Attachment XII - UPDATED SOW.docx

DOCX document 42 KB Posted

Attached to
Z1DA--Data and Power Requirements Contract Federal contract opportunity
Solicitation number
36C25023R0228
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 10

About this file

This statement of work outlines requirements for a data and power cabling contract at the Richard L. Roudebush VA Medical Center in Indianapolis. The contractor shall provide labor, materials, tools and equipment to complete cabling projects consisting of at least four locations each time a task order is issued. Work includes installing CAT6a data cables and jacks, connecting power outlets using EMT conduit, installing access points, racks and patch panels, updating as-built drawings, and performing testing and certifications. The contractor must respond within 24 hours and warrant workmanship for 15 years. The contract will have a term of five ordering period years with pricing established under multiple contract line items for various cabling and power installation projects.

View the file

Other files for this federal contract opportunity

Other files attached to Z1DA--Data and Power Requirements Contract, newest first.
File Type Posted
36C25023R0228 0004.pdf PDF
Attachment XIV - 2nd Set RFI Questions AND Answers.pdf PDF
36C25023R0228 0003.docx DOCX document
Attachment XI - Price Cost Schedule UPDATED.docx DOCX document
ATTACHMENT XIII - RFI Questions AND Answers.docx DOCX document
36C25023R0228 0002.docx DOCX document
36C25023R0228 0001.docx DOCX document
36C25023R0228_2.docx DOCX document
Attachment I - DBA WD.pdf PDF
ATTACHMENT X - Construction Waste Management Spec.pdf PDF
ATTACHMENT IX - PAST PERFORMANCE TEMPLATE.pdf PDF
ATTACHMENT VIII - General Specs.pdf PDF
Attachment V - Limitations on Subcontracting (JAN 2023).pdf PDF
Attachment IV - EMR.pdf PDF
Attachment III - RFI Template.pdf PDF
ATTACHMENT II - VHA Directive 1192 01.pdf PDF
ATTACHMENT VII - Electrical Specs.pdf PDF
Attachment VI - Data Specs.pdf PDF
Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

This requirements contract is to establish contract line-item number (CLIN) pricing for the term of five ordering period years to be used on various cabling projects and power installation projects at the Richard L. Roudebush VA Medical Center located at 1481 W. 10th Street, Indianapolis, IN 46202. The contractor shall provide all necessary services (i.e., labor, materials, tools, equipment, and competent supervision) as outlined below; including infection control risk assessment (ICRA) and interim life safety measures (ILSM) to meet the scope objectives and requirements and to provide the required outcome in terms of overall quality, timeliness, and documentation. Items listed below shall be included in the cabled location price unless specifically identified to be listed as a CLIN. Projects may be construction or otherwise. The cabling projects under this SOW shall consist of no less than 4 or more cabled locations which can either be new, moves, or a mix thereof, for a call requesting contractor dispatch. Conduit shall be provided by the contractor if and where required. The contractor must be able to be onsite within 24 hours from the time a task order is requested.

SCOPE

a. Cabling. Shall consist of 2 patch cords up to 10’ and two Blue Cat 6a data cables. Provide cable (i.e., backbone, outside plant, and horizontal cabling) conforming to accepted industry standards with regards to size, color code, and insulation (Plenum grade cable is not required unless the ceiling is air return). Cable shall be installed per BICSI and EIA TIA standards.

b. Jacks. Contractor shall use standard faceplates shall be a quad outlet, where the two data cables occupy the bottom two jacks. Faceplates and voice jacks shall be EI (electrical Ivory) in color and the data jacks shall be Green in color. The jacks and faceplates shall conform to accepted industry standards with regard to size, color code, and insulation When a single voice cable is pulled, a steel four-conductor wall mount is required. This shall be part of the cabling price and shall not be a separate CLIN number. See CLIN #’s 1-5 for further details.

c. Power Installations. All power installations shall be installed with 1/2” or 3/4” EMT conduit. Follow all current NEC guidelines. See CLIN number 21 for reference.

d. Electrical path installation- The contractor shall include all tools, materials, and labor to install all conduits, wiring, and equipment from the power source to the location where the electrical outlet will be installed. This task shall only include branch circuit runs up to 10’ to the electrical outlet or destination. If the task requires the outlet to be installed over 10’ then an additional CLIN will be applied to this task. This task shall include all conduit, wiring, conduit supports, conduit straps anchors, couplings, conduit bends and modifications, compression fittings, wire nuts, junction boxes, fasteners, and bushings that are required to complete the installation. All new electrical installations shall require the outlets to be labeled.

· The VA will verify that a sufficient power source has been identified and selected by the contractor prior to connection.

e. Duplex Receptacle- Provide and install 1 hospital-grade ivory or red duplex receptacle.

f. Quadruplex Receptacle- Provide and install 1 ivory or red quadruplex receptacle.

g. Drywall Repair- This task shall include all painting, wall modifications, and drywall/Gypsum board repair needed from receptacle installation.

h. Repair. This shall include any or all the items listed depending on the issue discovered during testing, re-termination, jack replacement, face plate replacement, labeling, cable and jack diagnostic testing, and cabling locates. If the cabling is damaged and needs replacement, another task order will be issued. This shall cover the cost of all repairs to an existing data jack or patch panel except for the cabling.

i. Numbering Scheme. Each cable shall have its own number and be labeled with floor and closet identifiers first in the numbering scheme, followed by the cable number for the data (i.e., 5C-001 5C-002). The voice shall have a V identifier after the closet identifier in the scheme (i.e., 5CV001). Numbering shall be displayed on the faceplate as close to the actual cable as possible. The voice number shall be on the top side of the jack and the data number shall be on the bottom. See example 1-1 below. This shall be part of the cabling price and shall not be a separate CLIN number.

Example 1-1 Voice w/bl w/or Voice w/gr w/br Data cable one Data cable two 5C001 5C002

5CV001

j. Patch Panels. Provide patch panels with a Cat 6a rating. A lower Cat rating patch panel may exist, and the selected contractor shall identify and advise the VA. Material shall conform to accepted industry standards with regards to size, color code, and quality with Cat 6a or higher rating.

k. Testing and certifications. All data cabling whether moved or installed new shall be tested and certified to the Cat rating applicable. Voice cabling is not required to be certified as a Cat rating but shall be wire map tested. All documentation shall be provided in softcopy as hardcopy is no longer desired. This shall be part of the cabling price and shall not be a separate CLIN number.

l. Wire Management. Existing vertical and horizontal organizers shall be used when needed. Provide new material where required.

m. Cisco Access Point. Install customer-provided equipment (CPE). VA shall provide CISCO Access points and mounting hardware. Vendor to install CPE at a predetermined location. Cost shall be 1 item per, as identified in CLIN #10.

n. Wall mount wall plate. See example 1-1 above for the wall mounting wall plate for hanging either an IP phone or a digital phone. For the IP phone, there shall be a way to hang the phone with a patch cable. If a standard jack does not work, then the middle of the wall plate can be empty, and the patch cord shall go through the wall plate and plug into the jack. For the digital phone, the wall plate shall have a connection for a voice line to plug in. The wall plate that needs an analog phone with a built-in plug shall not work. See example 1-1 above and use similar products.

o. Data Racks. Provide data racks, which shall be 19” x 84” and anchored to the floor. Provide a 4-post rack.

p. Panduit locations. Panduit shall be required where concrete and/or stone walls, etc. prevent a cut-in box from being installed for the cabling. The contractor shall provide a complete Panduit location when required to include ceiling grid clip, right or left angles, if necessary, surface mount box, and splice cap if necessary. Panduit shall be on the minimum size required so as not to have much waste. If the wall construction is drywall or other that is hollow, no Panduit is required and is prohibited. For any exceptions, please notify the COR. CLIN # 20.

q. Conduit locations. VA shall install conduit for the cable vendor to do their wire pull if required. In most cases, conduit shall not be required. If conduit has not been supplied, the contractor shall notify COR. Conduit shall be installed for all power installations.

r. Drywall rings. Drywall rings shall be supplied by the contractor to be included in the cabled location or existing cable move pricing. Metal cable caddies are not desired, but LV1-type plastic rings or higher quality are acceptable and desired. This shall be part of the cabling price and shall not be a separate CLIN number.

s. Fire Stop. Fire stop is required for all penetrations whether new or existing and shall be part of the cabling price and shall not be a separate CLIN number.

t. Penetrations. Contractor shall use existing penetrations whenever possible. Where a new penetration is required, the contractor shall notify the COR to start the penetration permit process. See CLIN # 15-18.

u. Cable tray. Contractor is required to use cable trays as much as possible and adhere to BICSI and EIA TIA standards. When removing fire stop and/or fire pillows from a tray that passes through a fire or smoke-rated wall, it is a VA fire code requirement that it be sealed back up at the end of each day regardless of returning to the area the next day or not. The ceiling cable tray is the standard and there should be adequate space for the additional cable. This shall be part of the cabling price and shall not be a separate CLIN number.

v. Cable Support. When leaving the cable tray, cable support (such as J hooks) of the appropriate size shall be used in accordance with BISCI and EIA TIA standards to be included in the cabled location pricing. This shall be part of the cabling price and shall not be a separate CLIN number. Do not use ceiling supports or Sprinkler pipes as cable support.

w. AutoCAD. Contractor is to update VA’s current Auto Cad as-built drawings at the end of each project. A printed paper copy and a digital copy shall be provided to COR every 6 months. This shall be part of the cabling price and shall not be a separate CLIN number.

x. Waste. Waste shall need to be removed, the area of work swept, and the closets kept clean daily. This shall be part of the cabling price and shall not be a separate CLIN number. (See infection control section.)

· Waste Management Documentation – The Contractor shall provide waste reports to the COR for each month for the entire duration of the project. Please reference the Construction Waste Management Specification.

y. Ceiling Tiles. Ceiling tiles needing to be pushed up (Above ceiling work permit needed) shall be pushed down when work is completed. This shall be part of the cabling price and shall not be a separate CLIN number. (See infection control section.)

z. Closet access. Keys for closets shall have to be signed out daily, not assigned for the term of the project or contract. Keys are never to be taken home or offsite. Contractor may be held responsible for the replacement of cores and keys should the signed-out keys get lost. Personal Identity Verification (PIV) card access is the preferred method of access and shall be provided by the VA if possible.

aa. Locked Closets. Closets are to remain closed and locked at all times. No propping of doors, taping the lockset, or any other manner of keeping the door open shall be allowed. If someone is in the closet the door may remain open, but if someone leaves the area (even only around the corner) the door shall be closed and locked. This is considered a security issue and has the attention of the highest levels within the facility and shall be considered a priority. Contractor may be responsible for fines if a security incident happens.

ab. Safety. At all times safety for patients, visitors, and employees should be held in the highest regard. Safety cones and OSHA safety standards shall be used. Non-compliance with Safety rules/OSHA shall be addressed and corrected immediately. Examples are, unattended ladders, cable loops hanging from the ceiling, etc. OSHA 10 or 30 hr. is required for all contractors.

ac. Conduct. Contractors shall conduct themselves professionally and shall NOT do work where there are patients in the room. No use of profanity is tolerated in the RLRVAMC. Also, NO loud music is allowed. Headphones for music while working in hallway areas are prohibited so patient safety is not inhibited.

ad. Dress code. Contractors shall wear PPE/work clothes conducive to the work environment as always expected, i.e., no offensive attire, no t-shirts with offensive print, no clothing that is torn or see-through, etc.

ae. Individual Room Access. VA personnel shall provide access to areas other than closets when required. VA personnel shall be from the following Services: Engineering, Police and Security, and Telecommunications.

af. General facility access. The facility is open from 6 am to 6 pm and VA Telecom hours are 7:30 am to 4:30 pm. Working outside the 6 am to 6 pm parameters shall require prior approval from the COR and/or the appropriate VA personnel.

ag. Project Manager. The Contractor shall supply a point of contact for each task order/project awarded.

ah. Warranty. Contractor shall warrant materials, test results, and workmanship for a minimum of 15 years.

ai. Dustcarts. Contractor shall adhere to VA standards, designated in the blueprints in the Telecom area, of patient care areas that shall require dustcarts. Contractor shall provide dustcarts while working in these areas.

aj. Infection Control. Contractor shall provide an infection control risk assessment (ICRA) while work is being performed. This includes using plastic barriers to prevent dirt/dust from spreading to patients/staff. Use of HEPA filtration with full drywall barriers for projects totally dedicated to cable replacement projects. COR and Contractor shall coordinate with the Infection Control Nurse for the type of barriers needed. Attaining negative

ak. Life Safety. Contractor shall provide interim life safety measures (ILSM) while work is being performed. This includes providing signage that limits exiting or going through the construction area. COR and Contractor shall coordinate with Safety Service for proper egress out of the construction area.

al. Deliverables. Penetration Permits for under 1” shall be submitted 1 week in advance of work. Above Ceiling work permit shall be submitted 1 week in advance of work. OSHA 10 HR or 30HR Certifications shall be included with initial project submittals.

am. Government Furnished Equipment. This shall include CISCO Access Points and mounting hardware.

an. Background Investigations. All contractor employees are subject to the same level of investigation as VA employees who have access to VA Sensitive Information. The level of background investigation commensurate with the level of access needed to perform the statement of work is NACI (National Agency Check with Inquiries). This requirement applies to all subcontractor personnel requiring the same access. For information regarding the risk or sensitivity level that corresponds to the level of background investigation required for the contract personnel, please refer to Homeland Security Presidential Directive (HSPD-12), Federal Information Processing Standards (FIPS) 201-3, VA Directive 0735, and VA Handbook 0735.

ao. Federal Holidays. Any day specifically declared a federal holiday by the President of the United States which includes New Year’s Day, Martin Luther King Jr. Day, President’s Day, Memorial Day, Juneteenth Independence Day, 4th of July/Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, Christmas Day

C. VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE

1. GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

1. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

1. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract or task order.

1. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with the VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

1. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, agreements, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with the Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

1. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policies or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

1. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

3. VA INFORMATION CUSTODIAL LANGUAGE

1. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in the performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

1. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that the VA’s information is returned to the VA or destroyed in accordance with the VA’s sanitization requirements. VA reserves the right to conduct on-site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

1. Prior to termination or completion of this contract, the contractor/subcontractor must not destroy information received from the VA or gathered/created by the contractor while performing this contract without prior written approval by the VA. Any data destruction done on behalf of the VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

1. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose, and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations, and policies. If Federal or VA information confidentiality and security laws, regulations, and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

1. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the contract or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

1. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent a contract to use or disclose protected health information, there is no business associate relationship.

1. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

1. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

1. Except for uses and disclosures of VA information authorized by this contract for the performance of this contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA Contracting Officer for response.

1. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, the confidentiality of medical quality assurance records, and/or Title 38 U.S.C. 7332, the confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor receives a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA Contracting Officer for a response.

k. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) every year and provide it to the COR.

6. SECURITY INCIDENT INVESTIGATION

1. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss, or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the agreement of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

1. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

1. Concerning unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

1. In instances of theft and/or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with the VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to the incident.

7. DAMAGES FOR DATA BREACH

1. Consistent with the requirements of 38 U.S.C. §5725, a contract/agreement may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

1. The contractor/subcontractor shall provide notice to VA of a “security incident” as outlined in the Security Incident Investigation section above. Upon such notification, the VA must secure from a non-department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

c. Each risk analysis shall address all relevant information concerning the data breach, including the following:

1) Nature of the event (loss, theft, unauthorized access);

2) Description of the event, including:

i. date of occurrence;

ii. data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, and disability code;

3) Number of individuals affected or potentially affected;

4) Names of individuals or groups affected or potentially affected;

5) Ease of logical data access to the lost, stolen, or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

6) Amount of time the data has been out of VA control;

7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);

8) Known misuses of data containing sensitive personal information, if any;

9) Assessment of the potential harm to the affected individuals;

10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate, and;

11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

d. Based on the determinations of the independent risk analysis; the contractor shall be responsible for paying to the VA liquidated damages in the amount of $37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

1) Notification;

2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

3) Data breach analysis;

4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals in bringing matters to resolution;

5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

File details come from the government source that posted it. Updated .