36C24820Q1393_1.docx

DOCX document 53 KB Posted

Attached to
6515--IV PREP IV Workflow Management System - Pharmacy Federal contract opportunity
Solicitation number
36C24820Q1393
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 8

About this file

This document is a combined synopsis and solicitation for commercial items requesting quotes for an IV workflow management system. The Department of Veterans Affairs C.W. Bill Young VA Healthcare System has a need to purchase both software and hardware components for an IV workflow management solution. Quotes are due by September 11, 2020 via email. The government will make a firm-fixed price award from this solicitation under NAICS code 339113. The solicitation is a full and open competition with small businesses welcome to submit quotes. Responses must address all requirements in the statement of need, including gravimetric verification, inventory management, workflow efficiency, documentation, and remote pharmacist verification capabilities. The awarded solution must be installed by November 30, 2020 at sites in Bay Pines and Cape Coral, Florida.

View the file

Other files for this federal contract opportunity

Other files attached to 6515--IV PREP IV Workflow Management System - Pharmacy, newest first.
File Type Posted
36C24820Q1393 0001_1.docx DOCX document
S06 AMEND 36C24820Q1393 0001.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment C - Clauses 36C24820Q1393

Contract Opportunity Combined Synopsis/Solicitation Notice

PRODUCT SERVICE CODE

SUBJECT

CONTRACTING OFFICE'S

ZIP-CODE

SOLICITATION NUMBER

RESPONSE DATE/TIME/ZONE

ARCHIVE

DAYS AFTER THE RESPONSE DATE

RECOVERY ACT FUNDS

SET-ASIDE

NAICS CODE

CONTRACTING OFFICE

ADDRESS

POINT OF CONTACT

(POC Information Automatically Filled from User Profile Unless Entered)

DESCRIPTION

See Attachment

AGENCY'S URL

URL DESCRIPTION

AGENCY CONTACT'S EMAIL

ADDRESS

EMAIL DESCRIPTION

ADDRESS

POSTAL CODE

COUNTRY

ADDITIONAL INFORMATION

GENERAL INFORMATION

PLACE OF PERFORMANCE

* = Required Field Contract Opportunity Combined Synopsis/Solicitation Notice IV PREP IV Workflow Management System - Pharmacy 33744 36C24820Q1393 09-11-2020 3:00 pm

EASTERN TIME, NEW YORK, USA

N 339113 Department of Veterans Affairs Network Contracting Office 8 (NCO 8) Room 315, Bldg. 2 10,000 Bay Pines Blvd Bay Pines FL 33744 Contracting Officer Janice Fornaro janice.fornaro@va.gov 727-398-9335 C.W. Bill Young VA Healthcare System 10,000 Bay Pines Boulevard Bay Pines

FL

33744

USA

https://www.va.gov Department of Veterans Affairs janice.fornaro@va.gov Contracting Officer Synopsis/Solicitation

Action Code: Combined Synopsis Solicitation Document Type: RFQ

RFQ Number:36C24820Q1393
Posted Date:August 25, 2020
Response Date:September 11, 2020
Classification Code:6515
Set Aside:Full and Open Competition (Unrestricted)
NAICS Code:339113

Contracting Office Address:

Network Contracting Office (NCO) 8 ATTN: Janice Fornaro – Contracting Officer 10,000 Bay Pines Blvd Bay Pines FL 33744

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested and a written solicitation will not be issued. The Department of Veterans Affairs, C.W. Bill Young VA Healthcare System, Contracting Office, Bay Pines, FL, 33744, has a need to purchase IV Workflow Management Solutions (IVWMS), consisting of both software and hardware components. The RFQ number is 36C24820Q1393.

The government anticipates making an award as a firm-fixed price contract resulting from this solicitation. This combined synopsis solicitation Request for Quote (RFQ) and the provisions and clauses incorporated are those in effect through Federal Acquisition Circular FAC 2020-08 (08/13/2020).

The North American Industrial Classification System (NAICS) code for this procurement is 339113, standard size is 750 employees. The combined synopsis solicitation is: Full and Open Competition (unrestricted); however all small businesses are welcome to submit quotations. Responses shall be on an all or none bases, no partial submissions will be accepted. New product(s) only. The Government reserves the right to make no award at all. Quotes must be valid for 60 days.

All quotes are due by September 11, 2020; NLT 3:00 PM Eastern Standard Time (EST) via e-mail to: janice.fornaro@va.gov. Offers received after the exact time specified in the solicitation are considered late and, may at the discretion of the Contracting Officer, be considered if the action would not unduly delay the acquisition or are deemed to be in the best interest of the Government. All questions or inquires must be submitted no later than September 1, 2020; NLT 3:00 PM EST. Use RFQ “36C24820Q1393-Company Name” in the subject line when emailing quotes and questions. One amendment will be posted to answer all questions.

ATTACHMENTS:

Attachment A: Statement of Need (SON) Attachment B: Schedule Attachment C: Clauses

DEPARTMENT OF VETERANS AFFAIRS

Bay Pines VA Healthcare System Statement of Need

I. GENERAL REQUIREMENTS:

The Bay Pines VA Healthcare System (BPVAHCS) Pharmacy Department at 10,000 Bay Pines Blvd, Bay Pines, Florida and Lee County VA Healthcare Center at 2489 Diplomat Parkway East, Cape Coral, Florida have a need IV workflow management solutions (IVWMS), consisting of both software and hardware components. The Government anticipates a single award for a Firm Fixed Price Purchase Order and anticipates and award will be made by mid-September 2020. The IVWMS must provide increased medication safety through barcode scanning and gravimetric analysis. In addition, it must have the ability to track inventory, manage inventory, and help with inventory optimization using the automated system to track usage, help manage stock levels, and reduce waste. IVWMS must increase workflow efficiency by utilizing electronic tracking of logs, productivity, and drug data; to be used for reporting and regulatory purposes. The workflow solution must have barcode verification available, which allows for identification of correct drug, drug strength, diluent, and containers used during compounding. IVWMS must have Camera verification that is configurable to be optional or mandatory during compounding. Finally, it must also provide gravimetric verification of the final product. All IV compounding workflow must be electronically tracked, recorded, and must allow for remote pharmacist final verification. The IVWMS product must have the ability to customize labels, including color print, and offer compliance reporting. It must also proactively recommend remnant vial and returned dose utilization for inventory optimization.

II. BACKGROUND:

Veterans’ Health Administration (VHA) Directive 1108.12 establishes national policy regarding in-house compounding of sterile preparations for compliance with the United States Pharmacopeia Chapters 797 and 800 (USP <797> and USP <800>). The basis of these regulatory directives is to provide oversight and ensure safe compounding of sterile products. Barcode scanning, and gravimetric analysis, provides reduced errors, by electronically checking for correct drug and volume; along with tracking each item that is being compounded. This will prevent multiple notable cases of compounding errors, unclean compounding facilities, which could result in patient harm or death. The Institute for Safe Medication Practices (ISMP), along with The Joint Commission (TJC), and other federal regulatory agencies, have analyzed the incidents and have made changes to operational processes, along with safety recommendations related to compounding processes. The use of barcode scanning, gravimetric verifications, and monitored environmental and competency assessments have been widely recognized as best practices and gold standards.

III. INTRODUCTION:

Guided, gravimetric based IV workflow management systems (IVWMS) are designed to support pharmacy’s compounding operations for all preparation types, including IVs, hazardous and nonhazardous preparations, sterile and nonsterile preparations and oral syringes. The unique combination of software and hardware enables gravimetric analysis along with barcode verification to help provide safety and efficiency for your compounding preparations while ensuring medication safety, inventory management, workflow efficiency, documentation and analytics, robust, onsite implementation and support.

IV. SALIENT CHARACTERISTICS

· Must have gravimetric verification

· Must have real-time gravimetric and barcode variation simultaneously

· Must have dosing error detection to include incorrect selection of drug, diluent, or and final container

· Must have calculation of diluent and drug quantities required to compound prescribed admixtures

· Must have immediate error notification and step by step-by-step remediation

· Must be able to verify doses are prepared within the institutional tolerances

· Must be able to allow pharmacist verification of preparations remotely

· Must be able to perform in-line verification prior to mixing ingredients

· Must be able to provide final pharmacist ability to review/verify/validate admixture was prepared correctly

· Must be able to digitally capture preparation times and drug waste

· Must be able to require hard-stops during preparation process to prevent potential errors from moving forward in the IV compounding production workflow

· Must provide electronic documentation to include:

· Fully automated documentation and audit trail for each compounding procedure

· History of all prepared medications

· Preparation details (dose used, preparer, products used)

· Must provide guidance and safety checks to comply with USP guidelines

· Must provide 24/7 technical and customer support

· Must include barcode automation to track dates

· Must have remote visibility using an integrated camera

· Must have configurable workflow dashboard showing which compounds are currently being prepared, as well as history of recent preparations, to aid efficient operational workflow

· Must print final label after successful completion of preparation

· Must have standard and customizable reports with showing operational, inventory, and productivity data

· Must have the ability to track returned, unused IV preparations to be reused for new patient orders

· Must have the ability to integrate with Active Directory to allow for better User Management and security

· Must have a footprint that is limited and does not require significant clean room layout changes

· Must have current VA customers with published results in accredited industry journals

V. INSTALLATION, INCLUDING VERIFICATION/VALIDATION, TRAINING:

· The contractor shall provide all labor, equipment, tools, software frameworks, applications, licenses, installation, supervisor, and other items necessary to deliver and install fully functional equipment.

· The IVWMS will require installation in all the IV clean rooms, throughout the BPVAHCS system, including two units for the Lee County Healthcare Clinic.

· The contractor will provide formal system administration training. Training dates and time frame shall be determined by the VA and contractor.

· The contractor will provide software support.

· Verification of network connectivity between gravimetric system and VA network

· Training shall be provided by the contractor.

· Training shall be scheduled within an 8-hour day with times specified by the POC.

· Test and Acceptance: Contractor shall test all equipment after installation. The government shall accept equipment once installation and successful testing has been completed and approved.

· Warranty/Service Contract: All equipment and materials shall come with a standard one-year warranty. Warranty shall begin after installation of equipment and completion of tests.

· All hardware will be installed and operational in accordance with manufacturer's specifications and VA IT requirements.

· Support shall be available and provided via telephone and on-site. Support shall be available in varying increments such as 2, 4, 8- or 24-hour response times.

· Support shall be provided by the company that the system is purchased from.

· Support shall be provided on all hardware and component pieces purchased with this system.

· Support shall be provided on all software, interfaces, and subscriptions purchased with this system.

VI. Contractor Responsibilities

· Assign a Project Manager upon award of contract. The Project Manager shall develop a project schedule and implementation plan.

· Contractor shall provide qualified and VA credentialed personnel to perform the installation of the items as noted in this Statement of Need (SON).

· Contractor shall schedule and coordinate the installation in agreement with the customer. The Contractor shall complete the install and configure all elements of the new system within the following hours: 8:00 AM and 4:00 PM EST, Monday thru Friday (no government holidays).

· Contractor shall be responsible for all system/software testing after installation and prior to government acceptance.

· Contractor is responsible for onsite training for approximately 1 day. Training times shall be coordinated with POC.

· Contractor is responsible to ensure all equipment to be installed meets VA standards.

· Contractor is responsible for ensuring the proper disposal of all debris generated from installation activities.

· Contractor is responsible for securing all materials, equipment and tools while on government property or in government facility. Government is not liable for any lost or stolen items that are not properly secured.

· Contractors coming on station or working remotely will be required to take the VA Privacy and Information Security Awareness Program and the Privacy and HIPAA Training. Completed training certificates should be maintained by the POC of this contract for audit purposes. Appropriate fingerprinting and background investigation are required.

· The vendor shall comply with the following VA Handbooks:

· VA Handbook 6500: Information Security Program

· VA Handbook 6550: Pre-Procurement Assessment for Medical Devices

VII. Government Responsibilities:

· The authorized POC will assume responsibility for the installation and performance of all other equipment and work necessary for completion of this project.

· Provide site access and escorts to the customer's location where the equipment is located.

· Provide adequate space for the work to be performed.

· Provide the contractor with contact information and the necessary authorization to coordinate connectivity issues with applicable U.S. Government POC's.

VIII. Specific Mandatory Tasks and Associated Deliverables

· Provide such software and hardware updates as needed to maintain and/or repair if such is commercially available and covered by standard maintenance agreements.

· Provide personnel (technicians, engineers, or others as required) to maintain and/or repair within 24 hours of a non-critical failure.

· Training for administrator level personnel and client user personnel. All trained personnel will be able to easily access the system and generate the needed reports and graphs.

· Provide Bay Pines VAMC with services as described above for the period of performance shown above.

IX. CHANGES TO THE STATEMENT OF NEED

Any changes to this statement of need (SON) shall be authorized and approved only through written correspondence from the contracting officer (CO). A copy of each change will be kept in a project folder along with all other products of the project. Costs incurred by the contractor through the actions of parties other than the CO shall be borne by the contractor.

With No Sensitive Data but Requires Training

The Certification and Accreditation (C&A) requirements do not apply and a Security Accreditation Package is not required for this SON.

Attachment A – Statement of Need 36C24820Q1393

Box 149971 Austin TX 78714-9971 ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

B.1 PRICE/COST SCHEDULE (BD CareFusion Brand Name or Equal)

ITEM INFORMATION

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12.00
EA
__________________
__________________

518048 BD CATO SW SUBSCRIPTION(11-20)

LOCAL STOCK NUMBER: 518048

1.00
EA
__________________
__________________

CATO,STD,NEW,PATIENT PROFILE

LOCAL STOCK NUMBER: 136605-01

1.00
EA
__________________
__________________

CATO,STD,NEW,ADT

LOCAL STOCK NUMBER: 136938-01

1.00
EA
__________________
__________________

CATO,STD,NEW,DISPENSE

LOCAL STOCK NUMBER: 136941-01

1.00
EA
__________________
__________________

CCE Site (Covered under Enterprise)

LOCAL STOCK NUMBER: 135343-01

12.00
EA
__________________
__________________

IV Prep Gravimetric Pack

LOCAL STOCK NUMBER: 137336-02

1.00
EA
__________________
__________________

CAREPAC 2kg/200g, MT,PRECISIO

LOCAL STOCK NUMBER: 518055

1.00
EA
__________________
__________________

BD CATO IMP FEE - STANDARDSIN

LOCAL STOCK NUMBER: 518051

1.00
EA
__________________
__________________

BD CATO IMP FEE TECHNICAL INST

LOCAL STOCK NUMBER: 518050

12.00
EA
__________________
__________________

Mettler Toledo Install & 5Yr

LOCAL STOCK NUMBER: 137928-01

1.00
EA
__________________
__________________

Viewer IV Prep Subscription

LOCAL STOCK NUMBER: 137876-01

12.00
EA
__________________
__________________

BD CATO SW MONTHLY SUPPORT [For 12 units]

LOCAL STOCK NUMBER: 518048

12.00
EA
__________________
__________________

IV Prep Gravimetric Pack MONTHLY SUPPORT [For 12 units]

LOCAL STOCK NUMBER: 137336-02

12.00
EA
__________________
__________________

22-inch LED MVA Panel with 1920 x 1080 resolution; Glass Edge-to-Edge Projected Capacitive Multi-Touch;UL/cUL 60601-1 & IEC 60601-1-2 4th Edition Medical Certified, FCC Class B, CE, UL60950, Energy Star 6.1;IP65 Sealed Front Bezel, IP54 Back Cover;White with Antimicrobial Germ protection;Intel HD Graphics 520;Dual 1 Gigabit Ethernet ports;Intelr CoreT 6th generation i5 vPro Processor; 8GB DDR4-2400MHz SO-DIMM;128GB 2.5" SSD Drive;Microsoftr Windowsr 10 Professional 64-bit;Intelr Dual Band Wireless-AC 7265 Plus Bluetooth;PCAP Touchscreen Stylus Pen for Medical Series;Skylake Series TPM Module;Security Cable Management Cover for CyberMed NB22/S22;3 Yr Comprehensive Warranty + Lifetime Phone Support (US Only)

LOCAL STOCK NUMBER: S22A-BDM5546

12.00
EA
__________________
__________________

ZEBRA GK420D DT 203 USB ENET (PRINTER)

LOCAL STOCK NUMBER: GK42-202210-000

12.00
EA
__________________
__________________

Seal Shield SILVER STORM Medical Grade Keyboard

LOCAL STOCK NUMBER: STK503

12.00
EA
__________________
__________________

DATALOGIC GBT4500 KIT USB HEALTHCRE (HARDWARESCANNER)

LOCAL STOCK NUMBER: GBT4500-HC-BTK1

12.00
EA
__________________
__________________

SEAL WRLS SILVER STORM MOUSE USB-BLK

LOCAL STOCK NUMBER: STMO42W

12.00
EA
__________________
__________________

ERGOTRON WORKfitLX-SIT-STAND DESK MOUNT SYSTEM

LOCAL STOCK NUMBER: 45-405-026

GRAND TOTAL
__________________

B.2 DELIVERY SCHEDULE

A quantity of ten (10) IV Workflow Management Systems will be delivered to:

C. W. Bill Young VA Healthcare System, 10,000 Bay Pines Boulevard, Bay Pines, FL 33744

A quantity of two (2) IV Workflow Management Systems will be delivered to:

Lee County VA Healthcare System, 2489 Diplomat Parkway East, Cape Coral, FL

Attachment B - Schedule 36C24820Q1393 Delivery, installation and implementation shall be completed by 11/30/2020.

Page 1 of Page 1 of

Page 1 of Page 1 of The provision at 52.212-1, Instructions to Offerors -- Commercial, applies to this acquisition. Quoters shall complete the following regarding instruction for Offerors:

Quotes shall be submitted via email to the Contracting Officer. The size limitation is 10 Megabytes per e-mail. The subject line of the email shall read the solicitation number (36C24C20Q1393) and the company name. For example: “36C24C20Q1393-Company Name”. Each quote shall be submitted to the mailbox separately using the naming convention described above. AT NO TIME WILL ZIP FILES BE ACCEPTABLE.

Terms and content of your quote. Your quote must be based on the terms of this RFQ. We might reject any quote that is not based on these terms in every respect. Your quote must contain all of the information described below.

Quoters shall complete the price and cost schedule in its entirety, however, if your products and price schedule differs from that of the schedule provided (Attachment B), please provide a line item comparison to show how your product will meet our needs.

Quoters shall submit their technical and description of supplies that addresses all requirements, to include characteristics, pertaining to the required supplies and services.

Quoters shall have the capability to provide Brand name or equal supplies.

Quoter shall provide a statement that the product meets all requirements of the Statement of Need.

Gray market items are Original Equipment Manufacturers’ (OEM) goods sold through unauthorized channels in direct competition with authorized distributors. This procurement is for new OEM medical supplies, medical equipment and/or services contracts for maintenance of medical equipment (i.e. replacement parts) for VA Medical Centers. No remanufactures or gray market items will be acceptable.

Vendor shall be an OEM, authorized dealer, authorized distributor or authorized reseller for the proposed medical supplies, medical equipment and/or services contracts for maintenance of medical equipment (i.e. replacement parts), verified by an authorization letter or other documents from the OEM, such that the OEM’s warranty and service are provided and maintained by the OEM. All software licensing, warranty and service associated with the medical supplies, medical equipment and/or services contracts for maintenance of medical equipment shall be in accordance with the OEM terms and conditions.

The delivery of gray market items to the VA in the fulfillment of an order/award constitutes a breach of contract. Accordingly, the VA reserves the right enforce any of its contractual remedies. This includes termination of the contract or, solely at the VA’s election, allowing the Vendor to replace, at no cost to the Government, any remanufactured or gray market item(s) delivered to a VA medical facility upon discovery such items.

The provision at 52.212-2, Evaluation -- Commercial Items, applies to this acquisition (OCT 2014) (Tailored) Comparative Evaluation

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:

The Government will award a Fixed Price Purchase Order to the responsible quoter using a comparative evaluation. The comparative evaluation will be performed in accordance with FAR 13.106-2(b)(3). The government reserves the right to select a quotation that provides benefit to the government that exceeds the minimum but is not required to do so. Quoters are advised that quotations may exceed the requirements, but the government is not requesting or accepting alternate quotes; each response must at a minimum meet the solicitation requirement statement.

The government will apply the following comparative evaluation process as the basis for award:

Assess the direct comparison of one quote with another using a uniform and fair approach to determine which quote provides the government what it needs, where and when in accordance with the SON and RFQ.

Once one quotation is found acceptable, it is compared to the remaining ones, and the “best” one is chosen for the best value to the government.

The Government may rely on internal documentation including the Federal Awardee Performance and Integrity Information System (FAPIIS) Past Performance Information Retrieval System (PPIRS) and contracting officer’s knowledge of and previous experience with supply or service being acquired for determining Past Performance. If no record of past performance is found in FAPIS or PPIRS, the contract shall not receive a favorable or unfavorable rating, but shall receive a rating of neutral.

Price shall be submitted using the enclosed Price Schedule, however, if your products and price schedule differs from that of the schedule provided (Attachment B), please provide a line item comparison to show how your product will meet our needs.

Information not contained in a vendor’s quote will not be considered during the evaluation. The Government intends to make award selection without clarification, but may determine after evaluating submitted quotes that the elements stated in FAR 13.106-2(b) for evaluation procedures are necessary, and conduct them as appropriate. The Government reserves the right to make no award if no quotes meet the requirements of this solicitation.

The following factors shall be used to evaluate offers:

Technical Capability. Each offeror’s quote shall be evaluated based on equipment and services specifications, to determine if the offeror provides a sound, compliant approach that meets the requirements of the Statement of Need and demonstrates a thorough knowledge and understanding of those requirements and their associated risks. The offeror shall submit for evaluation: (1) how their product(s) meet or exceed the products specified in the SON, (2) totality of equipment must fit within 24” by 24” space with compounding hood, (3) must have gravimetric verification capabilities.

Delivery Date. The purpose of the delivery factor is to assess the offeror’s shipment capability to meet the Government’s delivery timeframe of a minimum of 65 days after receipt of order.

Past Performance. The Government will perform an independent determination of relevancy of the data provided or obtained. The past performance evaluation factor assesses the degree of confidence the Government has in an offeror's ability to supply products and services that meet users' needs, based on a demonstrated record of performance. The Government will rely on internal documentation including the Contract Performance Assessment Reporting System (CPARS) for determining the Past Performance of the offeror.

Price. Price analysis techniques may be utilized to further validate price reasonableness. The Government shall evaluate for award purposes, the price of the supplies or services being acquired based upon the total price proposed for items identified for pricing which are applicable to the basic requirements.

The provision at 52.212-3, Offeror Representations and Certifications -- Commercial Items, applies to this acquisition. To be eligible for award offerors must be registered in System for Award Management (SAM) prior to award in accordance with the provision.

The following FAR clauses cited in the clause are applicable to the acquisition:

The clause at 52.212-4, Contract Terms and Conditions -- Commercial Items, applies to this acquisition and no additional addenda to the clause included.

The clause at 52.212-5, Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items, applies to this acquisition.

52.203-6, Restrictions on Subcontractor Sales to the Government (SEPT 2006 52.204-10, Reporting Executive Compensation & First-Tier Subcontract Awards (OCT 2016) 52.209-7, Information Regarding Responsibility Matters (OCT 2018) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (OCT 2015) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (JUL 2013) 52.216-1, Type of Contract (APR 1984) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (OCT 2014) 52.219-8, Utilization of Small Business Concerns (Oct 2019) 52.219-9, Small Business Subcontracting Plan (JUN 2020) 52.219-13, Notice of Set-Aside of Orders (NOV 2011) 52.219-14, Limitations on Subcontracting (MAR 2020) 52.219-16, Liquidated Damages – Subcontracting Plan (Jan 1999) 52.219-28, Post Award Small Business Program Representation (MAR 2020) 52.222222-3, Convict Labor (JUNE 2003) 52.222-19, Child Labor--Cooperation with Authorities and Remedies (JAN 2018) 52.222-21, Prohibition of Segregated Facilities (APR 2015) 52.222-26, Equal Opportunity (SEP 2016) 52.222-35, Equal Opportunity for Veterans (JUN 2020) 52.222-36, Equal Opportunity for Workers with Disabilities (JUN 2020) 52.222-37, Employment Reports on Veterans (JUN 2020) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (DEC 2010) 52.222-50, Combating Trafficking in Persons (MAR 2015) 52.222-54, Employment Eligibility Verification (OCT 2015) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (AUG 2011) 52.225-5, Trade Agreements (OCT 2019) 52.225-13, Restrictions on Certain Foreign Purchases (JUNE 2008) 52.232-33, Payment by Electronic Funds Transfer—System for Award Management (JUL 2013) 52.233-2, Service of Protest (SEP 2006) 52.242-5, Payments to Small Business Subcontractors (JAN 2017)

The clause at 52.204-24, Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment The clause at 52.216-18, Ordering, applies to this acquisition.

The clause at 52.216-21, Requirements, applies to this acquisition.

The clause at 52.216-27, Single or Multiple Awards, applies to this acquisition.

The clause at 52.217-6, Option for Increased Quantity, applies to this acquisition.

The clause at 52.219-14, Limitations on Subcontracting, applies to this acquisition.

The clause at 52.228-5, Insurance-Work on a Government Installation.

The following additional contract requirement(s) or terms and conditions determined by the contracting officer to be necessary for this acquisition and consistent with customary commercial practices are as follows:

VAAR 852.211-70, Equipment Operation and Maintenance Manuals VAAR 852.211-73, Brand name or equal VAAR 852.219-10 VA Notice of Total Service-Disabled Veteran-Owned Small Business Set-Aside (JUL 2016)(Deviation) VAAR 852.219-75, Subcontracting Commitments Monitoring and Compliance VAAR 852.233-71, Alternative Protest Procedure (JAN 1998) VAAR 852.232-72, Electronic Submission of Payment Requests (NOV 2012) VAAR 852.237-70, Contractor Responsibilities (APR 1984) VAAR 852-246-71, Inspection VAAR 852.252-70, Solicitation Provisions or Clauses Incorporated by Reference (JAN 2008) VAAR 852.270-1, Representatives of Contracting Officers

VAAR 852.212-70, Provision and Clauses Applicable to VA Acquisitions of commercial Items (APR 2020):

852.203-70, Commercial Advertising 852.215-70, Service-Disabled Veteran-Owned and Veteran-Owned Small Business Evaluation Factors 852.215-71, Evaluation Factor Commitments 852.219-9, VA Small Business Subcontracting Plan Minimum Requirements 852.232-72, Electronic Submission of Payment Requests 852.233-70, Protest Content/Alternative Dispute Resolution 852.233-71, Alternate Protest Procedure 852.246-71, Rejected Goods 852.246-73, Noncompliance with Packaging, Packing, and/or Marking Requirements 852.270-1, Representative of Contracting Officers

52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)

52.204-7, Systems for Award Management 52.204-16, Commercial and Government Entity Code Reporting 52.211-6, Brand Name or Equal

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

52.203-17, Contractor Employee Whistleblower Rights and Requirement to Inform Employees of Whistleblower Rights 52.204-4, Printed or Copied Double-sided on Post Consumer Fiber Content Paper 52.204-18, Commercial and Government Entity Code Maintenance 52.211-6, Brand Name or Equal 52.232-40, Providing Accelerated Payments to Small Business Contractors Defense Priorities and Allocations System (DPAS) and assigned rating, is not applicable to this acquisition.

Contractor will be required to comply with physical security guidelines by either checking in with the VA Police each time they come on-site to perform contracted services or by obtaining a VA Contractor ID badge from the VA Police.

Contractor staff must be escorted at all times when performing work in sensitive areas such as data closets.

The following language from VA Handbook 6500.6 is required in this contract:

· Appendix C: Paragraphs #2a, #2d, #2e, #3a, #4a, #5h, #6(all), #7(all), #9(all)

2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

d. Custom software development and outsourced operations must be located in the U.S.

to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

3. VA INFORMATION CUSTODIAL LANGUAGE

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data- General, FAR 52.227-14(d) (1).

4. INFORMATION SYSTEM DESIGN AND DEVELOPMENT

a. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COTR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.

5. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

h. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:

(1) Vendor must accept the system without the drive;

(2) VA’s initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or

(3) VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.

(4) Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;

(a) The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and

(b) Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be preapproved and described in the purchase order or contract.

(c) A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed. The ISO needs to maintain the documentation.

6. SECURITY INCIDENT INVESTIGATION:

a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

d. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

7. LIQUIDATED DAMAGES FOR DATA BREACH:

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

c. Each risk analysis shall address all relevant information concerning the data breach, including the following:

1. Nature of the event (loss, theft, unauthorized access);

(2) Description of the event, including:

(a) date of occurrence;

(b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;

(3) Number of individuals affected or potentially affected;

(4) Names of individuals or groups affected or potentially affected;

(5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

(6) Amount of time the data has been out of VA control;

(7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);

(8) Known misuses of data containing sensitive personal information, if any;

(9) Assessment of the potential harm to the affected individuals;

(10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and

(11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

d. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $42.00 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

(1) Notification;

(2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

(3) Data breach analysis;

(4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

(5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

(6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

9. TRAINING:

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;

(2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

(3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

(4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]

b. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training and sign the Rules of Behavior
annually, within the timeframe required, is grounds for suspension or termination of all

physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

· Appendix D - Before being granted access to VA information or information systems, all contractor employees and subcontractor employees requiring such access must sign the VA’s Contractor Rules of Behavior.

CONTRACTOR RULES OF BEHAVIOR

This User Agreement contains rights and authorizations regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the Department of Veterans Affairs (VA). This User Agreement covers my access to all VA data whether electronic or hard copy ("Data"), VA information systems and resources ("Systems"), and VA sites ("Sites"). This User Agreement incorporates Rules of Behavior for using VA, and other information systems and resources under the contract.

1. GENERAL TERMS AND CONDITIONS FOR ALL ACTIONS AND ACTIVITIES UNDER THE CONTRACT:

a. I understand and agree that I have no reasonable expectation of privacy in accessing or using any VA, or other Federal Government information systems.

b. I consent to reviews and actions by the Office of Information & Technology (OI&T) staff designated and authorized by the VA Chief Information Officer (CIO) and to the VA OIG regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA. These actions may include monitoring, recording, copying, inspecting, restricting access, blocking, tracking, and disclosing to all authorized OI&T, VA, and law enforcement personnel as directed by the VA CIO without my prior consent or notification.

c. I consent to reviews and actions by authorized VA systems administrators and Information Security Officers solely for protection of the VA infrastructure, including, but not limited to monitoring, recording, auditing, inspecting, investigating, restricting access, blocking, tracking, disclosing to authorized personnel, or any other authorized actions by all authorized OI&T, VA, and law enforcement personnel.

d. I understand and accept that unauthorized attempts or acts to access, upload, change, or delete information on Federal Government systems; modify Federal government systems; deny access to Federal government systems; accrue resources for unauthorized use on Federal government systems; or otherwise misuse Federal government systems or resources are prohibited.

e. I understand that such unauthorized attempts or acts are subject to action that may result in criminal, civil, or administrative penalties. This includes penalties for violations of Federal laws including, but not limited to, 18 U.S.C. §1030 (fraud and related activity in connection with computers) and 18 U.S.C. §2701 (unlawful access to stored communications).

f. I agree that OI&T staff, in the course of obtaining access to information or systems on my behalf for performance under the contract, may provide information about me including, but not limited to, appropriate unique personal identifiers such as date of birth and social security number to other system administrators, Information Security Officers (ISOs), or other authorized staff without further notifying me or obtaining additional written or verbal permission from me.

g. I understand I must comply with VA’s security and data privacy directives and handbooks. I understand that copies of those directives and handbooks can be obtained from the Contracting Officer's Technical Representative (COTR). If the contractor believes the policies and guidance provided by the COTR is a material unilateral change to the contract, the contractor must elevate such concerns to the Contracting Officer for resolution.

h. I will report suspected or identified information security/privacy incidents to the COTR and to the local ISO or Privacy Officer as appropriate.

2. GENERAL RULES OF BEHAVIOR

a. Rules of Behavior are part of a comprehensive program to provide complete information security. These rules establish standards of behavior in recognition of the fact that knowledgeable users are the foundation of a successful security program. Users must understand that taking personal responsibility for the security of their computer and the information it contains is an essential part of their job.

b. The following rules apply to all VA contractors. I agree to:

(1) Follow established procedures for requesting, accessing, and closing user accounts and access. I will not request or obtain access beyond what is normally granted to users or by what is outlined in the contract.

2) Use only systems, software, databases, and data which I am authorized to use, any copyright restrictions.

(3) I will not use other equipment (OE) (non-contractor owned) for the storage, transfer, or processing of VA sensitive information without a VA CIO approved waiver, unless it has been reviewed and approved by local management and is included in the language of the contract. If authorized to use OE IT equipment, I must ensure that the system meets all applicable 6500 Handbook requirements for OE.

(4) Not use my position of trust and access rights to exploit system controls or access information for any reason other than in the performance of the contract.

(5) Not attempt to override or disable security, technical, or management controls unless expressly permitted to do so as an explicit requirement under the contract or at the direction of the COTR or ISO. If I am allowed or required to have a local administrator account on a government-owned computer, that local administrative account does not confer me unrestricted access or use, nor the authority to bypass security or other controls except as expressly permitted by the VA CIO or CIO's designee.

(6) Contractors’ use of systems, information, or sites is strictly limited to fulfill the terms of the contract. I understand no personal use is authorized. I will only use other Federal government information systems as expressly authorized by the terms of those systems. I accept that the restrictions under ethics regulations and criminal law still apply.

(7) Grant access to systems and information only to those who have an official need to know.

(8) Protect passwords from access by other individuals.

(9) Create and change passwords in accordance with VA Handbook 6500 on systems and any devices protecting VA information as well as the rules of behavior and security settings for the particular system in question.

(10) Protect information and systems from unauthorized disclosure, use, modification, or destruction. I will only use encryption that is FIPS 140-2 validated to safeguard VA sensitive information, both safeguarding VA sensitive information in storage and in transit regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA.

(11) Follow VA Handbook 6500.1, Electronic Media Sanitization to protect VA information. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders.

(12) Ensure that the COTR has previously approved VA information for public dissemination, including e-mail communications outside of the VA as appropriate. I will not make any unauthorized disclosure of any VA sensitive information through the use of any means of communication including but not limited to e-mail, instant messaging, online chat, and web bulletin boards or logs.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .