36C25625Q0985.docx

DOCX document 144 KB Posted

Attached to
R612--SUBSCRIPTION SOFTWARE CONTRACT Federal contract opportunity
Solicitation number
36C25625Q0985
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 16

About this file

This is a Request for Quotation (RFQ) for Volpara Health software and support services issued by the Department of Veterans Affairs Gulf Coast Veterans Healthcare System Network Contracting Office. The solicitation (36C25625Q0985) seeks a small business to provide Volpara Patient Hub and Volpara Risk software for the Overton Brooks VA Medical Center in Shreveport, Louisiana. The procurement is structured as a 12-month base contract with four 12-month option periods, focusing on improving women's imaging services by implementing mammography software and supporting infrastructure.

Key details include a quote submission deadline of June 18, 2025 at 12pm CT, with all questions due by June 11, 2025. The contract will be awarded using FAR 13.106 Comparative Analysis Evaluation, considering technical capability, past performance, and pricing. The software requirements include customizable patient tracking, risk calculations, seamless integration with existing systems, staff and administrator licenses, interface capabilities, and on-site and remote training. The solicitation is set aside for small businesses, with evaluation factors emphasizing service-disabled veteran-owned and veteran-owned small business participation. The estimated contract value is approximately $47 million, with labor rates determined by the Caddo Parish, Louisiana wage determination.

View the file

Other files for this federal contract opportunity

Other files attached to R612--SUBSCRIPTION SOFTWARE CONTRACT, newest first.
File Type Posted
Wage Determination 2015-5191 Caddo.pdf PDF
ATTACHMENT 2 LIST OF PAST PERFORMANCE REFERENCES.docx DOCX document
ATTACHMENT 3 PAST PERFORMACE QUESTIONAIRE.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

36C25625Q0985

PAGE 1 OF

1. REQUISITION NO.

2. CONTRACT NO.

3. AWARD/EFFECTIVE DATE

4. ORDER NO.

5. SOLICITATION NUMBER

6. SOLICITATION ISSUE DATE

a. NAME

b. TELEPHONE NO. (No Collect Calls)

8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY

CODE

10. THIS ACQUISITION IS

UNRESTRICTED OR

SET ASIDE:

% FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ

IFB

RFP

15. DELIVER TO

CODE

16. ADMINISTERED BY

CODE

17a. CONTRACTOR/OFFEROR

CODE

FACILITY CODE

18a. PAYMENT WILL BE MADE BY

CODE

TELEPHONE NO.

UEI:

EFT:

PHONE:

FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19.

20.

21.

22.

23.

24.

ITEM NO.

SCHEDULE OF SUPPLIES/SERVICES

QUANTITY

UNIT

UNIT PRICE

AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA

ARE

ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________

29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED

SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION

(REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

667-25-3-133-0509 36C25625Q0985 Angela Kennedy 228-523-5000 x 40361 06- -2025 12pm

CDT

00586 Department of Veterans Affairs Gulf Coast Veterans Healthcare System Network Contracting Office 16 400 Veterans Avenue Biloxi MS 39531 X X 513210 $47 Million N/A X 00586 Department of Veterans Affairs

OVERTON BROOKS VA MEDICAL CENTER

Radiology

510 E STONER AVE

Shreveport LA 71101 10N16 Department of Veterans Affairs Gulf Coast Veterans Healthcare System Network Contracting office 16 400 Veterans Avenue Biloxi MS 39531

FSC e-Invoice Payment http://www.fsc.va.gov/fsc/einvoice.asp Invoice Setup Information 1-877-489-6135 invoice must be submitted electronically 1-877-489-6135 See CONTINUATION Page Network Contracting Office 16 is seeking small businesses capable of providing Volpara Health & Volpara Risk software and support, per the salient characteristics within the SOW, for the Overton Brooks VAMC.

All questions are due June 11, by 12pm CT, and all quotes are due June 18, by 12pm CT via email to angela.kennedy2@va.gov.

**PAY CLOSE ATTENTION TO SECTION E.1 INSTRUCTIONS TO OFFEROR

AND SECTION E.

EVALUATION FACTORS

This solicitation utilizes FAR 13.106 Comparative Analysis Evaluation.

Louisiana Parish of Caddo Wage Determination No.: 2015-5191 Revision 26 attached.

See CONTINUATION Page X X X Danette Impey Table of Contents

SECTION A1
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES1
SECTION B - CONTINUATION OF SF 1449 BLOCKS4
B.1 CONTRACT ADMINISTRATION DATA4
B.2 Statement of Work4
B.3 PRICE/COST SCHEDULE20
ITEM INFORMATION20
SECTION C - CONTRACT CLAUSES27
C.1 ADDENDUM to FAR 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES27
C.2 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)28
C.3 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)28
C.4 VAAR 852.201-70 CONTRACTING OFFICER'S REPRESENTATIVE (DEC 2022)28
C.5 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)28
C.6 VAAR 852.215-70 SERVICE-DISABLED VETERAN-OWNED AND VETERAN-OWNED SMALL BUSINESS EVALUATION FACTORS (JAN 2023) (DEVIATION)29
C.7 VAAR 852.215-71 EVALUATION FACTOR COMMITMENTS (OCT 2019)29
C.8 VAAR 852.219-76 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—CERTIFICATE OF COMPLIANCE FOR SUPPLIES AND PRODUCTS (NOV 2022)30
C.9 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV 2018)32
C.10 VAAR 852.237-75 KEY PERSONNEL (OCT 2019)33
C.11 VAAR 852.239-70 SECURITY REQUIREMENTS FOR INFORMATION TECHNOLOGY RESOURCES (FEB 2023)33
C.12 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)35
C.13 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)36
C.14 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (JAN 2025) (DEVIATION FEB 2025)36
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS44
ATTACHMENT 1 Wage Determination 2015-5191 Caddo.45
ATTACHMENT 2 LIST OF PAST PERFORMANCE REFERENCES.45
ATTACHMENT 3 PAST PERFORMACE QUESTIONAIRE.45
SECTION E - SOLICITATION PROVISIONS45
E.1 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES45
E.2 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)47
E.3 52.204-29 FEDERAL ACQUISITION SUPPLY CHAIN SECURITY ACT ORDERS—REPRESENTATION AND DISCLOSURES (DEC 2023)50
E.4 VAAR 852.239-71 INFORMATION SYSTEM SECURITY PLAN AND ACCREDITATION (FEB 2023)52
E.5 VAAR 852.239-75 INFORMATION AND COMMUNICATION TECHNOLOGY ACCESSIBILITY NOTICE (FEB 2023)52
E.6 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)52
E.7 VAAR 852.252-70 SOLICITATION PROVISIONS OR CLAUSES INCORPORATED BY REFERENCE (JAN 2008)53
E.8 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021)53
E.9 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (MAY 2024) (DEVIATION FEB 2025)54

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C256 Department of Veterans Affairs Gulf Coast Veterans Healthcare System Network Contracting Office 16 400 Veterans Avenue Biloxi MS 39531

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X]
52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[]
52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly[]
b. Semi-Annually[]
c. Other[X] monthly in arrears

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO
DATE

B.2 Statement of Work

1. PURPOSE

Overton Brooks VA Medical Center’s Veteran population is increasing, and the need to provide Women's imaging services is a National Agenda Hot Topic Item. OBVAMC currently has no Mammography services due to a lack of equipment and is relying solely on OCC at a significant cost to the facility. Also, utilization of OCC consistently results in delays in receiving the outside report and is often overburdened on those in the process of obtaining these reports. Radiology requests approval to procure software/license through Volpara Breast Health Software to include Volpara Patient Hub and Volpara Risk software. The software will be purchased to accompany the mammography unit. The addition of the mammography unit and software will significantly improve Veteran access to care at OBVAMC.

1.1 SCOPE:

The vendor shall install all listed software (Volpara Patient Hub and Volpara Risk). All software must meet all salient characteristics defined in this section. The vendor shall furnish all design, transportation, labor, supervision, and training to provide Volpara Software in support of VISN 16. The software shall be delivered/installed to the designated location within this SOW. The Volpara software shall meet all applicable documents, standards, and publications in effect at the time of installation. The vendor must also have the capability of providing software for a 12-month base period with (4) 12-month option periods.

1.2 PLACE OF PERFORMANCE:

Overton Brooks VAMC, Radiology Service (OBVAMC) 510 E. Stoner Ave. Shreveport, LA 71101

2. PERFORMANCE PERIOD:

The period of performance shall be a 12-month base for installation and support with four 12- Month option periods to provide annual software license, remote support, advisory/support services, and all other requirements under the U.S. Federal Software License and Services Agreement.

2.1 SPECIFIC TASKS AND DELIVERABLES:

At a minimum; the contractor shall:

· Provide software based on the requirements and functionalities of this Statement of Work

· Maintain responsibility for their software design and architecture as approved by VA OIT

· Provide technical support and maintenance of the software

· Provide on-site and remote training to required end users (staff)

· Provide software updates and ongoing software patches as required

3. GENERAL REQUIREMENTS:

3.1. Software for these items should meet all functional requirements described herein.

3.2 SALIENT CHARACTERISTICS

3.2.1 Volpara Patient Hub and Volpara Risk Includes

Features:

· Customizable patient tracking and report software worklists, patient record setup, and personal statistical report folders

· One-touch buttons to submit findings, assessments, conclusions, and final reports

· Risk calculations using multiple models, including Tyrer-Cuzick v8

· Seamless integration into RIS, PACS, Workstation, and voice recognition workflows

· Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports

· Customize mammography workflow and speed of performance with automated reports and communications (Volpara Patient Hub)

· A full program for identifying and managing high-risk patients (Volpara Risk) Staff Licenses:

· Saff access to all features and functionality of patient HUB and Volpara risk

· Licenses may be reassigned among staff as needed

System Administrator License:

· Access to all administrative controls and settings for system setup and maintenance Standard Interface - Patient Hub:

· HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM, and/or ORU messages.

· See the Interface and Integration Summary section below for details on the interfaces included in this quotation.

Third-Party Integration:

· Custom integration between Patient Hub and a third-party software system (e.g., PACS, RIS, digital reading workstations, and/or voice recognition systems) via DICOM Mammography CAD Structured Report or Fast Healthcare Interoperability Resource (FHIR).

· See the Interface and Integration Summary section below for details on the integrations included in this Quotation.

Interface and Integration Summary:

· One 2-way HL7 interface (ADT and ORM)

· One PowerScribe 360 integration

- Product

PRODUCT NAME
DESCRIPTION
Patient Hub – Risk Bundled Offering
Volpara Breast Health Software

• Customizable patient tracking and reporting software - custom worklists, patient record setup, and personal statistical report folders.

• One-touch buttons to submit findings, assessments, conclusions, and final reports.

• Risk calculations using multiple models, including Tyrer-Cuzick v8.

• Seamless integration into RIS, PACS, workstation, and voice recognition workflows.

• Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports

Staff Licenses
• Staff access to all features and functionality of Patient Hub and Volpara Risk

• Licenses may be reassigned among staff as needed.

System Administrator License
• Access to all administrative controls and settings for system setup and maintenance
Standard Interface - Patient Hub
• HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM,

and/or ORU messages

• See the Interface and Integration Summary section below for details on the interfaces included in This quotation.

Third-Party Integration
• Custom integration between Patient Hub and a third-party software system (e.g., PACS, RIS,

digital reading workstations, and/or voice recognition systems) via DICOM Mammography CAD Structured Report or Fast Healthcare Interoperability Resource (FHIR)

Patient Hub Remote Product Training (hours)
• Remote initial product training to staff on Patient Hub features and functionality
Patient Hub On-Site Initial Training (days)
• On-site initial training to staff on Patient Hub features and functionality

• Two (2) day minimum.

4. TRAINING:

The vendor shall provide the following training:

Patient Hub On-Site Initial Training (days) – Onsite Training shall be a minimum of two days. Training will be for four Radiologists.

Patient Hub Remote Product Training (hours) – Remote initial product training (Patient Hub features and functionality) will be provided to staff.

5. POST-AWARD MEETINGS:

· The vendor shall participate in a post-award technical review meeting. Attendees typically include but are not limited to Contracting Officer (CO) and Contracting Officer Representative (COR). The meeting shall be scheduled by the VA as soon after the award of the contract as practicable, but no more than 10 business days after the award of the contract.

· The vendor shall participate in two (2) Verification Design Review (VDR) meetings held via Teams. Attendees typically include but are not limited to agency end-user representative(s) and contracting personnel. The first meeting shall be scheduled by the VA for 30 days after the award of the contract the second shall be 60 days after the award of the contract and the third shall be 90 days after the award of the contract. All body and system drawings must be approved and signed by the end of the third VDR meeting. The vendor shall not proceed with the installation of software until approval to proceed is given by the government after the VDR meetings.

6. DELIVERY

6.1 Contractor shall deliver and install software within the Overton Brooks VAMC, Radiology Service (114) 510 E. Stoner Ave. Shreveport, LA 71101 on or before August 31, 2025.

6.2 Any government-requested delayed delivery up to 90 days after the initial award delivery date, shall be at no additional cost to the government.

6.3 A pre-delivery meeting will be conducted before the initial award delivery date for verification of delivery and installation dates.

6.4 All personnel in the contractors’ services shall have certified or proper training on the task they will be performing.

6.5 The Project Engineer or COR shall be informed by the contractor of the following situations/events in writing:

•The anticipated start date of any contract work.
•As soon as it is known that the work will take longer than expected.
•As soon as it is known that a possible change order will have to happen.
•To provide a written plan for corrective action for any work that cannot be completed within the

contract specified time.

• At completion of work prior to leaving each facility.

6.6. All work shall be completed in accordance with the contract.

6.7. All required contract work completed shall be approved and accepted by the Project Engineer or the COR prior to accepting and approving the contractor’s application for payment.

7. INSPECTION AND ACCEPTANCE

7.1 The contractor shall conduct a joint inspection with the COR upon delivery of equipment.

7.2 Contractor shall provide dates of completion of replacement parts and/or ship items from the manufacturer(s).

8. SECURITY REQUIREMENTS

VA ACQUISITION REGULATION SOLICITATION PROVISION AND CONTRACT CLAUSE

8.1 SUBPART 839.2 – INFORMATION AND INFORMATION TECHNOLOGY SECURITY REQUIREMENTS

839.201 Contract clause for Information and Information Technology Security:

a. Due to the threat of data breach, compromise or loss of information that resides on either VA-owned or contractor-owned systems, and to comply with Federal laws and regulations, VA has developed an Information and Information Technology Security clause to be used when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor, subcontractor or a third party in any format (e.g., paper, microfiche, electronic or magnetic portable media).

b. In solicitations and contracts where VA Sensitive Information or Information Technology will be accessed or utilized, the CO shall insert the clause found at 852.273-75, Security Requirements for Unclassified Information Technology Resources.

9. GENERAL

This entire section applies to all acquisitions requiring any Information Security and Privacy language.

Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives, and handbooks, as VA personnel regarding information and information system security and privacy.

10. VA INFORMATION CUSTODIAL LANGUAGE

This entire section applies to all acquisitions requiring any Information Security and Privacy language.

a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.

b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements, and media sanitization.

d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.

e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after the execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contractor.

h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA-approved Transport Layer Security (TLS) configured with FIPS-based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations.

i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for the performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA CO for response.

k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.

l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in the performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.

m. Any data destruction done on behalf of the VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

n. The contractor shall provide its plan for the destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.

o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices, or optical discs that are used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

p. All electronic storage media (hard drives, optical disks, CDs, backup tapes, etc.) used to store, process, or access VA information will not be returned to the contractor at the end of the lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

11. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in the performance or administration of the contract.

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliates of contractor/subcontractor and agent of contractor/subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with the VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations are required to be in the United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to the VA a detailed plan specifically addressing communications, personnel control, data protection, and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

1) Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

2) Contractor/subcontractor personnel are terminated, suspended, or otherwise have their work on a VA project discontinued for any reason.

3) The contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets, and/or VA data.

4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to a background investigation or employee record.

5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.

6) The agreement by which the contractor provides products and services to the VA has either been fulfilled or terminated, such that the VA can cut off electronic and/or physical access for contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to the VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV-- Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks, and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.

12. TRAINING

a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:

1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with an equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

13. SECURITY INCIDENT INVESTIGATION

This entire section applies to all acquisitions requiring any Information Security and Privacy language.

a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security/privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD

b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:

1) The date and time (or approximation of) the Security Incident occurred.

2) The names of individuals involved (when applicable).

3) The physical and logical (if applicable) location of the incident.

4) Why the Security Incident took place (i.e., catalyst for the failure).

5) The amount of data belonging to VA is believed to have been compromised.

6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.

c. After the contractor has provided the initial detailed incident summary to the VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor and their employees shall fully cooperate with the VA or third-party entity performing an independent risk analysis on behalf of the VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with the VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to the incident.

f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management, and reporting procedures associated with managing of breaches.

g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of the breach of such information. When a business associate is part of a VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach Costs.

14. PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT AND ANTI-TAMPERING

This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.

a. The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, “Securing the Information and Communications Technology and Services (ICTS) Supply Chain”, which prohibits ICTS Transactions from foreign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in, or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs, or the platforming or data hosting of applications for consumer download.

b. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor are authentic. If procurement is unavailable from an OEM or authorized reseller, the contractor shall submit in writing, details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.

c. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches), and firmware provided under this agreement. Documentation will include a chain of custody practices, an inventory management program, information protection practices, an integrity management program for sub-supplier-provided components, and replacement parts requests. The contractor shall make spare parts available. All contractor(s) shall specify how digital delivery for procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.

d. If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).

e. The contractor shall provide a software bill of materials (SBOM) for procured (to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials (SBOM).”

f. Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S.-registered mail and/or tamper-evident packaging for physical deliveries.

g. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering).

h. The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware.

15. VIRUSES, FIRMWARE AND MALWARE

This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.

a. The contractor shall execute due diligence to ensure all provided software and patches, including third-party patches, are free of viruses and/or malware before releasing them to or installing them on VA information systems.

b. The contractor warrants it has no knowledge of and did not insert, any malicious virus and/or malware code into any software or patches provided to VA which could potentially harm or disrupt VA information systems. The contractor shall use due diligence, if supplying third-party software or patches, to ensure the third party has not inserted any malicious code and/or virus which could damage or disrupt VA information systems.

c. The contractor shall provide or arrange for the provision of technical justification as to why any “false positive” hit has taken place to ensure their code’s supply chain has not been compromised. Justification may be required, but is not limited to when install files, scripts, firmware, or other contractor-delivered software solutions (including third-party install files, scripts, firmware, or other software) are flagged as malicious, infected, or suspicious by an anti-virus vendor.

d. The contractor shall not upload (intentionally or negligently) any virus, worm, malware, or any harmful or malicious content, component, and/or corrupted data/source code (hereinafter “virus or other malware”) onto VA computer and information systems and/or networks. If introduced (and this clause is violated), upon written request from the VA CO, the contractor shall:

1) Take all necessary action to correct the incident, to include any and all assistance to VA to eliminate the virus or other malware throughout VA’s information networks, computer systems, and information systems; and

2) Use commercially reasonable efforts to restore operational efficiency and remediate damages due to data loss or data integrity damage, if the virus or other malware causes a loss of operational efficiency, data loss, or damage to data integrity.

REFERENCE (S):

1. VA Affairs Handbook 6500, Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program, 10 Mar 2015.

2. Veterans Health Administration Procurement Manual (VHA PM) – 11/3/2014.

3. VA Handbook 1901.01, Health Information Management and Health Records – 19 Mar 15.

4. VHA Handbook 1605.5, Business Associate Agreements – 22 July 2014

5. Privacy Act of 1974 (5 U.S.C. 552a).

16. WARRANTY

The contractor shall provide all manufacturer’s warranty with products upon delivery

17. CONTRACT ADMINISTRATION

17.1. Changes to Contract or SOW: The CO is the only individual authorized to approve changes or modify any of the requirements under this SOW or impending contract. The vendor shall communicate with the COR on all matters pertaining to contract administration. Only the CO is authorized to make commitments or issue changes affecting the price, quantity, or performance of this contract. Costs incurred by the vendor through the actions of parties other than the CO shall be borne by the vendor.

(End of Statement of Work)

B.3 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM NUMBER
DESCRIPTION OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1.00
YR
__________________
__________________

Patient Hub - Risk Bundled Offering Features: Customizable patient tracking and reporting software - custom worklists, patient record set up, and personal statistical report folders. One-touch buttons to submit findings, assessment, conclusions, and final reports. Risk calculations using multiple models, including Tyrer-Cuzick v8. Seamless integration into RIS, PACS, workstation, and voice recognition workflows. Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports.

Contract Period: Option 2 POP Begin: 06-30-2027 POP End: 06-30-2028

0001AA

4.00
EA
__________________
__________________

Staff Licenses Staff access to all features and functionality of Patient Hub and Volpara Risk. Licenses may be reassigned among staff as needed.

0001AB

2.00
EA
__________________
__________________

System Administrator License Access to all administrative controls and settings for system set up and maintenance

0001AC

2.00
EA
__________________
__________________

Standard Interface - Patient Hub HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM, and/or ORU messages. See Interface and Integration Summary section below for details on the interfaces included in this quotation.

0001AD

1.00
EA
__________________
__________________

Third Party Integration Custom integration between Patient Hub and a third-party software system (e.g., PACS, RIS, digital reading workstations, and/or voice recognition systems) via DICOM Mammography CAD Structured Report or Fast Healthcare Interoperability Resource (FHIR). See Interface and Integration Summary section below for details on the integrations included in this Quotation.

0001AE

6.00
HR
__________________
__________________

Patient Hub Remote Product Training (hours) Remote initial product training to staff on Patient Hub features and functionality.

0001AF

4.00
DY
__________________
__________________

Patient Hub On-Site Initial Training (days) On-site initial training to staff on Patient Hub features and functionality. Two (2) day minimum.

1.00
YR
__________________
__________________

Patient Hub - Risk Bundled Offering Features: Customizable patient tracking and reporting software - custom worklists, patient record set up, and personal statistical report folders. One-touch buttons to submit findings, assessment, conclusions, and final reports. Risk calculations using multiple models, including Tyrer-Cuzick v8. Seamless integration into RIS, PACS, workstation, and voice recognition workflows. Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports.

Contract Period: Option 3 POP Begin: 06-30-2028 POP End: 06-30-2029

1001AA

4.00
EA
__________________
__________________

Staff Licenses Staff access to all features and functionality of Patient Hub and Volpara Risk. Licenses may be reassigned among staff as needed.

1001AB

2.00
EA
__________________
__________________

System Administrator License Access to all administrative controls and settings for system set up and maintenance

1001AC

2.00
EA
__________________
__________________

Standard Interface - Patient Hub HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM, and/or ORU messages. See Interface and Integration Summary section below for details on the interfaces included in this quotation.

1001AD

1.00
EA
__________________
__________________

Third Party Integration Custom integration between Patient Hub and a third-party software system (e.g., PACS, RIS, digital reading workstations, and/or voice recognition systems) via DICOM Mammography CAD Structured Report or Fast Healthcare Interoperability Resource (FHIR). See Interface and Integration Summary section below for details on the integrations included in this Quotation.

1001AE

6.00
HR
__________________
__________________

Patient Hub Remote Product Training (hours) Remote initial product training to staff on Patient Hub features and functionality.

1001AF

4.00
DY
__________________
__________________

Patient Hub On-Site Initial Training (days) On-site initial training to staff on Patient Hub features and functionality. Two (2) day minimum.

1.00
YR
__________________
__________________

Patient Hub - Risk Bundled Offering Features: Customizable patient tracking and reporting software - custom worklists, patient record set up, and personal statistical report folders. One-touch buttons to submit findings, assessment, conclusions, and final reports. Risk calculations using multiple models, including Tyrer-Cuzick v8. Seamless integration into RIS, PACS, workstation, and voice recognition workflows. Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports.

Contract Period: Option 4 POP Begin: 06-30-2029 POP End: 06-30-2030

2001AA

4.00
EA
__________________
__________________

Staff Licenses Staff access to all features and functionality of Patient Hub and Volpara Risk. Licenses may be reassigned among staff as needed.

2001AB

2.00
EA
__________________
__________________

System Administrator License Access to all administrative controls and settings for system set up and maintenance

2001AC

2.00
EA
__________________
__________________

Standard Interface - Patient Hub HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM, and/or ORU messages. See Interface and Integration Summary section below for details on the interfaces included in this quotation.

2001AD

1.00
EA
__________________
__________________

Third Party Integration Custom integration between Patient Hub and a third-party software system (e.g., PACS, RIS, digital reading workstations, and/or voice recognition systems) via DICOM Mammography CAD Structured Report or Fast Healthcare Interoperability Resource (FHIR). See Interface and Integration Summary section below for details on the integrations included in this Quotation.

2001AE

6.00
HR
__________________
__________________

Patient Hub Remote Product Training (hours) Remote initial product training to staff on Patient Hub features and functionality.

2001AF

4.00
DY
__________________
__________________

Patient Hub On-Site Initial Training (days) On-site initial training to staff on Patient Hub features and functionality. Two (2) day minimum.

1.00
YR
__________________
__________________

Patient Hub - Risk Bundled Offering Features: Customizable patient tracking and reporting software - custom worklists, patient record set up, and personal statistical report folders. One-touch buttons to submit findings, assessment, conclusions, and final reports. Risk calculations using multiple models, including Tyrer-Cuzick v8. Seamless integration into RIS, PACS, workstation, and voice recognition workflows. Easy and accelerated statistical reporting for FDA MQSA EQUIP inspection or ACR accreditation with simple exports.

Contract Period: Base POP Begin: 06-30-2025 POP End: 06-30-2026

3001AA

4.00
EA
__________________
__________________

Staff Licenses Staff access to all features and functionality of Patient Hub and Volpara Risk. Licenses may be reassigned among staff as needed.

3001AB

2.00
EA
__________________
__________________

System Administrator License Access to all administrative controls and settings for system set up and maintenance

3001AC

2.00
EA
__________________
__________________

Standard Interface - Patient Hub HL7 interface between Patient Hub and a third-party software system via transfer of ADT, ORM, and/or ORU messages. See Interface and Integration Summary section below for details on the interfaces included in this quotation.

3001AD

1.00
EA
__________________
__________________

Third Party Integration Custom integration between Patient Hub and a…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .