36C24819Q0511-001.pdf

PDF 234 KB Posted

Attached to
Clinical Communication System Federal contract opportunity
Solicitation number
36C24819Q0511
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 8

About this file

36C24819Q0511 Attachment A - Statement of Work.pdf

View the file

Other files for this federal contract opportunity

Other files attached to Clinical Communication System, newest first.
File Type Posted
36C24819Q0511-0002000.docx DOCX document
36C24819Q0511-0001000.docx DOCX document
36C24819Q0511-003.pdf PDF
36C24819Q0511-000.docx DOCX document
36C24819Q0511-002.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT A

STATEMENT OF WORK HEALTHCARE COMMUNICATION SYSTEM

Brand Name or Equal Referenced Manufacturer: Vocera

1. Background

The procurement of a clinical communication system for C.W. Bill Young VA Medical Center

(CWBYVAMC) campus of Bay Pines VA Healthcare System (BPVAHCS). This would include the integration of 677 badges to the existing nurse call system, Rauland‐Borg Responder 5 at

CWBYVAMC. Integration will be conducted during normal business hours M‐F, 0700 – 1630, excluding Federal Holidays.

Objectives:

Objective 1: Obtain a hands‐free method for health care and support team members to communicate with each other across the facility.

Objective 2: Obtain a system that provides a means of obtaining measurable data, that can lead to communication process improvements.

Objective 3: Obtain a system that offers immediate communications and needs identification between healthcare providers and patients across the organization.

Objective 4: Obtain a system that offers the ability to integrate with various biomedical and communication devices.

Objective 5: Obtain a system that offers immediate mass multi department notification capabilities.

Objective 6: Obtain a system that offers a single method for facility wide, notifications and communication.

2. Project Scope

Provide a hands‐free communication system to be deployed in the following 29 nursing units/departments:

1. MED RESPIRATORY

2. CATH LAB

3. SPS

4. ASU; OSC

5. OPERATING ROOM

6. 3D (Med‐Surg)

7. TRANSPORT

8. 5B (Med‐Surg)

9. SICU

10. MED SPECIALTY CLIN

11. 5A (Med‐Surg)

12. 4A (Med‐Surg)

13. EMERGENCY DEPT

14. MICU

15. MH OUTPATIENT (Mental Health)

16. GI LAB

17. INFUSION

18. MENTAL HEALTH BLDG. 111

19. MOD‐A‐D (4 X primary care clinics)

20. HEMODIALYSIS

21. CHEMO CLINIC

22. PACU

23. HOSPICE

24. ORTHO CLINIC

25. INTERVENTIONAL RADIOLOGY

26. FLOW CENTER

27. CLC West

28. CLC Central

29. CLC East

Other areas to be determined by Nursing Operations

The Communication System will be integrated with the Bay Pines current third‐party systems, indicated in the table below, for the purpose of secondary alarm and event notification delivery to the communication device. Alarm and event notification will be designed, configured and deployed in the following 28 nursing units:

1. MED RESPIRATORY

2. CATH LAB

3. SPS

4. ASU; OSC

5. OPERATING ROOM

6. 3D

7. 4A

8. SICU

9. MED SPECIALTY CLIN

10. 5A/5D

11. 5B

12. EMERGENCY DEPT

13. MICU

14. MH OUTPATIENT (Mental Health)

15. GI LAB

16. INFUSION

17. MENTAL HEALTH BLDG. 111

18. MOD‐A‐D (4 X primary care clinics)

19. HEMODIALYSIS

20. CHEMO CLINIC

21. PACU

22. HOSPICE

23. ORTHO CLINIC

24. INTERVENTIONAL RADIOLOGY

25. FLOW CENTER

26. CLC (All 3 units)

All three CLC units will share a single common workflow.

Stat Orders notifications will be configured for the following nine (9) units on:

1. Respiratory

2. 3D

3. 4A

4. 5A/5D

5. 5B

6. SICU

7. Inpatient Mental Health

8. MICU

9. CLC (All 3 units)

GetWell Network notifications will be configured for the following eight (8) nursing units:

1. 3D

2. 4A

3. 5A/5D

4. 5B

5. Hospice

6. MICU

7. SICU

8. CLC (All 3 units)

Staff assignments for alert routing will be managed in the Staff Assignment application. This alarm integration configuration supports the delivery of a nurse call alarm or event to the device as a text message notification. All alarm escalation workflow configurations are managed by the timeout escalation and retries settings established in the middleware platform.

3. Specifications Bay Pines VA is currently upgrading communication systems in inpatient areas to facilitate a more effective response time for patient care needs. Currently, Cisco VOIP phones are being used as a communication device. This system is not meeting the current needs of the facility. The solution must include:

• The solution includes the ability to initiate a call to a “panic group” directly from the device with the touch of a button ensuring safety of Responders, Social Service Assistant’s, etc.

• Additionally, this solution enables sending secure text messages which can be sent from the console to users on the badge or to other console users. This streamlines critical communication, allowing workers to instantly communicate with other staff using either voice or text messaging.

• The hands‐free “Badge” is FIPS 140‐2 certified for use on the VA Wi‐Fi network.

• The Communication Solution includes a hands‐free option; a voice controlled, wearable and lightweight communication device. This allows for increased mobility and greater practicality and productivity for workers whom often need to complete multiple tasks simultaneously.

• The Communication Solution enables voice calls to individuals, roles and teams/groups (e.g.

Executive Leadership or Supervisors) without having to know who is on shift, what number to call or where they are located. The solution can maintain an unlimited amount of these groups to eliminate the need to program groups ad hoc. This saves staff time and frustration associated with keeping up to date on‐call schedules and ensures that every call reaches its desired end‐point.

• Any, and all calls will capable of automatic escalation to a pre‐designed call flow path leading to no calls going unanswered. Customer‐defined workflows can be used to escalate calls to other users, groups, internal desk extensions and external numbers whenever the initial recipient is not available. The customer’s workflow defines how calls move to the appropriate backup in a timely fashion ensuring safety and satisfaction as well as communication efficiency.

• Has the ability to interrupt a busy device upon the request of an urgent call (permission based), i.e. Broadcasting an alert of an Active Shooter.

• Has the ability to initiate a “push to talk” session within a department or group of callers that allows all members to speak and hear the call.

• The Communication Solution will incorporate permission‐based controls for placing and receiving calls from a pre‐approved list of phone numbers, extensions, and pagers.

• The Communication Solution includes the ability to call any department or by name without knowing the extension number, eliminating time, steps, and the need to leave one’s workspace.

• Has the ability to enable off site users to participate in system commands such as calling by name or job function. For example, a Responder can place a call to “Supervisor” from anywhere outside the facility

• Has the ability to enable “permission based” calls to and from an outside number.

• Has the ability to enable calls to and from a landline extension in the facility.

• The hands‐free device incorporates anti‐microbial material to inhibit the growth of bacteria, mold and fungi.

• The Communication Solution has a Device Management reporting mechanism to minimize device loss.

• The solution has the ability to leave a voice message for a user or group of users that can be retrieved when logging back into the system from any device.

• The Communication solution does include a central monitoring visibility of user presence, allowing someone to view individual staff availability via a web‐based application used by staff coordinators and administrators to quickly and accurately view staff presence information and make staff assignments for dynamic role‐based groups.

• The solution is “User Centric”, not “device centric”. Upon log‐on, all profiles and privileges are automatically assigned to the device including roles/functions, group memberships and system settings. All these settings will reside on the server and be independent of the individual device.

• The solution includes the ability to load an application on a smartphone. This application enables the users to access all the functionality above (other than hands‐free answering).

o Can be used on VA Wi‐Fi or outside on the cell network enabling communication regardless of location o Additionally, encrypted messages can be sent and received from the console or other smartphones and tablets.

o Templates can be included to standardize communication between these devices o All the contacts and groups can from the Voice component are available for the encrypted message portion of the application.

Integration Platform and Workflow

The solution must include event‐driven alarm and alert management

• Data Aggregation‐aggregates data from multiple data sources simultaneously pulling data from patient monitors, the EMR, ADT, and lab systems and stages data in preparation for inclusion with alerts or alarms.

• Clinical Context ‐ Aware Event Response ‐ provides context about the alarm/event and the corresponding patient. This context is automatically provided when collaborating with care team members. This enables the clinician receiving alarms/events to be better prepared to respond to the patient event. This eliminates the need for the clinician to have to find a computer, login, find the patient and look in their EMR for the context they need in order to best respond to the event. This value Add alone is credited with saving 700 clinical FTE hours per unit per year at one of our customer sites.

• Multi‐Variable Advanced Rules Engine ‐ When an event or alarm is triggered, the Advanced Rules Engine can determine the appropriate context to deliver with the alarm, and also determine who the best caregiver is to notify depending on availability or “presence” in addition to caregiver assignment and role.

• Integrated Secure Messaging ‐ automatically prioritizes alarms (highest), alerts, and ad‐hoc secure messaging (lowest). When responding to critical events, integrated secure messaging enables the primary care giver to add one or more care team members to the alarm/alert “conversation”, thereby giving them access to the alarm/alert and the clinical context presented with it. Now, the messaging between the care team can focus on their response rather than on typing out the relevant patient name, patient demographics, room location, and context information –saving time and eliminating errors.

• Communication Device Interoperability ‐ facilitates alert, alarm and messaging between all FIPS‐140‐2 FACILITY approved VoIP and Smartphone devices.

Project Details – Voice

1. Project Management and Deployment Planning Services A Project Manager will be assigned to this project at order acceptance. Project scheduling requests for project kick‐off and other engagement activities, including but not limited to, workshop; call flow design; installation and implementation; end user training and go‐live services; as well as the required resources for these project activities, can only be committed by the assigned Project Manager.

The Project Manager will schedule a project kick‐off call with Bay Pines Project Management Team to officially initiate the project, review the scope of services to be provided, introduce team members, set expectations and develop a communications plan.

2. Performance Assessment Services Professional Services Milestone: Delivery of Assessment Report

Will conduct up to nine (9) days of on‐site readiness assessment of your wireless network covering a maximum of 905,800 square feet at Bay Pines VA Health Care System. The assessment is performed to ensure that the network infrastructure can support the Communications System, and the server hardware and software configuration. The WIFI coverage assessment will be completed after implementation in all areas covered within the scope of this project.

The solution will provide a comprehensive report to the Customer at the conclusion of the Performance Assessment. The Wireless Assessment for Performance Report will include:

• Assessment Results

• Network Topology Summary

• Data Capture Inventory and Procedure

• Findings and Recommendations

3. Workshop and Call Flow and Staff Assignment Design Services Professional Services Milestone: Delivery of the Workshop and Design Report

3.1 The solution will facilitate a workshop with the key stakeholders, including Customer’s executive sponsor, project manager, key clinical, IT, and telecommunications staff.

3.1.1 The solution will review policies and best practices for long‐term deployment success, specifically:

• Clinical and IT team sponsorship / roles

• Project Methodology

• Overview and Demonstration of the solution

• Goals, Objectives and Metrics

• Design Process

• Training and Go‐Live

• Best Practices for Success

3.2 The Workshop will be scheduled as an on‐site activity and should be scheduled for up to a maximum of three (3) hours.

3.3 The solution will conduct a series of call flow design sessions and develop the clinical design specification for up to a maximum of 29 nursing units. The design sessions will consist of clinical call flow analysis to develop clinical roles, groups, forwarding, naming conventions, and permanent and temporary group parameters. The solution will produce a Clinical Design specification describing the clinical group and department call flows.

3.4 The solution will document, design and develop patient room groups as applicable for the Staff Assignment application, allowing end user association with room/group roles nested within the call flow design. The Staff Assignment application will be documented, designed, and developed for up to a maximum of 29 nursing units.

4. Database Development Services Professional Services Milestone: Delivery of the Database

4.1 Upon Customer review and approval of the Clinical Design specification and completion of the provided User List, the Implementation Engineer will develop and document the initial database and call flow requirements. The database may be comprised of the following elements:

4.1.1 Sites (Global is default for single site installations)

4.1.2 Groups

4.1.3 Users

4.1.4 Group Members

4.1.5 Address Book Entries

4.1.6 Access Points

4.1.7 Locations

4.1.8 Devices

4.2 If Customer requests Call Flow or Database design changes after initial review and approval of the Call Flow or submission of the User List, the request will be handled through a Change Order for required rework as a result of those changes.

5. System Installation, Configuration and Testing Services Professional Services Milestone: Delivery of the Post‐Installation Report

The Implementation Engineer will complete the following tasks:

5.1 Install and configure the most current GA release of solution software on the servers

5.2 Set‐up the stand‐alone Device Configuration Station with dedicated access point.

5.2.1 Configure up to 677 devices

5.2.2 Review device configuration with your Systems Administrator. Your Systems Administrator will configure additional devices if needed.

5.3 Assist your System Administrator with the initial database installation and configuration.

5.4 Install and configure a two‐node SIP Telephony Gateway (VSTG) array and validate the installation is successful.

5.4.1 Connect the VSTG to the Dialogic Media Gateway (DMG) for non‐IP enabled PBXs.

5.4.1.1 Bay Pines VA is responsible for the procurement and installation of the DMG.

5.4.2 Assist your IT staff with integrating SIP with your PBX and validate that SIP is configured to operate in your environment.

5.5 Install and configure the Report Server.

5.6 Any variation from the best practice System Installation, Configuration and Testing Services deployment model may result in additional work effort and require a Change Order for required work as a result of those changes.

5.7 Conduct end‐to‐end testing of the solution, including calls between the solution and phones, calls to pagers. Troubleshoot issues which may arise during the end to end testing.

5.8 The solution will provide a Post‐Installation Technical Report documenting the initial configuration of the system at the completion of the installation.

5.9 Provide hands‐on review for up to five (5) people on the functionality of the Systems Administration console, including device management and scheduled reporting capabilities. The administrator will get an overview of the system architecture and system features that provide maximum workflow benefits. The review session will provide insight into the administrative and reporting functionality of Report Server.

6. Administrator Knowledge Transfer Services Professional Services Milestone: Delivery of Certificate of Completion

6.1 Provide a comprehensive overview of the Communication System, including the system architecture and its key features, with details on how to administer, maintain, and optimize the system post‐implementation.

6.1.1 System Administration training services will be provided over two (2) consecutive calendar days for up to five (5) participants.

6.2 System Administration Training session will be delivered by the Solution Implementation Engineer and will include training labs to reinforce the training material provided to and covered with participants.

7. Technical Knowledge Transfer Services Professional Services Milestone: Delivery of Certificates of Completion

7.1 Provide a comprehensive overview of the Communication System, from a technical perspective, including system functionality and operating requirements.

7.1.1Technical training will be focused on the Application Server and SIP Telephony Gateway server and will cover:

7.1.1.1 Server hardware

7.1.1.2 Operating system

7.1.1.3 IP PBX

7.1.1.4 Wireless infrastructure

7.1.1.5 Wired IP infrastructure

7.1.2 Technical training services will be provided over two (2) consecutive calendar days for up to five (5) participants.

7.2 Technical Training sessions will be delivered by the Implementation Engineer and will include training labs to reinforce the training material provided to and covered with participants.

8. Training and Go‐Live Support Services Professional Services Milestone: Delivery of the Post‐Training Report The solution’s Clinical Informaticist will develop and deliver customized training at the point of use, focusing on the best practices for using and maintaining the solution. The solution will provide a maximum of 1,200 total seats of Instructor Lead Training (ILT) over 12 consecutive days.

8.1 Provide up to a maximum of 1,200 total seats of device ILT. Training services will include up to one (1) Train‐the‐Trainer sessions; and up to 80 ILT sessions.

8.1.1 Train‐the‐Trainer class size not to exceed eight (8) seats and will be scheduled for up to two (2) hours.

8.1.2 ILT class size not to exceed 15 seats and will be scheduled for up to 30 minutes.

8.1.3 Maximum number of ILT classes per day not to exceed seven (7).

8.1.4 Class attendees must come to class after having completed the device and Staff Assignment Computer Based Training (CBT) modules via the vendor’s solution or the Customer’s Learning Management System

8.1.5 Customer is responsible for monitoring CBT compliance.

8.2 Provide consultation on training strategies and best practices to meet the needs of Customer as well as on‐unit support during training days to support staff to effectively utilize the solution.

8.3 Customer Trainer(s) will train all remaining staff.

8.4 The solution will work with Bay Pines Project Management team to establish the training schedule.

8.5 The Clinical Informaticist will provide a Post‐Training Report to Bay Pines Project Management team.

9. Post‐Deployment Assessment Services Professional Services Milestone: Delivery of the Assessment Report The solution’s Professional Services will provide up to two (2) of post‐deployment assessment. The post‐ deployment assessment includes remote evaluation of reports, on‐site clinical walk‐throughs and clinical interviews. The assessment will examine end user satisfaction and congruency with workflow to identify areas of optimizing critical processes and user/system performance and includes:

• Support for the System Administrator to:

o Provide system reports to departmental managers o Ensure the System Administrator is proficient to run, schedule and interpret system reports o Provide Support for the End Users o Independently build database based on clinical process

• End user support through:

o Collaboration with clinical staff o Incorporating changes to or new clinical process – independent database built by

System Administrator

• Identifying support:

o Trainers

• Support for struggling staff:

o Refresher classes

• Provide rounding support:

o Talk with staff, charge nurses and managers as available o Identify user issues (frustrations) and what is working well o Refresher training on broadcast feature

• Analysis, recommendations and communications to the deployment team o Debrief (review of findings) o Written report

The solution will provide a Post‐Deployment Assessment report documenting findings and recommendations.

Project Details – Integration

10. Third Party System Integration – Secondary Alarm Notification

10.1 Alarm Integration: Server Installation Services

Professional Services Billing Milestone: Delivery of Server Login Verification

10.1.1 Deliver hardware (if applicable) and software to the customer. Once in place, The Implementation Engineer will remotely build the technical architecture and work with the third‐party vendor representative(s) to configure the alarm data output connection to communicate with the solution.

10.1.1.1 The solution will remotely work with the third‐party vendor representative(s) to enable nurse call system caregiver call‐back functionality (if applicable).

10.2 Alarm Integration – Workflow Analysis, Integration Workshop and Design Services Professional Services Milestone: Delivery of the Integration Design Workbook

10.2.1 Conduct on‐the‐unit workflow analysis in the nursing units that will integrate third party alarm notifications for presentation on the communication device.

10.2.2 Facilitate a workflow design session to develop the integrated clinical design specifying the alarms; the routing of selected alarms to the appropriate caregiver role; the escalation of alert notifications and alert enunciation and presentation on the device. Design will be performed for:

1. Respiratory

2. 3D

3. 4A

4. 5A/5D

5. 5B

6. SICU

7. Inpatient Mental Health

8. MICU

9. CLC (All 3 units)

GetWellNetwork will integrate with:

1. 3D

2. 4A

3. 5A/5D

4. 5B

5. SICU

6. Inpatient Mental Health

7. MICU

8. CLC (All 3 units)

10.2.3.1 The three (3) CLC nursing units will share a single workflow.

10.3 Alarm Integration: Configuration and Testing Services Professional Services Billing Milestone:

Delivery of Technical Checklist

10.3.1 The Implementation Engineer will remotely build the custom configuration based on the customer’s agreed upon clinical design.

10.3.2 Upon configuration completion, the Implementation Engineer will coordinate with the customer to test the system remotely and onsite to ensure that appropriate connections are made and information flow is per design.

10.4 Alarm Integration: User Acceptance Testing Services

Professional Services Billing Milestone: User Acceptance Testing Sign‐Off

10.4.1 Conduct testing with clinical and technical stakeholders for each nursing unit to demonstrate the customized event notification and alarm design configuration in a controlled, pre‐go live setting.

Both technical and clinical teams should participate in order to verify messages and alarms to phones and to obtain Customer approval prior to the general deployment.

10.4.1.1 The Clinical User Acceptance Testing (CUAT) is planned per nursing unit and will focus on a sampling of patient rooms to be tested rather than all rooms being tested.

10.4.1.2 All alerts that are chosen by the customer to dispatch through middleware will be demonstrated, providing the alert can be generated by the alarm system used to facilitate alarm generation.

10.4.2 Once the system has been verified and approved by the customer’s clinical leadership team, the solution will obtain signed approval of CUAT. The solution will debrief the hospital team (PM, clinical leadership, system admin) with the final analysis of the CUAT and discussions will focus on any issues/concerns, technical hurdles, validation of the system and next steps. A signed copy of the document will be left with each unit’s clinical leadership representative.

10.5 Alarm Integration: Alarm‐to‐Device Training and Go‐Live Support Services Professional Services Milestone: Delivery of Post‐Training and Go Live Support Report

10.5.1 Provide up to a maximum of 625 alarm‐to‐device training seats via 79 alarm‐to‐device training sessions to educate end users on the processes for receiving, processing, retrieving and deleting alert notifications on their device.

10.5.1.1 Training sessions should be scheduled for up to 30 minutes.

10.5.1.2 Alarm‐to‐device class size is not to exceed eight (8) seats.

10.5.2 Bay Pines Trainer(s) will train all remaining staff.

10.5.3 The solution will work with the customer to establish the training schedule.

10.5.4 Provide alarm‐to‐device go‐live support on each nursing unit as alarm delivery is activated.

Alarm‐to‐device go‐live support should be scheduled for up to two (2) hours per nursing unit.

Delivery: Delivery and acceptance is to be F.O.B Destination (FAR 52.247‐34) at the Veterans Affairs Medical Center, located at:

Bay Pines VA Healthcare System Bldg. 36 Warehouse 10000 Bay Pines Blvd.

Bay Pines, FL 33744

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE

1. VA INFORMATION CUSTODIAL LANGUAGE:

a. Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

b. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

c. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

d. All contractors, subcontractors, and third‐party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

2. SECURITY INCIDENT INVESTIGATION:

a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to

VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach.

Notifications need to be made in accordance with the executed business associate agreement.

d. In instances of theft or break‐in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

3. LIQUIDATED DAMAGES FOR DATA BREACH:

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non‐Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

4. SECURITY CONTROLS COMPLIANCE TESTING: On a periodic basis, VA, including the Office of

Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract. With 10 working‐days’ notice, at the request of the government, the contractor must fully cooperate and assist in a government‐sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.

5. TRAINING:

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete VA Privacy and Information Security Awareness and Rules of Behavior Training before being granted access to VA information and its system (unless the national Business Association Agreement supersedes this requirement).

i. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Rules of Behavior before being granted access to VA information and its systems.

b. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

The Certification and Accreditation (C&A) requirements do not apply and a Security Accreditation

Package is not required for this SOW.

Records Management Contract Language

The following standard items relate to records generated in executing the contract and should be included in a typical Electronic Information Systems (EIS) procurement contract:

1. Citations to pertinent laws, codes and regulations such as 44 U.S.C chapters 21, 29, 31 and 33;

Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228.

2. Contractor shall treat all deliverables under the contract as the property of the U.S. Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.

3. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records.

4. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.

5. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.

6. The Government Agency owns the rights to all data/records produced as part of this contract.

7. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

8. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974.

These policies include the preservation of all records created or received regardless of format

[paper, electronic, etc.] or mode of transmission [e‐mail, fax, etc.] or state of completion [draft, final, etc.].

9. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules.

10. Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub‐contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub‐contractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

File details come from the government source that posted it.