36C24721Q0355_1.docx

DOCX document 139 KB Posted

Attached to
J063--CCTV Preventative Maintenance Services Federal contract opportunity
Solicitation number
36C24721Q0355
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 7

About this file

This pre-solicitation notice is for CCTV security system preventative maintenance services for the Atlanta VA Health Care System. The Department of Veterans Affairs intends to issue a solicitation for a firm-fixed-price base year and four option year renewal contract, with a projected period of performance of May 2021 to March 2026. The acquisition is set aside for Service-Disabled Veteran Owned Small Businesses. Interested contractors should monitor beta.SAM.gov for issuance of the solicitation on or around March 12, 2021. The applicable NAICS code is 561621 with a size standard of $22 million. Places of performance are specified VA facilities in the Atlanta area.

View the file

Other files for this federal contract opportunity

Other files attached to J063--CCTV Preventative Maintenance Services, newest first.
File Type Posted
36C24721Q0355 0001.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C24721Q0355

PAGE 1 OF

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

DUNS:

DUNS+4:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. 2/2012)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

508-21-1-445-0029 36C24721Q0355 03-15-2021 Quentin Deloney 404-321-6111 04-12-2021

1:00 PM

EDT

Department of Veterans Affairs VISN 7 Network Contracting Office LaVista Business Park - Bldg A 2008 Weems Road Tucker

GA

30084 X X 561621 $22 Million N/A X Atlanta VA Health Care System 1670 Clairmont Road Decatur

GA

30033 Department of Veterans Affairs VISN 7 Network Contracting Office LaVista Business Park - Bldg A 2008 Weems Road Tucker

GA

30084

Department of Veterans Affairs

FMS-VA-2(101)

Financial Services Center PO Box 149971 Austin

TX

78714-9971 See CONTINUATION Page See CONTINUATION Page X X X James Boles Table of Contents

SECTION A1
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS1
SECTION B - CONTINUATION OF SF 1449 BLOCKS3
B.1 CONTRACT ADMINISTRATION DATA3
B.2 PRICE/COST SCHEDULE20
ITEM INFORMATION20
SECTION C - CONTRACT CLAUSES23
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL ITEMS (OCT 2018)23
C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL ITEMS (JAN 2021)29
C.3 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)36
C.4 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)37
C.5 VAAR 852.212-70 PROVISIONS AND CLAUSES APPLICABLE TO VA ACQUISITION OF COMMERCIAL ITEMS (APR 2020)37
C.6 VAAR 852.219-74 LIMITATIONS ON SUBCONTRACTING—MONITORING AND COMPLIANCE (JUL 2018)39
C.7 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)39
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS41
SECTION E - SOLICITATION PROVISIONS62
E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL ITEMS (JUN 2020)62
E.2 52.212-2 EVALUATION—COMMERCIAL ITEMS (OCT 2014)67
E.3 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL ITEMS (FEB 2021)68
E.4 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (OCT 2020)86
E.5 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018)89
E.6 52.216-1 TYPE OF CONTRACT (APR 1984)90
E.7 52.233-2 SERVICE OF PROTEST (SEP 2006)90
E.8 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)91

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C247 Department of Veterans Affairs VISN 7 Network Contracting Office LaVista Business Park - Bldg A 2008 Weems Road Tucker GA 30084

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] Monthly

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

Department of Veterans Affairs

FMS-VA-2(101)

Financial Services Center PO Box 149971 Austin TX 78714-9971 ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

Statement of Work Cameras Maintenance & Service Support

A. GENERAL INFORMATION

1. Title of Project: Cameras Maintenance & Service Support

2. Scope of Work:

The contractor shall provide all resources necessary to accomplish the deliverables described in this statement of work (SOW), except as may otherwise be specified. Furnish labor, parts, supplies and components necessary to provide maintenance, emergency service, and periodic preventive maintenance inspections for the equipment contained herein. Components located at VAMC, 1670 Clairmont Road, Decatur, GA 30033, Fort McPherson, 1701 Hardee Ave SE Atlanta, GA 30310, Carrollton,180 Martin Dr. Carrollton, GA 30117 and AVC, 250 North Arcadia Ave, Decatur, GA 30030.

3. Background:

The goal of this Cameras Maintenance & Service Support is to enhance investment in the Physical Security System; to collaborate with customers and assist in creating a more safe and secure environment; to maintain security system to maximize up-time and minimize breakdown/repair costs; to minimize system downtime thus assisting customers in managing the risk; to keep the system up-to-date with the latest technology advancements.

4. Performance Period:

The contractor shall complete the work required under this SOW for the period, though, unless otherwise directed by the Contracting Officer (CO). Work at the Government site shall not take place on Federal holidays or weekends unless directed by the CO.

5. Type of Contract:

Firm-Fixed-Price

B. CONTRACT AWARD MEETING

The contractor shall not commence performance on the tasks in this SOW until the CO has conducted a kickoff meeting or has advised the contractor that a kickoff meeting is waived.

C. GENERAL REQUIREMENTS

Equipment and services included within this Statement of Work:

CLN
Mfg Name
Description
Model
EE/MX
Serial #

TRINKA DAVIS

40
Avigilon
Cameras
2
Avigilon
Servers
4
Cisco
Switches
1
Dell
Dual Monitor Workstations
2
APC
Rack Mount UPS

CLAIRMONT

439
Pelco
Cameras
4
Pelco
Dual Monitor Workstations
10
Pelco
Monitors
22
Cisco
Switches
16
APC
Rack Mounted UPS
10
Pelco
Servers

Fort McPherson

203
Avigilon
Cameras
3
Avigilon
Single Monitor Workstations
3
Avigilon
Dual Monitor Workstations
9
LG
Monitors
14
Cisco
Switches
11
APC
Rack Mount UPS
6
Avigilon
Servers

Decatur Clinic (AVC)

61
Avigilon
Cameras
2
Avigilon
Servers
4
Cisco
Switches
2
Avigilon
Dual Monitor Workstations
2
APC
Rack Mount UPS

For All visits by Contractor:

Contractor will be required to sign in at the location designated by Police Services Supervisor after contract award before beginning a service call, emergency service, etc. Upon completion of preventive maintenance (PM) inspection and/or emergency repair the Contractor shall leave a copy of the service report with the using service, and submit to the same location as designated above a service report annotating what repairs, service, calibration, etc., were performed and whether preventive maintenance was done. Each service report shall include the name of the contractor, name of Field Service Engineer (FSE), date, time (starting and ending), system downtime, hours of labor including costs (when emergency service is authorized outside of normal working hours), the parts utilized including costs, VA purchase order # (when emergency service is authorized outside of normal working hours), the nature of the problem, the nomenclature of the item repaired (serial number & VA inventory number), and the room number where component is located. The service designee and the FSE attesting that the system is in satisfactory working order and is functioning at an acceptable level of performance shall sign this report. The contractor shall sign out at the designated location before leaving. NOTE: Failure to furnish a service report or obtain a signed copy of the service report could result in delay of payment or non-payment. The Contracting Officer’s Technical Representative (COR), Biomedical Engineering Supervisor or VA’s designated alternate in the using service has the authority to approve/request a service call from the contractor.

D. SPECIFIC MANDATORY TASKS AND ASSOCIATED DELIVERABLES

Description of Tasks and Associated Deliverables:

The contractor shall provide the specific deliverables described below within the performance period stated in Section A.4 of this SOW.

Parts:

1. The contractors are required to replace inoperable cameras/equipment. The contractor must have ready access to all replacement parts. Contractor shall maintain an enough stock of all parts (meeting manufacture’s design and specification) needed for repair and maintenance of the equipment or be able to secure needed parts within one (1) calendar day. All parts supplied shall meet manufacturer approved specifications. This contract shall include all parts for PM/emergency service repairs and emergency after-hours service. The contract does not cover operating supplies that are consumed during normal operation of the covered equipment. The contractor shall use new parts only. If and when requested, the contractor shall provide the VAMC with a letter from the manufacturer of the components specifying that all parts for the equipment will be sold to the contractor. All replacement parts provided under this contract shall be warranted for a period of one (1) year for replacement of same including all applicable costs, e.g., travel, labor, etc. If published or issued by the component’s manufacturer, field service software/hardware updates/upgrades will be provided at no additional cost (to include parts and labor) during the contract period.

2. Software restoration shall be included in this contract. Contractor will reinstall the application software, database software, and operating system upon any failure that requires software restoration to return the system to full functionality.

Software Support:

1. Software support services include phone assistance during normal hours of coverage. The Contractor will assist with questions on using the application, on identifying and resolving problems, on recovering from system failure, and on implementing workarounds.

2. When authorized by the COR or the Contractor may access the system remotely to diagnose software problems.

3. When the Contractor determines that system performance has malfunctioned due to a software problem and cannot be restored remotely, technical personnel shall be dispatched to the VAMC-Atlanta to resolve the problem. Response times and coverage hours in the section, Normal Hours of Coverage, Response Time & Emergency Services will apply.

4. On-site application training and/or consulting are not included.

Updates:

1. Parts and labor costs for all software and hardware updates offered by the system manufacturer will be included in this contract.

2. Hardware updates are defined as hardware replacements offered by the system manufacturer to a) restore the system to existing functionality due to discontinued availability of parts or support of the system; b) correct defects in the intended application of the component’s; c) enhance existing functionality of the system; or d) accurately process date data including, but not limited to, calculating, comparing, and sequencing.

3. Software updates are defined as those offered by the system manufacturer which a) correct defects in the application software; b) enhance existing functionality in the software; c) insures accurate processing of date including, but not limited to, calculating, comparing, and sequencing; d) update the operating system software as required to install a, b, or c. New functionality is usually not included in a software update.

Service Manual:

The VA Medical Center (VAMC) will not provide service manuals or service diagnostic software to the contractor. The Contractor shall obtain, have on file, and make available to its FSE all operational and technical documentation (such as: operational and service manuals, schematics, and parts list), which are necessary to meet the performance requirements of this contract.

Normal Hours of Coverage, Response Time & Emergency Service:

1. All PM/emergency service repairs will be performed during normal hours of coverage (unless emergency after-hours service is requested). Emergency service after hours will be performed only when requested by COR, Biomedical Engineer or VA’s designated alternate in the using service. Emergency after hours service will be billed at () $__________ per hour or ( ) $__________ per incident. Billing will include time on-site only, i.e., labor costs; travel time will not be covered. When emergency after hours service is authorized, Contractor may be issued a VA purchase order to cover costs associated with applicable repairs (labor only, parts are already included – see Parts section in this document). Work performed outside normal hours of coverage without approval will be considered service during normal hours of coverage.

2. Normal hours of coverage for emergency service repairs or PM are Monday through Friday from 8:00AM to 5:00PM excluding Federal holidays. Federal holidays are: New Year’s Day, Martin Luther King Day, Presidents day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas day.

3. Contractor will provide a 24-hour telephone number for emergency service assistance. Contractor is responsible for notifying VA immediately if the 24-hour telephone number for emergency service is changed. Contractor will provide software phone support if requested.

4. Contractor will respond to all emergency service or emergency after-hours service calls by phone normally within two (2) hours, but no more than four (4) hours. Contractor will provide an on-site response time of no more than four (4) hours or next business day if call is made after 1:00 p.m. and be required to repair the system and place it back in service within twenty-four (24) hours after notification by telephone call (unless another specified time is agreed to by the VA representative placing the emergency call request). Above referenced response times are applicable to emergency service calls during normal working hours and emergency after-hours service when requested. Response time is defined as time vendor is first notified until the time vendor arrives on station. Failure to meet the required on-site response or repair time will allow the Government an option to contact a third-party vendor to provide services. Costs for services provided by a third-party vendor shall be billed against the Contractor. For each failure by the Contractor to respond to service calls or repair the equipment per the above procedures, a deduction of 1/22 of the monthly rate will be taken for each day equipment is inoperable. Furthermore, failure to perform any of the services as set forth in this contract will be considered for invoking provisions of Default.

Safety and License Requirements:

1. Contractor shall obtain all necessary licenses and permits required to perform this work. Contractor shall take all precautions necessary to protect persons and property from injury and/or damage during performance of this contract. Contractor shall be responsible for any injury to their employees as well as for any damages to personnel or Government property that occurs during the performance of this contract that is caused by the Contractor’s fault or negligence. Contractor shall insure that all areas where equipment is serviced under this contract are left in a clean, neat and orderly condition.

2. Contractor shall provide a current copy of the calibration certificates of all test equipment used to calibrate or adjust VAMC-Atlanta equipment upon request of the Contracting Officer and/or COR. Calibration of test equipment shall be traceable to the National Institute of Science and Technology (N.I.S.T.).

3. Contractor’s service personnel shall follow all applicable hospital policies while on site, i.e. smoking, sexual harassment, etc. The Contracting Officer and/or the COR reserve the right to remove any of the Contractor’s personnel and refuse them permission to work on VAMC-Atlanta equipment for serious violations of hospital policies.

4. Contractor’s service personnel shall wear visible identification while on the premises of the VAMC-Atlanta. A picture ID is preferred.

Removal of Equipment for Off-site Repairs:

1. Approval of the Biomedical Engineer or COR must be obtained before removing equipment to the Contractor’s location. A service ticket noting equipment description and other identification information signed by the authorization service personnel shall be provided to the Biomedical Engineer or COR before system is removed from the VAMC-Atlanta.

2. No transportation charges will be allowed for either repair or shipping the component to/from the Contractor’s plant. Contractor will be responsible for any damage or loss of equipment, to/from Contractor’s plant.

3. No component containing Personal Healthcare Information (PHI) shall be removed from the VAMC Atlanta. Refer to Information Security/Privacy section of this document for additional information.

Competency of Personnel Servicing Equipment:

1. The Contractor will provide written assurance of the competency of their personnel and a list of credentials of approved service personnel for each model the Contractor services at the VAMC-Atlanta to the Contracting Officer and/or the COR within 10 days after contract award. Contractor will revise this documentation whenever service personnel are assigned or re-assigned to the VAMC-Atlanta site.

2. The Contracting Officer or COR reserve the right to request authentication of factory training certificates or credentials from the Contractor at any time for any personnel who are servicing VAMC-Atlanta equipment.

3. VAMC-Atlanta specifically reserves the right to reject any of the Contractor’s personnel and refuse them permission to work on VAMC-Atlanta equipment.

E. CHANGES TO STATEMENT OF WORK

Any changes to this SOW shall be authorized and approved only through written correspondence from the CO. A copy of each change will be kept in a project folder along with all other products of the project. Costs incurred by the contractor through the actions of parties other than the CO shall be borne by the contractor.

F. REPORTING REQUIREMENTS

1. Upon completion of preventive maintenance (PM) inspection and/or emergency repair the Contractor shall leave a copy of the service report with the using service, and submit to the same location as designated above a service report annotating what repairs, service, calibration, etc., were performed and whether preventive maintenance was done. Each service report shall include the name of the contractor, name of Field Service Engineer (FSE), date, time (starting and ending), equipment downtime, hours of labor including costs (when emergency service is authorized outside of normal working hours), the parts utilized including costs, VA purchase order # (when emergency service is authorized outside of normal working hours), the nature of the problem, the nomenclature of the item repaired (serial number & VA inventory number), and the room number where system is located. The service designee and the FSE attesting that the system is in satisfactory working order and is functioning at an acceptable level of performance shall sign this report. The contractor shall sign out at the designated location before leaving. NOTE: Failure to furnish a service report or obtain a signed copy of the service report could result in delay of payment or non-payment.

G. CONTRACTOR EXPERIENCE REQUIREMENTS

The government will determine on a SR basis what positions are considered key personnel. The contractor shall identify, by name, the key management and technical personnel who will work under this task order at the time the work is being negotiated.

If a key person becomes unavailable to complete the SR, the proposed Substitutions of key personnel shall be made only as approved directed by the Contracting Officer and the COR. The government will not dictate specific experience and education requirements of the employees initially proposed to perform the work stated herein. The contractor shall submit a resume of qualifications for the COR and all other direct employees proposed for the project. All Contractor employees will be approved by the COR prior to bringing on duty. If, at any time from date of award to the end of the contract, non-key personnel Contractor personnel are no longer available, HES/HIS reserves the right to review the qualifications of the proposed replacement personnel and to reject individuals who do not meet the qualifications set forth in the TLO. Team personnel proposed by the contractor should possess some of the following knowledge and/or skills:

The contractor must notify VHA in advance and we will approve or reject proposed contractor key personnel for the performance of this contract. The contractor shall submit a resume of qualifications to the COR for key personnel and all other direct employees proposed for the project. All Contractor employees will be approved by the COR prior to bringing on duty. If, at any time from date of award to the end of the contract, Contractor personnel are no longer available, the VHA will approve the qualifications of proposed replacement personnel and will reject individuals who do not meet qualifications set forth herein. The contractor must inform the VHA COR, and Project Manager/Task Manager when personnel are removed from the contract for any reason. The Contractor shall remove any employee from the performance of this contract within five (5) workdays of receiving notice from the Contracting Officer that the employee's performance is unsatisfactory. All Contractor employees are subject to immediate removal from performance of this contract when they are involved in a violation of the law, VA security, confidentiality requirements and/or other disciplinary reasons.

· The contractor must inform the VHA COR, and Project Manager/Task Manager when personnel are removed from the contract for any reason.

· The contractor shall submit a resume of qualifications to the COR for all direct employees proposed for the project. All Contractor employees will be approved by the COR prior to bringing on duty.

H. CONFIDENTIALITY AND NONDISCLOSURE

It is agreed that:

1. The preliminary and final deliverables, and all associated working papers, application source code, and other material deemed relevant by VA which have been generated by the contractor in the performance of this task order, are the exclusive property of the U.S. Government and shall be submitted to the CO at the conclusion of the task order.

2. The CO will be the sole authorized official to release, verbally or in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this task order. No information shall be released by the contractor. Any request for information relating to this task order, presented to the contractor, shall be submitted to the CO for response.

3. Press releases, marketing material, or any other printed or electronic documentation related to this project, shall not be publicized without the written approval of the CO.

I. INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY

General

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

Contractor shall be required to enter into and sign a Business Associate Agreement upon award of contract unless a national BAA exists.

Access to Information and Information Systems

1. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

2. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

3. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

4. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

5. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

Information Custody

1. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

2. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures follow VA directive requirements.

3. The Certification & Accreditation (C&A) requirements do not apply, and a Security Accreditation Package is not required:

4. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

5. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

6. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

7. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

8. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.

9. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

10. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

11. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (I) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.

12. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.

13. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.

Information System Hosting, Operation, Maintenance, or Use

1. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.

2. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.

3. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.

4. The contractor/subcontractor’s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process. The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.

5. The contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

6. VA prohibits the installation and use of personally owned or contractor/subcontractor-owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.

7. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.

8. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:

1. Vendor must accept the system without the drive;

2. VA’s initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or

3. VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.

4. Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;

a. The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and

b. Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the purchase order or contract.

c. A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed. The ISO needs to maintain the documentation.

Security Incident Investigation

1. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

2. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

3. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

4. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

5. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $______ per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

a. Notification;

b. One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

c. Data breach analysis;

d. Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

e. One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

f. Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

Security Controls Compliance Testing

On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract. With 10 working-day’s notice, at the request of the government, the contractor must fully cooperate and assist in a government-sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.

Training

1. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

2. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems:

a. Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

b. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

c. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access.

3. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are completed.

J. CONTRACTOR RULES OF BEHAVIOR

This User Agreement contains rights and authorizations regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the Department of Veterans Affairs (VA). This User Agreement covers my access to all VA data whether electronic or hard copy ("Data"), VA information systems and resources ("Systems"), and VA sites ("Sites"). This User Agreement incorporates Rules of Behavior for using VA, and other information systems and resources under the contract.

General Terms And Conditions for All Actions And Activities Under the Contract

1. Understand and agree that there is no reasonable expectation of privacy in accessing or using any VA, or other Federal Government information systems.

2. Consent to reviews and actions by the Office of Information & Technology (OI&T) staff designated and authorized by the VA Chief Information Officer (CIO) and to the VA OIG regarding access to and use of any information assets or resources associated with the performance of services under the contract terms with the VA. These actions may include monitoring, recording, copying, inspecting, restricting access, blocking, tracking, and disclosing to all authorized OI&T, VA, and law enforcement personnel as directed by the VA CIO without prior consent or notification.

3. Consent to reviews and actions by authorized VA systems administrators and Information Security Officers solely for protection of the VA infrastructure, including, but not limited to monitoring, recording, auditing, inspecting, investigating, restricting access, blocking, tracking, disclosing to authorized personnel, or any other authorized actions by all authorized OI&T, VA, and law enforcement personnel.

4. Understand and accept that unauthorized attempts or acts to access, upload, change, or delete information on Federal Government systems; modify Federal government systems; deny access to Federal government systems; accrue resources for unauthorized use on Federal government systems; or otherwise misuse Federal government systems or resources are prohibited.

5. Understand that such unauthorized attempts or acts are subject to action that may result in criminal, civil, or administrative penalties. This includes penalties for violations of Federal laws including, but not limited to, 18 U.S.C. §1030 (fraud and related activity in connection with computers) and 18 U.S.C. §2701 (unlawful access to stored communications).

6. Agree that OI&T staff, in the course of obtaining access to information or systems on the contractor’s behalf for performance under the contract, may provide information about contractor personnel including, but not limited to, appropriate unique personal identifiers such as date of birth and social security number to other system administrators, Information Security Officers (ISOs), or other authorized staff without further notifying me or obtaining additional written or verbal permission from me.

7. Understand contractor must comply with VA’s security and data privacy directives and handbooks. Understand that copies of those directives and handbooks can be obtained from the Contracting Officer's Technical Representative (COR). If the contractor believes the policies and guidance provided by the COR is a material unilateral change to the contract, the contractor must elevate such concerns to the Contracting Officer for resolution.

8. Contractor will report suspected or identified information security/privacy incidents to the COR and to the local ISO or Privacy Officer as appropriate.

General Rules of Behavior

1. Rules of Behavior are part of a comprehensive program to provide complete information security.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .