Sources_Sought_Notice_-_SOW.docx

DOCX document 26 KB Posted

Attached to
PYXIS System - CO Federal contract opportunity
Solicitation number
36C25519Q0169
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 15

About this file

36C25519Q0169 Sources Sought Notice - SOW.docx

View the file

Other files for this federal contract opportunity

Other files attached to PYXIS System - CO, newest first.
File Type Posted
36C25519Q0169.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work Harry S. Truman Veterans’ Memorial Hospital, Columbia, MO Pharmacy Pyxis ES

1. Background

Columbia VAMC Pharmacy utilizes the Pyxis ES System to maintain and dispense all medications for the Main Hospital Campus and Community Based Outpatient Clinic (CBOC) sites.

2. Scope

In order to provide the same level of care, workflow practices, and policies pertaining to the current system used by the Columbia VAMC and CBOC locations, the system must integrate fully with the Pyxis ES Platform.

The following items are required to fulfill the clinical and Pharmacy needs.

a. Pyxis Anesthesia System 3500

b. Pysix Medstation 4000

The Vendor must provide any Hardware, tools, or supplies necessary for the configuration, installation, and training under the guidance of this procurement package as outlined by this Statement of Work.

3. Objective

The goal of the contract is to acquire an additional Pyxis equipment for the new construction area in the MRI Suite area so it can be delivered, configured, and brought online in time for the clinic opening. The Columbia VAMC Pharmacy Service is responsible for coordinating with the vendor for any installation and/or training necessary for the purchase and implementation of the device.

4. Task

The contract will include complete delivery the device, and any applicable installation fees. The device shall be fully operational and functioning at the same degree as the other Pyxis ES Medstations and SRM currently in use at the other Columbia VAMC and CBOC locations. Delivery from the Vendor to the Columbia VAMC Pharmacy should be TBD, this will allow for device preparation and loading medications prior to the clinic go-live date.

a. Deliver the equipment to the Columbia VAMC Pharmacy at the following address:

Attn: Pharmacy/XXXXXX 800 Hospital Drive

C/O: TBD

Columbia, MO, 65201-5275

b. Configure the device to integrate with the existing Pyxis ES Systems in use at the Columbia VAMC (inquire for account number upon award if needed).

c. Provide Training to the clinic staff at the site of installation.

d. The Vendor will insure all PM and/or Updates are current on the device at the point of installation that may have been issued since the device was manufactured and shipped.

e. Provide to Pharmacy and/or Biomedical Engineer (COR) all engineering documentation, including but not limited to, mechanical drawings, electrical/wiring diagrams, and support system layouts.

5. Government-furnished property

The vendor shall provide check-in services for any staff that are on site for installation.

The Vendor will require identification such as a company ID card while on site at the Columbia VAMC, and will be escorted by a member of Pharmacy during all times.

6. Security Requirement

The vendor will comply with all requirements outlined in the Business Associate Agreement (BAA) and Memorandum of Understanding or Interconnection Agreement (MOU-ISA) with the Department of Veterans Affairs.

The vendor must comply with VA information security and privacy requirements throughout the entire operation and be in compliance with VA Security Handbook 6500. Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

a. SUBPART 839.2 – INFORMATION AND INFORMATION TECHNOLOGY SECURITY REQUIREMENTS 839.201 Contract clause for Information and Information Technology Security:

i. Due to the threat of data breach, compromise or loss of information that resides on either VA-owned or contractor-owned systems, and to comply with Federal laws and regulations, VA has developed an Information and Information Technology Security clause to be used when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor, subcontractor or a third party in any format (e.g., paper, microfiche, electronic or magnetic portable media).

ii. In solicitations and contracts where VA Sensitive Information or Information Technology will be accessed or utilized, the CO shall insert the clause found at 852.273-75, Security Requirements for Unclassified Information Technology Resources. c. 852.273-75 -SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION TECHNOLOGY RESOURCES (INTERIM-OCTOBER 2008)

d. The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract.

e. A contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

f. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program).

g. The contractor/subcontractor shall certify to the COTR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 11 configured to operate on Windows 7 and future versions, as required.

h. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than 2 days.

The contractor shall ensure adequate LAN/Internet, data, information, and system security in accordance with VA standard operating procedures and standard contract language, conditions laws, and regulations. The contractor’s firewall and web server shall meet or exceed the government minimum requirements for security. All government data shall be protected behind an approved firewall. Any security violations or attempted violations shall be reported to the VA project manager and VA Information Security Officer as soon as possible. The contractor shall follow all applicable VA policies and procedures governing information security, especially those that pertain to certification accreditation.

Security Training

All contractor employees and subcontractors under this contract or order are required to complete the VA's on-line Security Awareness Training Course and the Privacy Awareness Training Course. The Privacy Awareness Training requirement may be fulfilled under additional privacy awareness training options, based on the prerogative of the Contracting Officer. Contractors must provide signed certifications of completion to the CO prior to on-site installation. Signed certifications of completions are also required for contractor employees that have remote electronic access to the system.

This requirement is in addition to any other training that may be required of the contractor and subcontractor(s).

Equipment

Contractor supplied equipment; PCs of all types, equipment with hard drives, etc. for contract services must meet all security requirements that apply to Government Furnished Equipment (GFE) and Government Owned Equipment (GOE) as identified in VA Policy. If non-VA owned equipment must be utilized, a waiver must be in place. VA Approved Encryption Software must be installed on all laptops before placed into operation, b) Bluetooth equipped devices are prohibited within the VA; Bluetooth must be permanently disabled or removed from the device, c) Equipment must meet all sanitization requirements and procedures before disposed of, d) All remote systems (VAGFE and OE) must be equipped with, and use, VA Approved Antivirus Software and a personal (host-based or enclave based) firewall that is configured with a VA Approved Configuration. The COR, CO, the Project Manager, and the ISO must be notified and verify all security requirements have been adhered to.

VA Information Custodial Language

1) Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data

- General, FAR 52.227-14(d) (1).

Security Incident Investigation

2) The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

Liquidated Damages for Data Breach

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $ 37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

c. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;

(2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

(3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

(4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]

d. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification

This User Agreement contains rights and authorizations regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the Department of Veterans Affairs (VA). This User Agreement covers my access to all VA data whether electronic or hard copy ("Data"), VA information systems and resources ("Systems"), and VA sites ("Sites"). This User Agreement incorporates Rules of Behavior for using VA, and other information systems and resources under the contract.

Contractor Personnel Security

All contractor employees who require access to the Department of Veterans Affairs' computer systems shall be the subject of a background investigation and must receive a favorable adjudication from the VA Security and Investigations Center (07C). This requirement is applicable to all subcontractor personnel requiring the same access. If the security clearance investigation is not completed prior to the start date of the contract, the employee may work on the contract while the security clearance is being processed, but the contractor will be responsible for the actions of those individuals they provide to perform work for the VA.

Background Investigation

The position sensitivity for this effort has been designated as high risk system and the level of background investigation is a high level agency investigation.

1. Place of performance

a. Columbia VAMC 800 Hospital Drive Columbia, MO 35201-5275

File details come from the government source that posted it.