36C25625Q0158.docx
DOCX document 110 KB Posted
- Attached to
- J065--Software Support Federal contract opportunity
- Solicitation number
- 36C25625Q0158
About this file
This document is a Sources Sought Notice from the Department of Veterans Affairs (VA) Veterans Health Administration, Veterans Integrated Service Network 16, seeking preferably Service Disabled Veteran Owned Small Businesses or Small Businesses (but will accept other than small business for market research purposes) capable of providing BioDose or NMIS Software Support Services for the Gulf Coast Veterans Health Care Systems in Biloxi, MS. The NAICS code is 811210 Electronic and Precision Equipment Repair and Maintenance, and the size standard is $34M. Responses must be received by 12:00 p.m. Central Time on June 12, 2024 and shall be emailed to the Contracting Officer. This is not a solicitation for proposals or quotes, and no contract will be awarded from this notice. The notice includes a draft Statement of Work detailing the required services, including 24-hour vendor support, software upgrades, and corrective and preventative maintenance.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SUBJECT*
Software Support
GENERAL INFORMATION
| CONTRACTING OFFICE’S ZIP CODE* |
| 39216 |
| SOLICITATION NUMBER* |
| 36C25625Q0158 |
| RESPONSE DATE/TIME/ZONE |
| 11-12-2024 12PM CENTRAL TIME, CHICAGO, USA |
| ARCHIVE |
| 60 DAYS AFTER THE RESPONSE DATE |
| RECOVERY ACT FUNDS |
| N |
SET-ASIDE
| PRODUCT SERVICE CODE* |
| J065 |
| NAICS CODE* |
| 811210 |
| CONTRACTING OFFICE ADDRESS |
| Department of Veterans Affairs |
G.V. (Sonny) Montgomery VAMC
1500 E. Woodrow Wilson Dr.
Jackson MS 39216
POINT OF CONTACT*
Contracting Officer Damuel Thomas damuel.thomas@va.gov 601-206-7042
PLACE OF PERFORMANCE
| ADDRESS |
| Gulf Coast Veterans Healthcare Sysytems |
400 Veterans AVE.
Biloxi MS
| POSTAL CODE |
| 39531 |
COUNTRY
ADDITIONAL INFORMATION
AGENCY’S URL
URL DESCRIPTION
AGENCY CONTACT’S EMAIL ADDRESS
EMAIL DESCRIPTION
This is a SOURCES SOUGHT NOTICE ONLY This SOURCE SOUGHT NOTICE is for the purpose of Market Research. Response to this notice will be used for information and planning purposes. No proposals or quotes are being requested or accepted with this notice. THIS IS NOT A SOLICITATION FOR PROPOSALS or QUOTES and NO CONTRACT SHALL BE AWARDED FROM THIS NOTICE. This notice shall NOT be construed as solicitation or as an obligation on the part of the Department of Veterans Affairs (VA). Responses to this notice is not a request to be added to a prospective bidders list or to receive a copy of the solicitation.
The Network Contracting Office (NCO) 16 is seeking preferably Service Disabled Veteran Owned Small Businesses or Small Businesses (but will accept other than small business for market research purposes), capable of providing BioDose or NMIS Software Support Services for the Gulf Coast Veterans Health Care Systems, 400 Veterans Avenue, Biloxi, MS 39531.
See DRAFT Statement of Work for detailed services.
The NAICS code is 811210 Electronic and Precision Equipment Repair and Maintenance, and Performers and the Size Standard is $34M. Responses must be received by no later than 12:00 p.m. Central Time, Tuesday, June 12, 2024. Responses shall be emailed to damuel.thomas@va.gov Capabilities Statements to include UEI number. Facsimile or Telephonic responses will not be accepted.
Note: All interested parties are reminded to be registered, active and verified in the following to be considered for Award.
· SAM:
https://www.sam.gov/portal/public/SAM/
· VETBIZ
https://www.vip.vetbiz.gov/Public/Search/Default.aspx
· Vet 4212 (Veteran owned small Business are reminded of Reporting Requirements) https://www.dol.gov/vets/vets4212.htm Sources Sought Notice Sources Sought Notice
| *= Required Field |
| Sources Sought Notice |
Sources Sought Notice
Statement of Work Service Plan/Agreement For Nuclear Medicine Information System License and Support Gulf Coast Veterans Health Care System Biomedical Engineering
1. OBJECTIVE: The Gulf Coast Veterans Health Care System requires the following services for the facility: Full-Service Plan/Agreement for Nuclear Medicine Information System (NMIS) License and Support. The service plan/agreement being sought includes but is not limited to the following: 24-hour vendor support, software upgrades and new software versions, and corrective and preventative maintenance services.
2. GENERAL: This is a non-personnel services requirement. The contractor shall provide all management, supervision, labor, transportation, tools, and other items necessary to perform work, execute services, and to successfully complete all deliverables as contained within this Statement of Work. The Government shall not exercise any supervision and/or control over contractor personnel (which includes contractor service providers, contractor representatives, and subcontractors employed with and/or being utilized by the prime contractor) during all active performance periods of the contract. All contractor personnel shall be accountable solely to the Contractor, who in turn is responsible to the Government.
3. BACKGROUND: NMIS is already utilized by the facility in support of facility operations for the delivery of veteran patient care. To continue providing the support needed for the Nuclear Medicine department, this license and support agreement is needed to continue providing updates to the system and have support available when issues arise. This tracking software, NMIS, allows the Nuclear Medicine department to keep track of inventory, doses, patient information, and billing. Furthermore, doses can be followed from arrival through disposition, along with a complete digital history that documents every exam and dose that a patient receives. This software is also known as Biodose.
4. SCOPE OF SERVICES: The services needed (to include required Deliverables) are described below. The manufacturer of the devices is EC2 Software Solutions.
1. Services must ONLY be performed by manufacturer trained technicians, who have evidence of current factory training on the specific software being serviced. This must be available 24 hours a day from the vendors help desk line.
2. Vendor must log all work done on the software for maintenance history. Work done remotely must be properly authorized by a Memorandum of Understanding – Information Safety Agreement with the Government.
3. Must guarantee that safety inspections performed will comply with all applicable federal, state, and regulatory requirements, manufacturer standards, and meet FDA alerts and recall requirements.
4. Each technician must be certified on the device prior to performing any service and/or maintenance on software.
5. Must maintain continuous access to the most up to date manufacturer software revisions of the equipment listed.
6. Must guarantee execution of all Manufacturer Service Recommendations during each service incident.
7. Must possess the legal rights to propriety software. Must provide updated versions of the software when released.
8. The service technician must have completed training for each specific device by a Manufacturer Authorized Trainer prior to performing service on said software.
9. The vendor must keep software functioning at a 95% uptime rate. The vendor must perform preventative maintenance that adheres to the original equipment manufacturer schedules.
5. PLACE OF PERFORMANCE: Work will be performed, services will be executed, and deliverables will be completed at the Gulf Coast Veterans Health Care System – Biloxi and Pensacola locations.
6. PERIOD OF PERFORMANCE: The expected period of performance for services executed under the final contract for this acquisition is the following:
| Base Year: | 2/11/2025 thru 09/30/2025 | ||
| Option Year One: | 10/01/2025 thru 09/30/2026 | ||
| Option Year Two: | 10/01/2026 thru 09/30/2027 | ||
| Option Year Three: | 10/01/2027 thru 09/30/2028 | ||
| Option Year Four: | 10/01/2028 thru 09/30/2029 |
Option years may or may not be exercised based on the needs of (and at the discretion of) the U.S. Government.
7. WORK HOURS AND SCHEDULE: All work, execution of services, and completion of deliverables must be accomplished during normal business hours, 8:00 a.m. through 4:30 p.m. Monday through Friday, Federal Holidays excluded. Prior to work being performed proper coordination shall be initiated between the contractor and the government to ensure that services/work can be executed when scheduled. Any work, services, and/or other tasks performed during other than normal business hours must be approved in advance by the Contracting Officer Representative (COR), Contracting Officer, and/or other authorized facility designee/representative before such work begins. The Federal Holidays that are currently being observed by the facility are listed in the table below.
| New Year’s Day |
| January 1 |
| Martin Luther King‘s Birthday |
| Third Monday in January |
| President’s Day |
| Third Monday in February |
| Memorial Day |
| Last Monday in May |
| Juneteenth Independence Day |
| June 19th |
| Independence Day |
| July 4 |
| Labor Day |
| First Monday in September |
| Columbus Day |
| Second Monday in October |
| Veterans Day |
| November 11 |
| Thanksgiving Day |
| Fourth Thursday in November |
| Christmas Day |
| December 25 |
| Other Federal Holidays (that could occur) |
| Any other day specifically declared to be a national holiday (per Federal Statute, Executive Order, or by the President’s Proclamation). |
An alternative schedule (different from the schedule described above) may be utilized if there is mutual agreement between the government and the contractor regarding this alternative schedule if implemented.
8. PERSONNEL PERFORMING WORK/SERVICES - REQUIRED “CORE COMPETENCIES”:
Personnel performing work, executing services, and completing deliverables during the active performance periods of the contract shall possess the knowledge, skills, and abilities required to successfully execute the services described herein. No unqualified individual shall be allowed to perform work, execute services, and to complete deliverables at any time under the contract while active.
9. KEY PERSONNEL
During the active performance periods of the contract a Key Personnel Person shall be designated by the contractor (to be contacted by the government when needed) regarding performance of work, execution of services, and completion of Deliverables as contained within this Statement of Work and covered by the final contract. This Key Personnel person must have sufficient knowledge to be able to respond to technical questions by the government.
10. DELIVERABLES:
DELIVERABLE #1:
ROUTINE REPORTING, DOCUMENTATION, AND SERVICE LOG
Documentation shall be provided following execution of services, performance of work, and completion of deliverables during the active performance periods of the contract. A service log describing the efforts completed under the final contract shall be prepared, maintained, and provided to the government if/when requested.
DELIVERABLE #2:
CHECK IN AND CHECK OUT PROCEDURES
Before beginning any work at any time during the active performance periods of the contract personnel performing services must physically check in with the appropriate facility representative to obtain approval and confirmation of the expected work to be performed and services to be executed. Check out procedures will be the same once work has been completed and services have been executed. Check in and check out procedures shall include the following: 1). Written documentation of the contractor’s arrival and departure while on site and 2). Written documentation showing the expected work to be performed, approval of such work before such work begins, and confirmation/completion status of the planned work that was scheduled to be performed. Facility personnel and the contractor may modify such procedures if there is mutual agreement among both parties regarding changes to these procedures if implemented.
11. RECORDS MANAGEMENT
1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be management and scheduled for disposition only as permitted by statute or regulation.
3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be management in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
4. Gulf Coast Veterans Health Care System (GCVHCS) and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of GCVHCS or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to GCVHCS. The agency must report promptly to NARA in accordance with 36 CFR 1230.
5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the contract. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. Contractor personnel shall sign VA Form 10-0708 “Employee Clearance from Indebtedness” before resigning or termination from Contractor working for GCVHCS Facility Records Officer must sign form. A copy of completed signed VA Form 10-0708 (Contractor personnel and Facility Records Officer signatures) shall be place in each competency folder. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to GCVHCS control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the contract. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
6. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take VHA provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training. TMS(Talent Management System) course VA 4192704 : “Records Management for Everyone”.
7. Flow-down of requirements to subcontractors
a. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this contract and require written subcontractor acknowledgment of same.
b. Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.
12. OTHER REQUIREMENTS:
12.1 Identification and Badges: Any individual performing work under this contract shall wear a badge or other identification while on site that is clearly displayed at all times. While on site, any person performing work directly or indirectly must be in a position to specify their authorized purpose for their presence at the facility in the event that such information is requested by VA facility personnel.
12.2 Parking: It is the responsibility of the contractor to park in the appropriate designated parking areas, to avoid ticketing or towing. Information on parking is available from the facility if requested by the contractor.
12.3 Contract Administration: The Contracting Officer is the only person authorized to approve changes or modify any of the requirements under this contract. The Contractor shall communicate with the Contracting Officer on all matters pertaining to contract administration. Only the Contracting Officer is authorized to make commitments or issue changes that will affect price, quantity, or quality of performance of this contract. In the event the Contractor makes any such change at the direction of any person other than the Contracting Officer, this change shall be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in costs incurred as a result thereof. All changes to the contract will be issued via an amendment and/or modifications in writing from the Contracting Officer to the Contractor.
12.4 Invoicing and Payment: Contractor is authorized prompt payment IAW applicable regulation following the successful performance of work, execution of services, and completion of required deliverables. Contractor invoices shall be submitted IAW VAAR Clause 852.232-72 Electronic Submission of Payment Requests. Invoices submitted for payment must be detailed to the extent necessary to reflect the work done and the services performed during the time periods when completed so an accurate assessment can be made by the facility for certification of these invoices for payment. Advance payments are not authorized, and contractor is not authorized payment for future work not performed and/or for work that has not been successfully completed.
13. VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VApersonnel regarding information and information system security.
2. ACCESS TOVAINFORMATION ANDVAINFORMATIONSYSTEMS
a. A contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
d. Custom software development and outsourced operations must be located in the U.S.
to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
3. VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data- General, FAR 52.227-14(d) (1).
b. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment.
APPENDIX C — VA INFORMATION AND INFORMATION SYSTEM SECURITY AND PRIVACY LANGUAGE FOR INCLUSION IN CONTRACTS, AS APPROPRIATE NOTE: Any sections (1-14) which DO NOT apply should not be included in the Statement of Work (SOW), Performance Work Statement (PWS), Product Description (PD) or contract.
1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.
2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.
b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.
c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.
d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), Page 1 of
Page 1 of C-and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.
e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.
f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.
g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.
h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.
i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.
k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality- assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain
C-medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above- mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.
l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.
m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.
n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.
o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA.The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.
p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.
3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.
b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.
c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).
d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.
e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:
(1) Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.
C-4
VA
Handbook
6500.6 APPENDIX C
April 22,
(2) Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.
(3) Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company- owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.
(4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.
(5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.
(6) Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.
f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.
g. Contractors/subcontractors who no longer require VA accesses will return VA- issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.
4. TRAINING. This entire section applies to all acquisitions which include section 3.
a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:
(1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.
(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and
(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role- based information security training].
b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.
c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.
5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.
b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:
(1) The date and time (or approximation of) the Security Incident occurred.
(2) The names of individuals involved (when applicable).
(3) The physical and logical (if applicable) location of the incident.
(4) Why the Security Incident took place (i.e., catalyst for the failure).
(5) The amount of data belonging to VA believed to have been compromised.
(6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.
c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.
d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.
e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.
g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.
h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages— Reimbursement for Data Breach Costs.
6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.
a. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).
b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain an Authority to Operate (ATO). VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides the security and privacy requirements for cloud environments.
c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced.
d. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M- 22-18 (September 14, 2022). The term “software” includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self- attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self- attestation.
e. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.
f. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.
g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository.
h. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems.
i. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.
j. The contractor-delivered solutions shall reside on VA approved operating systems. Exceptions to this will only be granted with the written approval of the COR/CO.
k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.
l. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224- 2 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.
m. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.
n.…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .