36C26325Q0371.pdf

PDF 780 KB Posted

Attached to
Osometer Analyzer Federal contract opportunity
Solicitation number
36C26325Q0371
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 23

About this file

This is a Request for Quotation (RFQ) issued by the Department of Veterans Affairs Network 23 Contracting Office for an OsmoPRO MAX Automated Osmometer and related services for the Iowa City VA Medical Center. The solicitation (36C26325Q0371) is a 100% Service-Disabled Veteran-Owned Small Business (SDVOSB) set-aside under NAICS code 334516 with a size standard of 1000 employees.

The RFQ requires one Advanced Instruments OsmoPRO MAX Osmometer with installation, validation, and operational services, including a one-year Advanced Care Plus service contract. The equipment must perform STAT testing of serum and urine osmolality in ≤ 3 minutes using freezing point depression methodology, with a measurement range of 0-2000 mOsm/kg H2O. Key requirements include automated liquid handling, continuous sample loading, barcode scanning capabilities, and bi-directional interface compatibility with the VA's laboratory software. Responses are due by February 17, 2025, at 10:00 AM CST. The delivery timeframe is 60 days after purchase agreement signing. The Buy American Act provisions apply, and offerors must be registered in SAM.gov at the time of offer submission.

View the file

Other files for this federal contract opportunity

Other files attached to Osometer Analyzer, newest first.
File Type Posted
SOW Osmometer.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

636-25-2-4154-0031

36C26325Q0371

Becky De Los Santos 320-255-6480 02-17-2025

10 AM CST

36C263 Department of Veterans Affairs

NETWORK 23 CONTRACTING OFFICE

1303 5th St Suite 300 Coralville IA 52241

X 100

X

334516

1000 Employees

N/A

X

36C636

Department of Veterans Affairs Iowa CIty VA Medical Center 601 Hwy 6 West

Iowa City IA 52246

Department of Veterans Affairs

NETWORK 23 CONTRACTING OFFICE

1303 5th St, Suite 300 Coralville IA 52241

FMS-VA-2(101)

Financial Services Center PO Box 149971 Austin TX 78714-9971

See CONTINUATION Page

RFQ for Brand Name Or Equal:

Osmometer Analyzer for Iowa City VA Medical Center

See Specifications inserted in RFQ This is a Service Disabled Veteran Small Business Set-aside.

The time of submission of offer, the offeror shal have an active registration in the System for Award Management(SAM) at www.sam.gov. The Buy American Act Provision apply. Check FAR 52.225-1 Buy American Supplies for more information.

FAR 52.225-2 Buy American Certificate is required Certificate attached to solicitation. Failure to submit any of the required information, Statement or Certification may result in rejection of the quote without further consideration for award. All offerors shall fill out the certificate of compliance for limitations on sub-contracting at C.7 and return with the quote. Failure to sign the Limitation of Subcontracting will result in quote being unresponsive.

Deliver: Department of Iowa City VA Medical Center

601 Hwy 6 West Iowa City, IA 52246

See CONTINUATION Page

636-3650160-4154-822300-3131-0400K1043 636-25-2-4154-0031 x X x 01

Melissa Garrett

VA-VHA-RPOC-2023-0009

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 STATEMENT OF WORK

B.3 PRICE/COST SCHEDULE

ITEM INFORMATION

SECTION C - CONTRACT CLAUSES

C.1 52.225-1 BUY AMERICAN—SUPPLIES (OCT 2022)

C.2 52.225-2 BUY AMERICAN CERTIFICATE (OCT 2022)

C.3 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (NOV 2023)

C.4 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR CERTIFIED

SERVICE-DISABLED VETERAN-OWNED SMALL BUSINESSES (JAN 2023)

(DEVIATION)

C.5 VAAR 852.219-76 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING—

CERTIFICATE OF COMPLIANCE FOR SUPPLIES AND PRODUCTS (JAN 2023)

(DEVIATION)

C.6 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV

2018)

C.7 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020)

C.8 VAAR 852.247-73 PACKING FOR DOMESTIC SHIPMENT (OCT 2018)

C.9 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.10 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT

STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (NOV 2024)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (SEP 2023)

E.2 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (NOV 2021)

ADDENDUM to 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

E.3 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS

AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)

E.4 52.204-29 FEDERAL ACQUISITION SUPPLY CHAIN SECURITY ACT

ORDERS—REPRESENTATION AND DISCLOSURES (DEC 2023)

E.5 52.216-1 TYPE OF CONTRACT (APR 1984)

E.6 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB

1998)

E.7 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—

COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (MAY 2024)

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C263

NETWORK 23 CONTRACTING OFFICE

1303 5th St

Suite 300

Coralville IA 52241

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [x] Upon receipt and acceptance

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

Department of Veterans Affairs http://www.tungsten-network.com/US/en/veterans-affairs

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

5. INVOICING: All invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.

VA’s Electronic Invoice Presentment and Payment System – The FSC uses a third-party contractor, Tungsten, to transition vendors from paper to electronic invoice submission.

Please go to this website: http://www.tungsten-network.com/US/en/veterans-affairs/ to begin submitting electronic invoices, free of charge.

More information on the VA Financial Services Center is available at http://www.fsc.va.gov/einvoice.asp.

Vendor e-Invoice Set-Up Information:

Please contact the phone numbers or email address listed below to begin submitting your electronic invoices to the VA Financial Services Center for payment processing, free of charge. If you have question about the e-invoicing program or Tungsten, please contact the FSC at the phone number or email address listed below:

• e-Invoice Setup Information:

• e-Invoice email:

• FSC e-Invoice Contact Information:

• FSC e-invoice email: vafsccshd@va.gov

Tungsten e-Invoice set-up information: 877-489-6135 Tungsten e-Invoice email: VA.Registration@Tungsten-Network.com FSC e-Invoice Contact Information: 877-353-9791 FSC e-Invoice email: vafsccshd@va.gov More information on the FSC electronic invoicing process can be found at http://www.fsc.va.gov/einvoice.asp.

6. VA ISSUED BADGE: Contract employees may be required to obtain a VA Flash Badge or Visitor Badge while physically located within the VA facility. Determination of badging will be made by the Omaha Project Manager. If required to obtain a VA Flash Badge, contract employees will be required to present 2 forms of government identification for verification of contract employee.

7. CONTRACTOR ATTIRE AND IDENTIFICATION. The Contractor shall wear industry clothing that enables easy recognition as a “Contract Employee.” Clothing shall present a neat, distinctive appearance; shall be clean and maintained in good repair; and shall be worn as designed by the manufacturer. The Contractor shall wear appropriate clothing with logo identifying the contractor’s and employee’s name. The Contractor’s attire and presentation shall be appropriate per industry standard.

8. EMERGENCY PROCEDURES. The Contractor shall take such safety precautions as necessary to protect the lives and health of occupants of the buildings. The Contractor shall comply with applicable Federal, State, Local and facility safety and fire regulations and codes which are in effect at the beginning of the contract period. The Contractor shall keep abreast of and comply with changes in these regulations and codes applicable to the contract. The Contractor shall follow applicable facility policies concerning fire and/or disaster events. The

Contractor shall display approved warning devices in all areas where operations may cause traffic obstruction or personnel hazard.

Iowa City, Iowa VHA Pathology & Laboratory Medicine (PLM) has a requirement for a capital purchase for an Osmometer analyzer. The desired analyzer must have the capability of performing or reporting the clinical parameters as defined in the statement of work. The instrument must be able to perform as described and meet the performance characteristics for accuracy and precision as defined by the Clinical Laboratory Improvement Act (CLIA) and the Clinical and Laboratory Standards Institute (CLSI).

The awarded purchase does not obligate any funds and there is no obligation to the Government to purchase and cover products until such time as the individual participating VA facility issues a purchase order.

This solicitation uses a Brand Name or Equal Description of the product required. This permits prospective contractors to offer products other than those specifically referenced by brand name.

B.2 STATEMENT OF WORK

Iowa City, Iowa VA Health Care System is requesting equipment for the following purpose:

requires a freezing point depression Osmometer to perform STAT testing of serum and urine osmolality in ≤ 3 minutes.

Operational Features:

1. Able to perform tests to specifications as defined by CLIA and CLSI standards including satisfactory CAP peer group comparison. All required tests must be FDA approved.

2. Freezing point depression methodology

3. Ability to cover a measurement range of at least 0 – 2000 mOsm/kg H2O.

4. Ability to perform fully automated muliti-sample testing in ≤ 3 minutes.

5. Small sample volume, 150 microliters or less.

6. Primary tube sampling capabilities to reduce variations in pipetting.

7. Minimal recurring preventative maintenance and time spent on routine maintenance

(daily, weekly, monthly, etc).

8. Ease of operation with state of the art technology.

9. Calibrators must be traceable to a recognized national standards organization as stated by the Clinical and Laboratory Standards Institute (CLSI) and/or College of American Pathologists (CAP).

10. A Quality Control software package with the capability to produce Levy-Jennings graphs and perform system linearity checks will meet the requirements of the laboratory’s regulatory agency.

11. To meet patient safety standards, the osmometer must also have a barcode scanner for positive patient identification.

Hardware Features

1. Operating conditions: 18°C to 35°C ; 5% to 80% relative humidity

2. Power - 100-240 Volt AC, (50-60 Hz).

3. The instrument when installed in the Iowa City VA laboratory shall not negatively impact on the functionality/operations of the laboratory and shall not require signification and/or costly infrastructure changes to the government.

Support Function

1. The contractor shall have available all reagents, calibrators, controls, consumable/disposable items, parts, and accessories required to establish operation and perform all validation studies and method comparisons with the current analyzer.

2. The contractor shall provide standard warranty response on instrumentation, as required. The contractor shall provide applicable manuals (electronic and hard copies) and schedules upon delivery and installation of the equipment.

3. If the repair record of any individual piece of the contractor’s equipment reflects a downtime of 5% or greater of the normal working days in one calendar month from the time of dispatch, the designated representative may decide to have the contractor replace the malfunctioning equipment with new equipment at no charge to the customer.

The contractor is ultimately responsible for ensuring its equipment is furnished in good condition in accordance with manufacturer’s instructions. The customer is ultimately responsible for ensuring the manufacturer’s recommended daily, weekly, monthly, and periodic maintenance is performed appropriately.

Upgrades The contractor shall provide upgrades to both the equipment hardware and software in order to maintain the integrity of the system and the state of the art technology at no additional charge to the customer. These must be provided as they become commercially available and at the same time as they are being provided to commercial customers. This requirement only applies to “system upgrades” that are required by the manufacturer for operation of the analyzer to continue or enhance the model of equipment being offered, i.e., new version of software, including database upgrades, correction of hardware defect, upgrade offered to commercial customers at no additional charge, upgrade to replace model of equipment no longer vendor supported, etc.

Computer Interfacing A fully operational interface (both hardware and software) must be available at the time of contract award as agreed upon.

If the vendor requires remote access via internet to any component of instrument or interface, vendor is responsible for pursing a National Business Associate Agreement with the VA, or a localized Site-to-Site agreement with the facility ISO office.

If any instrument or interface component is capable of storing data, the VA will retain the hard drive at end of instrument life for proper disposal.

Instrument interface will have bi-directional communication capability, and possess ability to read specimen barcodes in standard format such as Code 128 or Code 39. The VA laboratory software requires the use of non-proprietary universal interfacing system to provide bi-directional communication, which means laboratory instruments are not able to communicate with the VA lab software directly. The Iowa City facility laboratories currently use Instrument Manager by Data Innovations as the middleware system. To achieve connection with those systems, it is highly desirable that the awarded vendor will be responsible for the cost of interfacing, including cables, connectors, universal interfacing devices (Lantronix boxes) and software licenses. The VA will assume any annual license maintenance costs with the middleware vendor after initial interfacing is completed.

Brief Summary of VistA Functionality

1. VistA is a public domain system to the VA whose functionality includes:

2. Management of patient information through a database,

3. Acceptance of test ordering information,

4. Transmittal of patient laboratory test results.

5. Storage and retrieval of patient laboratory test results.

Commercial Offering The contractor shall provide any additional support materials routinely provided to equivalent commercial customers and will assist in regulatory compliance, e.g.

computer diskette of its procedure manual or an on-line procedure manual in the instrument software.

Waste Characterization The contractor shall provide a statement and description of the characteristics of the hazardous waste produced as a byproduct of the instrument operations that address the elements and criteria listed in the Code of Federal Regulations Title 40 “protection of the Environment” part 261 et al.

Equipment and Service Needs

Iowa City, Iowa VA needs a total of one Advanced Instruments OsmoPRO MAX Osmometer and listed items for installation, validation, and operation.

Item # Item Quantity

Advanced Instruments – OsmoPRO MAX Automated Osmometer and operation accessories

OSMOPRO MAX Advanced instruments; Model OsmoPRO MAX; For osmolality measurement of solutions using freezing point depression; Automated; Multi sample; Designed to process a 150uL sample; Test time: 180 sec.; 14 x 16.5 x 18 inches.

ITV-SKC-PRO MAX Instrument Installation, Training & Validation Service includes instrument installation & installation documents, on-site training (two hours) & training document, validation up to 6 hours and required consumables. Validation includes: • Method Comparison: 20 patient serum/plasma & urine samples (10 serum + 10 urine) • Precision/Accuracy:

Clinitrol 290 - 5 replicates, Protinol Protein-Based Control (3 levels) & Renol Urine Control (3 levels) – 5 replicates each/per level • Linearity: Osmolality Linearity Set (5 levels)

– 5 replicates per level • Summary page & comprehensive report • Certification of validation • Meets CAP and CLIA requirements

SC-PRO MAX-1YR-

ACP

1-Year Advanced Care Plus Service Contract for OsmoPRO MAX.

· One (1) annual on-site preventative maintenance service is covered under each year of a purchased agreement

· Onsite repairs and repair parts covered.

· Unlimited phone support.

· Loaner instrument covered.

135022_EX-EU Printer, Dot-Matrix_EX-EU – w/cable - OsmoTECH 1

AN2TP5 Paper roll for Dot-Matrix printer (pkg 5) 1

SK-PRO MAX Convenience kit – OsmoPRO MAX includes:

MAX500, 3MA552 (2X), 3MA002, 552923, 3MA029

Laboratory has limited staffing on evenings, weekends, and holidays therefore a fully automated osmometer will best fit the needs of our 24/7 laboratory. The listed requirements are essential for the laboratory to meet all Joint Commission and CAP regulations and maintain efficient workflow with the Core Laboratory.

Delivery and Inspection

Instrumentation shall be delivered to the requesting facility no later than 60 days after purchase agreement has been signed.

Delivery address is as follows:

Attn: Laboratory (Chemistry Supervisor) Iowa City VHA HCS 601 Hwy 6 W Iowa City, Iowa 52246

All instrumentation will be required to pass inspection by Iowa City VA BioMed prior to installation.

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE FOR

INCLUSION INTO CONTRACTS

1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.

2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language. a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.

b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.

e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.

h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.

i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.

k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.

l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.

m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA

Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.

o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA.The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

b. b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c. c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program.

The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

(1) Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

(2) Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

(3) Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

(5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.

(6) Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.

4. TRAINING. This entire section applies to all acquisitions which include section 3. a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems: (1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

b. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language. a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.

b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following: (1) The date and time (or approximation of) the Security Incident occurred.

(2) The names of individuals involved (when applicable).

(3) The physical and logical (if applicable) location of the incident.

(4) Why the Security Incident took place (i.e., catalyst for the failure).

(5) The amount of data belonging to VA believed to have been compromised.

(6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.

c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.

g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach Costs.

6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.

a. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).

b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain an Authority to Operate (ATO).

VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides the security and privacy requirements for cloud environments.

c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced.

d. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M-22-18 (September 14, 2022). The term “software” includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self-attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self-attestation.

e. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance.

This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.

f. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.

g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository.

h. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems.

i. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.

j. The contractor-delivered solutions shall reside on VA approved operating systems.

Exceptions to this will only be granted with the written approval of the COR/CO.

k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.

l. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224-2 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.

m. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.

n. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security Knowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as to not affecting the Systems within 10 business days.

7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (cloud and non-cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities. a. The contractor shall comply with all Federal laws, regulations, and VA policies for Information systems (cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities. Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the information system or systems by or on behalf of VA. This includes conducting compliance risk assessments, security architecture analysis, routine vulnerability scanning, system patching, change management procedures and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures shall be the same as procedures used to secure VA-operated information systems.

b. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require Assessment and

Authorization (A&A) of the contractor’s systems in accordance with VA Handbook 6500 as specified in VA Information Security Knowledge Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor’s cloud computing systems shall comply with FedRAMP and VA Directive 6517 requirements.

c. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT equipment used to store, process or access VA information to VA in accordance with A&A package requirements.

This applies when the contract is terminated or completed and prior to disposal of media.

The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-88.

The contractor shall send a self-certification that the data destruction requirements above have been met to the COR/CO within 30 business days of termination of the contract.

d. All external internet connections to VA network involving VA information must be in accordance with VA Trusted Internet Connection (TIC) Reference Architecture and VA Directive and Handbook 6513, Secure External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of Understanding (MOU) and Interconnection Security Agreements (ISA).

e. Contractor procedures shall be subject to periodic, announced, or unannounced assessments by VA officials, the OIG or a 3PAO. The physical security aspects associated with contractor activities are also subject to such assessments. The contractor shall report, in writing, any deficiencies noted during the above assessment to the VA COR/CO. The contractor shall use VA’s defined processes to document planned remedial actions that address identified deficiencies in information security policies, procedures, and practices.

The contractor shall correct security deficiencies within the timeframes specified in the VA Information Security Knowledge Service.

f. All major information system changes which occur in the production environment shall be reviewed by the VA to determine the impact on privacy and security of the system. Based on the review results, updates to the Authority to Operate (ATO) documentation and parameters may be required to remain in compliance with VA Handbook 6500 and VA Information Security Knowledge Service requirements.

g. The contractor shall conduct an annual privacy and security self-assessment on all information systems and outsourced services as required. Copies of the assessment shall be provided to the COR/CO. The VA/Government reserves the right to conduct assessment using government personnel or a third-party if deemed necessary. The contractor shall correct or mitigate any weaknesses discovered during the assessment.

h. VA prohibits the installation and use…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .