S02 36C25726Q0349 0005.pdf

PDF 429 KB Posted

Attached to
Camera Installation Federal contract opportunity
Solicitation number
36C25726Q0349
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 17

About this file

This document is an Amendment to Solicitation/Modification of Contract for the Department of Veterans Affairs, Network Contracting Office 17, issued on March 24, 2026. The amendment corrects the number of cameras specified in paragraph 5.2.7 PROJECT MANAGEMENT of the Statement of Work (SOW) and adjusts the corresponding quantity in the Price/Cost Schedule for Contract Line Item Number (CLIN) 0002. The solicitation number is 36C25726Q0349, with the effective date of April 10, 2026, and the requisition number is 549-26-2-5096-0065.

The underlying contract requirement involves the replacement of eight (8) existing PTZ cameras with new Avigilon 8MP PTZ cameras on the rooftop of the Dallas VA Medical Center (4500 S. Lancaster Rd., Dallas, TX 75216) and the installation of two (2) new cameras in the Executive Office. CLIN 0001 covers the replacement of eight cameras at 8.00 each unit, while CLIN 0002 covers the installation of two new cameras at 2.00 each unit. The work includes CAT6A Plenum cabling installation, data drop termination, comprehensive cable management compliant with BICSI standards and TIA specifications, removal of existing equipment, and preprogramming of cameras with IP addresses provided by the Dallas VA Medical Center. The contractor must provide necessary POE injectors, verify camera configuration and functionality, and conduct a final walkthrough upon completion. The contract also requires compliance with VA security protocols, background investigations for contractor personnel, proper handling of sensitive information, and adherence to federal accessibility standards (Section 508), physical security requirements, and records management procedures outlined in NARA guidance.

View the file

Other files for this federal contract opportunity

Other files attached to Camera Installation, newest first.
File Type Posted
BLDG 2J 5TH FL EHRM - Camera Locations.pdf PDF
S02 36C25726Q0349 0004.pdf PDF
BLDG 2 9TH FL EHRM - Camera Locations.pdf PDF
S02 36C25726Q0349 0003.pdf PDF
Site Visit Sign In Sheet.pdf PDF
S02 36C25726Q0349 0002.pdf PDF
S02 36C25726Q0349 0001.pdf PDF
S02 36C25726Q0349.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

5. PROJECT NUMBER (if applicable)

CODE 7. ADMINISTERED BY

2. AMENDMENT/MODIFICATION NUMBER

CODE

6. ISSUED BY

8. NAME AND ADDRESS OF CONTRACTOR

4. REQUISITION/PURCHASE REQ. NUMBER 3. EFFECTIVE DATE

9A. AMENDMENT OF SOLICITATION NUMBER

9B. DATED

PAGE OF PAGES

10A. MODIFICATION OF CONTRACT/ORDER NUMBER

10B. DATED

BPA NO. 1. CONTRACT ID CODE

FACILITY CODE CODE

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

E. IMPORTANT:

is extended,

(a) By completing Items 8 and 15, and returning __________ copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY is not extended.

12. ACCOUNTING AND APPROPRIATION DATA

(REV. 11/2016)

is required to sign this document and return ___________ copies to the issuing office. is not, A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN ITEM 10A.

15C. DATE SIGNED

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER

Contractor

16C. DATE SIGNED

14. DESCRIPTION OF AMENDMENT/MODIFICATION

16B. UNITED STATES OF AMERICA

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER 16A. NAME AND TITLE OF CONTRACTING OFFICER

15B. CONTRACTOR/OFFEROR

STANDARD FORM 30 PREVIOUS EDITION NOT USABLE

Prescribed by GSA - FAR (48 CFR) 53.243

(Type or print) (Type or print)

(Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

(Number, street, county, State and ZIP Code)

(If other than Item 6)

(Specify type of modification and authority)

(such as changes in paying office, appropriation date, etc.)

(If required)

(SEE ITEM 11)

(SEE ITEM 13)

(X)

CHECK

ONE

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

(Signature of person authorized to sign) (Signature of Contracting Officer)

1 10

0005 04-10-2026

549-26-2-5096-0065

36C257

Department Of Veterans Affairs Network Contracting Office 17

5441 Babcock Road Ste. 302 San Antonio TX 78240

36C257

Department Of Veterans Affairs Network Contracting Office 17

5441 Babcock Road Ste. 302 San Antonio TX 78240

To all Offerors/Bidders

36C25726Q0349

03-24-2026

X

X X

X one (1)

The purpose of this amendment is to correct the number of cameras needed in paragraph 5.2.7 PROJECT MANAGEMENT of the Statement of Work (SOW) and to correct the number of cameras within the Price/Cost Schedule for Contract Line Item Number (CLIN) 0002.

Melanie Williams Contracting Officer

A.1 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM

NUMBE

R

DESCRIPTION OF

SUPPLIES/SERVI

CES

QUANTI

TY

UNI

T UNIT PRICE AMOUNT

8.00 EA _______________

Replacement of eight (8) existing PTZ cameras with new Avigilon 8MP PTZ cameras on the rooftop

2.00 EA _______________

Install two (2) new cameras in the Executive Office of the Dallas VA Medical Center

GRAND TOTAL _______________

1.0 BACKGROUND

1.1 The Department of Veterans Affairs, VA North Texas, has a requirement for the replacement of eight (8) existing PTZ cameras with new Avigilon 8MP PTZ cameras on the rooftop and install two (2) new cameras in the executive office at the Dallas VA Medical Center. The current cameras are not functional and need to be replaced. This requirement is needed for physical security. The work will help provide a safe environment for patients and staff.

2.0 APPLICABLE DOCUMENTS

1. In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

2. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

3. VA OEHRM Site Infrastructure Requirements

4. SOCAMES 6 Design Alert(s)

5. Sensitive Infrastructure Data Classification FOUO

6. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January

18, 2017American National Standards Institute (ANSI) and Telecommunications Industry Association (TIA) standards that, at a minimum, include conformance with:

a. ANSI/TIA-942-B, Telecommunication Infrastructure Standard for Data Centers, which incorporates TIA-942-A Addendum 1.

3.0 SCOPE OF WORK

The contractor shall furnish all personnel, equipment, tools, materials, transportation, management supervision, other items (cabling raceways, face plates, MPLS caddies, ceiling-mounted cable trays, cable conduits, etc.), and services necessary to perform all cable installation tasks and all ten (10) cameras function. The contractor must perform to the standards identified in the performance work statement.

3.1.1 Data Cabling for Internet

• Install Category 6 Ethernet cables to support high-speed internet connectivity.

• Terminate cables at designated wall plates and patch panels, ensuring proper labeling for identification.

• Ensure cable management adheres to industry standards, avoiding excessive bends or stress.

• Test and certify all data drops for connectivity and performance using industry-standard testing tools.

4.0 PERFORMANCE DETAILS

There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1

Juneteenth June 19 Independence Day July 4 Veterans Day November 11 Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

4.1 PLACE OF PERFORMANCE

Dallas VA Medical Center 4500 S. Lancaster Rd.

Dallas, TX 75216

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the following:

The new Avigilon cameras will be installed to satisfy the physical security requirements of the Department of Veterans Affairs, VISN 17 North Texas Healthcare System (NTX).

5.1 New Cat6; COPPER (TWISTED PAIR):

5.1.1 Install at minimum CAT6A Plenum cabling and data drops in accordance with work orders, location drawings, and specifications.

5.1.2 Horizontal cabling shall be at minimum Category 6A (Cat6A) (ANSI/TIA-1179

Healthcare Facility Telecommunications Infrastructure).

5.1.3 Installation shall be compliant with the BICSI standards (ANSI/NECA/BICSI 568, Standard for Installing Commercial Building Telecommunications Cabling and ANSI/TIA-1179-A Healthcare Facility Telecommunications Infrastructure for new installations).

5.1.3.1 New cable installations additionally shall be compliant with TIA 568.2-D, TIA TSB-184-A, and NFPA-70 Section 725.144 to prevent PoE heat accumulation. Provide certification reports to the COR.

5.1.3.2 Alternatively, new UTP cabling shall carry a UL listed "LP" (Limited

Power) rating.

5.1.3.3 Cat6A cable shall be terminated to identified RJ-45 patch panel in IT closet and CAT6A RJ-45 jack at camera and labeled at both ends.

5.1.3.4 Use a cable analyzer to determine cable length (max cable length

90M/295 linear feet) and certify that cable meets or exceeds TIA-EIA- 568-C.2.

5.1.3.5 Cables shall be installed in continuous lengths from origin to destination, no splices with a one ft service loop.

5.1.4 Cable management shall be implemented for all patch cables in accordance with Infrastructure Standard for Telecommunications Spaces, Version 3.0, ensuring proper bend radius, bundling, airflow, support and labeling.

5.1.5 Copper structured cabling shall be certified as meeting or exceeding TIA-EIA-

568.1-D (max fixed cable length 90M/295 linear feet) independent of media type.

5.1.6 Use existing raceways as much as possible. Cable shall be installed in accordance with manufacturer’s recommendations and best industry practices.

Existing raceways shall not be filled greater than the NEC maximum fill for the raceway type. Cables shall be supported with J hooks or cable bags every four

(4) to five (5) feet whenever there is an absence of a cable tray. Any areas requiring the use of fire sealing material will conform to the ANSI/NFPA-70 FIRE SEALING / SAFETY standard. The VA, upon written request, will authorize the contractor to provide a quote to increase number or size of pathways only in the event the total pathways provided to any given area are inadequate.

5.1.7 Patch panel labels shall include outlet #, jack #. All label printing shall be machine generated

5.1.8 Confirm locations, including installation height, with COR.

5.1.9 Patch and finish disturbed surfaces to match existing.

5.1.10 All material, installed by the contractor, shall be new, tested, and certified. Any station cables testing with bad pairs will be reinstalled. Provide the certification report to COR.

5.1.11 All new Station Data / Voice cable sheaths will be color coded. Blue Sheath will be a 4 pair Data Cable; White Sheath will be a 4 pair Voice Cable; Purple sheath will be a 4 pair video/security cable and shall conform to the requirements of ICEA Publications S-80-576-1988 (Ref. B1.6) as to size, color code, and insulation.

5.1.11.1 CAT6A Plenum cable used in this installation will be purple sheath 4 pair video/security cable

5.1.12 Conductors shall be cabled to insure against induction in voice/data circuits.

Crosstalk attenuation within the cable system shall be more than 80dB throughout the frequency range (UL, ISO 2000).

5.1.13 If temporary cable and wire pairs are used, they shall be installed to present no pedestrian safety hazard and the contractor shall be responsible for all work associated with this temporary installation and for removal when no longer necessary.

5.1.14 The Contractor shall ground all metallic cable sheaths, etc. per NEC requirement (e.g. risers, underground, station wiring).

5.1.15 All outside cable shall be shielded, 24AWG solid conductors, solid PIC insulation, and filled core (flex gel) (waterproof) REA LISTED PE 39 or PE 89 Code. The outside cable plant cable shall be grounded with 6-gauge green ground cable.

Access to the manholes will be coordinated with the VAMC (Quality Management-Safety). This will allow time to air and test the manhole environment to ensure a safe entry.

5.1.16 All inside riser communications cables shall be listed as being suitable for that purpose and marked accordingly.

5.1.17 All inside riser communications cables shall be shielded, 24AWG solid, thermoplastic insulated conductors. It shall be enclosed with a thermoplastic outer jacket. The maximum DC resistance shall be no more than 28.6 Ohms per 1000 feet.

5.1.18 Once terminated, the cable sheath is clamped which provides for strain relief.

After termination, wire colors should be visible for verification of correct installation.

5.1.19 Perform a site survey to confirm exact cable routing, outlet placement, and any potential obstacles.

5.1.20 Adhere to local, state, and federal regulations, including building codes and safety standards.

5.1.21 Maintain a clean and organized work environment, disposing of waste materials properly.

5.1.22 Coordinate with the facility manager to minimize disruption to occupants and operations.

5.1.23 Provide a warranty for workmanship and materials as specified in the contract.

5.2 Avigilon Cameras

5.2.1 The Contractor shall remove the existing PTZ, wall mount bracket, seal tight, and old COAX cabling back to the IDF. Contractor will install new CAT6 cabling routed from the nearest IDF closet to the exterior junction box located next to the camera pole.

5.2.1.1 Once cabling is in place contractor will install new seal tight pathways from the exterior junction box located next to the camera pole into the new wall mount bracket that will be installed on the existing camera pole.

5.2.2 Contractor shall preprogram the cameras with the IP addresses information provided by the Dallas VA Medical Center and install them on the mounting brackets connected to the camera pole.

5.2.3 Contractor shall verify that all cameras are configured for the correct retention time and are functioning as designed.

5.2.4 Contractor shall provide necessary POE injectors for each PTZ camera and will utilize existing switches provided by the Dallas VA.

5.2.5 Once new cameras are installed, configured, and fully functional, contractor shall provide a final walk through to confirm completion of project.

5.2.6 The Rooftop installation will utilize:

Avigilon

• 8ea. 8.0C-H5A-IRPTZ-DP36-WP H5A IR PTZ Camera

• 8ea. WLMT-1001

• 8ea. POE90U-1BT

5.2.7 The Executive office cameras to be installed will be:

Avigilon

• 1 ea 8.0C-H6A-D2-IR H6A Dome Camera

• 1 ea 32C-H5A-4MH H5A Multi-Sensor Camera

5.3 PROJECT MANAGEMENT

5.3.1 Contractor will assign a Project Manager (PM) in writing, who will be the key point of contact for VA when communication with contractor throughout the period of this contract. All proposed substitutions are to be submitted to the CO in writing, at least 30 calendar days in advance of the proposed effective date.

Contractor will not team with another Vendor or contractor in performance of this scope of work.

5.3.2 Work will be accomplished Monday through Friday 8:00 a.m. to 4:30 p.m.

excluding Federal holidays. There may be instances in which the Contractor's workday may be outside this time frame. Contracting personnel working on-site at any VA location shall adhere to the rules and regulations in place at the specific VA location.

5.3.3 Contractor shall remove, daily, all debris and scrap generated in the performance of work.

5.3.4 Contractor shall obtain all required licenses required to perform the required work.

5.3.5 Contractor shall comply with all local building and fire codes. Where cable and wire penetrate through fire/smoke partitions, firewalls, or floors the Contractor shall provide and install fire stopping material, type approved by VAMC Chief, Engineering. Which is 3M Fire barrier CP 25WB+Caulk and 3M Fire Barrier Moldable Putty+.

5.3.6 Contractor shall be responsible for the removal and replacement of ceiling tiles during installation of the CAT6 cable. The contractor shall be responsible for replacement and installation of any ceiling tiles they damage with a matching tile.

5.3.7 Contractor, to ensure the fire safety code of the facility(s), the following must take place. When a cable pull is taking place in a corridor and the installer can’t see the other end of the installation. A second installer must be present under that open ceiling tile.

5.3.8 Not use gasoline, benzene, alcohol, naphtha, carbon tetrachloride, or turpentine for cleaning any part of the equipment. Flammable materials shall be kept in suitable places outside the building. OSHA safety standards and local VAMC safety standards shall prevail.

5.3.9 The Contractor shall be responsible for all communication closet keys that are issued to accomplish the work. The telecommunication closets will be secured at all times.

5.3.10 Work timelines and an updated weekly schedule shall be communicated to the

COR for tracking purposes.

5.4 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.

b. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the VA Point of Contact (POC) to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section

6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the VA POC. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

d. The Contractor shall ensure the following required forms are submitted to the VA POC within five (5) days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

f. The Contractor employee shall certify and release the e-QIP document, print, and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-

QIP).

g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

h. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM.

However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.

i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.

Deliverable:

A. Contractor Staff Roster

5.5 METHOD AND DISTRIBUTION OF DELIVERABLES

The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include: Microsoft 365, MS Word 2000/2003/2007/2010/2019, MS Excel 2000/2003/2007/2010/2019, MS PowerPoint 2000/2003/2007/2010/2019, MS Project 2000/2003/2007/2010/2019, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010/2019, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).

5.6 PERFORMANCE METRICS

The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.

Performance Objective

Performance Standard Acceptable Levels of Performance

A. Technical / Quality of Product or Service

1. Demonstrates understanding of requirements

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/products

5. Incorporates “ease of use” Human Centered Design principles in any software developed.

Satisfactory or higher

B. Project Milestones and Schedule

1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems

Satisfactory or higher

C. Cost & Staffing 1. Currency of expertise and staffing levels appropriate to perform tasks required

2. Personnel possess necessary knowledge, skills, and abilities to perform tasks

Satisfactory or higher

D. Management 1. Integration and coordination of all activities to execute effort

Satisfactory or higher

The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.

5.7 FACILITY/RESOURCE PROVISIONS

The Government will provide storage space when authorized contract staff work at a Government location as required in order to accomplish the tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact.

The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

5.8 SHIPMENT OF HARDWARE OR EQUIPMENT

Inspection: Destination Acceptance: Destination Free on Board (FOB): Destination

For any delivery of equipment to be shipped to site by Contractor prior to start of onsite installation, the ordered equipment, materials and supplies may be shipped to:

Point of Contact: Jose Gongora or Carnell Mathis

Electronics Mechanic

Mailing Address: 4500 E. Lancaster Rd.

Warehouse Bldg. 44

Dallas, TX 75216

Contractors shall coordinate deliveries with Site POCs before shipment of hardware or materials to ensure sites have adequate storage space.

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

A1.0 Cyber and Information Security Requirements for VA IT Services – N/A

A2.0 VA Enterprise Architecture Compliance- N/A

A2.1. VA Internet and Intranet Standards N/A

A3.0 Notice of the Federal Accessibility Law Affecting All Information and Communication Technology (ICT) Procurements (Section 508)

On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.

A3.1. Section 508 – Information and Communication Technology (ICT) Standards

The Section 508 standards established by the Access Board are incorporated into, and made part of all VA orders, solicitations and purchase orders developed to procure ICT. These standards are found in their entirety at: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines. A printed copy of the standards will be supplied upon request.

Federal agencies must comply with the updated Section 508 Standards beginning on January 18, 2018. The Final Rule as published in the Federal Register is available from the Access https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines

Board: https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule.

The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:

E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines)

E204 Functional Performance Criteria E206 Hardware Requirements E207 Software Requirements E208 Support Documentation and Services Requirements

A3.2. Compatibility with Assistive Technology

The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.

A3.3. Acceptance and Acceptance Testing

Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.

The Government reserves the right to test for Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.

A4.0 Physical Security & Safety Requirements:

The Contractor and their personnel shall follow all VA policies, standard operating procedures, applicable laws and regulations while on VA property. Violations of VA regulations and policies may result in citation and disciplinary measures for persons violating the law.

1. The Contractor and their personnel shall wear visible identification at all times while they are on the premises.

https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule

2. VA does not provide parking spaces at the work site; the Contractor must obtain parking at the work site if needed. It is the responsibility of the Contractor to park in the appropriate designated parking areas. VA will not invalidate or make reimbursement for parking violations of the Contractor under any conditions.

3. Smoking is prohibited inside/outside any building other than the designated smoking areas.

4. Possession of weapons is prohibited.

5. The Contractor shall obtain all necessary licenses and/or permits required to perform the work, with the exception of software licenses that need to be procured from a Contractor or vendor in accordance with the requirements document. The Contractor shall take all reasonable precautions necessary to protect persons and property from injury or damage during the performance of this contract.

6. The contractor will be escorted and given access to communication closets and other areas as needed. No keys will be provided.

A5.0 Confidentiality and Non-Disclosure The Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations.

The Contractor may have access to Protected Health Information (PHI) and Electronic Protected Health Information (EPHI) that is subject to protection under the regulations issued by the Department of Health and Human Services, as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA); 45 CFR Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45 CFR Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”). Pursuant to the Privacy and Security Rules, the Contractor must agree in writing to certain mandatory provisions regarding the use and disclosure of PHI and EPHI.

1. The Contractor will have access to some privileged and confidential materials of VA. These printed and electronic documents are for internal use only, are not to be copied or released without permission, and remain the sole property of VA. Some of these materials are protected by the Privacy Act of 1974 (revised by PL 93-5791) and Title 38. Unauthorized disclosure of Privacy Act or Title 38 covered materials is a criminal offense.

2. The VA CO will be the sole authorized official to release in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this contract. The Contractor shall release no information. Any request for information relating to this contract presented to the Contractor shall be submitted to the VA CO for response.

3. Contractor personnel recognize that in the performance of this effort, Contractor personnel may receive or have access to sensitive information, including information provided on a proprietary basis by carriers, equipment manufacturers and other private or public entities. Contractor personnel agree to safeguard such information and use the information exclusively in the performance of this contract. Contractor shall follow all VA rules and regulations regarding information security to prevent disclosure of sensitive information to unauthorized individuals or organizations as enumerated in this section and elsewhere in this Contract and its subparts and appendices.

4. Contractor shall limit access to the minimum number of personnel necessary for contract performance for all information considered sensitive or proprietary in nature. If the Contractor is uncertain of the sensitivity of any information obtained during the performance this contract, the Contractor has a responsibility to ask the

VA CO.

5. Contractor shall train all of their employees involved in the performance of this contract on their roles and responsibilities for proper handling and nondisclosure of sensitive VA or proprietary information. Contractor personnel shall not engage in any other action, venture or employment wherein sensitive information shall be used for the profit of any party other than those furnishing the information. The sensitive information transferred, generated, transmitted, or stored herein is for VA benefit and ownership alone.

6. Contractor shall maintain physical security at all facilities housing the activities performed under this contract, including any Contractor facilities according to VA-approved guidelines and directives. The Contractor shall ensure that security procedures are defined and enforced to ensure all personnel who are provided access to patient data must comply with published procedures to protect the privacy and confidentiality of such information as required by VA.

7. Contractor must adhere to the following:

a. The use of “thumb drives” or any other medium for transport of information is expressly prohibited.

b. Controlled access to system and security software and documentation.

c. Recording, monitoring, and control of passwords and privileges.

d. All terminated personnel are denied physical and electronic access to all data, program listings, data processing equipment and systems.

e. VA, as well as any Contractor (or Subcontractor) systems used to support development, provide the capability to cancel immediately all access privileges and authorizations upon employee termination.

f. Contractor PM and VA PM are informed within twenty-four (24) hours of any employee termination.

g. Acquisition sensitive information shall be marked "Acquisition Sensitive" and shall be handled as "For Official Use Only (FOUO)".

h. Contractor does not require access to classified data.

8. Regulatory standard of conduct governs all personnel directly and indirectly involved in procurements. All personnel engaged in procurement and related activities shall conduct business in a manner above reproach and, except as authorized by statute or regulation, with complete impartiality and with preferential treatment for none. The general rule is to strictly avoid any conflict of interest or even the appearance of a conflict of interest in VA/Contractor relationships.

9. VA Form 0752 shall be completed by all Contractor employees working on this contract, and shall be provided to the CO before any work is performed. In the case that Contractor personnel are replaced in the future, their replacements shall complete VA Form 0752 prior to beginning work.

A6.0 INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS

The Contractor shall comply with Sections 524 and Sections 525 of the Energy Independence and Security Act of 2007; Section 104 of the Energy Policy Act of 2005; Executive Order 13834, “Efficient Federal Operations”, dated May 17, 2018; Executive Order 13221, “Energy-Efficient Standby Power Devices,” dated August 2, 2001; and the Federal Acquisition Regulation (FAR) to provide ENERGY STAR®, Federal Energy Management Program (FEMP) designated, and Electronic Product Environmental Assessment Tool (EPEAT) registered products in providing information technology products and/or services.

Information Security

1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.

2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.

a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.

b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations

e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.

h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.

i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.

k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality- assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above- mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.

l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service

m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.

o. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.)

used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

(1) Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

(2) Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

(3) Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company- owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

(5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.

(6) Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to):

removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.

4. TRAINING. This entire section applies to all acquisitions which include section 3.

a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:

(1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role- based information security training].

b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language.

a. The contractor, subcontractor, their employees, or business associates shall immediately…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .