36C24722Q1087 RSO.pdf

PDF 566 KB Posted

Attached to
Radiation Safety Officer Federal contract opportunity
Solicitation number
36C24722Q1087
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 7

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

36C24722Q1087 09-30-2022

Shasheshe Goolsby 912-373-6123 10-05-2022

5:00PM EDT

Department of Veterans Affairs Carl Vinson VA Medical Center 1826 Veterans Blvd.

Dublin GA 31021

X 100

541690

N/A

X

See Delivery Schedule Department of Veterans Affairs Carl Vinson VA Medical Center 1826 Veterans Blvd.

Dublin GA 31021

Department of Veterans Affairs

FMS-VA-2(101)

Financial Services Center PO Box 149971 Austin TX 78714-9971

See CONTINUATION Page

Radiological Safety Officer (RSO) Services

POP:

Base: NOVEMBER 5, 2022 through NOVEMBER 4, 2023 Option Year 1: NOVEMBER 5, 2023 through NOVEMBER 4, 2024 Option Year 2: NOVEMBER 5,2024 through NOVEMBER 4, 2025 Option Year 3: NOVEMBER 5, 2025 through NOVEMBER 4, 2026 Option Year 4: NOVEMBER 5, 2026 through NOVEMBER 4, 2027

See CONTINUATION Page

X

Lasonja Harvey Contracting Officer, NCO 7 x

36C24722Q1087

Table of Contents

SECTION A .................................................................................... Error! Bookmark not defined.

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES ..................................... Error! Bookmark not defined.

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 PRICE/COST SCHEDULE

ITEM INFORMATION

B.3 DELIVERY SCHEDULE

SECTION C - CONTRACT CLAUSES

C.1 FSS RFQ INTRODUCTORY LANGUAGE

C.2 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000) ...11

C.3 VAAR 852.212-70 PROVISIONS AND CLAUSES APPLICABLE TO VA

ACQUISITION OF COMMERCIAL ITEMS (APR 2020)

C.4 VAAR 852.219-75 SUBCONTRACTING COMMITMENTS MONITORING AND

COMPLIANCE (JUL 2018)

C.5 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS

AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)

E.2 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (NOV 2021)

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C247

Shasheshe Goolsby, shasheshe.goolsby@va.gov

Department of Veterans Affairs

Tuscaloosa VA Medical Center

3701 Loop Road East

Tuscaloosa, Alabama 35404

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [x] Monthly

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

Statement of Work (SOW) Radiation Safety Officer (RSO)

The Contractor shall furnish all labor, material, supplies, equipment, and qualified personnel to provide on-site Radiation Safety Officer (RSO) support or services for the Tuscaloosa Veterans Administration Medical Center (TVAMC), under the terms and conditions stated herein and must adhere to VHA Handbook 1105.04, Fluoroscopy Safety, dated June 21, 2018, https://www.va.gov/vhapublications/ViewPublication.asp?pub_ID=7454

The RSO shall comply with radiation protection standards in 29 CFR 1910.1096 and immediately report any unsafe conditions with the potential to adversely impact the facility radiation workers or patients to the Imaging and Bio Medical Engineering supervisors. The X-ray units and radiation protection apparel in this contract are located at two locations:

1) Radiology Dept; Building 135, 2nd Floor; Tuscaloosa VA Medical Center 3701 Loop RD. Tuscaloosa, AL 35404

2) Dental Clinic; Building 1, 1st Floor; Tuscaloosa VA Medical Center 3701 Loop RD.

Tuscaloosa, AL 35404

GENERAL REQUIRMENTS

Period of Performance

1. The Government and the Contractor understand and agree that the services to be delivered under this contract by the Contractor to the Government are non-personal services and the parties recognize and agree that no employer-employee relationships exist or will exist under the contract between the Government and the Contractor’s employees. Performs physicist inspections on facilities’ radiological equipment (such as lead aprons, (1) CT machines, (2) X-ray machines, (1) Bone Density Scanner, (1) panoramic and (1) intra-oral x-ray) and provides findings and recommendations in a written report.

Base Year: 5 November 2022 – 4 November 2023

1st Option Period 5 November 2023 – 4 November 2024

2nd Option Period 5 November 2024 – 4 November 2025

3rd Option Period 5 November 2025 – 4 November 2026

4th Option Period 5 November 2026 – 4 November 2027 https://www.va.gov/vhapublications/ViewPublication.asp?pub_ID=7454

2. Hours of Work: This contract is a full-service contract to include all necessary support calls and services, five (5) days per week, between the hours of 8:00 AM and 4:30 PM, Monday through Friday, excluding weekends and Federal Holidays.

Contracting Officer’s Representative (COR):

1. No Government personnel, other than the Contracting Officer (CO), have the authority to change or alter these requirements. The COR shall clarify technical points or supply relevant technical information, but no requirements in this scope of work may be altered as a sole result of such verbal clarification.

2. Agency Contact: The Contracting Officer’s Representative (COR) for this contract will be Andrea Prewitt, Email: andrea.prewitt@va.gov or 205-554-2000 extension 2126.

SCOPE OF WORK

1. Performance

RSO will provide their own transportation to TVAMC and come as frequently as required at no additional cost to the government. RSO will provide written feedback on Personnel Dosimetry Badge readings to Supervisory DRT. RSO will not place limitations on the number of duplicates requested.

2. Mandatory Services to be Performed

a. The Radiation Safety Officer (RSO) will review the monthly Personnel Dosimetry Badges readings for the Radiology and Dental departments and report the compliance\noncompliance with recommendations, if necessary, to the Contracting Officer Representative (COR) in a written report within ten (10) business days. Performs physicist inspections on facilities’ radiological equipment (such as lead aprons, (1) CT machines, (2) X-ray machines, (1) Bone Density Scanner, (1) panoramic and (1) intra-oral x-ray) and provides findings and recommendations in a written report.

b. The RSO will be available for consultation by phone and email for issues such as patient and staff radiation exposures, radiation safety issues, machine QA, etc. The RSO will provide a monthly written report to the COR on these issues via e-mail.

c. The RSO will complete all training required of other VHA RSO Safety Officers.

Provide proof of training within 5 days of contract execution.

mailto:andrea.prewitt@va.gov

d. Review, update, and implement a written Radiation Protection Program policy compliant with the provisions of VHA NHPP, Nuclear Regulatory Commission (NRC), regulations and TVAMC local policies within 90 days of contract award.

Annually, the RSO shall review, update, and submit the program for renewal via email to the COR.

e. Observe radiation safety practice in the clinical environment and ensure compliance with TVAMC local policies, industry best practice and protocols in person once every 3rd month (quarterly) for 4 hours minimum. Within five (5) days of visit, provide a written report of observations via email to the COR.

f. The RSO will serve on the TVAMC Radiation Safety Committee as an active member, attend all meetings and participate in the meeting telephonically/virtually. Radiation Safety Committee is conducted on the 2nd Wednesday of every 3rd month (quarterly). The RSO will sign into the meeting, review, and approve meeting minutes.

g. In addition to the reporting requirements already stated herein, the Contractor shall maintain an internal record keeping system to document the work being performed.

3. Confidentiality and Nondisclosure It is agreed that:

1. The preliminary and final deliverables, and all associated working papers, application source code, and other material deemed relevant by VA which have been generated by the contractor in the performance of this task order, are the exclusive property of the U.S. Government and shall be submitted to the CO at the conclusion of the task order.

2. The CO will be the sole authorized official to release, verbally or in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this task order. No information shall be released by the contractor. Any request for information relating to this task order, presented to the contractor, shall be submitted to the CO for response.

3. Press releases, marketing material, or any other printed or electronic documentation related to this project, shall not be publicized without the written approval of the CO.

4. Security and Contingency Plan

The contractor shall provide a contingency plan in writing to the agency prior to the award of the contract for agency review which details how the contractor shall deal with unplanned events such as vehicle breakdowns, communication, transfer of materials, vehicle security, breach of security of documents, etc.

5. Quality Assurance

The VA may request, at any time, a quality assurance monitor related to security and customer service to ensure all agency regulations and scope of work is being met and is acceptable to the agency.

The contractor shall adhere to the VA policies and applicable to include guidelines designed to protect sensitive and confidential information from being disclosed to unauthorized parties and adhere to the Privacy Act and the HIPPA Privacy Rules and regulations. Examples of sensitive information include but are not limited to:

Individually identifiable medical, benefits, and personnel information; financial, budgetary, research, quality assurance, confidential commercial, critical infrastructure, investigatory, and law enforcement information.

Note: If required to be implemented at any time during the contract period, the contractor shall display an agency identification badge and photograph.

6. Contractor Personal Security Requirements

All contractor employees who require access to the Department of Veterans Affairs’ computer systems shall be the subject of a background investigation and must receive a favorable adjudication from the VA Office of Security and Law Enforcement prior to contract performance. This requirement is applicable to subcontractor personnel requiring the same access.

7. Procedures for Access

Access requirements to VA information systems by contractors and contractor personnel shall meet or exceed those requirements established for personnel as described in VHA directives. A written and signed request for user access by VHA management, or designee(s), constitutes management approval (sponsorship) to initiate a request for access to any sensitive automated information system. Access shall be granted to non- VA users only if the purpose for access meets criteria of the Privacy Act and VA Confidentiality Regulations and Transfer.

Any of the contractor’s personnel shall be required to sign-in before starting work under this contract and abide by the VA Computer Access Security Agreement and Confidentiality Agreement.

In the performance of official duties, the contractor’s personnel may regular access to printed and electronic files containing sensitive information, which must be protected under the provisions of the Privacy Act of 1974, HIPAA and other applicable Federal laws and regulations. The employee is responsible for:

1.Protecting that information from unauthorized release or from loss, alteration, or unauthorized deletion, and

2. Following applicable regulations and instructions regarding access to computerized files, release of access codes, etc. as set out in a computer access agreement which the employee signs.

8. Adherence to Information Security, Privacy, and Records Requirements

Upon completion or termination of the applicable contract(s) or agreement(s), return and/or destroy, at Covered Entity’s option, VA information gathered, created, received, or processed during the performance of the contract(s) or agreement(s). No data will be retained by Business Associate, or contractor, subcontractor, or other agent of Business Associate, unless retention is required by law and specifically permitted by Covered Entity.

As deemed appropriate by and under the direction of Covered Entity, Business Associate shall provide written assurance that all VA information has been returned to Covered Entity or destroyed by Business Associate. If immediate return or destruction of all data is not possible, Business Associate shall notify Covered Entity and assure that all VA information retained will be safeguarded to prevent unauthorized Uses or Disclosures.

Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor while performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

B.2 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM

NUMBE

R

DESCRIPTION OF

SUPPLIES/SERVIC

ES

QUANTIT

Y

UNI

T UNIT PRICE AMOUNT

12.00 MO ________________

Radiaological Safety Officer (RSO) Services Contract Period: Base POP Begin: 11-05-2022 POP End: 11-04-2023

Radiaological Safety Officer (RSO) Services Contract Period: Option 1 POP Begin: 11-05-2023 POP End: 11-04-2024

Radiaological Safety Officer (RSO) Services Contract Period: Option 2 POP Begin: 11-05-2024 POP End: 11-05-2025

Radiaological Safety Officer (RSO) Services Contract Period: Option 3 POP Begin: 11-05-2025 POP End: 11-04-2026

Radiaological Safety Officer (RSO) Services Contract Period: Option 4 POP Begin: 11-05-2026 POP End: 11-04-2027

GRAND TOTAL ________________

B.3 DELIVERY SCHEDULE

ITEM NUMBER QUANTITY

DELIVERY

DATE

0001-

SHIP TO: Tuscaloosa VA Medical Center 3701 Loop Road East Tuscaloosa, AL 35404

US

12.00 30 DAYS ARO

MARK

FOR:

Andrea Prewitt 205-554-2000 x2126 andrea.prewitt@va.gov

SECTION C - CONTRACT CLAUSES

C.1 FSS RFQ INTRODUCTORY LANGUAGE

The terms and conditions of the contractor's FSS contract (including any contract modifications) apply to all Blanket Purchase Agreements (BPA) and task or delivery orders issued under the contract as a result of this RFQ. When a lower price has been established, or when the delivery terms, FOB terms, or ordering requirements have been modified by the BPA or task/delivery order, those modified terms will apply to all purchases made pursuant to it and take precedence over the FSS contract. Any unique terms and conditions of a BPA or order issued under the contract that are not a part of the applicable FSS contract will govern. In the event of an inconsistency between the terms and conditions of a BPA or task/delivery order and the Contractor's FSS terms, other than those identified above, the terms of the FSS contract will take precedence.

C.2 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR

2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 60; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 30 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 5 years.

(End of Clause)

C.3 VAAR 852.212-70 PROVISIONS AND CLAUSES APPLICABLE TO VA

ACQUISITION OF COMMERCIAL ITEMS (APR 2020)

(a) The Contractor agrees to comply with any provision or clause that is incorporated herein by reference to implement agency policy applicable to acquisition of commercial items or components. The following provisions and clauses that have been checked by the Contracting Officer are incorporated by reference.

[X] 852.203–70, Commercial Advertising.

[] 852.209–70, Organizational Conflicts of Interest.

[] 852.211–70, Equipment Operation and Maintenance Manuals.

[] 852.214–71, Restrictions on Alternate Item(s).

[] 852.214–72, Alternate Item(s). [Note: this is a fillable clause.]

[] 852.214–73, Alternate Packaging and Packing.

[] 852.214–74, Marking of Bid Samples.

[X] 852.215–70, Service-Disabled Veteran-Owned and Veteran-Owned Small Business Evaluation Factors.

[X] 852.215–71, Evaluation Factor Commitments.

[] 852.216–71, Economic Price Adjustment of Contract Price(s) Based on a Price Index.

[] 852.216–72, Proportional Economic Price Adjustment of Contract Price(s) Based on a Price Index.

[] 852.216–73, Economic Price Adjustment—State Nursing Home Care for Veterans.

[] 852.216–74, Economic Price Adjustment—Medicaid Labor Rates.

[] 852.216–75, Economic Price Adjustment—Fuel Surcharge.

[] 852.219–9, VA Small Business Subcontracting Plan Minimum Requirements.

[] 852.219–10, VA Notice of Total Service-Disabled Veteran-Owned Small Business Set-Aside.

[] 852.219–11, VA Notice of Total Veteran-Owned Small Business Set-Aside.

[] 852.222–70, Contract Work Hours and Safety Standards—Nursing Home Care for Veterans.

[] 852.228–70, Bond Premium Adjustment.

[] 852.228–71, Indemnification and Insurance.

[] 852.228–72, Assisting Service-Disabled Veteran-Owned and Veteran-Owned Small Businesses in Obtaining Bonds.

[X] 852.232–72, Electronic Submission of Payment Requests.

[] 852.233–70, Protest Content/Alternative Dispute Resolution.

[] 852.233–71, Alternate Protest Procedure.

[] 852.237–70, Indemnification and Medical Liability Insurance.

[] 852.246–71, Rejected Goods.

[] 852.246–72, Frozen Processed Foods.

[] 852.246–73, Noncompliance with Packaging, Packing, and/or Marking Requirements.

[X] 852.270–1, Representatives of Contracting Officers.

[] 852.271–72, Time Spent by Counselee in Counseling Process.

[] 852.271–73, Use and Publication of Counseling Results.

[] 852.271–74, Inspection.

[] 852.271–75, Extension of Contract Period.

[] 852.273–70, Late Offers.

[] 852.273–71, Alternative Negotiation Techniques.

[] 852.273–72, Alternative Evaluation.

[] 852.273–73, Evaluation—Health-Care Resources.

[] 852.273–74, Award without Exchanges.

(b) All requests for quotations, solicitations, and contracts for commercial item services to be provided to beneficiaries must include the following clause:

[] 852.237–74, Nondiscrimination in Service Delivery.

(End of Clause)

C.4 VAAR 852.219-75 SUBCONTRACTING COMMITMENTS MONITORING

AND COMPLIANCE (JUL 2018)

(a) This solicitation includes the clause: 852.215-70 Service-disabled veteran-owned and veteran-owned small business evaluation factors. Accordingly, any contract resulting from this solicitation will include the clause 852.215-71 Evaluation factor commitments.

(b) The Contractor is advised that in performing contract administration functions, the Contracting Officer may use the services of a support contractor(s) to assist in assessing Contractor compliance with the subcontracting commitments incorporated into the contract. To that end, the support contractor(s) may require access to the Contractor's business records or other proprietary data to review such business records regarding contract compliance with this requirement.

(c) All support contractors conducting this review on behalf of VA will be required to sign an “Information Protection and Non-Disclosure and Disclosure of Conflicts of Interest Agreement” to ensure the Contractor's business records or other proprietary data reviewed or obtained in the course of assisting the Contracting Officer in assessing the Contractor for compliance are protected to ensure information or data is not improperly disclosed or other impropriety occurs.

(d) Furthermore, if VA determines any services the support contractor(s) will perform in assessing compliance are advisory and assistance services as defined in FAR 2.101, Definitions, the support contractor(s) must also enter into an agreement with the Contractor to protect proprietary information as required by FAR 9.505-4, Obtaining access to proprietary information, paragraph (b). The Contractor is required to cooperate fully and make available any records as may be required to enable the Contracting Officer to assess the Contractor compliance with the subcontracting commitments.

(End of Clause)

C.5 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT

2020) The Contracting Officer reserves the right to designate an Administrative Contracting Officer (ACO) for the purpose of performing certain tasks/duties in the administration of the contract.

Such designation will be in writing through an ACO Letter of Delegation and will identify the responsibilities and limitations of the ACO. A copy of the ACO Letter of Delegation will be furnished to the Contractor.

(End of Clause)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR

ATTACHMENTS

Department of Veterans Affairs VA HANDBOOK 6500.6 Washington, DC 20420 Transmittal Sheet

MARCH 12, 2010

CONTRACT SECURITY

1. REASON FOR ISSUE: This Handbook establishes the procedures to implement security policy, and communicate responsibilities and departmental framework for the Department of Veterans Affairs (VA) contracts and acquisitions.

2. SUMMARY OF CONTENTS/MAJOR CHANGES: This Handbook establishes VA’s procedures, responsibilities, and processes for implementing security in appropriate contracts and acquisitions. This Handbook applies to all VA Administration and Staff Offices and pertains to VA sensitive information which is stored, generated, transmitted or exchanged by VA, a contractor, subcontractor or a third party, or on behalf of any of these entities regardless of format or whether it resides on a VA system or contractor or subcontractor’s electronic information system(s) operating for or on the VA’s behalf.

3. RESPONSIBLE OFFICE: The Office of the Assistant Secretary for Information and Technology (OI&T) (005).

4. RELATED DIRECTIVE: VA Directive 6500, Information Security Program.

5. RESCISSIONS: None.

CERTIFIED BY: BY DIRECTION OF THE SECRETARY

VETERANS AFFAIRS:

/S/ /S/ Roger W. Baker Roger W. Baker Assistant Secretary for Information Assistant Secretary for Information and Technology and Technology Distribution: Electronic Only.

VA HANDBOOK 6500.6

MARCH 12, 2010

CONTRACT SECURITY

CONTENTS

PARAGRAPH PAGE

1.

PURPOSE/SCOPE……………………………………..………………………………………..

2. BACKGROUND...

3.

PROCEDURES

4. RESPONSIBILITIES

a. Secretary of Veterans Affairs

b. Assistant Secretary for Office of Information and Technology (AS/OI&T)

c. Assistant Secretary for Operations, Security, and Preparedness (AS/OSP)

d. Associate Deputy Assistant Secretary for Acquisition and Logistics Programs & Policy

e. Office of Inspector General (OIG)

f. Office of General Counsel (OGC)

g. Deputy Assistant Secretary for Information Protection and Risk Management

h. Associate Deputy Assistant Secretary of Cyber Security

i. Associate Deputy assistant Secretary for Risk Management & Incident Response .. 10

j. Associate Deputy Assistant Secretary of Privacy and Records Management

k. Under Secretaries, Assistant Secretaries, and Other Key Officials

l. Program Directors andFacility Directors, through the Information Security Officer

m. Information Security Officers (ISOs)

n. Local Privacy Officers

o. Local Program Managers-Information System Owners

p. Contracting Officers (COs)-Contracting Officer’s Technical Representatives (COTRs) 5.

REFERENCES

6.

DEFINITIONS

7. ACRONYM LIST

LIST OF APPENDICES

APPENDIX A: Checklist for Information Security in the Initiation Phase of Acquisition A- APPENDIX B: VA Acquisition Regulation Solicitation Provision and Contract Clause B-1 APPENDIX C: VA Information and Information System Security/Privacy Language for Inclusion into Contracts, as Appropriate C-1 APPENDIX D: Contractor Rules of Behavior D-1

VA HANDBOOK 6500.6

MARCH 12, 2010

CONTRACT SECURITY

1. PURPOSE AND SCOPE

a. This handbook establishes the security requirements, procedures, responsibilities, and departmental framework for ensuring that security is included in appropriate Department of Veterans Affairs (VA) contracts and acquisitions.

b. This handbook applies to all VA contracts in which VA sensitive information is stored, generated, transmitted or exchanged by a VA contractor, subcontractor or third-party, or on behalf of any of these entities regardless of format and whether it resides on a VA or a non-VA system, for the contractor, subcontractor, or third party to perform their contractual obligations to VA for the acquisition of goods or services where they stand in lieu of VA and act on VA’s behalf. Other agreements that involve disclosures of VA sensitive information (e.g., Business Associate Agreement (BAA), Data user Agreement (DUA), Data Transfer Agreement

(DTA),

Memorandum of Understanding (MOU), or sharing, executive, or computer matching agreements with another federal agency that is subject to FISMA) are outside the scope of this handbook and are not governed by these provisions.

2. BACKGROUND

a. The Federal Information Security Management Act (FISMA) (116 Stat. 2946, 2950) states that “each agency shall…provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.” Information security is an important business process and must be considered in all phases of an acquisition and contract life cycle to ensure that VA’s sensitive information and information technology assets are adequately protected. Failure to adequately address security in appropriate VA agreements or solicitations can jeopardize mission success and undermine public confidence.

Contracting Officials (CO) together with Chief Information Officers (CIO), Information Security Officers (ISO), Privacy Officers (PO), and legal counsel provide a valuable service in the acquisition and contracting process to help identify and mitigate security issues in solicitations, contracts, task orders, and third party agreements that involve VA’s sensitive information.

b. When relying on contractors, subcontractors, or third party servicers or associates, VA transfers operational responsibilities for performing one or more business functions (e.g., Information Technology (IT) services) to these partners. However, it still remains VA’s responsibility to ensure the protection of these assets is addressed via compliance with applicable security regulations and policy on the part of these partners and contractors.

c. In order to comply with FISMA and other Federal legislation, VA has established its Information Security Program by issuing VA Directive 6500 and its accompanying handbooks to assist in complying with this program. To ensure security is included in appropriate

VA

acquisitions and contracts, the following appendices are being issued with this Handbook to assist the field:

(1) Checklist for Information Security in the Initiation Phase of Acquisitions, Appendix A.

VA HANDBOOK 6500.6 MARCH 12, 2010

(2) VA Acquisition Regulation (VAAR) Solicitation Provision and Contract Clause, Appendix B.

(3) VA Information and Information System Security/Privacy Language for Inclusion into Contracts, as Appropriate, Appendix C.

(4) Contractor Rules of Behavior, Appendix D.

3. PROCEDURES

a. Information generated by a contractor or subcontractor as part of the contractor/subcontractor’s normal business operations, such as health record information created in the course of providing treatment or health care services to VA’s Veterans is subject to review to determine if the information is owned by VA and subject to VA security policy. VA sensitive information that has been properly disclosed by VA to the contractor is not subject to the VAAR security clause. If the information is not owned by VA, the requirements outlined in this Handbook do not apply and the VAAR security clause should not be added to the contract.

The CO, the PO, and if required, Regional Counsel can be consulted. VA OIG counsel will conduct the review for the OIG generated contracts.

b. VA requires that facilities and program offices ensure that contractors, subcontractors, and third-party servicers or associates, or on behalf of any of these entities, regardless of format or whether the VA information resides on a VA system or contractor/subcontractor’s electronic information system(s) operating for or on VA’s behalf, employ adequate security controls as appropriate in accordance with VA directives and handbooks, regulations, guidance, and established service level agreements.

c. Information security requirements must be considered in all phases or stages of VA’s procurement process. The applicable Program Manager, Information System Owner, and

Information Owner are responsible for ensuring that the solicitation document includes the appropriate information security and privacy requirements. The information security requirements must be sufficiently detailed to enable service providers to understand what is required. A general statement that the service provider must agree to comply with applicable requirements is not acceptable. See Appendix C for a catalog of security and privacy language statements that have been developed, reviewed, and approved and can be used in contracts, as appropriate. This language summarizes for the contractors the most important Federal and VA policy issues that need to be addressed, as appropriate, in contracts to ensure adequate security and privacy controls are included in the contract vehicle. Additional security or privacy language can be added, as required. Program managers, project designers, and acquisition professionals must take security requirements, measures, and controls into account when designing and making agency acquisitions; appropriate security controls drive requirements, specifications, deliverables, and costs. Acquisition staffs need to consult information security officials to determine what level of security and which security controls may be required in this process. VA Handbook 6500, Information Security Program, provides the security requirements and policy for VA.

VA HANDBOOK 6500.6

MARCH 12, 2010

d. The applicable VA Program Manager, Information System Owner, Information Owner, the CO, PO, ISO, and the Contracting Officer’s Technical Representative (COTR) are responsible for ensuring that VA information system security and privacy requirements, as appropriate, are implemented and complied with per the requirements detailed in the contract.

Compliance and Records Management Officers should also be contacted, as appropriate, to ensure the requirements and language they require are included in the contract.

e. VA requires that all facilities and program offices monitor information security control compliance of their respective contracts and acquisitions by doing the following:

(1) Adhere to the security and privacy contract language as outlined in the contracts.

(2) Ensure that COs work with their COTR, ISO, and PO and other applicable staff to complete Appendix A for all service acquisitions and contracts. This appendix assists in determining the security requirements for VA acquisitions and contracts during the planning phase of the acquisition process. The checklist must be included as part of the overall contract file by the CO for new service acquisitions and contracts and a copy must be maintained in the applicable contracts file and accessible to the COTR, ISO, and PO.

(3) Ensure that contracting officials include VA’s approved security clause, Appendix B, into any applicable contracts, if required as indicated by completing Appendix A. NOTE:

The security clause in Appendix B is currently undergoing official VA rulemaking by the Office of Acquisitions and Logistics (OA&L). The final version of the clause may be revised after it is presented to the public for review via the Federal Register.

(4) Ensure that contractors, third party partners, and servicers implement the VA security and privacy requirements, as defined in the contract. These requirements can also be added to the contract Statement of Work (SOW). The requirements apply to applicable contracts in which VA sensitive information is stored, generated, transmitted, or exchanged by VA, a contractor, subcontractor or a third-party, or on behalf of any of these entities regardless of format or whether it resides on a VA system or contractor or subcontractor’s electronic information system(s) operating for or on the VA’s behalf.

(5) Ensure that contractor systems that have negotiated with VA to store, generate, transmit, or exchange VA sensitive information in a contractor developed and maintained system are certified and accredited (authorized), and registered and monitored in VA’s Security Management and Reporting Tool (SMART) database that monitors FISMA compliance.

The Program Manager and/or the ISO is responsible for contacting the Information Protection and Risk Management’s (IPRM) Certification Program Office (CPO) within OI&T to register the system or to answer questions regarding the authorization of systems.

(6) Ensure that Certification and Accreditation (Authorization) (C&A), is accomplished in compliance with VA policy (per the results of the completed checklist provided in Appendix A) and VA Handbook 6500.3, Certification and Accreditation of VA Information Systems.

The OI&T CPO within the Office of Cyber Security (OCS) must be contacted regarding procedures for C&A (Authorization) of contractor managed systems.

(7) Ensure that the Program Manager, the COTR and the CO, with the assistance of the ISO, monitor compliance with the contract or agreement security requirements throughout the

VA HANDBOOK 6500.6 MARCH 12, 2010

life of the contract. For IT systems, this includes ensuring that annual self-assessments are conducted by the contractor with appropriate Plan of Actions and Milestones (POA&M) initiated and completed.

(8) Ensure that service providers and contractors who have negotiated agreements with VA that involve VA sensitive information, but do not maintain systems that require C&A, complete a Contractor Security Control Assessment (CSCA) within 30 days of contract approval and annually on the due date of the contract renewal. The ISO/COTR or CO can also request that a CSCA be completed by the contractor anytime there are potential security issues identified or suspected by VA or to ensure that applicable security controls are being implemented. The completion of the CSCA by the contractor is the responsibility of the

COTR.

The CSCA template is maintained on the IPRM portal under the C&A Section. The COTR can contact the ISO to obtain a copy of the CSCA from the portal or to seek assistance in the completion of the assessment. The completed CSCA must be provided and reviewed by the ISO and by the CPO to ensure that adequate security is being addressed by contractors in situations where the C&A of a system is not applicable. A copy of the CSCA is uploaded by the ISO and maintained in the document section of the SMART database.

(9) Ensure that contractors and third party servicers accessing VA information sign the Contractor Rules of Behavior, Appendix D. The VA National Rules of Behavior do not need to be signed if the VA Contractor Rules of Behavior” are signed.

(10) Ensure that contractors and third party service positions receive the proper risk level designation based upon the review of the Position Designation System and Automated Tool (PDAT) established by the Operations, Security, and Preparedness Office (007).

Background investigations of all contractors must adhere to the results of the PDAT per VA Directive and Handbook 0710, Personnel Suitability and Security Program.

(11) Ensure that contractors take the required security and privacy training as outlined in Appendix C.

(12) Ensure that all IT procurements, including contracts, are submitted through the IT Acquisition Request System (ITARS), VA’s acquisition approval system for review and approval as required by the VA CIO.

(13) Ensure that language is included in appropriate contracts to ensure new acquisitions include Federal Desktop Core Configuration (FDCC) settings and products of information technology providers operate effectively using them.

4. RESPONSIBILITIES

a. Secretary of Veterans Affairs has designated the CIO as the senior Agency Official responsible for ensuring enforcement and compliance with the requirements imposed on VA under FISMA.

b. Assistant Secretary for Office of Information and Technology (AS-OI&T) is responsible for:

VA HANDBOOK 6500.6

MARCH 12, 2010

(1) Providing leadership for the Department-wide information security program;

(2) Approving all VA policies and procedures that are related to information security;

and

(3) Authorizing a review process with assigned resources for the technical review of IT acquisitions, including contracts, to ensure that compliance with VA and Federal IT security standards and requirements are fulfilled per VA Directive and Handbook 6500.

c. Assistant Secretary for Operations, Security, and Preparedness (AS-OSP) has the authority to establish and maintain personnel security and suitability programs throughout the Department consistent with applicable laws, rules, regulations, and Executive Orders.

The responsibilities include:

(1) Providing broad departmental-wide direction, standards setting, coordination, and performance assessment for organization components within VA and develop policies, procedures, and practices relating to background investigations of employees and contractors and the determinations of risk and sensitivity levels of employee position descriptions.

(2) Implementing appropriate laws, rules, and regulations related to the personnel security and suitability program and taking actions to address and correct conditions that are noncompliant with applicable laws, rules, and regulations.

d. Associate Deputy Assistant Secretary for Acquisition and Logistics Programs and Policy is responsible for:

(1) Providing acquisition policy to VA COs, Program Managers (PM) and COTRs to facilitate implementation of VA’s information security program within the Department.

This applies to all contracts in which VA sensitive information is stored, generated, transmitted, or exchanged by VA;

(2) Ensuring policy requires that the approved VAAR security clause is included in all applicable contracts; and

(3) Ensuring policy requires the CO consult with the COTR and the ISO, as necessary to monitor contracts to ensure that all Federal and VA security and privacy requirements are being met per the contract.

e. Office of Inspector General (OIG) is responsible for conducting regular reviews of the security program to ensure that all Federal and VA security and privacy requirements are being met.

f. Office of General Counsel (OGC) is responsible for providing guidance to the field regarding the applicability of the provisions in this handbook to specific VA contracts and agreements, as requested.

g. Deputy Assistant Secretary for Information Protection and Risk Management has been designated by the VA CIO, under the provisions of FISMA, to be the VA Chief Information Security Officer (CISO) and responsible for establishing, managing, and directing the VA Information Security and Risk Management Program. These responsibilities include:

VA HANDBOOK 6500.6 MARCH 12, 2010

(1) Establishing, maintaining, and monitoring Department-wide information security policies, procedures, control techniques, training, and auditing requirements as elements of the Department’s Information Security Program; and

(2) Ordering and enforcing Department-wide compliance with and execution of any information security policy.

h. Associate Deputy Assistant Secretary for Cyber Security has been designated as the Deputy Chief Information Security Officer and is responsible for:

(1) Developing directives and handbooks to provide direction for implementing elements of the Information Security Program to all Department organizations; and

(2) Reviewing all policies and procedures related to information security under the management and oversight of other Department organizations.

i. Associate Deputy Assistant Secretary for Risk Management and Incident Response is responsible for providing incident response related to information security breaches throughout the Department.

j. Associate Deputy Assistant Secretary for Privacy and Records Management is responsible for:

(1) Providing guidance and procedures for protecting personally identifiable information (PII) as required by the Privacy Act of 1974;

(2) Providing oversight and guidance in order to ensure VA compliance with applicable privacy laws, regulations, and policies;

(3) Establishing VA requirements and providing guidance regarding the development, completion, and updating of Privacy Impact Assessments (PIA); and

(4) Ensuring that Privacy Awareness Training is provided and available for VA employees, contractors, volunteers, and interns.

k. Under Secretaries, Assistant Secretaries, and Other Key Officials are responsible for:

(1) Implementing the policies, procedures, practices, and other countermeasures identified in the Department’s Information Security Program that comprise activities that are under their day-to-day operational control or supervision;

(2) Coordinating with OI&T and the CPO to periodically test and evaluate information security controls that comprise activities that are under their day-to-day operational control or supervision to ensure effective implementation; and

VA HANDBOOK 6500.6

MARCH 12, 2010

(3) Developing mechanisms for communicating, on an ongoing basis, each workforce member’s roles and responsibilities specific to information security and privacy policies and practices to enhance VA’s security and privacy culture.

l. Program Directors and Facility Directors, through the ISO, are responsible for:

(1) Ensuring compliant implementation and providing the necessary support to the Information Security Program in their organizations to ensure the facility meets all applicable information security requirements mandated by VA policy and other Federal legislation (e.g., FISMA, Health Insurance Portability and Accountability Act (HIPAA); and

(2) Ensuring ISOs are fully involved in all new projects concerning the development or acquisition of systems, equipment, or services including risk analysis, security plans, Request for Proposals (RFPs), and other procurement documents that require the ISO’s participation.

m. ISOs are the agency officials assigned responsibility to ensure compliance with Federal security legislation and VA security directives and handbooks. The VA ISOs are responsible for:

(1) Supporting the Program Manager or Information System Owner during the requirements analysis phase by evaluating requirements and providing advice on appropriate security measures;

(2) Reviewing proposed SOWs to ensure that the resulting contracts and service providers sufficiently define information security responsibilities, provide a means to respond to information security problems, and include a right to terminate the contract if it can be shown that the contractor does not abide by the information security terms of the contract;

(3) Participating in the review and completion of Appendix A, Checklist for Information Security in the Initiation Phase of Acquisitions;

(4) Managing their local information security programs and serving as the principal security advisor to COTRs, COs, and PMs regarding security considerations in applications, systems, procurement or development, implementation, operation and maintenance, and disposal activities (e.g., life cycle management);

(5) Advising the PM or System Owners in coordinating the development and maintenance of information system security plans and contingency plans for contractor systems, as requested;

(6) Advising the PM or System Owners on the Certification and Accreditation (Authorization) process for applicable contractor systems;

(7) Assisting the COTR and CO in verifying and validating that appropriate security measures are implemented and functioning as intended in accordance with the contract or agreement provisions;

(8) Monitoring compliance with the security awareness and training requirements for each employee and contractor;

VA HANDBOOK 6500.6 MARCH 12, 2010

(9) Coordinating, monitoring, and conducting periodic reviews to ensure compliance with the Rules of Behavior requirement for each system information user;

(10) Serving as the primary point-of-contact for security awareness and training within their area of responsibility;

(11) Coordinating with the facility PO for the assurance of reasonable safeguards as required by VA policy, the HIPAA Privacy Rule as appropriate, and other Federal privacy statutes; and

(12) Consulting with the PO, as necessary, to monitor contracts to ensure that all Federal and VA privacy requirements are being met per the contract.

n. Local Privacy Officers (PO) are the agency officials assigned responsibility for managing the risks and business impacts of privacy laws and policies and they assist the ISO with the development and implementation of an information protection infrastructure for

VA

data. The VA POs assist by:

(1) Providing guidance for compliance with applicable privacy laws, regulations, and VA privacy policies, as required;

(2) Participating in the review and completion of Appendix A, Checklist for Information Security in the Initiation Phase of Acquisitions;

(3) Assisting PMs or Information System Owners and contractors in conducting PIAs, as required;

(4) Coordinating with and assisting ISOs with privacy-related issues in acquisition documents (i.e., SOWs, contracts, service agreements);

(5) Coordinating with COTRs and ISOs, as appropriate, to ensure that all privacy breaches involving VA sensitive information are reported to the VA-National Security Operations Center (VA-NSOC) within one hour of receipt of breach notification from the contractor;

(6) Coordinating with the appropriate facility officials, to restore or maintain compliance with the execution and administration of the BAA process, where applicable; and

(7) Monitoring the facility’s BAAs to determine if the business associate meets the terms of their BAA with the facility.

o. Program or Project Managers and Information Systems Owners who are requesting or managing a contract or service must determine whether contractors or third party servicers require information access (documents or electronic) in the accomplishment of the VA mission. Specifically, these individuals are responsible for:

VA HANDBOOK 6500.6

MARCH 12, 2010

(1) Identifying information security and privacy requirements…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .