36C26219Q0831-003.docx
DOCX document 45 KB Posted
- Attached to
- Patient Data Management Software Federal contract opportunity
- Solicitation number
- 36C26219Q0831
About this file
36C26219Q0831 Technical specifications.docx
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C26219Q0831-002.docx | DOCX document | |
| 36C26219Q0831-001.docx | DOCX document | |
| 36C26219Q0831-000.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
REQUIREMENTS
The following list outlines the clinical, technical, support service requirements for a VISN 1 eye PACS. The Offeror shall note in their proposals how they meet or exceed each requirement listed.
a. Clinical Requirements
i. In general, the eye picture archiving and communication system (PACS) should allow for post-image processing, dynamic review, and raw data manipulation at every clinical work station in the eye clinic.
1. FORUM allows post image processing such as measurements, brightness & contrast enhancement, scrolling through OCT Data from multiple vendor OCTs that support this standard ie Zeiss & Heidelberg OCT. Allows manipulation of RAW Data for the HFA IIi and HFA 3 devices as well as CIRRUS OCT. FORUM also can enable launching of native applications if desired. This can be done at every clinical workstation in the eye clinic. In addition with certain instruments Zeiss FORUM can actually touch and manipulate down to algorithmic level. (OCT, HFA, OCT) Etc. Allows of API, which is third party manufacturer review software embedded within FORUM. Only Zeiss FORUM can provide this capability of manipulating the Visual Field (HFA raw data, removal and or changing of baseline exams dates interacting with GPA, which is Glaucoma Progression Analysis.
ii. A minimum requirement is the ability to manipulate the raw data from ocular coherence tomography (OCT) images of the optic nerve, retina and macula. This should include images from different instrument companies with proprietary capture software, as listed in Attachment B. Of note, PDF images from any source are not sufficient enough for clinical analysis or medical documentation, especially when progression or regression analysis is desired. Hence, an Offeror providing only PDF imaging capabilities will not meet VISN 1 eye PACS requirements.
1. FORUM allows post image processing such as measurements, brightness & contrast enhancement, scrolling through OCT Data from multiple vendor OCTs that support this standard ie Zeiss & Heidelberg and certain Topcon OCT units. FORUM allows manipulation of RAW Data CIRRUS OCT within Retina Workplace. FORUM also can enable launching of native applications if desired, which is again is the API functionality of 3rd party manufacturer. This can be done at every clinical workstation in the eye clinic.
iii. Another requirement is the ability to perform raw data analysis of visual field results from one or multiple instruments from one or multiple sites. The eye PACS system should provide capabilities to manipulate data according to original software progression or regression algorithms. The platform should allow for continuous (ongoing) data assimilation into any image set data previously acquired.
1. FORUM allows for RAW data analysis of Visual Field Data within the FORUM Glaucoma Workplace portion of the FORUM viewer. This allows FDA 510K cleared progression & regression algorithms to be run and manipulated down to algorithmic level. The platform will allow for continuous data assimilation and will incorporate all available history currently existing on stand-alone devices. Also can take several visual fields (HFA’s), and merge into on central database acting as one unit instead of several separate HFA’s in a clinic. Lastly this is done by REMOVING the data from the HFA’s and putting each instrument database into one central database on the server.
iv. The eye PACS should allow for point of care (viewing station) manipulation of images and image sets. For example, a clinic team should be able to remove technically inaccurate or poor test results from the PACS acquired data or images.
1. FORUM allows the POC manipulation, Admin users can remove technically inaccurate data or poor test results from PACS.
v. The eye PACS should have capability to receive raw data from intraocular lens biometers and operating scopes for intraoperative toric marking overlay during cataract surgery.
1. FORUM allows for transmission and receipt/storage of data from Optical & OCT Based biometry units and transmission to and from intraoperative microscopes for toric marking and overlay during cataract surgery to Callisto Eye enabled Lumera surgical microscopes. Further defined, as the taking the biometer reading of Zeiss IOL Master, feeding into FORUM that then feeds directly into Callisto Eye Cataract Suite into the screen and oculars of the Microscope. Without any additional effort, or usage of “USB sticks”, or printouts.
vi. The eye PACS should be capable of receiving biometry and IOL lens calculation data directly from instruments (see Attachment B) to avoid duplicate data entry efforts and potential data entry error.
1. FORUM is capable to receive biometry data from and IOL lens calculations via DICOM directly from instruments. Therefore avoiding duplicate data entry efforts/errors. This function is again from IOL Master into FORUM, then seamlessly feeding into Callisto Eye Cataract Suite on the microscope. No additional effort needed.
vii. The eye PACS must be able to receive third party DICOM images from other currently operating PACS server systems in VISN , such as Merge Healthcare’s OIS, our legacy system.
1. FORUM can accept DICOM data from third party systems such as Merge Healthcare. As DICOM Data is universal this data is able to be ingested into FORUM.
viii. All images and raw data collected in the eye PACS system should be stored on the eye PACS server. The system must be able to serve as a raw data back up in case of end instrument failure, loss or obsolescence. This is particularly important for the back-up of raw data associated with guided progression analysis.
1. FORUM can collect RAW data and images and serve as a RAW data back up for the VISN devices that are using Guided Progression AnalysisTM
ix. The eye PACS must be DICOM compliant and one should be able to create Consults or Orders from CPRS or VistA and transfer the patient demographic data into its system with VA VistA being specified as the Issuer of Patient ID. PACS system must able to send the Consult or Order to the instrument’s DICOM modality worklist.
1. FORUM is capable of managing consults and demographic data with VA VistA as the Issuer if Patient ID and can send order to the DICOM modality worklist.
x. The eye PACS must connect to any brand of non-DICOM capable diagnostic instrument with an export capability, and label the device type and laterality in the PACS system.
1. FORUM can connect to non-DICOM enabled diagnostic modalities with the LinkNet application. LinkNet manages the Modality Worklist as supplied by VistA Imaging/FORUM and can mark laterality for storage within FORUM
xi. The eye PACS must be able to automatically send images and reports from the instrument to its system via a DICOM gateway.
1. FORUM can send images and reports directly from instrument to the Archive via DICOM Gateway.
xii. The eye PACS must not require the use of an external PC or import computer for a DICOM capably instrument modalities.
1. Native DICOM modalities do not require any external PC or import computer to send data to FORUM.
xiii. The eye PACS must be able to store and access raw instrument data from equipment listed in Attachment B and also must be able to download all past raw data from that same equipment.
1. FORUM can store and access raw data from some of the equipment listed in the attachment. Some devices have proprietary methods of storing the raw data that are the intellectual property of the vendor. The past RAW data can be downloaded in a variety of ways into the system if the device is capable. Devices where the raw data can not be sent can still send past data in DICOM format in a variety of methods. Again NO Pacs system can digest “Raw Data” if instrument does NOT allow or cannot send the “Raw Data” for this capability to happen. However FORUM can not only store and access RAW data from many of the instruments listed, some of the databases from the instruments can be removed from the device and stored on the actual FORUM Server, further protecting the clinic and management of risk should a device be lost/ destroyed and hard drive not be able to be accessed.
xiv. The eye PACS must create in its viewer all past visual field test reports in color from one or more visual field analyzers located in the main eye clinics and all satellite clinics at the time of installation.
1. FORUM and the included Glaucoma Workplace Application can reprocess all RAW visual field data from HFA units in color from all of the units within the VISN main locations and satellites at time of installation. Providing the function that the past visual reports were all run, captured, as if FORUM has been in the clinic at the time of the past visual fields were captured.
xv. The eye PACS must be able to display Glaucoma Progression Analysis (GPA) and enable the clinician to manipulate data and store baseline changes at the workstation.
1. FORUM and the included Glaucoma Workplace Application can reprocess all RAW visual field data for GPA analysis at the workstation.
xvi. The eye PACS must be able to present VFI Index, Mean Deviation, Pattern Standard Deviation and Global Indices at a glance summary of all past and present tests.
1. FORUM and the included Glaucoma Workplace Application can reprocess all RAW visual field data from HFA units from all of the units within the VISN main locations and satellites and present VFI Index, Mean Deviation, Pattern Standard Deviation and Global Indices at a glance summary of all past and present tests. Also within FORUM glaucoma workplace these reports listed, can be touched and manipulated.
xvii. The eye PACS must be able to display all OCT past and present test data from one or more OCT instruments located in one or more VA clinics. This data must be accessible to enable viewing and manipulation at the workstation.
1. FORUM can display all available OCT data for viewing and/or manipulation at the workstation.
xviii. The eye PACS must be able to display and allow the clinician to scroll through the various B-scan ultrasound slices .
1. If the ultrasound can export B-Scan slices in OPT/IOD DICOM format FORUM can display the slices. If the device cannot export. Multiple images can be imported into FORUM so that physician can scroll through.
xix. The eye PACS must be able to automatically label images and reports coming from the instruments to enable the clinician to sort test data by visit date(s), modality type(s), right eye, left eye or both eyes.
1. As FORUM is 100% DICOM based the data visit date(s), modality type(s), right eye, left eye or both eyes is directly imported into the system. Enhanced search functionality of FORUM allows clinician to sort by any number of those criteria and additional criteria.
xx. The eye PACS must be able to display images in pre-formatted clinical display groupings for Glaucoma, Retina and Cataract cases.
1. FORUM has clinical display settings for Glaucoma (OD & OS) OCT-VF-FI, Glaucoma OU OCT-VF-FI, Glaucoma Progression (OD & OS) FI, Glaucoma Progression (OU) OCT-VF, AMD Progression OCT (OD & OS), Angiography (2 Visits) (OD & OS), Choroidal Procedure (OD & OS), Retina Overview (OD & OS), Cataract (OD & OS). This provides extreme clinical efficiency but automatically all historical, and current relevant data in “1 click”, as opposed to having to hunt, then click, and look at each historical test individually.
xxi. The eye PACS viewer must be able to display images in a right eye / left eye display format.
1. FORUM has a Compare OD/OS Button for displaying images in this manner.
xxii. The eye PACS must be able to tag individual test reports/images as “Favorites” to enable easy access on future patient visits.
1. FORUM has the ability to star images as favorites that can be recalled with the filter/search function on subsequent visits or review of images.
xxiii. The eye PACS should afford clinicians the ability to view images from exam rooms/offices without returning to the instrument.
1. FORUM affords the clinicians the ability to view images from any computer in the exam lane or office with the software deployed.
xxiv. The eye PACS shall provide a user experience capable of satisfying multiple user roles within the department, at various examination rooms and surgery suites, configurable by an individual’s scope of practice. It shall provide functionality to sort and filter studies, configurable by fields such as originating location, study date/time, modality, and ordering provider. The system shall be able to provide preconfigured ophthalmic displays. The system shall permit remote viewing, manipulation of data elements, and application of scientifically validated analytical algorithms to the data from any networked PC in the department or the VISN.
1. FORUM has multiple user roles Admin, Editor, Reader & EMR Reader that can be tied to the user log in. Studies can be sorted and filtered by originating location, study date/time, modality, and ordering provider when that information is supplied by the MWL server. FORUM has preconfigured ophthalmic displays. for Glaucoma (OD & OS) OCT-VF-FI, Glaucoma OU OCT-VF-FI, Glaucoma Progression (OD & OS) FI, Glaucoma Progression (OU) OCT-VF, AMD Progression OCT (OD & OS), Angiography (2 Visits) (OD & OS), Choroidal Procedure (OD & OS), Retina Overview (OD & OS), Cataract (OD & OS). The system can permit remote viewing, manipulation of data elements RAW and Slice data and has built-in scientifically validated workplaces for analytical algorithm interrogation. Which can be access from any PC where the viewer is deployed.
b. Technical Requirements
i. Hardware
1. All servers, racks, cabling, etc. that are required to perform the operations of using the eye PACS to its full potential at all facilities will be provided by the Offeror.
a. Included in pricing proposal
2. All servers provided must operate using a fully supported operating system. For example if the server is Microsoft Windows-based, the operating system must be Microsoft Windows Server 2012 or newer.
a. Included in pricing proposal
3. The Offeror must specify the size, power, and networking specifications of all servers and racks being supplied.
a. Included in proposal
i. VISN 1 Server Specifications.docx
4. The Offeror shall have a MOU/ISA with the VA to provide remote access to configure the servers or provide on site installation services.
a. Onsite installation included in proposal
5. All images and raw data collected in the eye PACS system should be stored on the eye PACS server and a data backup solution be offered.
a. Included in proposal
ii. Software
1. All viewing software must function on VA OIT exam room workstations which will be running Microsoft Windows 7 or newer. Current VA exam room computer specifications are listed in Attachment B.
a. FORUM is TRM Approved to run on VA workstations W7 & W10 are supported as well as OSX
2. All viewing software must be on VA TRM approved list at: http://trm.oit.va.gov/.
a. FORUM is TRM Approved https://www.va.gov/TRM/ToolPage.aspx?tid=8167
3. Viewing software must not require a separate workstation to run the software due to space requirements in exam rooms.
a. Viewing software can run on exam room stations, separate PC is not required.
4. Software licensing can be floating(shared among workstations) or static(one license per workstation). A non-web based software client is preferred but not required.
a. Software licensing is floating/concurrent
iii. Networking
1. The eye PACS shall have the ability to receive HL7 ADT and ORM messages for patient demographic data from VA VISTA CPRS or VA Clinical Procedures.
a. FORUM system can accept receive HL7 ADT and ORM messages for patient demographic data from VA VISTA CPRS or VA Clinical Procedures
2. All studies shall be stored in Digital Imaging and Communications in Medicine (DICOM) format and adhere to DICOM conformance standards. The eye PACS shall provide a DICOM Modality Worklist (DMWL) for all modalities listed in Attachment B . The system shall be capable of sending to a Vendor Neutral Archive (VNA) and have the VNA act as the eye PACS long term archive for storage and retrieval.
a. FORUM only stores images in DICOM Format within it’s archive. FORUM can provide a DMWL for the modalities listed in attachment B. VNA Licensing is included in the proposal for connecting to a VNA as desired for long term archive & storage/retrieval
3. The eye PAC shall integrate with the VA (CPRS) Health Record. Data and images shall automatically be purged from short-term storage on a first-in-first-out basis to create space for additional studies. This feature shall be site configurable. Privileged users shall be able to selectively protect studies and reports from such automatic deletion. The system shall have a mechanism in place (e.g. DICOM storage commitment) to ensure only studies stored on the VNA are processed for deletion in the PACS.
a. FORUM supports the above and has a DICOM Storage Commitment to ensure only studies stored on the VNA are processed for deletion in the PACS.
4. The offereor must include a networking diagram with minimum bandwidth requirements listed for main sites and their satellite clinics(CBOCs).
a. Included in proposal.
i. 1 - VA - VISN1 - Site Map_Rev A_Main Proposal.pdf
ii. 1 - VA - VISN1 - Site Map_Rev B_Optional Proposal.pdf
5. The eye PACS must be able to support CBOCs with bandwidth issues connecting to main site. CBOCs may be using a smaller bandwidth and may require a cache server as a solution.
a. CBOC sites as noted in the document for this solicitation meet the requirement of 40/20 bandwidth or higher. Cache server solution is not required with 40/20 or higher.
6. The eye PACS shall have the capability of operating in both a stand-alone or client-server mode. In other words, if the network connectivity goes down the Veteran’s images can still be stored and analyzed, then sent at a later time.
a. Modalites in the event of the a network connectivity down situation will store all data locally for manipulation and printing. Once network connectivity resumes data can be archived to FORUM server
iv. Interface
1. The Offerer shall provide as an option, a VISN-centric solution which will allow clinicians to view images across all VISN 1 sites
a. Included as VISN Centric – Viewing Option.
2. The eye PACS must be able to interface with 3rd party vendor equipment as listed in Attachment B.
a. FORUM can interface with the 3rd party vendor equipment listed in Attachment B.
3. The eye PACS must send data/images to patient record-VISTA/CPRS/VISTA Imaging.
a. FORUM will be configured to DICOM Forward data/images to patient record-VISTA/CPRS/VISTA Imaging.
4. The eye PACS must be approved for VISTA Imaging/DICOM, see list at: http://vaww.oed.portal.va.gov/applications/VistAImaging/Lists/Device%20Validation%20Database%20%20SharePoint%202003%20Archiv/User%20View.aspx
a. FORUM is approved on the VISTA Imaging DICOM list
v. Data Migration
1. The Offerer must provide a data migration plan to move data from existing modalities and legacy eye PACS(Merge-OIS) to the new eye PACS.
a. Data in DICOM Format can be ingested by the FORUM system from the legacy PACS system
2. The Offerer must include project support hours to assist in data migration efforts.
a. Support hours included in proposal for migration of DICOM Data from legacy PACS.
vi. Expansion
1. The eye PACS must be a scalable solution that will allow for expansion of equipment, exam rooms, or data.
a. FORUM is completely scalable as the clinics grow.
2. The Offerer shall provide a plan for sites to add more software licenses when needed.
a. Licenses for additional devices can be supplied at any time. Contacting the local Zeiss FORUM Sales Manager a quotation can be generated and submitted to contracting.
c. Support Service Requirements
i. Project/Implementation Support
1. It is preferred that the Offerer provide project managers that are assigned to VISN 1 during the eye PACS installation and for continuing support after implementation.
a. Zeiss Project Managers will be assigned to the deployment and will stay involved after installation for needed support.
2. It is preferred that the Offerer provide project managers that have obtained VA security clearance and have active PIV cards.
a. Zeiss Project Managers have PIV cards
3. The Offerer shall provide an overall schedule for implementation and establish recurring meetings with point of contacts at each site.
a. Upon award of contract Zeiss will coordinate with each site for development of installation schedule and will have recurring meetings to work through action items.
ii. Tech support
1. The Offerer shall provide clinical & technical support (phone and/or remote access) during normal business hours (M-F, 8am-5pm EST ) and after hours support , seven days a week, 365 day a year.
a. FORUM support is available 8am ET to 8pm PT M-F after hours support is available as needed seven days a week 365 days per year.
2. The Offeror shall provide a verbal response within 1 hour of notification of an emergency service issue and/or request by VISN 1.
a. Agreed
3. The Offeror shall provide a verbal response within 24 hours of notification of a nonemergency service issue and/or request by VISN 1.
a. Agreed
4. The Offerer must have an existing national MOU/ISA with VA for remote connection approvals.
a. 2 of our Project Managers have PIV cards.
5. The Offeror shall utilize the VA’s national Site-to-Site Virtual Private Network (VPN) or shall work with the Office of Cyber and Information Security and the VISN 1 Information Security Office to establish a client-based VPN.
a. Agreed
6. The Offeror shall provide two copies of the operator’s instruction manual per facility identified.
a. This is standard for our VA clients.
7. The Offeror shall provide two copies of complete technical service manuals including detailed troubleshooting guides, necessary diagnostic software, service, keys, schematic drawings, and part lists per facility identified.
a. This is standard for our VA clients.
8. The Offeror shall provide two copies of a systems manager’s manual outlining backup procedures, managing privilege group limits, routine tasks, etc.
a. This is standard for our VA clients.
iii. Continuing Maintenance & Support
1. The Offerer shall provide as an option, a service Contract or extended warranty available for at least 1 year after implementation.
a. Initial purchase will include the first year of warranty/support as part of the agreement for the software. The hardware will include 3 years of support.
2. The Offeror shall specify the warranty period for all software and hardware provide to the VA by the Offeror.
a. Initial purchase will include the first year of warranty/support as part of the agreement for the software. The hardware will include 3 years of support.
3. The Offeror shall provide, at no additional charge, any and all equipment service programs, such as remote diagnostics and equipment replacement, during the warranty period.
4. The Offeror shall provide post-warranty remote diagnostic service program as an “Add Option” with their proposal.
a. VISN 1 - FORUM Connectivity Plan Option_Forum_PA.pdf
5. The Offerer shall discuss any annual licensing fees or maintenance fees that are associated with the eye PACS.
a. The only yearly fees would be the connectivity service plan that covers support and upgrades and updates for modules of the PACS owned by the VISN. Also important note regarding licenses, is that once you have purchased a “Zeiss instrument Connection”, or “3rd Instrument Connection”, you own that license. Meaning as the modalities, instruments gets refreshed and or removed and replaced there is NOT a need to purchase additional licenses if the clinic is refreshing or replacing their old instruments for new instruments.
b.
iv. Education & Training
1. The Offeror must provide education to clinical personnel in the operation of the eye PACS to provide meaningful patient data to be used in reporting and decision making. 2-3 days of onsite training per site for clinicians is preferred.
a. This is included in the installation/training of the system as proposed
2. The Offerer must provide system administration training to at least one VA Biomedical Equipment Support Specialist (technician) per site, who will be supporting the eye PACS. Training should at a minimum address server maintenance, server backup,and troubleshooting connectivity issues. If applicable, the Offerer should include travel and accommodations.
a. This is included in the installation/training of the system as proposed
3. The Offerer must provide options for additional and/or refresher training after implementation. 2 days of additional training per site is is preferred.
a. This is included in the installation/training of the system as proposed.
2. ADDITIONAL DOCUMENTATION
The Offeror is required to complete VA Directive 6550 Pre-Procurement Assessment, Appendix A Form Attachment (See Attachment A)as part of their proposal. This attachment shall be completed by the Offeror for each type of device that will be provided and connected to the VA OIT network (i.e. server and workstations).
VA Directive 6550 - Appendix A1-REV-1.pdf
ATTACHMENT A:
VA DIRECTIVE 6550 PRE_PROCURMENT ASSESSMENT, APPENDIX A FORM ATTACHMENT
The Offeror shall provide an answer to each of the questions below, providing the reason why where noted for each device in the system. The Offeror shall provide the answers in either a separate Microsoft Word or Adobe .pdf as part of their proposal. The Offeror shall also provide the configuration guide that supports all answers on this attachment in a separate file as part of their proposal.
1) Is there an installation guide for this project? If yes, attach a copy to this 6550.
a. Yes. See” VA - VISN1-Project Plan_RevA.doc” Page A-1
1) Vendor: Vendor’s Entire Name
a. Carl Zeiss Meditec, INC
2) Model: Name of the specific piece of equipment being assessed, if this is a system, state the system name and then the device as you will have to provide a 6550 per device within the system.
a. ZEISS FORUM
3) Vendor Contact: Name, email, and contact number
a. Dennis Ramirez, dennis.ramirez@zeiss.com 925-353-7419 (technical lead)
b. Michael Turano. michael.turano@zeiss.com 856 340 5675 (Local, Regional Sales)
c. Brian Close, brian.close@zeiss.com (US Fed Govt. National Strategic Accounts Manager)
4) If Server based, specify rack space and power requirements if applicable?
a. 2U , NEMA 5-15 P 120v
5) Equipment Description: Describe what this device does and how it act in the system of devices
a. Ophthalmic PACS (picture archive and communication system). Allows for storage of ophthalmic images, raw data, and display and manipulation of that raw data.
Page A-2:
Medical Device /System Configuration
1) What OS and version/Service Pack does the system utilize (e.g., Win7- SP1, Win Svr 2008, Linux)? What is the bit (32 or 64) what is the service pack? What is the exact software version?
a. Windows Server 2012 R2, Windows Server 2008 R2
b. 64-BIT
c. Latest Version will be deployed Current Production version as of this document 4.1.1
2) Does the system use a database application to operate (yes or no)? Specify the exact application and version.
a. YES
b. MySQL V5.5.15 (Enterprise MySQL will be released in 4th qtr of FY, or 1st Qtr of 2018)
3) Membership in the facility’s Windows Domain is: Required, Recommended, Not Recommended or Not Applicable? Will this device be a member of the facility’s Windows Domain?
a. Recommended.
b. Yes.
4) Is a desktop web browser required to access the medical system/application? Why or why not?
a. No. FORUM is application based not web based If browser, will it be intranet access only? (N/A) If yes, specify which browser and version supported:
If yes, does it require the use of https: and the VA SSL certificates – explain why?
If a browser is required, does it require a specific version of JAVA?
5) Does active X required for client operation? If yes, specify the configuration requirement.
a. No.
6) If Windows based, can the system use the National Medical Device Update Server for OS patches? If not, why not? Who will configure this? Can it be automated? If not, when will the updates occur?
a. Yes
b. The VA’s designated team will be responsible for updating and maintaining the server.
c. Yes can be automated
7) Will Critical and Routine OS and system security patches be applied as they become available without prior vendor approval? If no, why not and specify how approval notification to VA will be accomplished? Is how this will be handled in writing (must be- installation guide)?
a. Yes Page A-3
1) Will this device utilize McAfee Anti-Virus (AV) software? Is the VA going to load the McAfee Anti-Virus (AV) software? Does Clinical Engineering have the licenses, will it be automated, and how will it be managed?
· The FORUM server can utilize McAfee if required by the VA.
· Zeiss does not mandate any particular AV software.
· The VA’s designated team will be responsible for maintaining the server.
a. If McAfee is not supported, what AV packages and versions are supported and describe the mechanism to provide updates?
2) Can USB ports be logically disabled on the device without compromising operation? Will the vendor or CE disabled the unused ports? Will this be done logically or physically? If they aren’t disabled logically will there be port locks applied to the device? What is the purpose of not logically disabling the ports if applicable? Who will disable these?
a. YES
b. The VA’s designated team will be responsible for maintaining the server.
3) Can auto run be disabled for portable media?
Yes.
a. If not, why can’t it be disabled?
b. If so, will it be disabled? Will it be disabled at install?
i. The VA’s designated team will be responsible for maintaining the server. It can be disabled at install
4) Can VA install host-based security components such as a firewall, host intrusion prevention (HIPS), anti-malware software, and/or any other security suite software required to operate on the VA production network? Will Encase and Sanctuary software be installed? If no, Why can’t we install this software?
a. YES
b. The VA’s designated team can install Encase and Sanctuary software if desired
Authentication and User Account
1) Is an administrator or power user account required to operate the device? If yes, explain need and duties of admin or power user?
a. No.
2) Will the device be made to require individual user authentication? How will authentication be configured(LDAP)?
a. Configuration of users is configured through FORUM. Version 4.2 pending release fall 2017 will support LDAP/AD current version 4.1.1 does not. This is being tested at Walter Reed National Medical Center and with the Dept of Defense for accreditation and RMF approval.
3) Will the device be configured to support password aging and strong user password accounts? If yes, How will it be done (AD?)?
a. No. Version 4.2 pending release fall 2017 will support LDAP/AD current version 4.1.1 does not. This is being tested at Walter Reed National Medical Center and with the Dept of Defense for accreditation and RMF approval.
4) Will the device be configured to support auto logoff and session lock? If not why (Example: We don’t want to it to log off during patient care)?
a. Yes if desired. Can be configured to any time required by VA in minutes.
5) Does the system support use of active directory for user authentication? If yes, What is LDAP being used if it’s being used and what are the configuration requirements?
a. No. Version 4.2 pending release fall 2017 will support LDAP/AD current version 4.1.1 does not. Kerberos v5 will be the version of LDAP on release of 4.2. This is being tested at Walter Reed National Medical Center and with the Dept of Defense for accreditation and RMF approval.
b.
6) Does the system support the use of PIV/SMART Card only authentication? Will it be utilized? Why?
a. No. Not currently. Version 4.2 pending release fall 2017 will support single sign on CAT card authentication. This is being tested at Walter Reed National Medical Center and with the Dept of Defense for accreditation and RMF approval.
b.
Page A-4 Data Handling
1) Specify in detail which Electronic Protected Health Information ePHI data elements are stored on the device (e.g. last name, SSN, DOB, Medical record number, account number, telephone number, fax number, email address, certificate/license number, Biometric identifiers, including finger or voice prints, Full-face photographic images, Other).
a. First Name, Last Name, DOB, Patient ID, Sex
2) How many records with sensitive information can be stored on the device?
a. Unlimited, dependent on storage space on the FORUM server or datacenter.
3) How long will they be retained on the device?
a. Indefinite. Unless configured with VNA to offload.
4) Is ePHI encrypted prior to transmission? Yes or no.
a. No, and Yes
b. If yes, what is the encryption mechanism(s)?
c. SSL encryption for data-in-transit within the system (FORUM 4.1 and later)
5) What is the media used for long term storage (write out acronyms)?
a. Server local disk, Datacenter
6) How is data transmitted to the storage repository (e.g. LAN, DVD, USB, etc.)?
a. LAN
7) Is ePHI stored only on a drive partition or a separate drive to assist with end-of-line media sanitization, Yes or No? If no, Does the VA retain the hard drives?
a. Yes
8) Will the medical device require data backups? If Yes, Specify how the system and data are backed up and what media is used in detail and who will do the backups.
a. Yes
b. Backup Array is supplied as part of project. FORUM installers will configure backup with support of Biomed & IT teams. Backups will be scheduled to occur on a frequent basis for data redundancy and recovery.
9) Where will backups be stored and secured?
a. Backup Array is supplied as part of project will be secured in the data center of choice by the VISN.
10) Does the device have the ability to assign unique ID numbers (accession numbers) instead of using patient identifying information (e.g. Social Security Number)?
a. The Patient ID’s or Accession Numbers are assigned entering the order or directly from CPRS/Vista or the leading EMR system. This number is then assigned to the MWL order.
10) If yes, how is it generated?
a. The Patient ID’s or Accession Numbers are assigned entering the order or directly from CPRS/Vista or the leading EMR system. This number is then assigned to the MWL order.
6) Does the device utilize a laptop for system operation? If yes, can it be encrypted without impacting clinical functionality? What encryption software will be used?
a. No Page A-5 Networking
1) What are the LAN bandwidth requirements for full connectivity/performance?
a. 1000/100 Mbps LAN
2) What are the WAN bandwidth requirements for full connectivity/performance?
a. 40/20 Mbps WAN
3) Provide a comprehensive list of all TCP and UDP ports that are required for operation? How often will each port be used? Note: Inactivity on ports suggests no need for them. Specify direction flow.
a. Ports will be used daily
| Low Port |
| High Port |
| Protocol |
| Service |
| Description |
| 104 |
| 104 |
| TCP |
| DICOM |
| Enterprise Clinical Imaging Archive (ECIA) - Navy's VNA solution |
| 3306 |
| 3306 |
| TCP |
| MYSQL |
| Database port |
| 3700 |
| 3700 |
| TCP |
| IIOP |
| Application Server IIOP port (glassfish.iiop.port) |
| 3820 |
| 3820 |
| TCP |
| TLS |
| Application Server Corba SSL port |
| 4848 |
| 4848 |
| TCP |
| Glassfish (Oracle) |
| Application Server Administration port (glassfish.admin.port) |
| 5353 |
| 5353 |
| UDP |
| mDNS |
| mDNS (AutoConnect for instruments) |
| 7676 |
| 7676 |
| TCP |
| JMS (Oracle) |
| Application Server JMS port (glassfish.jms.port) |
| 8080 |
| 8080 |
| TCP |
| HTTP |
| Application Server HTTP port (glassfish.http.port) |
| 8181 |
| 8181 |
| TCP |
| TLS |
| Application Server HTTPS port (glassfish.https.port) |
| 10101 |
| 10101 |
| TCP |
| HTTP |
| FORUM Glaucoma Workplace Server |
| 10102 |
| 10102 |
| TCP |
| HTTP |
| FORUM Retina Workplace |
| 10234 |
| 10234 |
| TCP |
| JMS (Oracle) |
| JMS IMQ Broker port |
| 11119 |
| 11119 |
| TCP |
| DICOM |
| DICOM port (forum.dicom.port) |
| 51000 |
| 51000 |
| TCP |
| DICOM |
| DICOM Gateway port |
| 8085 |
| 8085 |
| TCP |
| HTTP |
| Mirth Connect (HL7 Interface Engine) - Web Start Port |
| 8443 |
| 8443 |
| TCP |
| HTTP |
| Mirth Connect (HL7 Interface Engine) - Administrative Port |
| 11119 |
| 11119 |
| TCP |
| DICOM |
| DICOM port (forum.dicom.port) |
| 51000 |
| 51000 |
| TCP |
| DICOM |
| DICOM Gateway port |
| 8080 |
| 8080 |
| TCP |
| HTTP |
| FORUM ASSISTS match |
| 8085 |
| 8085 |
| TCP |
| HTTP |
| Mirth Connect (HL7 Interface Engine) - Web Start Port |
| 8443 |
| 8443 |
| TCP |
| HTTP |
| Mirth Connect (HL7 Interface Engine) - Administrative Port |
4) How many fixed IP addresses does the device require? List names of devices if applicable. Will it be configured as a cluster? Does the cluster have an IP?
a. FORUM server and instruments connecting to FORUM need a static IP. Each server in the final configuration will need a Static IP. All Devices in the equipment list provided in the Solicitation for each location will need a static IP.
5) Is the device compatible with IP V6?
a. No.
6) Vendors’ products should be designed such that only services required for the intended operation of the device are active. Are unused ports disabled? If not, have the vendor provide this in writing on an official document?
a. Yes.
6) Can this be accomplished without impacting system operation?
a. Yes
7) Vendors’ products should be designed such that only services required for the intended operation of the device are active. Are unused services (e.g., Telnet, IIS, etc.) disabled?
a. Yes
8) Can this be accomplished without impacting system operation?
a. Yes
9) Provide a comprehensive list of all services that are required for system operation? Who will configure unused services?
a. CZM-Database, CZM-Forum-Glaucoma-Workplace, CZM-Forum-Glaucoma-Workplace-Analysis, CZM-Retina-Workplace, CZM-Retina-Workplace-Analysis, CZM-Server-Service, CZM-CALLISTO-eye-Plugin-Service, DICOM Gateway 2.1.4, Mirth Connect Service.
b. Zeiss and VAMC IT and BIOMED can configure unused services
10) Can the device be secured remotely? Why is this function a necessity?
a. Not sure if we understand the question. If this means can the device be serviced remotely? Yes, it’s necessary to properly provide support. If onsite support is required, this will greatly reduce the response time.
11) Does the vendor have an existing Site to Site (S2S) VPN tunnel or individual user VPN account(s)?
a. No currently S2S VPN tunnel. Zeiss has 2 individuals with VA PIV cards.
13) What remote access software does the system utilized? How is the vendor planning to remote into the servers, What’s the exact process? i.e. CAG, SMC, PC Anywhere, Dameware etc.
a. Zeiss will use any access software required or approved by the VA.
14) What remote access software does the system utilize?
a. Zeiss will use any access software required or approved by the VA.
15) Does the device require connection to the internet to operate? If yes, please justify and provide connection info (IP, port, protocol and traffic direction).
a. No.
Page A-6 Wireless
1) Does the device utilize wireless communication? If yes, what protocols are used?
a. No.
2) The encryption module must have FIPS 140-2 certification. Provide certificate number.
a. N/A
3) Are any ePHI data elements transmitted via the wireless link? If yes, list each element (e.g. last name, DOB, SSN).
a. N/A Integration with VA Healthcare Information Systems (If applicable)
1) Has the device been validated with VA’s Clinical Procedures package?
a. Yes.
2) Has the device been validated with VA’s Vista Imaging?
a. Yes.
3) Does the device have bi-directional HL7 interface?
a. Yes
4) List all other systems that the device will communicate with in order to operate properly e.g. Vista, domain controllers, vendor’s support network etc.
a. Domain Controllers, Vista, Medical Devices
Offerors shall fully describe the following items/factors as part of their proposal:
FACTOR 1: Software and Hardware Capabilities
i. Applications requirement – ability to collect instrument specific data FORUM by the nature of it’s design has the ability to collect DICOM and RAW data from disparate devices that are connected to the system.
ii. Reports requirement – ability to generate / create ad-hoc reports FORUM can also generate unique reports that are not able to be generated by modalities or instruments themselves. Using the RAW data within the archive FORUM can create reports that combine the information from disparate devices that are useful for treatment of certain disease processes like Glaucoma.
iii. Interface requirement – ability interface to system as described in the statement of work and provide DICOM compatible hardware/licenses if required All receiving DICOM licenses are part of this proposal.
iv. Server requirement – ability to provide physical or virtual hardware solution that is least intrusive on the VA (limit the number of servers, etc.)
The proposal supplies 1 server per main location ie Boston, Maine, Providence, Manchester. All CBOCs from the proposal look to have sufficient bandwidth for direct connection without cache servers. An optional VISN wide server is proposed for high availability of data from all locations instantly if desired by the VISN.
v. Display workstation requirement – ability to function on OIT hardware with TRM approval The FORUM product can install on OIT hardware and is TRM approved.
vi. Networking- ability to migrate data from legacy PACS to new PACS DICOM Data from Legacy PACS can be incorporated into the system.
VISN 1 - FORUM DICOM PACS CONVERSION_Forum_PA.pdf
FACTOR 2: Installation, Configuration, Training, Warranty Capabilities
i. Implementation/Installation support – ability to provide an onsite solution, remote installation will not be considered.
Onsite installation is key to the success of deployment for the VISN system. Onsite installation and training are supplied in the proposal.
ii. Configuration – ability to provide onsite configuration of the system Onsite configuration will be performed by our dedicated team of Field Implementation Specialist and Clinical Application Specialists along with Field Service Engineers.
iii. Tech support/ Warranty- ability to meet timelines described in statement of work FORUM support is available 8am ET to 8pm PT M-F after hours support is available as needed seven days a week 365 days per year.
iv. Continuing Maintenance & support- annual software service agreement costs Supplied in proposal.
VISN 1 - FORUM Connectivity Plan Option_Forum_PA_1.pdf
v. Education & training – ability to provide onsite end user training Supplied in proposal
Offerors must describe the server requirements needed this shall include all of the proposed software, including all security access needed, data sharing, communication protocols, and functionality that the VA has to provide in order for the proposed PACS system to fully function. This information should be included in the completed VA form 6550. See attachment in Section D.
Server Requirements Supplied and all hardware included in proposal.
VISN 1 Server Specifications.docx VA form 6550 is attached.
VA Directive 6550.pdf
File details come from the government source that posted it.