36C26319Q0276-008.doc
DOC document 26 KB Posted
- Attached to
- Document Destruction - MPLS Federal contract opportunity
- Solicitation number
- 36C26319Q0276
About this file
This notice is for document destruction services for the Minneapolis VA Health Care System. The solicitation will seek a contractor to physically collect and destroy confidential paper and media materials from consoles throughout the MVAHCS facilities on a regularly scheduled basis. Materials must be destroyed onsite to a 5/8 particle size and witnessed by a VA employee. Destructed documents then must be pulped to 1x5 millimeters at an approved facility on the same day. Media destruction may occur on or offsite as long as materials are contained until final destruction. The electronic solicitation will be announced on or about March 1, 2019 via FedBizOpps and will be set aside 100% for small businesses. The offeror must download solicitation documents and amendments without further notice from the VA. No questions will be accepted prior to issuance of the solicitation.
36C26319Q0276 P10 Security Language.doc
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C26319Q0276-0001000.docx | DOCX document | |
| 36C26319Q0276-007.xlsx | XLSX spreadsheet | |
| 36C26319Q0276-006.docx | DOCX document | |
| 36C26319Q0276-009.pdf | ||
| 36C26319Q0276-005.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
MARCH 12, 2010
VA HANDBOOK 6500.6
APPENDIX C
VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE FOR INCLUSION INTO CONTRACTS, AS APPROPRIATE
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
3. VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
6. SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.
b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.
File details come from the government source that posted it. Updated .