36C25520Q0614 Sources Sought.pdf

PDF 386 KB Posted

Attached to
Ceiling Mounted Patient Lift Federal contract opportunity
Solicitation number
36C25520Q0614
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 15

About this file

This sources sought notice requests information from potential vendors to provide and install fifty-eight ceiling mounted patient lift systems at the John J. Pershing VA Medical Center in Poplar Bluff, Missouri. Interested parties must respond with their company information, capability statement demonstrating experience providing similar solutions, and plans for equipment certification, training, seismic compliance, and installation by July 29, 2020.

The Department of Veterans Affairs seeks to procure Guldmann GH3+ or equal ceiling mounted patient lift systems with a lifting capacity of 770 pounds for installation in various sized patient rooms. The contractor will be responsible for providing all necessary equipment, performing a site evaluation, generating installation plans, completing seismic bracing, testing and certifying the systems, and training staff on operation. The award will be made based on technical qualifications, past performance, personnel expertise, and ability to minimize disruption during the installation process.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Contract Opportunity Sources Sought Notice

PRODUCT SERVICE CODE

SUBJECT

CONTRACTING OFFICE'S

ZIP-CODE

SOLICITATION NUMBER

RESPONSE DATE/TIME/ZONE

ARCHIVE DAYS AFTER THE RESPONSE DATE

RECOVERY ACT FUNDS

SET-ASIDE

NAICS CODE

CONTRACTING OFFICE

ADDRESS

POINT OF CONTACT

(POC Information Automatically Filled from User Profile Unless Entered)

DESCRIPTION See Attachment

AGENCY'S URL

URL DESCRIPTION

AGENCY CONTACT'S EMAIL

ADDRESS

EMAIL DESCRIPTION

ADDRESS

POSTAL CODE

COUNTRY

ADDITIONAL INFORMATION

GENERAL INFORMATION

PLACE OF PERFORMANCE

* = Required Field Contract Opportunity Sources Sought Notice

Ceiling Mounted Patient Lift l Poplar Bluff VAMC

66048

36C25520Q0614

07-29-2020 2:00 PM CENTRAL TIME, CHICAGO, USA

N

339113

Department of Veterans Affairs Network Contracting Office (NCO) 15 3450 S 4th Street Trafficway

Leavenworth KS 66048

Jim Lewis james.lewis114fbb@va.gov

John J Pershing VAMC 1500 Nort Westwood Blvd Poplar Bluff, MO

63901

USA

This Sources Sought Notice is for planning purposes only and shall not be considered as an invitation for bid, request for quotation, request for proposal, or as an obligation on the part of the Government to acquire any products or services. Your response to this Sources Sought Notice will be treated as information only. No entitlement to payment of direct or indirect costs or charges by the Government will arise as a result of contractor submission of responses to this announcement or the Government use of such information. This request does not constitute a solicitation for proposals or the authority to enter into negotiations to award a contract. No funds have been authorized, appropriated, or received for this effort.

The information provided may be used by the Department of Veterans Affairs in developing its acquisition approach, statement of work/statement of objectives and performance specifications. Interested parties are responsible for adequately marking proprietary or competition sensitive information contained in their response. The Government does not intend to award a contract on the basis of this Sources Sought Notice or to otherwise pay for the information submitted in response to this Sources Sought Notice.

The purpose of this sources sought announcement is for market research to make appropriate acquisition decisions and to gain knowledge of potential qualified Service Disabled Veteran Owned Small Businesses, Veteran Owned Small Businesses, 8(a), HubZone and other Small Businesses interested and capable of providing the services described below.

Documentation of technical expertise must be presented in sufficient detail for the Government to determine that your company possesses the necessary functional area expertise and experience to compete for this acquisition. Responses to this notice shall include the following:

(a) company name (b) address (c) point of contact (d) phone, fax, and email (e) DUNS number

(f) Cage Code (g) Tax ID Number (h) Type of small business, e.g. Services Disabled Veteran Owned small Business, Veteran-owned small business, 8(a), HUBZone, Women Owned Small Business, Small disadvantaged business, or Small Business HUBZone business and (i) must provide a capability statement that addresses the organizations qualifications and ability to perform as a contractor for the work described below.

The VA Heartland Network 15, Contracting Office located at 3450 South 4th Street, Leavenworth, KS, 66048-5055 is seeking a potential qualified contractor to provide and install Ceiling Mounted Patient Lifts, for Veterans Health Administration, John J. Pershing VA Medical Center, 1500 North Westwood Blvd., Poplar Bluff, MO 63106.

Classification System (NAICS) code for this acquisition is 339113 (Surgical Appliance and Supplies Manufacturing) with a size standard of 750 Employees.

Important information: The Government is not obligated to nor will it pay for or reimburse any costs associated with responding to this sources sought synopsis request. This notice shall not be construed as a commitment by the Government to issue a solicitation or ultimately award a contract, nor does it restrict the Government to a particular acquisition approach. The Government will in no way be bound to this information if any solicitation is issued.

Currently a total set-aside for Service-Disabled Veteran Owned Small Business firms is anticipated based on the Veterans Administration requirement with Public Law 109-461, Section 8127 Veterans Benefit Act and VAAR 808.002 (Class Deviation), Priorities for use of Department of Veterans Affairs (VA).

However, if response by Service-Disabled Veteran Owned Small Business firms proves inadequate, an alternate set-aside or full and open solicitation may be published.

POTENTIAL SOURCES SHALL PROVIDE THE FOLLOWING

INFORMATION IN THE RESPONSE:

1) Company name, address, phone number, primary contact(s), e-mail address, NAICS code(s), business size (i.e. small/large), and DUNS Number.

2) Statement of Capability that demonstrates ability of providing the item in accordance with the attached Statement of Requirement (SOR) and past performance in providing this type of service.

Include examples of prior completed Government contracts, references, and other related information.

This notice is to assist the NCO 15 in determining SOURCES ONLY. This announcement is not a request for proposals or quotations. The Government is not committed to award a contract pursuant to this announcement. The Government will not pay for any costs incurred in the preparation or submission of information in response to this announcement.

Notice to potential offerors: All offerors who provide goods or services to the United States Federal Government must be registered in the System for Award Management (SAM located on the web at www.sam.gov).

Additionally, all Service Disabled Veteran Owned Businesses or Veteran Owned Businesses who respond must be registered with the Department of Veterans Affairs Center for Veterans Enterprise VetBiz Registry located at http://vip.vetbiz.gov.

Any response to this source sought from Interested parties must be received NLT July 29, 2020. Attention: Jim Lewis, Contracting Specialist.

Email: james.lewis114fbb@va.gov.

http://vip.vetbiz.gov/ mailto:james.lewis114fbb@va.gov.

PBVAMC

Statement of Work

Ceiling Mounted Patient Lifts

Background:

The Poplar Bluff VA Medical Center, Poplar Bluff, MO, is soliciting a contractor to furnish all design, site evaluation, labor, materials, and equipment to install permanent ceiling mounted patient care lifts in the existing facility. Many hospital buildings were constructed in the early 1950’s and have limited above ceiling clearance. Additionally, numerous utility systems occupy this space and must be considered when installing new equipment above the ceiling. It is strongly recommended that the contractor perform a thorough site evaluation prior to submitting a proposal.

Scope of Work:

The Contractor shall provide a technical and cost proposal for turn-key services to install (58) patient lift systems in accordance with this scope of work. This cost proposal shall be for providing all lift system equipment including but not limited to; lift devices, rails, support material, bracing and all other associated components required for complete, functional installation by a certified installer. This proposal shall also be for installation of the lift systems including but not limited to any required plans, engineering details and documents, tools, labor, testing, training, cleaning supplies, containment systems, etc. All new lift systems must have a lifting capacity of no less than 770 lbs. The rail systems must be designed, constructed, and installed in an X-Y (room-covering) design; in such a manner as to allow for maximum utilization of patient room space. Operation of the system must be smooth with no fast or jerky starts and stops.

Operation of the system must allow for adequate lifting height allowing for transfer of patient from bed. Track systems shall be self-supporting either from the ceiling or from a post mounted system as required due to existing conditions. Existing hangers, Unistrut, or other support components shall not be utilized to support the lift tracks. No existing utility systems or supports shall be used for support or for bracing of the lift system. All new supports must be connected directly to building structural components. The new systems will be continuous charge. This proposal shall also be for installation of the lift systems including but not limited to any required plans, engineering details and documents, tools, labor, testing, training, cleaning supplies, containment systems, etc. All new ceiling lift system installations must have a single motor weight capacity of up to 770 pounds (facilities may specify less lifting capacity in their individual facility lift procurement requirement packages) with an integrated hand control digital patient weight scale. The manufacturer must also offer expanded ceiling lift capacities/accessories that support greater than 880 pounds in a dual motor/similar configuration.

The manufacturer must also be able to provide ceiling lifts that have the ability to connect two rail systems together when tracks are required to align that allow the same lift system motor to travel from one location to another within a defined area without having to actuate a separate hand/remote control to connect the two systems (often referred to as a combi lock or gate/switch capacity that links two rail systems together).

All ceiling lift and rail systems must be designed, constructed, and installed in an X-Y (room-covering) design; in such a manner as to allow for maximum utilization of patient room space.

Operation of the system must be smooth with no fast or jerky starts and stops. Operation of the system must allow for adequate lifting height allowing for transfer of patient from bed. Track systems shall be self-supporting either from the ceiling or from a post mounted system as required due to existing conditions. Existing hangers, Unistrut, or other support components shall not be utilized to support the lift tracks. No existing utility systems or supports shall be used for support or for bracing of the lift system. All new supports must be connected directly to building structural components.

Lifts will be installed in the following rooms of the John J Pershing VAMC Building 1 and we are requesting Brand Name or Equal to Guldmann GH3+ system as outlined below:

Description QTY

GH2 to GH3 system update; 770 w/scale, con. Charge 4m straight; RM 2005

GH2 to GH3 system update; 770 w/scale, con. charge 3m x 3m; RM 4037A, RM 4040

GH2 to GH3 system update; 770 w/scale, con. charge 4m x 4m; 3003, RM 3017, RM 3018, RM 4003A, RM

4010, RM 4017, RM 4023, RM 4030, RM 4063, RM 4073A, RM 4080A, RM 4083, RM 4096

GH2 to GH3 system update; 770 w/scale, con. charge 5m x 5m; RM 2030, RM 3009, RM 3011, RM 3012, RM 3014, RM 3020, RM 3029, RM 3030, RM 3033, RM 4004, RM 4009, RM 4018, RM 4048, RM 4049, RM 4065, RM 4076, RM 4076A, RM 4081, RM 4090, RM 4095, RM 4109, RM 4109A, RM 1113, RM 3154

GH2 to GH3 system update; 770 w/scale, con. charge 7m x 5m; RM 1144, RM 3111, RM 3111A, RM 4003, RM 4012, RM 4020, RM 4024, RM 4027, RM 4037, RM 4038C, RM 4051, RM 4059, RM 4073, RM 4086, RM 4089, RM 4093, RM 4110

GH2 to GH3 system update; 770 w/scale, con. charge 8m x 5m; RM 18

Technical Requirements:

1) Contractor shall provide a plan for each room detailing location of lift rails, support structure above, and means of attachment.

2) The lift systems must meet or exceed seismic bracing requirements as outlined in the VA Seismic Guidelines (H18-8). A written report certifying compliance with this standard shall be provided to the facility for each lift installation.

3) Door frames are not to be cut or modified. If contractor proposes to cut or modify an existing door frame, documentation supporting this practice and providing modification procedures must be provided and certified by a licensed structural engineer and accepted by the VA.

4) All lifts shall be weight tested prior to acceptance. Test weight shall be 150% of rated capacity and shall be applied to all points of suspension and traverse rail. Prior to testing, contractor shall submit rail deflection testing standards to the VA. Testing shall be observed by the VA COTR and a written report shall be provided following each test.

The report shall include deflection measurements taken at locations of maximum deflection during the weight test. All deflection points shall be within defined code limitations. For patient safety purposes, a certified contractor (certified by the lift manufacturer) will not perform any work/preventive maintenance inspections in an area/room occupied by a patient. Unless otherwise approved by the contract COR (or designee), the lift manufacturer certified contractor will be required to perform all work during the hospital normal business hours (M-F 8:00 AM – 4:30 PM) excluding federal holidays. The contractor will provide all travel, labor, parts, test equipment (to include weight set), tools, and incidentals necessary to perform all required inspection services.

Any overtime needed that would cause an increasing in invoicing must receive prior approval by the VISN Contracting Officer, through the COR (or designee).

5) All services for this contract must meet manufacturer's performance and technical specifications, Federal Regulations, and other specifications that may apply such as National Electric Code (NEC), Life Safety Code (LSC), Joint Commission (JC), and VA Regulations. There is a potential for exposure to blood borne or other infectious material with equipment throughout the hospital.

6) All contractor maintenance persons must use the “Universal Precautions” during cleaning and maintenance/repair procedures required by this service request. Contractor will be responsible for providing their own Personal Protective Equipment as applicable.

7) A manufacturer certified ceiling lift contractor must annotate all aspects of initial and annual inspections performed on the manufacturer annual inspection checklist to include: date and time of completed preventive maintenance; type, model, and serial number of the lifting system on which preventive maintenance was performed, maintenance performed and all repairs and/or repair parts (if applicable) used to maintain operating efficiency per manufacture specifications of the equipment.

8) The manufacturer certified ceiling lift contractor will also complete checklists for Installation or Relocation Checklist for Ceiling Mounted Patient Lifts and/or Corrective and Preventive Maintenance Checklist for Ceiling Mounted Patient Lifts as outlined in VACO Patient Safety Alert AL14-07. The applicable checklist must be completed and signed by the inspector/technician, the facility representative, and the unit manager where the work is done. The annual inspection checklist along with the VA inspection checklists (as applicable) shall be sent to the applicable facility point of contact (Biomedical Equipment Repair, Facilities, Engineering, or SPHM Facility Coordinator).

9) Final equipment certification shall be provided in writing prior to acceptance by the VA.

10) Any lift installation that modifies the function of a room’s privacy curtains shall be addressed by lift installer. The mitigation plan must be submitted to and approved by the

VA.

11) Lift installation shall include dust containment during installation. All rooms shall be returned to the VA in their original condition. Any damage inflicted shall be corrected by the contractor. Contractor shall provide tacky mats at each entrance to the area where work is being done. Upon completion of installation all surfaces shall be vacuumed and/or wet wiped to remove dust/debris.

12) Dismantle/remove old system concurrent with installation.

Contractor shall provide the following to be considered for award:

1) Disclosure of all Tort claims against vendor either pending or resolved regarding proposed system.

2) Education/Training Plan by vendor on use of all equipment, after installation completion, with specific timelines -- all shifts, all areas and possibly refresher courses. Include training plan for Bio-Medical staff which details any annual weight testing/inspection requirements required system warranty/certification

3) Standardization of location of charging units in identified rooms.

4) Written plan for installation of track lift system as applicable including mechanical anchor designs.

5) Written plan for modifying existing structural, mechanical, electrical and other infrastructure systems if necessary.

6) Provide drawings to show how rail system will be anchored to the structural concrete.

7) Provide a specific timeline for installation.

8) Provide an installation Infection Control Plan that meets the facility’s infection control risk assessment requirements.

9) Provide an Installation Plan including phasing and indicating time per unit with minimum interference with patient care. Example: installed on days when patient population is down, possibly weekend or Monday and Friday. The least amount of disruption to patient’s comfort and care is expected.

10) A two-year warranty on equipment and five-year warranty on installation shall be provided for each unit installed.

11) Specify all previous work done by vendor in VISN 15 and PBVAMC. Is it complete, including all training?

12) Provide Plan of Equipment Certification after install.

13) Provide Plan reflecting availability of vendor for follow- up, to include but not limited to repairs, adjustment, sling replacement after installation is complete; and address after hours and weekend response during warranty period.

14) Initial set up must include expendable accessories, such as slings. Provide one non-disposable, or two disposable, slings per lift, as per facility specifications.

15) Shall submit enough product information to allow the Government to evaluate the product(s) being offered. In addition to any literature provided, the offeror is encouraged to install a lift system in one of the rooms of the Poplar Bluff VAMC in order for a full evaluation to occur.

16) Equipment installed shall be subject to the following Specs:

• Available as UL listed full-system installations (UL 60601-1)

• X-Y configuration up to 9’10” x 9’10” with 770lb ceiling lift system with scale.

• Supplier system engineered lateral bracing brackets (Not after-market)

• Optional InfraRed remote control of lift available

• Optional InfraRed remote control of lateral movement for motor and traverse rail

• O.S.H.P.D. (California seismic resistance) approved system installations available

• Rust/stain-resistant, single-bar-design hangar bar with integrated bearing-swivel and closed-cell handgrip; available in multiple sizes

• 100% motor testing before shipment

• In-field-serviceable software-based controller boards

• Anodized aluminum rail finish to prevent flaking, chipping, fading, or peeling

• Over-speed safety governor on motor

• Soft start/stop control

• Visual low battery indicator

• Battery charger is splash proof and double insulated

• Sound level of lifting motor to be less than or equal to 52dB(A)

• Emergency switch to offer disengagement then emergency lower at controlled speed

• All installations are completed by Factory Certified, US installers.

• Available UL certification of entire installation; as opposed to UL listing on the transformer only

• Provision of system approval on room covering according to ISO EN 60601-1 Medical Equipment

• Provision of system approval on room covering according to ISO EN 10535 Safe Patient Handling Equipment

• Installation hardware meets IBC 2006 (International Building Code) standards

Source Selection Criteria:

Source Selection will be based on technical and performance requirements as well as factors indicated below.

Payment will be made monthly in arrears upon receipt of a properly prepared invoice, referencing all lifting systems that received the Required Services the contract number and assigned purchase order number.

Personnel Qualifications:

Contractor personnel performing preventive maintenance inspections and repair services must be fully qualified as per the original manufacture technical certification requirements. Installers must provide and show evidence of current manufacturer certification to COR and facility engineering prior to commencing any work. Listing of equipment to be covered under the Required Services as stated in paragraph1 above.

This will be awarded based on the best value to the Government. The best value analysis will be an analysis based on the above required information. A site visit is required to be considered for award. To schedule a site, visit please contact the contract COR (or designee)/ Facility Coordinator/Project Engineer/BMET Office.

Seismic Requirements:

Regarding the existing patient lifts, our general recommendations are the following:

Lifts that have the same maximum load capacity or higher, the new GH3 770lb lifts can be installed without any problem;

After the installation of the new patient lifts, a vertical load test must be carried out with the responsibility of the lift manufacturer.

More specifically:

1) For ceiling mounted patient lifts that are connected with anchors to the above structure:

a) if the existing patient lift has already a maximum loading capacity of 770lb or higher, the existing lift-to-slab connection can be kept and the upgrade to the new model lift (GH3) with maximum load capacity of 770lb can be done;

b) if the existing patient lift has a maximum loading capacity lower than 770lb, the existing lift-to-slab connection cannot be used unless the results of an additional in-depth room-by

CONCLUSIONS AND

RECOMMENDATIONS

c) the flat slab should never been used as anchorage for anchor bolts due to its low thickness (2- 2½”); only after confirming a minimum value of the concrete compression strength of 2,500psi and when the minimum distance from the center of the anchor bolts to the edge of the RC structure meets the requirements of ACI 318-19, on a case by case basis, the designer can connect the anchor bolts to the ribs of the RC slab and/or beams.

2) For ceiling mounted patient lifts that are attached to the above structure with tubular steel that goes through the slab (as shown in Figure 2.5):

a) if the existing patient lift has already a maximum load capacity of 770lb or higher, the existing structure can be kept and the upgrade to the new model lift (GH3) with maximum load capacity of 770lb can be done;

b) if the existing patient lift has a maximum loading capacity lower than 770lb, the existing structure that connects the lift to the above concrete slab needs to be checked by the manufacturer or the professional who have designed it (to be noted that the details of this solution have not been provided and that the layout differs from the solution with anchors proposed by Eng.

Holbrook and shown in Appendix 1). It is necessary to verify this with them and see if an increase in load capacity of the lift can be taken by the structure that the manufacture has designed and is responsible for, usually this should not implies a problem in upgrading the lift systems to the new load capacity of 770lb but needs to be assured by who has designed and detailed this type of connection for which any information has been given.

3) For wall mounted patient lifts, although this existing patient lift are not in the specified category of the ceiling mounted patient lifts as per the current scope of work, we can recommend the following:

a) if the existing wall mounted patient lift has already a maximum load capacity of 770lb or higher, the existing structure can be kept and the upgrade to the new model lift (GH3) with maximum load capacity of 770lb can be done;

b) if the existing patient lift has a maximum loading capacity lower than 770lb, the existing lift-to-structure connection needs to be checked by the manufacturer or the professional who have designed it (to be noted that the details of this solution have not been provided and that the layout differs from the solution with anchors proposed by Eng. Holbrook and shown in Appendix 1). It is necessary to verify this with them and see if an increase in load capacity of the lift can be taken by the structure that the manufacture has designed and is responsible for;

c) if the existing wall mounted patient lift is going to be removed and replaced with a ceiling mounted lift as the solution proposed by Eng. Holbrook of Guldmann company

(see Appendix CONCLUSIONS AND RECOMMENDATIONS Correct Seismic Deficiencies For Building 1 - Study to Connect Ceiling Mounted Patient Lifts May 29, 2020 John J. Pershing VAMC Poplar Bluff, Missouri for further information regarding concrete compression strength.)

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE FOR

INCLUSION INTO CONTRACTS

1. GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

3. VA INFORMATION CUSTODIAL LANGUAGE

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

b. If VA determines that the contractor has violated any of the information confidentiality, privacy, security, and other provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

4. SECURITY INCIDENT INVESTIGATION

a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

d. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

5. LIQUIDATED DAMAGES FOR DATA BREACH

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis.

Failure to cooperate may be deemed a material breach and grounds for contract termination.

c. Each risk analysis shall address all relevant information concerning the data breach, including the following:

(1) Nature of the event (loss, theft, unauthorized access);

(2) Description of the event, including:

(a) date of occurrence;

(b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;

(3) Number of individuals affected or potentially affected;

(4) Names of individuals or groups affected or potentially affected;

(5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

(6) Amount of time the data has been out of VA control;

(7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);

(8) Known misuses of data containing sensitive personal information, if any;

(9) Assessment of the potential harm to the affected individuals;

(10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and

(11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

d. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $__37.50__ per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

(1) Notification;

(2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

(3) Data breach analysis;

(4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

(5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

(6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

6. TRAINING

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Successfully complete the appropriate VA privacy training and annually complete required privacy training (See below training); and

(2) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access

b. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

7. ADDITIONAL REQUIREMENTS

a. The COR is responsible for coordinating with the Police prior to contractor arrival to identify the names of contractor personnel so that Police can ensure sufficient number of contractor badges are available for issuance prior to beginning work. COR is also responsible for signing out and signing in temporary contractor badges.

b. The COR is also responsible for maintaining copies of signed Privacy training for all contractors according to RCS 10-1.

c. Any work performed outside of official VA business hours after hours will require escorts.

d. Escort duties for un-cleared contractors are strictly limited to government officials, specifically VA employees. At no time are contractors allowed to escort other contractors.

VA Privacy Training for Personnel without Access to VA Computer Systems or Direct Access or Use to VA Sensitive Information

The Department of Veterans Affairs, VA must comply with all applicable privacy and confidentiality statutes and regulations. One of the requirements in VA is to have all personnel trained annually on privacy requirements. “Privacy” represents what must be protected by VA in the collection, use, and disclosure of personal information whether the medium is electronic, paper or verbal.

This document satisfies the “basic” privacy training requirement for a contractor, volunteer, or other personnel only if the individual does not use or have access to any VA computer system such as Time and Attendance, PAID, CPRS, VistA Web, VA sensitive information or protected health information (PHI), whether paper or electronic. You will find this training outlines your roles and responsibility for protecting VA sensitive information (medical, financial, or educational) that you may incidentally or accidentally see or overhear.

If you have direct access to protected health information or access to a VA computer system where there is protected health information such as CPRS, VistA Web, you must take “Privacy and HIPAA Focused Training” (TMS 10203). “VA Privacy and Information Security Awareness and Rules of Behavior” (TMS 10176) is always required in order to use or gain access to a VA computer systems or VA sensitive information, whether or not protected health information is included. Both trainings are located within the VA Talent Management System (TMS):

https://www.tms.va.gov

What is VA Sensitive Information/Data?

All Department information and/or data on any storage media or in any form or format, which requires protection due to the risk of harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes not only information that identifies an individual but also other information whose improper use or disclosure could adversely affect the ability of an agency to accomplish its mission, proprietary information, and records about individuals requiring protection under applicable confidentiality provisions.

What is Protected Health Information?

https://www.tms.va.gov/

The HIPAA Privacy Rule defines protected health information as Individually Identifiable Health Information transmitted or maintained in any form or medium by a covered entity, such as VHA.

What is an “Incidental” Disclosure?

An incidental disclosure is one where an individual’s information may be disclosed incidentally even though appropriate safeguards are in place. Due to the nature of VA communications and practices, as well as the various environments in which Veterans receive healthcare or other services from VA, the potential exists for a Veteran’s protected health information or VA sensitive information to be disclosed incidentally.

For example:

• You overhear a healthcare provider’s conversation with another provider or patient even when the conversation is taken place appropriately.

• You may see limited Veteran information on sign-in sheets or white boards within a treating area of the facility.

• Hearing a Veteran’s name being called out for an appointment or when the Veteran is being transported/escorted to and from an appointment.

Safeguards You Must Follow To Secure VA Sensitive Information:

• Secure any VA sensitive information found in unsecured public areas (parking lot, trash can, or vacated area) until information can be given to your supervisor or Privacy Officer.

You must report such incidents to your Privacy Officer timely.

• Don’t take VA sensitive information off facilities grounds without VA permission unless the VA information is general public information, i.e., brochures/pamphlets.

• Don’t take pictures using a personal camera without the permission from the Medical Center Director.

• Any protected health information overheard or seen in VA should not be discussed or shared with anyone who does not have a need to know the information in the performance of their official job duties, this includes spouses, employers or colleagues.

• Do not share VA access cards, keys, or codes to enter the facility.

• Immediately report lost or stolen Personal Identity Verification (PIV) or Veteran Health Identification Cards (VHIC), any VA keys or keypad lock codes to your supervisor or VA police.

• Do not use a VA computer using another VA employee’s access and password.

• Do not ask another VA employee to access your own protected health information. You must request this information in writing from the Release of Information section at your facility.

What are the Six Privacy Laws and Statutes Governing VA?

1. Freedom of Information Act (FOIA) compels disclosure of reasonably described VA records or a reasonably segregated portion of the records to any person upon written request unless one or more of the nine exemptions apply.

2. Privacy Act of 1974 provides for the confidentiality of personal information about a living individual who is a United States citizen or an alien lawfully admitted to U.S. and whose information is retrieved by the individual’s name or other unique identifier, e.g. Social Security Number.

3. Health Insurance Portability and Accountability Act (HIPAA) provides for the improvement of the efficiency and effectiveness of health care systems by encouraging the development of health information systems through the establishment of standards and requirements for the electronic transmission, privacy, and security of certain health information.

4. 38 U.S.C. 5701 provides for the confidentiality of all VA patient and claimant information, with special protection for their names and home addresses.

5. 38 U.S.C. 7332 provides for the confidentiality of drug abuse, alcoholism and alcohol abuse, infection with the human immunodeficiency virus (HIV) and sickle cell anemia medical records and health information.

6. 38 U.S.C. 5705 provides for the confidentiality of designated medical-quality assurance documents.

What are the Privacy Rules Concerning Use and Disclosure?

You are not authorized to use or disclose protected health information. In general, VHA personnel may only use information for purposes of treatment, payment or healthcare operations when they have a need-to-know in the course of their official job duties. VHA may only disclose protected health information upon written request by the individual who is the subject of the information or as authorized by law.

How is Privacy Enforced?

There are both civil and criminal penalties, including monetary penalties that may be imposed if a privacy violation has taken place. Any willful negligent or intentional violation of an individual’s privacy by VA personnel, contract staff, volunteers, or others may result in such corrective action as deemed appropriate by VA including the potential loss of employment, contract, or volunteer status.

Know your VA/VHA Privacy Officer and Information Security Officer. These are the individuals to whom you can report any potential violation of protected health information or VA sensitive information, or any other concerns regarding privacy of VA sensitive information.

YOU ARE RESPONSIBLE FOR PROTECTING THE CONFIDENTIAL INFORMATION OF

OUR VETERANS

Employee (Print Name) Date

Employee Signature

Print Name of Contract Agency, if contractor

Print Name of VHA Department/Supervisor/Local COR

PROVIDE A COPY OF THIS FORM TO YOUR SUPERVISOR/LOCAL COR

FOR DATA ENTRY INTO TALENT MANAGEMENT SYSTEM

File details come from the government source that posted it. Updated .