this contract which shall include, but is not limited to pick up, barcoding, presorting mail, and delivery to the Post Office. Contractor to provide mail trays and plastic wrap and to have equipment available to load and unload pallets (pallet jack). Permit mail report
(PS 3600-R), bar-coding and presort shall be in accordance with the latest United States Postal regulations and with the Domestic Mail Manual (DMM). All contract work shall be performed in Contractor-owned facilities.
4.7 INVOICING
4.7.1 The Contractor shall submit bimonthly (twice monthly) invoices, in arrears, for monies due. This invoice shall include a breakdown of cost and number of pieces, number of pieces not qualifying for a presort rate (residual, which will not exceed 3% of total volume), the cost for encoding, and any special services which will have been provided. Services billed the Hines ITC shall be specified by cost and number of pieces processed.
4.7.2 Contractor will be required to invoice postage for mail pieces sent to International to include Canadian and Philippian addresses to Hines ITC and not deduct them from the Hines ITC EPS account. No advanced payments will be allowed for this service.
4.7.3 The postage and presort fees for flats are to be invoiced to Hines ITC and not deducted from the Hines ITC EPS account.
4.7.4 The Contractor shall submit bimonthly (twice monthly) invoices for actual quantities of mail processed.
4.7.5 The Contractor shall not exceed the maximum estimated quantities stated for each specific Line Item, unless notified in advance for occasional high volume letter projects .
5.0 DELIVERABLES
DELIVERABLE EVENT DUE BY
4.5 Kick-Off Meeting NLT five (5) business days after the date of award
3.7.1 Previous Week's Processing Weekly
3.7.2 Daily Postage Report Next business day after mail is delivered
6.0 PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Performance Levels for Objectives associated with this effort. The Government will not exercise the next option year term unless all regulatory requirements are met, and the Contractor meets the acceptable performance definition.
PRS Standard Threshold Surveillance
Method Incentive
1. Pick up letters for barcoding, presorting and delivery to
USPS. PWS 3.1,
3.2, 3.3
Pick up mail a minimum of once per day;
mail delivery
No less than 90% of the picked-up mail processed same day; No more than 5 piece of mail lost per month.
Invoice verification, customer feedback, random facility inspection.
(+) Meet the acceptable performance definition as a condition for exercise of option (-) Does not meet the acceptable performance definition as a condition for exercise of an option
2. PRS 2:
Computer output is stored at the Contractor warehouse in
As released to the Contractor, in daily, weekly and monthly cycles
No less than 90% of the picked-up mail processed same day; No more
Invoice verification, customer feedback, (+) Meet the acceptable performance definition as a condition for
Mail Trays prior to its release.
PWS 3.6.1
than 5 piece of mail lost per month.
random facility inspection.
exercise of option (-) Does not meet the acceptable performance definition as a condition for
3. PRS 3: Mail with delivery addresses in
Philippines. The Contractor handles this mail, pays postage and invoices VA separately from the EPS account.
PWS 3.4.1
Process mail a mail a minimum of once per day.
No less than 90% of the picked-up mail processed same day; No more than 5 piece of mail lost per month.
Invoice verification, customer feedback, random facility inspection.
(+) Meet the acceptable performance definition as a condition for exercise of option
(-) Does not meet the acceptable performance definition as a condition for
4.PRS 4: Mail with delivery addresses in Canada and
International delivery addresses. The Contractor handles this mail in accordance with the proposed and approved system to achieve the best postage discount available. PWS 3.4.2
In accordance with the process approved at the time of the contract award.
No less than 90% of the picked-up mail processed same day; No more than 5 piece of mail lost per month.
Invoice verification, customer feedback, random facility inspection.
(+) Meet the acceptable performance definition as a condition for exercise of an option.
(-) Does not meet the acceptable performance definition as a condition for option.
5.PRS 5: Special Projects. Process Cost of Living Adjustment
(COLA) letters, Basic Allowance Housing letters, and occasional ad hoc high volume batch letters. PWS 3.5
Process mail as-needed, on the same day.
No less than 90% of the picked-up mail processed same day; No more than 5 piece of mail lost per month.
Invoice verification, customer feedback, random facility inspection.
(+) Meet the acceptable performance definition as a condition for exercise of an option (-) Does not meet the acceptable performance definition as a condition for
7.0 GENERAL REQUIREMENTS
7.1 POSITION/TASK RISK DESIGNATION LEVEL(S) AND CONTRACTOR
PERSONNEL SECURITY REQUIREMENTS
The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the Performance Work Statement is low.
Contractor employees handling Hines ITC mail and picking up mail at the Hines site may undergo a security clearance in the form of a basic background investigation.
Position Sensitivity and Background
Investigation Requirements Task Number
Low/NACI Moderate/MBI High/BI 3.1 3.2, 3.3
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the Contractor will be working. The submitted Contractor Staff Roster must indicate the required Background
Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
7.1.1 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
Contractor Responsibilities:
a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and can read, write, speak and understand the English language.
b. The Contractor shall bear the expense of obtaining background investigations.
c. Within three (3) business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations. The roster shall contain the Contractor’s Full Name, Full Social Security Number, Date of Birth, Place of Birth, and individual background investigation level requirement (based upon Section 6.2 Tasks).
d. The Contractor should coordinate the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized.
e. For a Low Risk designation the following forms are required to be completed: 1. OF-306 and
2. DVA Memorandum – Electronic Fingerprints. These should be submitted to the COR within 5 business days after award.
f. The Contractor personnel will receive an email notification from the Security and Investigation Center (SIC), through the Electronics Questionnaire for Investigations Processes (e-QIP) identifying the website link that includes detailed instructions regarding completion of the investigation documents (SF85, SF85P, or SF 86). The Contractor personnel shall submit all required information related to their background investigations utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP).
g. The Contractor is to certify and release the e-QIP document, print and sign the signature pages, and send them to the COR for electronic submission to the SIC. These should be submitted to the COR within three (3) business days of receipt of the e-QIP notification email.
h. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.
i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.
j. Failure to comply with the Contractor personnel security investigative requirements may result in termination of the contract for default.
7.2 FACILITY/RESOURCE PROVISIONS
The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact.
The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work. For detailed Security and Privacy Requirements refer to ADDENDUM A and
ADDENDUM B.
8.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
I. FIPS Pub 201, “Personal Identity Verification of Federal Employees and Contractors,”
March 2006 II. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
III. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964” IV. Department of Veterans Affairs (VA) Directive 0710, “Personnel Suitability and Security
Program,” May 18, 2007 V. An Introductory Resource Guide for Implementing the Health Insurance Portability and
Accountability Act (HIPAA) Security Rule, October 2008 VI. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the
Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998 VII. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
VIII. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
IX. VA Handbook 6500.2, “Management of Data Breaches Involving Sensitive Personal Information (SPI)”, January 6, 2012
X. VA Handbook 6500.6, “Contract Security,” March 12, 2010 XI. VA Directive 6508, VA Privacy Impact Assessment, October 3, 2008 XII. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
ADDENDUM A
A1. VA Enterprise Architecture Compliance
The applications, supplies, and services furnished under this contract must comply with One-VA Enterprise Architecture (EA), available at http://www.ea.oit.va.gov/index.asp in force at the time of issuance of this contract, including the Program Management Plan and VA's rules, standards, and guidelines in the Technical Reference Model/Standards Profile (TRMSP). VA reserves the right to assess contract deliverables for EA compliance prior to acceptance .
A1.1. VA Internet and Intranet Standards The Contractor shall adhere to and comply with VA Directive 6102 and VA Handbook 61 02, Internet/Intranet Services, including applicable amendments and changes, if the Contractor’s work includes managing, maintaining, establishing and presenting information on VA’s Internet/Intranet Service Sites. This pertains but is not limited to: creating announcements;
collecting information; databases to be accessed, graphics and links to external sites.
Internet/Intranet Services Directive 6102 is posted at (copy and paste the following URL to browser): http://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=409&FType=2 Internet/Intranet Services Handbook 6102 is posted at (copy and paste following URL to browser):
http://www1.va.gov/vapubs/viewPublication.asp?Pub_ID=410&FType=2
A2. Physical Security & Safety Requirements
The Contractor and their personnel shall follow all VA policies, standard operating procedures, applicable laws and regulations while on VA property. Violations of VA regulations and policies may result in citation and disciplinary measures for persons violating the law.
a) The Contractor and their personnel shall wear visible identification at all times while they are on the premises.
b) VA does not provide parking spaces at the work site; the Contractor must obtain parking at the work site if needed. It is the responsibility of the Contractor to park in the appropriate designated parking areas. VA will not invalidate or make reimbursement for parking violations of the
Contractor under any conditions.
c) Smoking is prohibited inside/outside any building other than the designated smoking areas.
d) Possession of weapons is prohibited.
e) The Contractor shall obtain all necessary licenses and/or permits required to perform the work, except for software licenses that need to be procured from a Contractor or Contractor in accordance with the requirements document. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of this contract.
A3. Confidentiality and Non-Disclosure
The Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations.
The Contractor may have access to Protected Health Information (PHI) and Electronic Protected Health Information (EPHI) that is subject to protection under the regulations issued by the
Department of Health and Human Services, as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA); 45 CFR Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45
CFR Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”). Pursuant to the Privacy and Security Rules, the Contractor must agree in writing to certain mandatory provisions regarding the use and disclosure of PHI and EPHI.
1. The Contractor may have access to some privileged and confidential materials of VA. These printed and electronic documents are for internal use only, are not to be copied or released without permission, and remain the sole property of VA. Some of these materials are protected by the Privacy Act of 1974 (revised by PL 93-5791) and Title 38. Unauthorized disclosure of
Privacy Act or Title 38 covered materials is a criminal offense.
2. The VA CO will be the sole authorized official to release in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this contract. The Contractor shall release no information. Any request for information relating to this contract presented to the Contractor shall be submitted to the VA CO for response.
3. Contractor personnel recognize that in the performance of this effort, Contractor personnel may receive or have access to sensitive information, including information provided on a proprietary basis by carriers, equipment manufacturers and other private or public entities.
Contractor personnel agree to safeguard such information and use the information exclusively in the performance of this contract. Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations as enumerated in this section and elsewhere in this Contract and its subparts and appendices.
4. Contractor shall limit access to the minimum number of personnel necessary f or contract performance for all information considered sensitive or proprietary in nature. If the Contractor is uncertain of the sensitivity of any information obtained during the performance this contract, the Contractor has a responsibility to ask the VA CO.
5. Contractor shall train all their employees involved in the performance of this contract on their roles and responsibilities for proper handling and nondisclosure of sensitive VA or prop rietary information. Contractor personnel shall not engage in any other action, venture or employment wherein sensitive information shall be used for the profit of any party other than those furnishing the information. The sensitive information transferred, generated, transmitted, or stored herein is for VA benefit and ownership alone.
6. Contractor shall maintain physical security at all facilities housing the activities performed under this contract, including any Contractor facilities according to VA-approved guidelines and directives. The Contractor shall ensure that security procedures are defined and enforced to ensure all personnel who are provided access to patient data must comply with published procedures to protect the privacy and confidentiality of such information as required by VA.
7. Contractor must adhere to the following:
a. The use of “thumb drives” or any other medium for transport of information is expressly prohibited.
b. Controlled access to system and security software and documentation.
c. Recording, monitoring, and control of passwords and privileges.
d. All terminated personnel are denied physical and electronic access to a ll data, program listings, data processing equipment and systems.
e. VA, as well as any Contractor (or Subcontractor) systems used to support development, provide the capability to cancel immediately all access privileges and authorizations upon employee termination.
f. Contractor PM and VA PM are informed within twenty-four (24) hours of any employee termination.
g. Acquisition sensitive information shall be marked "Acquisition Sensitive" and shall be handled as "For Official Use Only (FOUO)".
h. Contractor does not require access to classified data.
8. Regulatory standard of conduct governs all personnel directly and indirectly involved in procurements. All personnel engaged in procurement and related activities shall conduct business in a manner above reproach and, except as authorized by statute or regulation, with complete impartiality and with preferential treatment for none. The general rule is to strictly avoid any conflict of interest or even the appearance of a conflict of interest in VA/Contractor relationships.
ADDENDUM B
B1. GENERAL
Contractors, Contractor personnel, Subcontractors, and Subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
B2. SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The Contractor/Subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the Contractor/Subcontractor has access.
b. To the extent known by the Contractor/Subcontractor, the Contractor/Subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the Contractor/Subcontractor considers relevant.
c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.
d. In instances of theft or break-in or other criminal activity, the Contractor/Subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The Contractor, its employees, and its Subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The Contractor/Subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
B3. LIQUIDATED DAMAGES FOR DATA BREACH
a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the Contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the Contractor/Subcontractor processes or maintains under this contract.
b. The Contractor/Subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other th an that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis.
Failure to cooperate may be deemed a material breach and grounds for contract termination.
c. Each risk analysis shall address all relevant information concerning the data breach, including the following:
i. Nature of the event (loss, theft, unauthorized access);
ii. Description of the event, including:
iii. date of occurrence;
iv. data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;
v. Number of individuals affected or potentially affected;
vi. Names of individuals or groups affected or potentially affected;
vii. Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;
viii. Amount of time the data has been out of VA control;
ix. The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);
x. Known misuses of data containing sensitive personal information, if any;
xi. Assessment of the potential harm to the affected individuals;
xii. Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and
xiii. Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.
d. Based on the determinations of the independent risk analysis, the Contractor shall be responsible for paying to VA liquidated damages in the amount of $37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:
i. Notification;
ii. One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;
iii. Data breach analysis;
iv. Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;
v. One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and
vi. Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.
B4. SECURITY CONTROLS COMPLIANCE TESTING
On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the Contractor under the clauses contained within the contract. With 10 working-days’ notice, at the request of the Government, the Contractor must fully cooperate and assist in a Government-sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The Government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.
B5. TRAINING
1. All Contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
i. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix D relating to access to VA information and information systems;
ii. Successfully complete the VA Privacy and Information Security Awareness and Rules of
Behavior training and annually complete required security training;
iii. Successfully complete Privacy and HIPAA Training if Contractor will have access to PHI;
iv. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and v. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access
2. The Contractor shall provide to the CO and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
3. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or e lectronic access privileges and removal from work on the contract until the training and documents are complete.
B6. GOVERNMENT RESPONSIBILITIES
The following needs to be provided by the COR to the Contractor:
The Security Investigations Center will require the following forms from the Contractor or to the Contractor’s personnel: Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations.
The roster shall contain:
1. Contractor’s Full Name, Full Social Security Number, Date of Birth, Place of Birth, and individual background investigation level requirement (based upon Section 6.2 Tasks).
2. The Contractor should coordinate the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized.
3. For a Low Risk designation the following forms are required to be completed: 1. OF-306 and
2. DVA
Memorandum – Electronic Fingerprints. For Moderate or High Risk, the following forms are required to be completed: 1. VA Form 0710 and 2. DVA Memorandum – Electronic Fingerprints. These should be submitted to the COR within 5 business days after award. (DVA Memorandum – Electronic Fingerprints is filled out by the VA Facility that took the electronic fingerprints)
4. The Contractor personnel will receive an email notification from the Security and Investigation Center (SIC), through the Electronics Questionnaire for Investigations Processes
(e-QIP) identifying the website link that includes detailed instructions regarding completion of the investigation documents (SF85, SF85P, or SF 86). (The SF85 does not need to be uploaded because OPM is going paperless and the Contractor will complete this questionnaire online when the e-QIP link is sent.) (DVA Memorandum – Electronic Fingerprints is filled out by the VA
Facility that took the electronic fingerprints) (Please be advised that the Contractor will need all the necessary information easily accessible as the website will time out and they can lose the information they inputted if they take too long to fill it in.)The Contractor personnel shall submit all required information related to their background investigations utilizing the Office of
Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP).
5. The Contractor is to certify and release the e-QIP document, print and sign the signature pages, and send them to the COR for electronic submission to the SIC. These should be submitted to the COR within 3 business days of receipt of the e-QIP notification email.
6. The SIC will then upload the e-QIP signature pages to e-QIP and release the case file to OPM for investigation.
7. The SIC will notify the CO and Contractor after adjudicating the results of the background investigations received from OMB.
File details come from the government source that posted it. Updated .