36C26324Q1213.docx
DOCX document 2 MB Posted
- Attached to
- J065--BD Pyxis Service - VISN Federal contract opportunity
- Solicitation number
- 36C26324Q1213
About this file
This document is a Notice of Intent for a proposed sole source firm fixed price contract for BD Pyxis equipment and software maintenance services to support the VA Veterans Integrated Service Network (VISN) 23. The sole source contractor is Carefusion Solutions, LLC. The contract will have a base year and four option years, from 1/1/25 to 12/31/29. The services required include repair, preventive maintenance, remote support, and software updates for the BD Pyxis pharmacy and dental equipment and software at VA facilities in VISN 23, which includes locations in Minnesota, Nebraska, Iowa, and Wisconsin. The North American Industry Classification System (NAICS) code is 811210 (Electronic and Precision Equipment Repair and Maintenance) and the Product Service Code (PSC) is J065 (Maintenance Repair, and Rebuilding of Equipment - Medical, Dental, and Veterinary Equipment and Supplies). While this is not a solicitation, interested vendors can submit a capability statement to the contracting specialist by the response date of 10/4/2024.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SUBJECT*
BD Pyxis Service - VISN 23
GENERAL INFORMATION
| CONTRACTING OFFICE’S ZIP CODE* |
| 56303 |
| SOLICITATION NUMBER* |
| 36C26324Q1213 |
| RESPONSE DATE/TIME/ZONE |
| 10-04-2024 13:00 CENTRAL TIME, CHICAGO, USA |
| ARCHIVE |
| 90 DAYS AFTER THE RESPONSE DATE |
| RECOVERY ACT FUNDS |
| N |
| PRODUCT SERVICE CODE* |
| J065 |
| NAICS CODE* |
| 339112 |
| CONTRACTING OFFICE ADDRESS |
| Department of Veterans Affairs |
NETWORK 23 CONTRACTING OFFICE
Contract Officer 4801 Veterans Drive St. Cloud MN 56303
POINT OF CONTACT*
Contract Specialist Emanuel Nevarez emanuel.nevarez@va.gov (320)255-6354
ADDITIONAL INFORMATION
AGENCY’S URL
URL DESCRIPTION
| AGENCY CONTACT’S EMAIL ADDRESS |
| emanuel.nevarez@va.gov |
| EMAIL DESCRIPTION |
| Contract Specialist |
DESCRIPTION
This is a Notice of Intent published in accordance with Federal Acquisition Regulation (FAR) 5.101(a)(1) requiring the dissemination of information regarding proposed contract actions. This Notice of Intent is for a proposed award of a sole source firm fixed price contract to the following contractor in support of a needed BD Pyxis equipment and software maintenance services to support the VA Veterans Integrated Service Network (VISN) 23.
Carefusion Solutions, LLC
SAM UEI: JEC9J3E8QBJ7
3750 Torrey View CT San Diego, California 92130-2622, United States
This is done under authority of 41 U.S.C. 3304(a)(1), as implemented by FAR 6.302-1: Only one source and no other supplies or services will satisfy agency requirements.
This is not a request for competitive quotes.
Market research revealed that Carefusion Solutions, LLC is the sole company that is able to maintain and support the needed BD Pyxis equipment and software maintenance services for the VA VISN23.
Additionally, Carefusion Solutions, LLC provides support to maintain current equipment in VISN 23. This will enable the VA to continue use of the Pyxis products currently in use.
The North American Industry Classification System (NAICS) code for this service is 811210 (Electronic and Precision Equipment Repair and Maintenance) and the Product Service Code (PSC) is J065 (Maintenance Repair, and Rebuilding of Equipment – Medical, Dental, and Veterinary Equipment and Supplies).
While this synopsis does not constitute a solicitation, interested vendors may identify their interest and capability to satisfy the requirement, including documentation from the proprietary rights holder Carefusion Solutions, LLC that such contractor could provide this service as an authorized reseller, authorized dealer or third party.
All responsible sources may submit a capability statement, which shall be considered by the agency by e-mailing such statement and supporting documentation to Emanuel Nevarez, Contracting Specialist emanuel.nevarez@va.gov. No phone calls please. Please indicate “36C26324Q1213 BD Pyxis Service” in subject line of e-mail.
Such documentation will be reviewed solely for the purpose of determining whether or not to conduct the procurement on a competitive basis. A determination not to compete this requirement, based upon responses to this notice, is solely within the discretion of the Government under authorities cited above.
See Attached Statement of Work (SOW)
Special Notice Special Notice
| *= Required Field |
| Special Notice |
Special Notice
Statement Of Work-Services Contents
| Statement Of Work-Services | 3 |
| A. Project Title | 5 |
| B. Procurement Type | 5 |
| C. Background | 5 |
| D. Scope | 5 |
| E. Period of Performance | 5 |
| F. Place of Performance | 6 |
| G. Equipment Inventory | 6 |
| H. Equipment Changes | 7 |
| I. Work Performance | 7 |
| J. Facility Check In Requirements | 8 |
| K. Service Reports | 8 |
| L. Out of Scope Services | 9 |
| M. Service and Operator Manuals | 9 |
| N. Training | 9 |
| O. Security Requirements | 10 |
| P. Hardware Requirements | 11 |
| Q. Implementation/Project Management Services | 12 |
| R. Invoicing and Pricing | 12 |
| S. Inspection and Acceptance | 13 |
| T. Disposal of Waste and Job Site Cleanup | 13 |
| U. Delivery and Materials Requirements | 13 |
| V. Order of Precedence | 13 |
A. Project Title VISN 23 BD Pyxis Medication System Service Contract Procurement
B. Procurement Type Sole Source
C. Background VA Midwest Healthcare Network (VISN 23) has existing BD Pyxis medication equipment and software that requires a support maintenance contract. Existing support on the BD Pyxis medication equipment and software is ending 12/31/24.
BD Pyxis medication system is an automated medication dispensing system supporting decentralized medication management in a pharmaceutical environment. The system helps clinicians dispense medications in a safe, efficient way and provides enterprise-ready integration capabilities. The software records the medication being dispensed and ensures it is the right patient, medication, dosage, and time. This technology also provides access to allergy warnings, safety alerts, and order verification. The system supports nursing workflows by decreasing the number of steps in the medication management process and supports diversion efforts by providing discrepancy reports.
This Pharmacy system solution is important because it intercepts errors, reduces waste, lowers inventory spending, and improves regulatory compliance. Waste is reduced with clean room inventory management tracking software and the process is streamlined with remote pharmacist review and verification. It improves visibility between Pharmacy and Nursing. Also, it increases security and control of medication and controlled substance management.
D. Scope VA Midwest Healthcare Network (VISN 23) requires a 5 year support repair and maintenance service agreement contract on all the BD Pyxis medication equipment, including Pharmacy and Dental, and software, including Knowledge Portal, at the following VISN 23 sites: VA Minneapolis (MIN) and VA Nebraska-Western Iowa (NWI) locations including: Omaha, Lincoln, Grand Island, Shenandoah, Norfolk, North Platte, Bellevue (Sarpy), Holdrege, O’Neill, and Papillion Midlands.
E. Period of Performance Overall period for performance shall begin 1/1/25 and shall include one base year and 4 option years:
| Ordering Period |
| Period of Performance |
| Base Year |
| 1/1/25-12/31/25 |
| Option Year 1 |
| 1/1/26-12/31/26 |
| Option Year 2 |
| 1/1/27-12/31/27 |
| Option Year 3 |
| 1/1/28-12/31/28 |
| Option Year 4 |
| 1/1/29-12/31/29 |
Unless otherwise noted, work shall be performed during normal business days and hours at each VA facility, which is typically comprised of Monday through Friday each week (except federal holidays) between 8:00 a.m. and 4:30 p.m. local standard time. Contractor shall confirm each facility normal business days and hours with onsite POC (s).
F. Place of Performance Unless otherwise noted, the contractor shall provide service and support at the VA facilities listed below:
| Station-Facility |
| Address |
| Technical-Biomed |
| Pharmacy |
| 636-Omaha |
| Omaha VA Medical Center, 4101 Woolworth Avenue, Omaha, NE 68105 |
Holdrege CBOC 1118 Burlington Street Holdrege, NE 68949-1705
Sarpy CBOC 1330 Jersey St Papillion, NE 68046
Shenandoah CBOC VA Clinic, 2043 A Ave, Shenandoah, IA 51601-4505
Grand Island VA Clinic, 2201 N Broadwell Ave, Grand Island, NE 68803-2153
Lincoln VA Clinic, 420 Victory Park Dr Lincoln, NE 68510
Norfolk 3204 Raasch Drive Norfolk, NE 68701
Papillion CLC at Midlands Hospital 11111 S 84th St, Papillion, NE 68046
| 618-Minneapolis |
| Minneapolis VA Health Care System, 1 Veterans Dr, Minneapolis, MN 55417 |
Northwest Metro Clinic 7545 Veterans Drive, Ramsey, MN 55303
Twin Ports Clinic 3520 Tower Ave, Superior, WI 54880
| 499-VISN 23 |
| N/A |
G. Equipment Inventory
Upon request, the contractor shall confirm and provide equipment quantities and serial numbers covered under the service contract at each site in an excel document.
H. Equipment Changes Equipment may be deleted from the Service Contract if replaced or "in excess" during the period of this contract at the discretion of the CO/COR. New equipment may be added as needed at the discretion of the CO/COR. Deleted equipment will be credited in the full amount if deleted before any scheduled maintenance has been performed on it. The Government reserves the right to purchase additional medical equipment not contained within the Service Contract as well as delete existing items upon the approval of the AO. The Service Contract shall be updated with the addition of new equipment and existing items that are taken out of service shall be deleted upon contract renewal and upon request.
I. Work Performance Contractor shall perform the following work at the VISN 23 sites:
1. Furnish all labor, transportation, tools, parts, materials, test equipment, and expertise necessary to provide repair service and annual preventive maintenance and support of the BD Pyxis equipment hardware, software and databases.
2. Provide repair service, which may consist of calibration, cleaning, oiling, adjusting, replacing parts, and installing parts.
3. Provide remote support services (“RSS”) on a 24/7/365 basis through CareFusion’s Technical Support Center (“TSC”). BD utilizes RSS feature to connect into any Pyxis Server or console to help resolve issues. RSS allows BD to provide software updates remotely.
4. Adjust and replace non-consumable parts in Pyxis equipment, including Pyxis CUBIE® Pockets, which are not properly performing for any reason other than an external cause.
5. Perform onsite repair and preventive maintenance of Pyxis equipment inspections in accordance with current manufacturer/factory specifications and maintenance schedule.
a. Contract service shall ensure that the equipment/system functions in conformance with the latest published edition of NFPA-99, OSHA, manufacturer’s Network Equipment/System upgrades/updates shall be installed in strict accordance with manufacturer’s specifications and must operate within manufacturer’s specifications and must operate within manufacturer’s specified parameters.
b. Contractor shall provide and utilize procedures and checklists with worksheet originals indicating work performed and actual values obtained (as applicable) provided to the onsite POC (s) at the completion of the PM.
6. PM services shall include, but need not be limited to, the following:
a. Cleaning of equipment to include filters, gearing, and other parts.
b. Reviewing operating system software diagnostics to ensure that the system is operating as specified by the manufacturer’s specifications.
c. Calibrating and lubricating the equipment.
d. Performing remedial maintenance of non-emergent nature.
e. Performing electrical safety inspection IAW NFPA 99.
7. Provide 24/7/365 access to BD’s technical support phone and web portal to receive technical support for repairs and maintenance, and answer any questions about the BD Pyxis medication equipment:
a. 1-866-488-1408
b. https://bd.com/self-service
8. Address VA support issues/requests within the following timeline, when contractor receives a VA support request via email, phone call or web inquiry:
a. 24 hours for NWI
b. 8 hours for MIN
9. If the problem cannot be corrected by phone or by remote diagnostics the contractor will dispatch a technician to arrive not later than the next business day after the call is placed.
10. Supply and bear the cost of all parts, and software updates required for service repair and maintenance and, as a result of normal wear and tear, restore equipment to full performance system in operating condition as originally designed by the manufacturer.
a. All parts shall meet the original manufacturer’s design specifications.
b. Parts may be repaired or replaced, as the contractor deems appropriate. No used parts will be used to repair this equipment.
11. Provide VA access to new software/firmware versions, updates, enhancements, bug fixes and patches as they are released. Provide all third-party licensing.
12. Promptly notify the CO/COR and the VA POC (s) listed in this Statement of Work (SOW) of any recalls and end of life/service cycles.
13. Test equipment calibration shall be traceable to National Institutes of Standard Technology standards. Each service report shall list test equipment used and date calibration to NIST is due. Test equipment out of calibration shall not be used.
J. Facility Check In Requirements Upon arrival at the VA facilities the contractor is required to check in with Biomed in the following locations:
| Facility |
| Room # |
| Omaha VA Medical Center |
| B556 |
| Grand Island VA Clinic |
| C09 |
| Lincoln VA Clinic |
| 7-3-LN |
| Holdrege CBOC |
| Clinic Reception Desk |
| Sarpy CBOC |
| Clinic Reception Desk |
| Norfolk VA Clinic |
| Clinic Reception Desk |
| Shenandoah CBOC VA Clinic |
| Clinic Reception Desk |
| Papillion CLC at Midlands Hospital |
| Clinic Reception Desk |
| Minneapolis VA Healthcare System |
| BG101-70 |
| Northwest Metro Clinic |
| Clinic Reception Desk |
| Twin Ports Clinic |
| Clinic Reception Desk |
This check in is mandatory as well as wearing the contractor badge issued upon checking in. Contractor’s FSE(s) shall wear visible identification at all times while on the premises of the VA. Identification shall include, as a minimum, the employee’s name, position, and the contractor’s trade name. In addition, if required the contractor shall submit fingerprints through the VA police for issuance of a VA identification badge that shall be worn at all time while working at a VA facility.
Before leaving the VA facility, the contractor shall checkout with Biomed. In those cases when the Biomed office is closed, contractor personnel will log in and/or out directly with Pharmacy and after hours service shall be prearranged with the VA onsite POC (s).
K. Service Reports When service is completed, the FSE shall document services rendered on a legible ESR(s) and submit to the onsite POC (s) who set-up the service. The service report can be submitted when logging out with Biomed, via an internet web site or e-mail. Contractor shall provide all service reports within 72 hours of completed service to the following VA facility POC emails:
a. NWI: ***
b. MIN: *** Documentation shall include detailed descriptions of the scheduled and unscheduled maintenance procedures performed, including replaced parts and prices required to maintain the equipment in accordance with manufacturer specifications.
L. Out of Scope Services Contractor shall immediately, but not later than 24 consecutive hours after discovery, notify the CO and COR, (in writing), of the existence of the development of any defects in, or repairs required to, the scheduled equipment which the contractor considers he/she is not responsible for under the terms of the contract.
Contactor shall furnish the COR with a written estimate of the cost to make necessary repairs.
Any additional charges claimed will be approved by the CO via the COR before service is completed.
M. Service and Operator Manuals VA will not provide service manuals of service diagnostic software to the contractor. The contractor shall obtain, have on file, and make available to its FSEs all operational and technical documentation, (such as: operational and service manuals, schematics, and parts list), which are necessary the meet the performance requirements of this contract. The location and listing of the service data manuals, by name, and/or the manuals themselves shall be provided to the Contracting Officer upon request.
Upon request, the contractor shall provide the following documentation for the equipment being serviced:
1. Unlimited electronic copies of the Operators Manual and ongoing web-based access.
2. Unlimited electronic copies and ongoing web-based access of complete technical service manuals including troubleshooting guides, necessary diagnostic software/firmware and equipment, schematic diagrams, and parts lists.
3. Electronic schematics, troubleshooting guides and parts lists for each piece of equipment purchased.
4. Manuals shall include all components and subassemblies, including those not manufactured by the contractor.
5. Manuals and documentation shall be identical to the ones supplied to the manufacturer’s service representatives and shall contain the diagnostic codes, commands, and passwords used in maintenance, repair and calibration of the equipment.
6. Unlimited copies of any DVD training (and/or access to web-based training).
7. Ongoing access to training materials for future staff, online or DVD.
8. Any upgrades to these documents shall be provided by the contractor free of charge.
N. Training The contractor providing the support and maintenance service will be responsible for staff/user clinical and Biomed Technician service and support training technical training remotely and/or on-site. A System Technology and Services education professional (not sales reps) shall administer the training.
Upon request, the contractor shall provide additional professional training opportunities for designated staff technicians for the maintenance and troubleshooting to qualify them to completely maintain the system. The technicians shall be trained to diagnose failures, perform repairs, verify proper operation, and perform quality assurance checks required for Preventive Maintenance standards. Contractor shall provide all service manuals, schematics, diagrams, diagnostic software, firmware, and hardware keys equivalent to what OEM field service reps have available to diagnose, troubleshoot, repair and maintain the equipment.
Training materials provided (instructional texts, audio-visual materials) will become the property of the government and will be reproduced as needed.
Education curriculum must include the following:
1. Operations and set-up
2. User maintenance
3. Repair in house
4. Safety
5. User troubleshooting tips
6. Service Passwords for using the software
O. Security Requirements The contractor shall comply with all VHA security protocols, procedures and requirements of the VA’s Office of Information Technology including filling out and providing all necessary forms upon request within 10 days from receipt from the VA:
1. Any connections to the VA OI&T network shall be compliant with VA Directive 6500 and 6550.
a. The contractor shall complete and return separate 6550 forms with accurate information for the equipment and software.
b. Additionally, the contractor shall provide each product’s MDS2 and a diagram of data flow for each product.
2. Any offsite server or network maintenance or support provided by the contractor can only be done via VPN access after the contractor has obtained the Site-to-Site (S2S) VPN access from the VA. A Business Associates Agreement (BAA) and Memorandum of Site Site-to-Site Understanding/Interconnection Security Agreement (MOU/ISA) may be required.
a. The contractor shall complete and return BAA forms for the equipment upon request within 10 days from receipt from the VA.
b. Contractor shall have an active MOU-ISA in place, or the contractor shall work with VA to get an MOU-ISA in place within 6 months of award if determined beneficial. The contractor shall return completed forms within 10 days of receipt/request from the VA.
3. If applicable, the equipment software shall be approved in the Office of Information Technology’s Technical Resource Manual (TRM) or the contractor shall be willing to gain approval in TRM.
4. The equipment shall be FIPS 140-2 compliant. The contractor will identify the certificate number for FIPS compliance.
5. The medical equipment covered by this contract may contain electronic patient health information (EPHI). The vendor shall not remove/copy/delete any of the EPHI. If a computer hard drive needs to be replaced, the old hard drive must be turned-in to biomedical engineering for destruction. The vendor will not receive compensation for the hard drive.
6. If a cloud service Platform as a Service (PaaS), Cloud Instance or Software as a Service (SaaS) is selected as part of the project to include providing software patches, please review and reference VA Directive 6517 Cloud Computing Services and follow VA Enterprise Cloud Solution Intake processes.
7. Contractors shall allow for SMAK installation on all endpoint and server-based equipment. SMAK-AM = System Monitoring and Accountability Knowledge AntiMalware (SMAK-AM) toolset.
8. Contractor must supply all MAC addresses for networked devices at least one week prior to delivery of equipment.
P. Hardware Requirements
1. Hardware servers must be from a major brand manufacturer (Cisco, Dell, HP, Intel, etc.) and must include the following:
a. 19” rackmount chassis, prefer 2U or less per hardware server
b. Redundant components for networking at least 1Gbps per interface
c. Redundant components for power supply, capable of 208V operation
d. Out of Band management (iDRAC, iLO, etc.)
e. Current generation CPUs (dual or more per server)
f. Vendor’s recommended quantity of RAM per software application specifications.
g. Contractor shall allow for additional data storage quantity if desired by the site.
h. Redundant solid-state drives (SSD) for Operating System/Boot (RAID 1 or better)
i. Applications and data may reside on standard hard drives in a RAID configuration for redundancy.
j. Currently supported operating system (OS), preferably Windows Server 2019 or Windows Server 2022 Long-Term Support Channel build or most recent release. If a Long-Term Support Channel build cannot be supplied, Vendor must supply OS upgrades at no additional charge prior to currently installed OS reaching End of Support for the full term of the warranty or contract support coverage.
k. Sufficient capacity for future expansion of memory and disk space
l. ALL hardware or software login credentials must be documented and supplied.
2. Virtual servers are presented with a standard virtual hardware environment running on our Nutanix HCI system running the Acropolis hypervisor. At this time, VMWare OVA/VMDK packages are supported, Hyper-V packages are not supported. This environment provides a standard intel-compatible virtual server environment meeting the virtual hardware specifications required by the software being installed. All virtual servers are archived on a nightly basis by the Nutanix system.
3. Workstations must be from a major brand manufacturer (Dell, HP, etc.) and must include the following:
a. Current Trusted Platform Module (TPM) chip
b. Solid state drive for the Operating System. Applications and Data may be stored on additional standard or solid-state drives as needed; solid state drives are preferred.
c. Ability to encrypt drives for security.
d. Vendor’s recommended quantity of RAM per software application specifications.
e. Contractor shall allow for additional data storage quantity if desired by the site.
f. Currently supported operating system, preferably Windows 10 Enterprise Long-Term Support Channel build 1809, 21H2 or most recent release. If a Long-Term Support Channel build cannot be supplied, Vendor must supply OS upgrades at no additional charge prior to currently installed OS reaching End of Support for the full term of the warranty or contract support coverage.
g. Current generation CPU, Intel preferred. Processor shall be I5 equivalent or greater.
h. Display should be 24” class non-glare, and support at least FHD resolution (1920x1080) unless otherwise stated.
i. Laptops: Screen should be 15” class or larger, non-glare, and support at least FHD resolution (1920x1080) unless otherwise stated.
j. ALL hardware or software login credentials must be documented and supplied.
Q. Implementation/Project Management Services The contractor shall provide implementation and project services as part of the service purchase for maintenance, training, support, and licensing/software updates and upgrades. Implementation and Project Management Services shall include, but are not limited to, a project manager, a detailed project timeline including a Gantt Chart with defined roles and responsibilities (including contractor provided and VA resources), a detailed schedule for on-site Preventive Maintenance and Clinical and Biomed Training coordination of all equipment, technical support, and licensing/software updates/upgrades.
1. The contractor shall work with the COR and onsite POC (s) to coordinate and implement the maintenance, services and support. The contractor shall collaborate with onsite POC (s) to minimize down time and impact to patient care related to this implementation, including accommodating site requests for after-hours work. The dates resulting from this collaboration will be recorded in the project plan for each facility.
2. Contractor shall provide at least 60-day notice to onsite POC (s) when downtime is required for routine maintenance and training. Emergency maintenance to be planned with the onsite POC (s).
3. Within 1 week of the award date, the contractor shall provide a generic project management plan for maintenance, training, support, software updates and upgrades with milestones, deliverables and timeline, including the activities required in support of the services and clearly delineating the party responsible for accomplishing each activity.
4. Within 2 weeks of the award date, the contractor shall hold a kickoff meeting with the designated technical and clinical points of contact for each facility and COR. The project management plan and communications plan shall be reviewed at the kickoff meeting. Discussion about site order and schedule for service implementation will begin at the kick-off meeting.
5. The project manager shall hold as needed periodic project meetings with the facility POC (s) and COR to report progress, challenges and lessons learned for all facilities.
6. When the implementation service is complete at each facility, the contractor shall present an acceptance letter to the onsite POC (s) and COR for signature.
R. Invoicing and Pricing Detailed invoices will be submitted by the contractor in arrears after VA receipt and acceptance of equipment services. Invoices must include purchase order (PO) number, contract number, PO line items and description, period of service covered/dates, and cost at a minimum. The contractor shall reduce the number of invoices by including all relevant line items onto one invoice. Each line item on the invoice shall include the facility, POP and CLINS each line item pertains to. Invoices may be rejected that do not conform to this requirement. Pricing shall be competitive market value and reasonable.
Contractor shall submit invoices electronically through the VA’s Financial Service Center (FSC) for payment. Paper, emailed and faxed invoices are not accepted by the government. Electronic invoicing process can be found at http://www.fsc.va.gov/einvoice.asp Contact vafsccshd@va.gov or call 877-353-9791 for questions on invoicing.
Number for technical support: 866-340-4980 Technical Support site: https://www.tungsten-network.com/us/contact-us/#email-us https://www.tungsten-network.com/customer-campaigns/veterans-affairs/
S. Inspection and Acceptance Contractor shall inspect, adjust, repair and test to ensure safe reliable service within all tolerances as required by manufacturer’s specifications. The contractor shall conduct a joint inspection of services with the on-site POCs upon completion of the project. In the event deficiencies are identified, the contractor shall provide the date when the identified deficiencies will be addressed if not addressed on the date of installation. The contractor shall conduct a joint inspection of services with the on-site POCs after addressing all deficiencies. All deficiencies identified in the joint inspections shall be fixed by the contractor prior to government acceptance of the item. Any disputes shall be resolved by the Contracting Officer.
T. Disposal of Waste and Job Site Cleanup The contractor shall provide, maintain, and dispose of all material waste and packaging associated with the delivery of the specified services and/or waste generated during the services provided. Contractor will be responsible for moving waste materials daily from job site(s) to a contractor-provided waste container, and then off site.
U. Delivery and Materials Requirements The contractor shall coordinate delivery of all services and parts with the on-site POC (s) and COR prior to shipment/arrival. Parts shall not be delivered more than one week prior to installation. Parts shall be stored no longer than one week in the warehouse. The contractor shall provide parts delivery, shipping and tracking information to the on-site POC (s) and COR in advance before equipment arrival at the facility. Materials provided shall be new equipment, parts, and accessories. The contractor shall deliver materials to the job site in OEM's (Original Equipment Manufacturer) original unopened containers, clearly labeled with the OEM's name, equipment model and serial identification numbers, Purchase Order (PO) number and site Technical POC. The contractor is responsible for inventorying materials prior to delivery to VA sites to check for accuracy in quantity and part number. The contractor shall tag the bill of materials by area/room for ease of installation. Site POC (s) may reject items that do not conform to this requirement.
The contractor shall coordinate in advance with on-site designated facility POC (s) the delivery of equipment to final destination and obtain the appropriate Supply Chain Management POC. All equipment must be processed through Supply Chain Management prior to going to final destination.
V. Order of Precedence All work described and provided by the contractor, shall be performed in accordance with this SOW and Addendum applicable. The VA provided SOW shall become effective on the date the contractor receives a signed Purchase Order. Contractor shall be bound by any conflicting terms that may appear in any contractor provided documentation presented as part of the bid solicitation. Any services that are not in this SOW are considered Out-of-Scope.
Page 1 of image1.emf
VA Site to Site Configuration Worksheet.xlsx S2S Modification (Tab 1)
Modification to Existing S2S Connection
Use this spreadsheet to do one of the following:
Add a new partner system to an existing Site to Site VPN.
Add a new protocol/port to an existing Site to Site VPN.
Do not use this form to add a new VA system to an existing Site to Site VPN. Use the ISO Portal.
This spreadsheet is intended to help with an ESCCB request. It does not replace any ESCCB forms that may be required.
Instructions
If this is a request for a NEW connection, please go to "New S2S (Tab 2)", step 1. If not, proceed to step 1 below.
1. Enter the S2S Connection ID to the right. Yes
2. Enter the name of the Site to Site to the right. No
3. List the partner addresses to be added (if any).
Please list partner addresses seen over the VPN tunnel, ex: 64.64.64.1 do not list private addresses from the partner's internal network.
4. Enter the addresses of the VA systems that will communicate over the Site to Site tunnel to partner systems.
Source Destination Ports example: 10.0.0.1 10.0.0.2 tcp80, tcp443 example: 10.0.0.0/8 99.99.99.0/24 tcp80, tcp443
5. Enter the addresses of the partner systems that will communicate over the Site to Site tunnel to VA systems.
Source Destination Ports example: 10.0.0.2 10.0.0.1 tcp80, tcp443 example: 99.99.99.0/24 10.0.0.0/8 tcp80, tcp443
New S2S (Tab 2)
New S2S Connection
Use this spreadsheet to request a new Site to Site VPN.
This spreadsheet is intended to help with an ESCCB request. It does not replace any ESCCB forms that may be required.
Instructions
If this is a request for a EXISTING connection, please go to "S2S Modification (Tab 1)", step 1. If not, proceed to step 1 below.
1. Enter POC information. Yes
Role Name Phone Number Email Address
VA ISO Yes
VA Business POC
VA Technical POC
Partner Business POC
Partner Technical POC
2. Enter technical information for the Partner firewall. (Technical information for the VA firewall is shown as an example.) No
Partner Firewall VA Firewall
Vendor Cisco
Model 2 x ASA 5585
Software Version 9.6
ISP AT&T, CenturyLink
Circuit type (T1, frac-T1, etc.) Single Mode Fiber
Bandwidth 10 Gbps
3. Enter technical information for the VPN tunnel. (Technical information for the VA side is shown as an example.) No
Partner Side VA Side
Peer address 152.13x.32.60
IKE Version IKEv2
IKE Encryption AES-256
IKE Hash SHA-384 or Higher
NAT-T support Yes
Diffie Hellman support Group 19 or Higher
IKE Default Lifetime 86400
Authentication Preshared key
IPSec Encryption AES-256
IPSec Hash SHA-384 or Higher
IPSec Default Lifetime 3600
PFS No
4. Enter the addresses of the VA systems that will communicate over the Site to Site tunnel to partner systems.
Source Destination Ports example: 10.0.0.1 10.0.0.2 tcp80, tcp443 example: 10.0.0.0/8 99.99.99.0/24 tcp80, tcp443
5. Enter the addresses of the partner systems that will communicate over the Site to Site tunnel to VA systems.
Source Destination Ports example: 10.0.0.2 10.0.0.1 tcp80, tcp443 example: 99.99.99.0/24 10.0.0.0/8 tcp80, tcp443 image2.emf
VA MOU ISA Approved Final Template-09092020.docx
FOR OFFICIAL USE ONLY
Template color key (This Text Box to be removed from final draft)
Black text: boilerplate text that has been approved by VA management and must remain in document (flag/ comment on any areas of concern to discuss with the VA)
[VA Organization 1]: Replace with name of the VA organization (can be performed by a find and replace all (CTRL+H)
[Organization 2]: Replace with name of non-VA organization / company name
[VA Organization 1 System]: Replace with correct name of system or informational asset
[Organization 2 System]: Replace with correct name of system or informational asset
Blue text: replace with appropriate text and change to black once done
Green text: this is informational/instructional text that should be removed from final draft
Last – Update the Document Control Change Sheet to reflect the most recent status changes of the MOU/ISA.
MEMORANDUM OF UNDERSTANDING AND INTERCONNECTION SECURITY AGREEMENT
Between [VA Organization 1] Use the full name that appears in the current Governance, Risk and Compliance (GRC) tool]
And [Organization 2] Company name listed as primary from contract and/or BAA. List fully spelled out name.
[September 9, 2020] Enter date document finalized for signature in this format
[Version 2.0] Fill in based on Document Change Control Sheet or set as 1.0 if this is a new agreement
DOCUMENT CONTROL CHANGE SHEET
Date
Filename/Version #
Authors
Revision Description
09/09/2020
Template 2.0
Joseph Decoteau/Leigh Zirbel/Crystal White/James Mark McGee
Update VA Template and release new version to the field.
10/07/2022
Template 2.1
VA ECSD
Updated Topology Diagram Instructions with link to samples and templates
MM/DD/YYYY
Example: [Organization 2] Area Anytown MOU ISA 1.0
VA POC Name / Org 2 POC Name
[Include 2 Authors: VA and Organization 2 point of contact (POC) who drafted this document]
[Indicate New Agreement or Description of revision to existing agreement]
1. New document: Keep Template 2.0 log line. Complete log history for new agreement. Complete all 4 columns.
2. Renewal/revision to existing document: include the change log history of the older MOU agreement in the format of the example in the chart above.
Table of Contents
INTRODUCTION 5
1 SUPERSEDES: 6
1.1 Authority 6
2 MEMORANDUM OF UNDERSTANDING 7
2.1 Background 7
2.2 Communications 7
2.2.1 Security Incidents 8
2.2.2 Disasters and Other Contingencies 8
2.2.3 Material Changes to System Configuration 8
2.2.4 New Interconnections 9
2.2.5 Personnel Changes 9
2.2.6 Security 9
2.2.7 Cost Considerations 9
3 INTERCONNECTION SECURITY REQUIREMENTS 9
3.1 Background 9
3.1.1 System Description 9
3.1.2 System Hardware and Software Requirements 10
3.2 System Security Considerations 10
3.2.1 General Information/Data Description 10
3.2.2 Security Assessment 11
3.2.3 Services Offered 11
3.2.4 Information System Security Officer at Interconnection Site 12
3.2.5 Sensitivity Categorization 12
3.2.6 User Community 12
3.2.7 Information Exchange Security 12
3.2.8 Trusted Behavior Expectations 12
3.2.9 Formal Security Policy 12
3.2.10 Audit Trail Responsibilities 13
3.2.11 Security Parameters 13
3.2.12 Training and Awareness 14
3.3 TOPOLOGICAL DRAWING 14
4 Duration 15
5 SIGNATORY AUTHORITY 16
Appendix A: Points of Contact 17
Appendix B: Definitions of Sensitive Information Types 18
Appendix C: Interconnection Ports and Protocols 21
INTRODUCTION
The purpose of this document is to establish a management agreement between [VA Organization 1] and [Organization 2] regarding the development, management, operation, and security of a system interconnection between [VA Organization 1 System], owned or leased by [VA Organization 1], and [Organization 2 System], owned or leased by [Organization 2]. This agreement will govern the relationship between [VA Organization 1] and [Organization 2], including designated managerial and technical staff, in the absence of a common management authority.
[VA Organization 1] utilizes a Memorandum of Understanding (MOU) to document the terms and conditions for sharing data and information resources in a secure manner. The following supporting information within the MOU will define the purpose of the interconnection, identify relative authorities, specify the responsibilities of both organizations, and define the terms of the agreement. Additionally, the MOU provides details pertaining to apportionment of cost and timeline for terminating or reauthorizing the interconnection.
Technical details on how the interconnection is established or maintained are included within the Interconnection Security Agreement (ISA). A system interconnection is a direct connection between two or more information technology (IT) systems for sharing data and other information resources. [VA Organization 1] uses the ISA to formally document the reasons, methodology, and approvals for: interconnecting IT systems; to identify the basic components of an interconnection; to identify methods and levels of interconnectivity; and to discuss potential security risks associated with the interconnections.
This document does not replace any existing contract(s) between [VA Organization 1] and [Organization 2]. This fully executed agreement will be documented in applicable security controls in the current Governance and Risk Compliance tool and will be maintained as evidence for the respective system(s).
SUPERSEDES:
[Indicate if this is a new agreement or if it supersedes another agreement]
Authority
The [VA Organization 1] Information Security Officer is responsible for listing all relevant legislative, regulatory, or policy authorities. Examples provided below.
The authority for this interconnection is based on:
· Federal Information Security Modernization Act (FISMA)
· NIST 800-47 Rev 1 Managing the Security of Information Exchanges
· VA Directive and Handbook 6513, Secure External Connections
· VA Directive 6500, VA Cybersecurity Program
· VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program
· Health Insurance Portability and Accountability Act (HIPAA) Security Rule, 45 C.F.R. Part 160
· 38 United States Code (U.S.C.) §§ 5721-5728, Veteran’s Benefits, Information Security
· OMB Circular A-130, Managing Information as a Strategic Resource
· 18 U.S.C. 641 Criminal Code: Public Money, Property or Records
· 18 U.S.C. 1905 Criminal Code: Disclosure of Confidential Information
The Privacy Officer must ensure the correct authorities are identified below, based on the type of information being transmitted.
The authority for [VA Organization 1] to share data for the purpose outlined under this Agreement with [Organization 2] is as follows:
· HIPAA Privacy Rule, 45 Code of Federal Regulations (C.F.R.) Part 164, Standards for Privacy of Individually Identifiable Health Information [Add specific HIPAA provisions where applicable]
· Privacy Act of 1974, 5 U.S.C. § 552a, as amended
· [Add System of Records Notice (SORN) Name, Routine Use, or other Privacy Act authority if applicable]
· VA Claims Confidentiality Statute, 38 U.S.C § 5701 [Add specific citation (e.g., (b)(3) or (e)) if applicable]
· Confidentiality of Certain Medical Records, 38 U.S.C. § 7332 [Add specific citation if applicable]
MEMORANDUM OF UNDERSTANDING
Background
It is the intent of both parties to this agreement to interconnect the following IT systems to exchange data between [VA Organization 1 System] and [Organization 2 System]. [VA Organization 1] requires the use of or access to [Organization 2 System], and [Organization 2] requires the use of or access to [VA Organization 1 System], via an interconnection as approved by the VA Office of Information Technology (OIT) System Owner. The expected benefit of the interconnection is to expedite the processing of data associated with [VA Organization 1] and [Organization 2].
Each IT system is described below:
[VA Organization 1]’s System
– Name
[Enter full name of [VA Organization 1 System] here]
– Function
[Enter details about the function of [VA Organization 1 System] here]
– Location
[Enter physical location(s) of [VA Organization 1 System] here (Include street address, city, state and zip code)]
[Organization 2]’s System
– Name
[Enter full name of [Organization 2 System] here]
– Function
[Enter details about the function of [Organization 2 System] here]
– Location
[Enter physical location of [Organization 2 System] here. (Include street address, city, state and zip code)]
Communications
Frequent formal communications are essential to ensure the successful management and operation of the interconnection. The parties agree to maintain open lines of communication between designated staff at both the managerial and technical levels. Communications described herein must be conducted in writing (mail or email, excluding any sensitive VA information) unless otherwise noted.
The owners of [VA Organization 1 System] and [Organization 2 System] agree to designate and provide contact information for the technical lead(s) for their respective system and to facilitate direct contact between technical leads to support the management and operation of the interconnection (see Appendix A). To safeguard the confidentiality, integrity, and availability of the connected systems and the data stored, processed, and transmitted, the parties agree to provide notice of specific events within the timeframes indicated below.
Security Incidents
If [Organization 2] employee, contractor, or agent becomes aware of the theft, loss or compromise of any device used to transport, access, or store VA data, [Organization 2] shall notify [VA Organization 1] POCs listed in Appendix A by telephone or email within one hour upon discovery of a security incident.
[Organization 2] will provide details of the security incident, the potential risk to VA data, and all actions taken to remediate the issue. Reportable items include event type, date and time of event, user identification, workstation identification, success or failure of access attempts, and security actions taken by system administrators or security officers. VA Information System Security Officers (ISSO) or Privacy Officers (PO) will contact VA-CSOC within one hour of notification.
[Organization 2] will also provide VA with a written closing action report once the security event or incident has been resolved. VA will follow this same notification process should a security event occur within the VA boundary involving [Organization 2]’s provided data. Designated POCs will follow established incident response and reporting procedures, determine whether the incident warrants escalation, and comply with established escalation requirements for responding to security incidents.
[VA Organization 1] will report security incidents to the [Organization 2] POCs listed in Appendix A. [Enter a brief description of Organization 2’s security incident reporting requirements.]
Disasters and Other Contingencies
Technical staff will immediately notify their designated counterparts listed within Appendix A by telephone or email in the event of a disaster or other incident that disrupts the normal operation of one or both connected systems.
Material Changes to System Configuration
A significant change to an information system may include changes to the system itself or to the environment of operation. Significant changes to the information system may include but are not limited to: installation of new or major upgrades to the operating system, middleware component, or application; modifications to system ports, protocols, or services (see Appendix C); installation of a new or upgraded hardware platform; modifications to cryptographic modules or services; or modifications to security controls. Significant changes to the environment of operation which materially impact the interconnection to require reporting, may include, but are not limited to: moving to a new facility; adding new core missions or business functions; acquiring specific and credible threat information that the organization is being targeted by a threat source; or establishing new or modified laws, policies or regulations. Major changes to the information collected or maintained are those changes that could result in greater disclosure of information or a change in the way personal information/data is used.
Planned technical changes to the system architecture will be coordinated with the appropriate security and technical staff. All changes must be submitted, approved, and implemented as a modification to the existing connection through the appropriate change management process. Prior to requesting or implementing a change to the interconnection, the System Owner will conduct a risk assessment based on the new system architecture and determine if the proposed change requires reauthorization of the interconnection. Formal reauthorization is required whenever a system undergoes a significant change. The MOU/ISA must be updated and re-signed within 30 calendar days of implementation. The POCs listed in Appendix A are responsible for updating and reauthorizing this document.
New Interconnections
The initiating party will notify the other party at least 30 calendar days before it connects its IT system, described in Section 2.1, with any other IT system that materially impacts the security of the interconnection covered by this MOU/ISA. This includes connecting the IT system with systems that are owned and operated by third parties.
Personnel Changes
The responsible parties for each system are listed in Appendix A. The parties agree to provide notification of the separation, long-term absence or any other significant status changes in user profiles or personnel listed in Appendix A. The appendix will be updated as necessary to ensure accuracy.
Updating Appendix A does not require the re-signing of this MOU/ISA by either party. It is the responsibility of each respective approving authority to ensure the timely updating of this appendix and for the notification of such changes to the alternate party within thirty (30) days of any personnel change.
Security
Both parties agree to work together to ensure the joint security of the connected systems and the information/data stored, processed, and transmitted, as specified in the ISA section of this document.
Cost Considerations
Both parties agree to share the costs of the interconnecting mechanisms and/or media. Percentage of cost assumed by each organization (e.g., 50/50, 40/60, etc.) must be agreed upon in advance, and no such expenditures or financial commitments shall be made without the written concurrence of both parties. Modifications to either system that are necessary to support the interconnection are the responsibility of the respective system owner’s organization.
INTERCONNECTION SECURITY REQUIREMENTS
Background
The technical details of the interconnection are detailed in this ISA section of the document. The parties agree to work together to develop the ISA section. The MOU/ISA must be signed by both parties before the interconnection is activated. Proposed changes to either system or the interconnecting medium will be reviewed and evaluated as outlined in Section 2.2.3 Material Changes to System Configuration and 2.2.4 New Interconnections. The MOU/ISA must be updated and re-signed within 30 calendar days before changes (as described in Section 2.2.3 and 2.2.4) are implemented. Signatories to the MOU/ISA shall be the [VA Organization 1] System Owner, ISSO and PO and at least one (1) [Organization 2] System Owner. The document will become an integral piece of the VA Assessment and Authorization (A&A) documentation and will be included in subsequent authorization requests.
System Description
[VA Organization 1 System] and [Organization 2 System] system descriptions are listed in Section 2.1 of this document.
System Hardware and Software Requirements
[Identify hardware that will be needed to support the interconnection, including communications lines, routers, firewalls, hubs, switches, servers, and computer workstations. If existing hardware is not sufficient or compatible, specify what new hardware is required.]
[Identify software (must be VA TRM (Technical Reference Model) approved) that will be needed to support the interconnection, including software for firewalls, servers, and computer workstations. If existing software is not sufficient, specify what new software is required.]
System Security Considerations
General Information/Data Description
[VA Organization 1 System]
The following is a description of information/data to be transmitted from [VA Organization 1] to [Organization 2] including Federal Information Processing Standard (FIPS) 199 sensitivity categorization level.
· Information Type Transmitted: [Describe what information/data types will be transmitted from [VA Organization 1] to [Organization 2]. Example answers include, PII (Personally Identifiable Information), PHI (Protected Health Information), VA owned sensitive information, and financial data. See Appendix B for definitions of sensitive information types.]
· Data Flow Description: [Describe how information/data will be transmitted from [VA Organization 1] to [Organization 2]. Describe if it is collected, transmitted and/or stored.]
· The FIPS 199 Sensitivity Categorization Level is [Low/Moderate/High]. [The FIPS Level is to be filled out by the sponsoring facility’s VA staff (ISSO/Contracting Officer’s Representative (COR)/etc.).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .