36C24218Q0512-001.doc

DOC document 74 KB Posted

Attached to
CARESTREAM DRX SERVICE MAINTENANCE AGREEMENT Federal contract opportunity
Solicitation number
36C24218Q0512
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 2

About this file

36C24218Q0512 Statement of Work - Carestream DRX.doc

View the file

Other files for this federal contract opportunity

Other files attached to CARESTREAM DRX SERVICE MAINTENANCE AGREEMENT, newest first.
File Type Posted
36C24218Q0512-00001000.docx DOCX document
36C24218Q0512-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

A.3. SCOPE OF WORK

A.3.1. SCOPE AND EQUIPMENT:

1. This firm fixed-price purchase order, to include four option years, is for service support agreements for four Carestream DRX-Revolution mobile x-ray units (see table below) located at the East Orange Campus of the NJ VA Healthcare System, 385 Tremont Av, East Orange, New Jersey, 07018 from 07/01/2018 through 06/30/2019. The service support agreement includes: cart/battery and tube coverage, scheduled preventive maintenance services, telephone and on-site emergency support. The contractor shall furnish only new standard parts (manufactured by the maker of the equipment, or equal thereto) including all glass parts, vacuum tubes, x-ray tubes, and imaging panels. All parts shall be of current manufacture (or equal thereto) and shall have full versatility with presently installed equipment. This agreement specifically excludes consumables. All service support provided under this service agreement shall be provided by technicians trained and certified on this system by the Original Equipment Manufacturer (OEM) to ensure that the equipment functions in conformance with the original equipment manufacturers performance standards.

Equipment List

Equipment Model
Site/Serial Number
VA ID#
Carestream DRX-Revolution Mobile X Ray Unit
52409516/696
86652
Carestream DRX-Revolution Mobile X Ray Unit
52409527/752
86717
Carestream DRX-Revolution Mobile X Ray Unit
52414288/976
88251
Carestream DRX-Revolution Mobile X Ray Unit
52414301/978
88256

A.3.2. HOURS OF COVERAGE:

1. Contractor shall furnish all labor, parts, tools, and equipment as applicable to perform: full service maintenance and repairs on identified equipment and associated software during normal working hours, unless otherwise specified. Normal working hours shall be defined as 8:00 AM to 5:00 PM, Monday through Friday, except federal holidays. Federal Holidays shall be defined as:

New Year’s Day Martin Luther King Day Presidents Day

Memorial Day Independence Day Labor Day

Columbus Day Veteran’s Day Thanksgiving Day

Christmas Day

A.3.3 PERSONNEL

1. All work shall be performed by competent personnel, experienced and qualified to work on the specific equipment listed on the schedule. Contractor shall provide certification as required by the Joint Commission on the Accreditation of Healthcare Organizations (JCAHO) that all personnel authorized to maintain the equipment specified by the contract are competent and able to perform all duties listed under the terms of the contract. CONTRACTING OFFICER RESERVES THE RIGHT TO REQUEST PROOF OF APPROPRIATE TRAINING AND EXPERIENCE FROM VENDOR PERSONNEL FOR SERVICING THE EQUIPMENT ON THE SCHEDULE. It is the Contractors responsibility to provide all personnel, equipment, manuals, tools, and schematics to perform contracted services.

2. All vendors/contractors will sign-in at the Biomedical Engineering Lab, Building 1, B-level Room B154, before reporting to their respective work site. Each vendor/contractor will be issued a temporary identification badge that must be worn at all times above the waist, in front, with the face of the card visible.

3. Upon completion of the scheduled work, the vendor/contractor will return to the Biomedical Engineering Lab, Building 1, B-level Room B154, to sign-out, return the temporary identification badge, and leave any Field Service Reports if necessary.

A.3.4 SCHEDULED PREVENTATIVE MAINENANCE SERVICES

1. Scheduled preventative maintenance services shall include, but not be limited to, electrical safety testing, lubrication, adjustment, calibration, testing and replacement of faulty parts and/or parts which are likely to fail at no additional charge. The contractor’s preventative maintenance procedures and inspection intervals shall be in accordance with Original OEM service specifications. At the conclusion of the preventive maintenance visit, the instrument(s) and/or equipment shall be returned to the operating condition stipulated by the manufacturer's factory specifications.

2. The contractor is responsible for scheduling all PM service visits prior to the end of the month in which they are due. Any deviations from this schedule must be approved in advance by the COR.

3. The contractor shall be responsible for informing the COR of any uncorrected deficiencies and noting these on the service ticket. Notation will include the type of deficiency, dated and initialed. Any deficiency which poses hazard to patients, staff, or other equipment shall immediately be called to the attention of the users and the COR.

4. Upon completion of the scheduled work, the vendor/contractor will return to the Biomedical Engineering Lab, Building 1, B-level Room B154, to sign-out, return the temporary identification badge, and leave any Field Service Reports if necessary.

A.3.5 TELEPHONE AND EMAIL SUPPORT

1. Contractor shall provide a toll-free technical and applications (clinical product) phone support during normal operating hours for both hardware and software issues. This service will also be offered through e-mail. Issues that cannot be resolved will be forwarded to service dispatch for resolution.

2. Contractor shall respond to all telephone and email support requests within 60 minutes of receiving the initial request.

A.3.6 ON-SITE SUPPORT

1. Contractor shall provide emergency on-site field service support for equipment covered under the terms of this contract and for issues that cannot be resolved by telephone or remote support (if available) during regular business hours as defined in section A.3.2 within 4 hours of receiving the initial request if telephone, email and remote diagnostic and remedial support cannot resolve the issue within one hour of initial contact.

2. The contract price shall include all travel, fees, accommodations, and any other costs incurred by the contractor, in performing covered services.

3. Contractor shall provide a formal escalation protocol in the event of extended downtime for the covered equipment and all components.

4. Contractor shall be responsible for informing the COR of any uncorrected deficiencies and noting these on the service ticket. Notation will include the type of deficiency, dated and initialed. Any deficiency which poses hazard to patients, staff, or other equipment will immediately be called to the attention of the users and the COR.

5. Additional surcharges for emergency on-site service support outside regular business hours shall not be covered under this service agreement and shall require a separate procurement.

B.3.7 REMOTE ACCESS USING VPN

1. Contractor may provide remote monitoring, trouble shooting, corrective action and software upgrade functionalities via VPN. To provide this service the contractor shall require a local Memorandum of Understanding – Interconnection Security Agreement (MOU-ISA) to be established before a VPN connection can be created.

2. Contractor shall provide any documentation required by law regarding the final disposal of any components and/or supplies, as defined by the EPA, the Resource Conservation & Recovery Act, and 6NYCRR, replaced during any service performed on the listed equipment. This documentation shall include, but not be limited to, manifests, detailed lists of disposed waste, etc. showing “cradle-to-grave” documentation of proper disposal.

A.3.8 OTHER REQUIREMENTS

1. The VAMC shall not provide service manuals or service diagnostic software to the contractor. The contractor shall obtain, have on file, and make available to its FSE's all operational and technical documentation, (such as; operational and service manuals, schematics, and parts list), which are necessary to meet the performance requirements of this contract. The location and listing of the service data manuals, by name, and/or the manuals themselves shall be provided to the CO upon request.

2. Contractor shall comply with all applicable HIPAA regulations and requirements necessary to protect the privacy, integrity & reliability of electronic Protected Health Information (ePHI) and provide proof of an existing Business Associate Agreement with the VA. This includes any exposures to ePHI by support personnel or disclosure of any ePHI to any other agents during the course of regular service and support activities, and to any ePHI obtained during the course of complaint investigation or any other FDA mandated activity. Upon termination of this contract, the contractor shall continue to extend this protection to any ePHI retained during this activity. NOTE: Under no conditions shall any electronic storage media be removed from Veterans Affairs (VA) premises without being thoroughly sanitized to VA standards. Electronic media that cannot be sanitized to VA standards shall be destroyed on-site by VA.

3. Contractor shall repair, modify, or correct as necessary software/hardware deficiencies related to any and all hazard alerts from the manufacturer, FDA, or Veterans Administration, etc. at no additional cost. These modifications shall be performed during regular business hours and coordinated with the COR at least one week in advance of the requested date and time.

4. Contractor shall perform all mandatory safety and reliability modifications for the software/hardware covered under this agreement during normal working hours at no additional cost. These modifications shall be performed during regular business hours and coordinated with the COR at least one week in advance of the requested date and time.

5. If removable media (i.e. USB or DVD/CD Device) is required to service, troubleshoot or install/update software, then it must be scanned with an anti-virus program. The removable media is scanned with anti-virus software running current virus definitions prior to connection to any medical device at the scanning workstation located in Biomedical Engineering. Any vendor/contractor with patient sensitive information that is imported into the removable media device for any reason must purge all patient sensitive information prior to departure from the facility.

6. All items covered by the manufacturer's warranty, contractor service of any devices, systems, or other equipment containing media (hard drives, optical disks, etc.) with VA sensitive information must not be removed / returned to the vendor at the end of life, for trade-in, or other purposes.

7. All medical device workstations and servers must be in compliance with MDIA (Medical Device Infrastructure Architecture) as well as comply with all FDA regulations.

A.4 IT CONTRACT SECURITY

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY

1. GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor's employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

3. VA INFORMATION CUSTODIAL LANGUAGE

a. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

b. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

c. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

d. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

e. The contractor/subcontractor's firewall and Web services security controls, if applicable, shall meet or exceed VA's minimum requirements. VA Configuration Guidelines are available upon request.

4. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

a. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:

(1) Vendor must accept the system without the drive;

(2) VA's initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or

(3) VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.

(4) Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;

(a) The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and

(b) Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the purchase order or contract.

(c) A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed. The ISO needs to maintain the documentation.

5. SECURITY INCIDENT INVESTIGATION

a. The term "security incident" means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/ subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/ subcontractor has access.

6. SECURITY CONTROLS COMPLIANCE TESTING

On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract. With 10 working-day's notice, at the request of the government, the contractor must fully cooperate and assist in a government-sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.

7. TRAINING

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;

(2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

(3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

(4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document - e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]

b. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

File details come from the government source that posted it.