36C24419Q0467-001.pdf
PDF 416 KB Posted
- Attached to
- PM Fire Detection and Suppression System Federal contract opportunity
- Solicitation number
- 36C24419Q0467
About this file
36C24419Q0467 S02.36C24419Q0467.460 FIRE.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C24419Q0467-0005001.docx | DOCX document | |
| 36C24419Q0467-0005000.docx | DOCX document | |
| 36C24419Q0467-0003000.docx | DOCX document | |
| 36C24419Q0467-0002000.docx | DOCX document | |
| 36C24419Q0467-0001000.docx | DOCX document | |
| 36C24419Q0467-000.docx | DOCX document | |
| 36C24419Q0467-002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
36C24419Q0467
COMBINED SYNOPSIS/SOLICITATION FOR
460 FIRE DETECTION & SUPPRESION SYSTEM
General Information
Document Type: Combined Solicitation/Synopsis
Solicitation Number: 36C24419Q0467
Posted Date: 3/25/2019
Response Date: 4/5/2019
Product or Service Code: H312
Set Aside (SDVOSB/VOSB): SDVOSB
NAICS Code: 541350
Contracting Office Address
Department of Veterans Affairs
Network Contracting Office 4
1010 Delafield Road
Pittsburgh, PA
15215-1802
Description
This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Federal Acquisition Regulation (FAR) subpart 12.6, “Streamlined Procedures for Evaluation and Solicitation for Commercial Items,” as supplemented with additional information included in this notice. This announcement constitutes the only solicitation;
quotations are being requested, and a written solicitation document will not be issued.
This solicitation is a Request for Quotations (RFQ) and the solicitation number is 36C24419Q0467. The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2005-97 effective January 24, 2018.
The complete text of any of the clauses and provisions may be accessed in full text at https://www.acquisition.gov/browsefar; http://farsite.hill.af.mil; and/or http://www.va.gov/oal/library/vaar/index.asp.
The associated North American Industrial Classification System (NAICS) code for this procurement is 541350, Building Inspection Services, with a small business size standard of $7.5 Million.
The Department of Veterans Affairs, Wilmington VA Medical Center, 1601 KIRKWOOD
HWY
WILMINGTON, DE 19805 is seeking Building Inspection Services.
All interested companies shall provide quotations for the following:
The anticipated Period of Performance will be being 4/18/2019 following Contract award.
Place of Performance
Address:
WILMINGTON VA MEDICAL CENTER 460
1601 KIRKWOOD HWY
WILMINGTON, DE 19805
Country: UNITED STATES
All work shall be completed in accordance with the Statement of Work (SOW).
Offerors are requested to quote Firm Fixed Price for any and all of the line items on the Schedule of Supplies and Services attached to this solicitation.
Service Contract Act Wage Determination Number 2015-4215, Revision Number 7, dated 12/26/2018, applies to this acquisition and will be incorporated into the resulting contract.
A copy of the Wage Determination is included with this solicitation.
Any award resulting from this solicitation will be issued on a Standard Form 1449.
https://www.acquisition.gov/browsefar http://farsite.hill.af.mil/ http://www.va.gov/oal/library/vaar/index.asp
NOTE: To receive an award resulting from this solicitation, offerors MUST be registered in the System for Award Management (SAM) database IAW FAR 52.212-(k) & VETBIZ.
Registration may be done online at: www.acquisition.gov or www.sam.gov, & https://www.vip.vetbiz.va.gov/
Site Visit: None
Questions pertaining to this solicitation are due on Wednesday March 27th, 2019 (12:00 PM Noon EST) to Contracting Officer Amanda Saunders, Amanda.Saunders@va.gov. No questions will be answered following this date.
All quotes must be received by Friday April 5th, 2019 (12:00 PM NOON ET) to be considered for award. Send to Contracting Officer Amanda Saunders, Amanda.Saunders@va.gov.
http://www.sam.gov/ https://www.vip.vetbiz.va.gov/ mailto:Amanda.Saunders@va.gov mailto:Amanda.Saunders@va.gov
SECTION B - CONTINUATION
B.1 PRICE/COST SCHEDULE
ITEM INFORMATION
ITEM
NUMBE
R
DESCRIPTION OF
SUPPLIES/SERVICE
S
QUANTIT
Y
UNI
T UNIT PRICE AMOUNT
1.00 JB _________________
BASE YEAR: Fire detection and suppression systems annual service contract.
Perform IAW the SOW Contract Period: Base POP Begin:
POP End:
OPTION YEAR 1: Fire detection and suppression systems annual service contract.
Perform IAW the SOW Contract Period: Option 1
OPTION YEAR 2: Fire detection and suppression systems annual service contract.
Perform IAW the SOW Contract Period: Option 2
OPTION YEAR 3: Fire detection and suppression systems annual service contract.
Perform IAW the SOW Contract Period: Option 3
OPTION YEAR 4: Fire detection and suppression systems annual service contract.
Perform IAW the SOW Contract Period: Option 4
GRAND
TOTAL
STATEMENT OF WORK FOR
FIRE DETECTION AND SUPPRESSIONS SYSTEMS
TESTING, INSPECTION, AND MONITORING AT
WILMINGTON VA MEDICAL CENTER
1601 KIRKWOOD HIGHWAY
WILMINGTON, DE 19805-4917
1. Scope. Contractor shall provide labor and materials for the testing of the Notifier System with related components, the fire sprinkler system, and the standpipes and fire pumps at the Wilmington VA Medical Center as indicated herein.
2. Description of Work.: The Prime Contractor shall be a certified “Notifier System” contractor and shall not subcontract any part or parts of this contract. The contractor shall perform annual tests and inspections on the fire alarm system in accordance with National Fire Protection Association (NFPA) recommendations, manufacturer’s recommended procedures, and following the frequency standards required by The Joint Commission on Accreditation of Healthcare Organizations (TJC). The contractor shall deliver an electronic written (not handwritten) record, in conjunction with its digital file, which shall describe the test and inspection results, and services performed. This report shall be detailed based on the Elements of Performance (EP) specified by The Joint Commission. It is to include the name, number, and location of the device of activity, date of activity, required frequency of activity, NFPA standard referenced for activity, TJC Element of Performance referenced for the activity, results of the activity and name/contact information including affiliation of the person who performed the activity. In addition to an EP-based report, the contractor shall also provide a spreadsheet database file of all testable items which may be cross-referenced by device number to the EP-based report.
2.1 Current fire alarm system component inventory count, including standpipes and fire pumps:
2.1.1 Air Compressors – 6
2.1.2 Dry Pipe Valves – 6
2.1.3 Alarm Pressure Switches – 7
2.1.4 Alarm Valves – 5
2.1.5 Door Holders – 44
2.1.6 Dry Systems – 6
2.1.7 Duct Detectors – 79
2.1.8 Fire Department Connections – 12
2.1.9 Fire Pumps – 1
2.1.10 Heat Detectors – 42
2.1.11 High/Low Pressure Switches – 6
2.1.12 Hose Valve Outlets (Standpipes) – 86
2.1.13 Hydrants – 10
2.1.14 Main Drains – 24
2.1.15 Fire Alarm Control Panels – 22
2.1.16 Pre-Action Systems – 5
2.1.17 Pull Stations – 154
2.1.18 Remote Annunciators – 12
2.1.19 Roll down doors – 2
2.1.20 Smoke Detectors – 271
2.1.21 Speaker/Strobes – 21
2.1.22 Strobes – 507
2.1.23 Speakers – 522
2.1.24 Tamper Switches – 97
2.1.25 Water Flow Switches – 62
2.1.26 Water Motor Alarms – 2
2.1.27 Wet Risers – 4
2.2 The contractor shall provide all transportation, labor, tools equipment, and material to accomplish the following: All fire alarm and detection systems will be inspected and functionally tested in accordance with National Fire Protection Association recommendations and manufacturer’s specifications.
2.2.1 All non-disruptive work is to be completed between 8:00 a.m. and 4:30 p.m. (normal WVAMC working hours) Monday through Friday, except as requested or approved by the VA for special circumstances. Work which would be disruptive to the daily operations of the facility, such as the testing of annunciation devices, shall be performed after normal working hours. Contractor must report to Wilmington VAMC Safety Office personnel in room G114 for instructions each time they are on site.
2.2.2 Contactor must be able to provide an Original Equipment Manufacturer (OEM) trained and qualified fire alarm service technician, capable of performing programming on a Notifier fire alarm panel and can be on-site within four (4) hours of any emergency service call. This requirement shall not be subcontracted.
2.2.3 An emergency service situation is one in which the fire alarm system has a significant loss in functionality and requires a fire watch be instituted until repairs have been made.
Service calls will be addressed with a purchase order separate from this contract.
2.2.4 Contractor shall obtain most current and up to date device count by means of a panel download prior to first quarter testing.
2.2.5 Contractor shall wear VA issued I.D. badge at all times while on campus.
2.2.6 Contractor must provide proof that the testing team includes at least one member with NICET 1 certification.
2.2.7 Contractor testing team shall include no fewer than two qualified individuals.
Contractor must also provide proof of at least one NICET 3 certified employee and one Notifier certified employee on staff for support of the testing team.
2.2.8 Contractor shall furnish information about qualifications, ability to perform the work, and references regarding related experience in health care facilities. Any NICET certifications must be on file with the VA Contracting Office.
2.2.9 All tests and inspections are to be performed in accordance with the most recent edition of NFPA 101, 25, 72, and 13, as applicable.
2.2.10 All inspection and testing shall be completed before the end of the middle month of any given quarter in which inspection and testing is due.
2.2.11 No valves, gauges, or other parts will be replaced and charged to VA without prior approval from VAMC Wilmington Safety Office.
2.2.12 Testing of audible notification devices shall be conducted with the aid of a decibel meter, and audio levels shall be submitted as part of the testing report.
2.2.13 Testing of all smoke and duct detector devices shall involve the application of artificial smoke or magnetic activation testing.
2.2.14 No system will be left out of service at the end of a workday or over a weekend without written permission of the Wilmington VA Safety Office. All switches must also be verified as reset prior to end of workday.
2.2.15 Contractor will provide a list of deficiencies noted during testing on the final day of the testing or inspection; upon Completion of Inspection. Contractor will provide a complete report of all devices tested within one week of completion of inspection.
2.2.16 Access for locked areas will be provided by the Wilmington VAMC Safety Office.
Contractor shall complete all Privacy/ Information Security Training assigned by the Wilmington VA Medical Center.
2.2.17 Contractor shall follow all Wilmington VA Medical Center guidance on patient confidentiality.
2.2.18 Taking photographs is strictly prohibited while on V.A. Property.
2.2.19 Contractor must provide all tools, supplies, equipment and personnel to perform the work of this contract. Contractor is expected to work independently once oriented, with adequate personnel to accomplish all testing in an efficient manner.
2.2.20 The Wilmington VAMC Safety Office will provide a block diagram of the building listing all stairwells, elevators, and major hallway locations. Wilmington VAMC Safety Office will also provide an escort, if needed, during the contractor’s first testing quarter to properly orient the contractor with building layout. During all subsequent testing quarters, the contractor shall be expected to perform testing with minimal assistance.
2.2.21 Work is to be conducted in a manner which would present the least amount of disruption to the healthcare facility
2.2.22 Testing staff will follow VA dress procedures for entering clean areas (operating room suites, Sterile Processing, etc.) prior to entering clean areas. Sterile garments will be provided to testing staff by the VA.
2.2.23 In those cases where contractor is required to verify that alarms operate and transmit to VA main fire panel, the contractor may need to have a person at the building’s fire alarm panel to confirm the signal.
2.2.24 Work dates must be scheduled with Wilmington VAMC Safety Office, telephone
(302) 633-5518, (302) 994-2511 x5138, (302) 633-5270 933-8101 xt4299/4288
2.2.25 Written reports shall be delivered in hardcopy digital print format, and digital files emailed, to both members of Wilmington VAMC Safety Office at:
marshall.murdaugh@va.gov x5518 (Wilmington VAMC Safety Office) lon.sullivan@va.gov x5138 (Wilmington VAMC Safety Office)
3. Fire Alarm System
3.1 Annual Testing. The contractor shall provide labor, time, materials and equipment, necessary to perform annual testing and inspection of:
3.1.1 Each fire alarm system control panel, all input and all output devices, and batteries.
3.1.2 Test, inspection and operation to be performed on all manual fire alarms pull stations, smoke detectors (including elevator shafts), duct detectors, and heat detectors. Any smoke or heat detector that does not operate properly will be calibrated or replaced from hospital stock and reported to the Wilmington VAMC Safety Office supervisor. Before the removal of smoke detectors can begin, advance notice shall be given to the Wilmington VAMC Safety Office personnel.
3.1.3 Testing and inspection of all detectors
3.1.4 Inspection of all building alarm notification devices (audible devices, speakers, and visual devices)
3.1.5 Inspection and testing of all electro-mechanical releasing devices.
3.1.6 Ground fault for fire alarm system.
3.2 Semi-Annual Testing. The contractor shall provide labor, time, materials and equipment, necessary to perform semi-annual testing and inspection of: Valve tamper switches and water flow devices
3.3 Quarterly Testing. The contractor shall provide labor, time, materials and equipment, necessary to perform quarterly testing and inspection of:
3.3.1 Fire alarm equipment for notifying off-site responders
3.3.2 All supervisory signal devices (Done with Fire Sprinkler Inspection). Must be clearly stated on inspection form individually.
4. Fire Sprinkler System. The contractor shall provide parts, labor, time, materials, preventive maintenance, testing, equipment and emergency call back necessary to maintain and perform testing and inspection of the wet sprinkler systems and pre-action suppression systems at the proper frequency for all buildings at the medical center to meet or exceed NFPA requirements.
4.1 Annual Testing. Contractor to provide labor, time, materials and equipment to perform inspection of:
4.1.1 Each fire alarm system control panel, all input and all output devices.
4.1.2 All system riser main drains
4.1.3 Perform maintenance on all jockey pumps.
4.2 Semi-Annual Testing. Contractor to provide labor, time, materials and equipment to perform inspection of wet system sprinkler systems and pre-action suppression systems:
Test of fire alarm system circuits for proper operation.
4.2.1 Fire sprinkler system valve tamper switches and water flow devices (flow and tamper switches are chained and padlocked) in the months approved by the Health and Safety Office.
4.2.2 Full water flow testing of each device shall be performed during at least one of the semi-annual tests. Performance and documentation are to be in accordance with the most recent edition of the applicable National fire Protection Association Standards 25 and 72.
4.2.3 Inspection and testing of pre-action suppression systems. This testing is to be coordinated with Safety and Emergency Management. Performance and documentation are to be in accordance with the most recent edition of the applicable National fire Protection Association Standards 25 and 72.
4.3 Quarterly Testing. Contractor to provide labor, time, materials and equipment to perform inspection and preventive maintenance of:
4.3.1 All supervisory signal devices and fire department notification devices.
4.3.2 Compressors and pressurization components as part of pre-action suppression systems.
4.3.3 All post indicator valves (PIV’s).
4.3.4 Fire department connections (i.e., interior and exterior FDC’s). All fire department connections will be listed individually by location on the inspection report.
4.3.5 Inspect all jockey pumps.
4.3.6 Performance and Documentation. Performance and documentation are to be in accordance with the most recent edition of the applicable National fire Protection Association Standards 25 and 72.
4.4 General Requirements.
4.4.1 The contractor shall provide a schedule of all buildings to be tested. The Fire and Emergency Manager must give prior approval for the shut-down of the fire alarm of each building. Tests must be performed as fast and expertly as possible. No building will have a zone or a complete system shutdown more than one working shift.
4.4.2 The contractor shall provide all software updates to the system within the parameters of all the maintenance being done.
4.4.3 The contractor will be responsible for all bells, lights, buzzers, switches, batteries, battery chargers, and any equipment associated with the fire alarm system.
4.4.4 The contractor shall keep all equipment clean and well ventilated, inspect all system components and note any unusual performance, test-check operation of all the equipment as part of the inspection program and perform minor adjustments as needed at the time of inspection, including all Edwards System 3 systems and software.
4.4.5 A record of all repairs, abnormal findings and results of tests on equipment shall be maintained and turned over to Wilmington VAMC Safety Office.
4.4.6 The contractor shall provide Wilmington VAMC Safety Office with two copies of all inspection reports and emergency repair reports and fire alarm smoke detector test results.
Contractor also to notify Wilmington VAMC Safety Office of any equipment repair ready for final inspection. All testing and repair reports must be provided to the VA within five working days.
4.5 Wet System Specifications.
4.5.1 Test of water flow alarms. All water flow alarm switches will be tested by drawing water through inspector’s test valve.
4.5.2 Test of electric supervisory alarms: Test all supervisory alarm switches on supply valves, by closing all supervised valves and reopening the valves, verify that all local alarms operate, verify that all alarms transmit to Fire Alarm Control Panel (FACP). Note number of turns of valve stem required to activate the supervisory alarm.
4.5.3 Inspect and service all fire department connections: (i.e., interior and exterior FDC’s) On all fire department pumper connections, Siamese, etc. Remove caps; replace any missing/damaged caps. Lube threads, replace gaskets.
4.5.4 Inspect and service all main supply valves: Operate full close and reopen all P.I.V and O.S. and Y. valves on each system. Replace valve stem packing where leaking is evident and lubricate stems. (Rather than replacement of valve stem packing, tightening (but not over-tightening) is acceptable if adequate to stop leaking).
4.5.5 Inspection and flushing of main drain: Operate the main drain on each system to dislodge and flush any debris in main riser between supply main and cross mains.
4.5.6 Re-seal all valves in open position with wire seal where now sealed, re-lock all chains and padlocks where locked. Contractor furnishes wire seals.
4.5.7 Test of water flow alarms.
4.5.7.1 Water flow alarm switches will be tested by drawing water through inspector’s test valves.
4.5.7.2 Record elapsed time (switch retard) for switch activation-alarm initiation-local alarm, to determine if retard setting meeting VA standards (45 seconds from water flow to alarm signal activation).
4.5.7.3 Verify that alarm signals transmit to Fire Alarm Control Panel (FACP).
4.5.8 Test of supervisory alarms: Test of supervisory alarm on main P.I.V. supply to Building (one P.I.V.). Assure that supervisory alarm transmits to FACP.
4.5.9 Inspect and service all fire department connections: (i.e., interior and exterior FDC’s) On all fire department (Siamese) pumped connections, remove caps, replace any missing caps, lubricate threads, and replace gaskets as needed.
4.5.10 Inspect and service main supply valves:
4.5.10.1 Tests operate for close and reopen all O.S.Y. main riser valves.
4.5.10.2 Lubricate all threads and bearings, to assure normal operation.
4.5.10.3 Re-seal with wire seals if sealed.
4.5.10.4 Replace valve stem packing if leakage is evident.
4.5.11 Test flow 6 roof standpipes and hydrants: Calculate and record GPM flows for each standpipe and hydrant.
4.5.12 Test run fire pump and locked pump as specified in NFPA annual performance test for fire pumps. Record pilot reading, calculate and record GPM flow. As referenced in the most recent edition of NFPA 20.
4.5.13 Inspect all Wet and Dry Systems.
4.6 Dry (Pre-Action) System Specifications.
4.6.1 Trip test of main dry pipe valves. Trip test each main system riser dry valve by opening inspectors test valve to simulate sprinkler flow.
NOTE: The time (seconds) required from inspection valve open to trip (clapper valve open) and water flow at inspection test valve.
4.6.2 Rapid air exhauster test. Observe the function of the rapid air exhauster during the trip test of the main dry pipe clapper valve, to determine if the air exhauster function is adequate.
4.6.3 Water supply valves function tests. Manually operate, fully close and reopen all O.S.
& Y. main valves and P.I. Valves to assure easy normal operation. Repack any leaks in glands. Lubricate stems as necessary, one full closure and open of each valve minimum, for each function test.
4.6.4 Test all electric supervisory alarm switches on supply valves: Concurrent with item 4, assure that all supervisory alarm switches are operating and transmitting to fire alarm system in boiler plant indicating valve closed and valve open as required.
4.6.5 Inspect and repair all fire department connections: (i.e., interior and exterior FDC’s) Inspect all pumper connections to system (Siamese etc.). Replace any missing caps, gaskets, etc. and lube all cap threads lube to prevent rust or seizure.
4.6.6 Test all water flow alarm switches and alarm circuits: Test the function of all water flow alarm switches to assure they transmit water-flow alarm to local (building) bell/gong, and to control center and that switch settings are under 45 seconds.
NOTE: Record delay time on each test report form.
4.6.7 Re-seal all valves in open position with wire/lead seal where sealed with wire. Re-secure all valves locked with chain/padlock with chain/padlock only. Contractor furnishes wire seals.
4.6.8 Test all air loss alarms: Test to determine if air loss switches functions any building alarm local device and if building fire alarm interface transmits low air alarm signal to boiler plant.
4.6.9 Dry pipe system low points are to be drained upon completion of the trip tests.
5. Standpipes and Fire Pumps. Provide all labor, tools, equipment, materials and supervision for the annual test, inspection and maintenance of 11 standpipes. Annual test, inspection and maintenance of these fire suppression systems per NFPA specifications are to be done during the month of June or as agreed to by VA.
5.1 Annual Standpipe Flow Test.
5.1.1 The contractor will perform the annual standpipe flow test in accordance with NFPA 25.
5.1.2 This test to be performed in the uppermost or most remote part of each building to determine the flow rate in gallons per minute (gpm) and the residual pressure in pounds per square inch (psi). The flow will be maintained for at least 30 minutes.
5.1.3 Fire pump controls will be switched off during the first half of the test and on the second half of the test with results recorded for both operations.
5.1.4 Contractor will provide all tools required including a water diverter funnel and fall protection for standpipes located on the roof.
5.1.5 Test data will be properly recorded on forms approved by NFPA 25 and signed by the inspector.
5.2 Annual Fire Pump Full Flow Test:
5.2.1 The contractor will test each fire pump annually to determine flow rate, pump pressure, pump motor current, voltage and speed at peak load. All valves in suction line will be checked to assure that they are fully open.
5.2.2 The flow will be maintained for at least one hour.
5.2.3 The inspector will record the date, total flow rate, test meter gpm, suction and discharge pressure, number and size of hose nozzles with corresponding psi and total gpm, pump motor current, voltage and speed, and sign for each fire pump.
5.2.4 Performance curves will be documented showing pressure at 0%, 100%, and 15Q% flow rate of pump. This graph will be completed in accordance with NFPA 20-11.3 and presented to Wilmington VAMC Safety Office.
5.3 Inspection Forms. Additional inspection forms can be obtained from the applicable NFPA codes. Contractor will provide a list of deficiencies noted during testing on the final day of the testing or inspection; upon Completion of Inspection. Contractor will provide a complete report of all devices tested within one week of completion of inspection.
5.4 Sensitivity testing for fire alarm and detection systems. To ensure accuracy, and in accordance with NFPA or Joint Commission requirements/guidelines, sensitivity testing will be performed on all smoke detectors at a rate of 100% annually. Testing will be performed using only UL approved sensitivity testing equipment. Devices performing outside the listed sensitivity range shall be re-cleaned and tested, and if necessary, noted and recommended for replacement as per the Fire and Emergency Manager
6. Joint Commission Inspection Requirements. All inspections listed above will be conducted as required by the Joint Commission on Healthcare Accreditation. The following items will be inspected and documented at the periodicity indicated. Below is a summary of all tests and inspections covered in this statement of work.
6.1 At least quarterly test supervisory signal devices (except valve tamper switches). The completion date of the tests is documented.
6.2 At least quarterly test water-flow devices. Every 6 months test valve tamper switches.
The completion date of the tests is documented.
6.3 Every 12 months test duct detectors, electromechanical releasing devices, heat detectors, manual fire alarm boxes, and smoke detectors. The completion date of the tests is documented.
6.4 Every 12 months test visual and audible fire alarms, including speakers. The completion date of the tests is documented.
6.5 Every 12 months test fire alarm equipment for notifying off-site fire responders. The
6.6 For automatic sprinkler systems: Every 12 months, test main drains at system low point or at all system risers. The completion date of the tests is documented.
6.7 For automatic sprinkler systems: Every quarter, inspect all fire department water supply connections. The completion dates of the inspections are documented.
6.8 For automatic sprinkler systems: Every 12 months test fire pumps under flow. The
6.9 Provide testing and documentation for magnetic release for fire/smoke barriers and release of exterior doors during fire alarm testing with door lock system located in police service.
Provide testing and documentation for automatic smoke detection shutdown devices for air handling equipment every 12 months.
Records Management Language for Contracts
The following standard items relate to records generated in executing the contract and should be included in a typical Electronic Information Systems (EIS) procurement contract:
1. Citations to pertinent laws, codes and regulations such as 44 U.S.C chapters 21, 29, 31 and 33; Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228.
2. Contractor shall treat all deliverables under the contract as the property of the U.S.
Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.
3. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records.
4. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.
5. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.
6. The Government Agency owns the rights to all data/records produced as part of this contract.
7. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
8. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format [paper, electronic, etc.] or mode of transmission [e-mail, fax, etc.] or state of completion [draft, final, etc.].
9. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules.
10. Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub-contractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
B.3 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR: TBD
b. GOVERNMENT: Contracting Officer 36C244 AMANDA SAUNDERS
Department of Veterans Affairs
Network Contracting Office 4
1010 DELAFIELD ROAD
PITTSBURGH PA 15215
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System for Award Management, or
[] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other []
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
Austin Payment Center
Department of Veterans Affairs
PO Box 149971
Austin TX 78714-9971
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.4 IT CONTRACT SECURITY
VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service
(DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor's employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
3. VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
b. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor's information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA's information is returned to the VA or destroyed in accordance with VA's sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, contractor/ subcontractor must not destroy information received from VA, or gathered/ created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
g. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
i. The contractor/subcontractor's firewall and Web services security controls, if applicable, shall meet or exceed VA's minimum requirements. VA Configuration Guidelines are available upon request.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA's prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
k. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.
l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.
4. INFORMATION SYSTEM DESIGN AND DEVELOPMENT
a. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R.
Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.
b. The contractor/subcontractor shall certify to the COR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.
c. The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration.
Information technology staff must also use the Windows Installer Service for installation to the default "program files" directory and silently install and uninstall.
d. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
e. The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to
Federal Information Systems, VA Handbook 6500, Information Security Program and VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle.
f. The contractor/subcontractor is required to design, develop, or operate a System of Records Notice (SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.
g. The contractor/subcontractor agrees to:
(1) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:
(a) The Systems of Records (SOR); and
(b) The design, development, or operation work that the contractor/ subcontractor is to perform;
(1) Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and
(2) Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.
h. In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish an agency function, the contractor/subcontractor is considered to be an employee of the agency.
(1) "Operation of a System of Records" means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.
(2) "Record" means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person's name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.
(3) "System of Records" means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
i. The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as "Systems"), throughout the life of this contract and any extension, warranty, or maintenance periods.
This includes, but is not limited to workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the Systems.
j. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system).
Such issues shall be remediated as quickly as is practical, but in no event longer than days.
k. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within days.
l. All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph (e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA Assistant Secretary for Office of Information and Technology.
5. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerablity scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor's security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA's network involving VA information must be reviewed and approved by VA prior to implementation.
b. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
c. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor's systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government- owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.
d. The contractor/subcontractor's system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA's POA&M management process. The contractor/subcontractor must use VA's POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/ subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re- authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.
e. The…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.