SOW 2024_Sensitive Trash Disposal Updated.pdf
PDF 247 KB Posted
- Attached to
- Sensitive Trash Destruction Federal contract opportunity
- Solicitation number
- 36C77025Q0002
About this file
This document is a Statement of Work (SOW) for providing sensitive material destruction and disposal services to the Charleston Consolidated Mail Outpatient Pharmacy (CMOP) of the Department of Veterans Affairs (VA). The SOW describes the scope of work, period of performance, invoicing requirements, and the need for a Business Associates Agreement (BAA).
The key details are: The CMOP generates an estimated 13 tons of mixed solid waste weekly, 15% of which contains sensitive information such as Personally Identifiable Information (PII) and Health Insurance Portability and Accountability Act (HIPAA) data. The contractor must provide destruction and disposal services for this sensitive material without impacting CMOP's production rates or increasing storage requirements. The contract is for a base year with four option years. The SOW outlines specific requirements regarding the trash segregation schema, handling by CMOP staff, and documentation of proper disposal. The related federal contract opportunity is solicitation number 36C77025Q0002 for "Sensitive Trash Destruction" issued by the VA Veterans Integrated Service Network 15.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ SENSITIVE TRASH DESTRUCTION 36C77025Q0002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
CHARLESTON CMOP HIPAA/PII DESTRUCTION SERVICES
1) SCOPE
The Department of Veterans Affairs (VA) Consolidated Mail Outpatient Pharmacy (CMOP) Charleston located at 4136 Carolina Commerce Pkwy, North Charleston, SC 29456 requires Sensitive Material destruction and disposal services. Contractor will provide destruction (e.g.:
burning, shredding, etc.) and disposal of material containing Health Insurance Portability and Accountability Act (HIPAA), Personally Identifiable Information (PII) data, and VA Sensitive Information, which consists of a variety of trash steams. These streams include but are not limited to paper, labels, pharmaceutical bottles with affixed labels, mylar and bubble mailers with affixed labels, and printer ribbons. The vendor must minimize the trash segregation schema to prevent negative impacts to production throughput. Contractor must also complete a Business Associates Agreement (BAA), as shown in paragraph 4 below and meet the appropriate security requirements of the solicitation. Destruction will be accomplished in accordance with the descriptions contained in paragraph 5.d.4.d.3 below.
2) PERIOD OF PERFORMANCE
The Government is seeking to establish a service contract of a base year with four option years:
BASE YEAR OCTOBER 01, 2024 TO SEPTEMBER 30, 2025
OPTION YEAR 1 OCTOBER 01, 2025 TO SEPTEMBER 30, 2026
OPTION YEAR 2 OCTOBER 01, 2026 TO SEPTEMBER 30, 2027
OPTION YEAR 3 OCTOBER 01, 2027 TO SEPTEMBER 30, 2028
OPTION YEAR 4 OCTOBER 01, 2028 TO SEPTEMBER 30, 2029
3) INVOICES
Contractor shall invoice the CMOP facility for services monthly. The issuing contracting officer is responsible for any necessary oversight to ensure proper invoice processing. The invoicing method used by the vendor must be in accordance with VAAR 852.232-72, Electronic Submission of Payment Requests (Nov 2018). The EFT rule (31 CFR Part 208) requires that most federal payments be made electronically. Waivers are available to agencies and to individual recipients, however, no waivers are available to vendors. As a result, any vendor of the Federal government is required to receive payment by direct deposit (electronic funds transfer (EFT)).
4) BUSINESS ASSOCIATES AGREEMENT (BAA)
This document is required to fulfill certain requirements of the Health Insurance Portability and Accountability Act (HIPAA). The VA requires the offeror to have a BAA in place and submitted with the offeror's quotation. If a prospective offeror does not have a BAA with the VA, the BAA draft at the end of this Work Statement is an example of what needs to be in place prior to the POP start date, signed by the offeror. Offeror must be able to fully execute a valid BAA prior to commencement of the contract.
5) WORK STATEMENT
A. INTRODUCTION
The Charleston Consolidated Mail Outpatient Pharmacy (CMOP) is located at 4136 Carolina Commerce Pkwy, North Charleston, South Carolina 29456. Charleston CMOP dispenses approximately 115,000 prescriptions daily for direct to patient delivery. Charleston CMOP operates two shifts, Monday through Friday from 6:00AM until Midnight. Charleston CMOP generates over 25 tons of bulk trash weekly, which consists of eight (8) tons of recyclable cardboard, four (4) tons of food and general, solid waste, and thirteen (13) tons of production related solid waste co-mingled with the sensitive information. The sensitive information comprises approximately 15% or an estimated two (2) tons. The sensitive information includes, but not limited to the following:
• VA patient Personally Identifiable Information (PII)
• HIPAA information
• VA Sensitive Information
The material includes but not limited to the following media types:
• Printed paper
• Labels
• Plastic bottles with adhesive labels
• Mylar shipping bags and padded mailers with labels
• Printing Ribbon
• Coolers with labels
• Cardboard boxes with labels
Charleston CMOP requires shredding, burning, or other acceptable method of sufficient destruction to dispose of this protected information in accordance with National Association for Information Destruction (NAID) and National Archives and Records Administration (NARA) regulations, whichever is more restrictive. The service shall not interfere with production work and should minimize the impact on productivity of the individual workstations. The service may be conducted on or off-site. Appropriate documentation of proper disposal is required (see
Administration). Contractor shall be able to process the mixed stream, solid waste from the CMOP without significant separation or onsite storage of trash.
B. SYSTEM FUNCTION AND PERFORMANCE
(1) CMOP produces an estimated thirteen (13) tons of mixed stream, solid waste weekly from the processing of orders for Veteran patients. Charleston CMOP must properly destroy and dispose of the various media in the trash stream. CMOP must also properly destroy paper records including VA Sensitive Information from offices and official records. An estimated 15% (two tons) of the waste stream is VA Sensitive or Patient Sensitive Information. This portion of the mixed trash stream includes office paper, adhesive labels on plastic bottles, mylar and padded mailer bags. The non-sensitive solid waste stream contains shrink wrap, plastic bottles and caps, paper and pamphlets, vinyl and nitrile gloves, and other general trash. All waste streams will be collected at over 150 workstations with a minimal impact on production staff cycle times and minimal separation requirements. There is insufficient space at the production workstations to have multiple bin types and a complex trash segregation schema. Housekeeping Staff pull the bags when full and remove from the work area at least once per shift. The segregation schema and collection requirements should not significantly increase the amount of cycles that Housekeeping Staff perform to prevent the need for modification to that contract vehicle and increased cost to the Government.
(2) Currently, CMOP separates Patient Sensitive Information and general trash at each workstation into two (2) open top, Slim Jim type trash cans. Charleston CMOP has contract Housekeeping Staff that consolidate the Patient Sensitive and general trash material into a 34 yd compacting dumpster for transport to the designated destruction facility via a separate waste management contract. The ribbon material is consolidated into a common area receptacle in each of the Production Sub-Areas. Housekeeping Staff consolidate these containers into a lockable, 4 yd Closed Top dumpster for transport to the designated destruction facility. Once received at the designated destruction facility, all media with privacy information must be destroyed in accordance with federal, state, VA directives and regulations and appropriate documentation of destruction provided to the VA CMOP Charleston.
(3) CMOP currently has a waste management contract for two (2) 10-yd closed top dumpsters for food waste and general landfill disposal, Cardboard recycling pick-ups, and a 34-yd compacting dumpster for all processing related trash (including the Sensitive Material) for transport to a regional, certified destruction facility. If these services will need to be altered or deleted, contractor must note this in the proposal.
(4) CMOP requires Sensitive Material destruction services to process the stated volume of trash without impact to production rates or increase in trash storage requirements.
(a) CMOP operators are required to process 100+ orders/hr to maintain proper rates and meet the demand of Veteran patient workload. As such, they cannot leave their workstation to approach a common area bin whenever they encounter a situation that requires a discard of sensitive information. In some high-volume areas, a common area bin is the only solution based on size and volume, but this is limited to a few dozen areas. To ensure that workstations are ergonomic and highly efficient, the number and size of trash receptacles at each workstation must be minimal. Operators cannot be expected to keep high processing rates if there is a complex segregation schema with multiple bins. The concentration needed to track proper trash segregation will negatively impact production rates. Additionally, the receptacles cannot have a thin slit for paper because the bags, bottles and materials must be easily placed into the receptacle.
(b) CMOP has a severely limited footprint and additional storage of containers on-site is not likely. Housekeeping Staff consolidate the bags from the individual containers into rolling carts and immediately place the processing trash and sensitive material into the compacting dumpster. There is no standing storage of trash or containers inside the building. The seven
(7) containers that are used for ribbon disposal are immediately taken outside to the locked dumpster when they become full. The only reason for the ribbon segregation is for evaluation of the impact of the ribbon on the current shredding equipment at the destruction facility. This will likely not be continued beyond the end of FY24. Workstations are extremely constrained by space and adding additional trash containers to each station will inhibit ease of movement and add to the congestion potentially creating safety hazards.
(c) CMOP alters schedules around Federal Holidays which requires 4-6 schedule adjustments during the year. During holiday and overtime periods, an additional service may be required to handle unexpected volumes of trash (<10% of the total number of service visits).
(d) Destruction may be conducted on-site or off-site, but the security of the material must be maintained in either case. CMOP reserves the right to conduct spot inspections during destruction operations to ensure the proper disposal of Sensitive Material.
(i) On-Site: Fire lanes and parking areas adjacent to the facility must remain clear. Any staff that will need to access the building will need to either be properly vetted and issued a PIV card. If staff consistency is not tenable, then they will need to have a VA escort at all times. This will require advance notice and coordination of pick-ups so that escorts are available. If timely coordination is not provided, access will be denied and the pick-up rescheduled at VA convenience.
(ii) Off-Site: Chain of custody and security of the material must be maintained. Any loss of control of sensitive information requires immediate notification of CMOP Contracting Officer’s Representative (COR). Charleston CMOP has an existing contract which provides transport of the 34yd compacting dumpster to locations within the local area (<25 miles). If the vendor will provide material transport to off-site locations, then contractor must note this in the proposal. If existing transport is required to travel >25miles, additional cost will be passed to the vendor.
(iii) Destruction Requirements: Material must be destroyed in a manner that meets all Federal, State and VA Requirements for HIPAA material, VA Sensitive Information, or NARA requirements for Government Records destruction, whichever is more restrictive.
VA Directive 6371 and NIST Special Publication 800-88 provide guidance. Proof of destruction must be provided to CMOP COR.
C. ADMINISTRATION
(1) Invoices must be submitted no less than monthly. Invoices must include all information to properly certify the invoice, including but not limited to: date(s) of service, unit of measure, unit cost, total cost, date, invoice number. Invoices must be submitted following destruction, and contractor shall deliver copies of destruction. Service will not be considered completed until certificate of destruction is received either electronically or hard copy. Verification must indicate the method of destruction.
(2) Contractor shall maintain licenses and/or permits required by Federal, State, County and City laws, rules, and regulations governing removal of waste materials and recycling.
(3) Background checks for personnel requiring PIV badges will be at the contractor’s expense, including any replacement of lost/damaged badges.
(4) Vendor must have a Business Associates Agreement with the VA and provide documentation at time of quote.
(5) Vendor must provide a Point of Contact for the administration of this contract to the CMOP COR. This person will be the primary for making adjustments to the schedule, invoices, and all administrative and operational matters. The POC must work with the Contracting Officer for any matters that could impact cost or contractual changes to the services.
Sample Business Associate Agreement
Purpose. The purpose of this Business Associate Agreement (Agreement) is to establish requirements for the Department of Veterans Affairs (VA), Veterans Health Administration (VHA), <Insert Facility Name> and <Company/Organization> in accordance with the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH) Act, and the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (“HIPAA Rules”), 45 C.F.R. Parts 160 and 164, for the Use and Disclosure of Protected Health Information (PHI) under the terms and conditions specified below.
Scope. As described this Agreement and other applicable contracts or agreements, <Company/Organization> will provide <BRIEFLY DESCRIBE SERVICES (i.e., medical device, transcription, publishing)> services to, for, or on behalf of <Insert Facility Name>.
In order for <Company/Organization> to provide such services, <Insert Facility Name> will disclose PHI to <Company/Organization>, and <Company/Organization> will use or disclose PHI in accordance with this Agreement.
Definitions. Unless otherwise provided, the following terms used in this Agreement have the same meaning as defined by the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, PHI, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use.
“Breach” shall have the same meaning as described at 45 C.F.R. § 164.402. For the purposes of this Agreement, Breach shall refer to an acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Rules or by this Agreement.
“Business Associate” shall have the same meaning as described at 45 C.F.R. §
160.103. For the purposes of this Agreement, Business Associate shall refer to <Company/Organization>, including its employees, officers, or any other agents that create, receive, maintain, or transmit PHI as described below.
“Covered Entity” shall have the same meaning as the term is defined at 45
C.F.R. § 160.103. For the purposes of this Agreement, Covered Entity shall refer to <Insert Facility Name>.
“Incident” shall have the same meaning as described in VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which is an event that has resulted in, or had the potential to result in, unauthorized access to or disclosure of VA sensitive personal information in a manner not permitted under the applicable confidentiality provisions. An incident that involves access or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule is presumed to be a breach unless Business Associate demonstrates that there is a low probability that the
PHI has been compromised based on a risk assessment using at least the listed factors in the Breach Notification Rule.
“Protected Health Information” or “PHI” shall have the same meaning as described at 45 C.F.R. § 160.103. “Protected Health Information” and “PHI” as used in this Agreement include “Electronic Protected Health Information” and “EPHI.” For the purposes of this Agreement and unless otherwise provided, the term shall also refer to PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity or receives from Covered Entity or another Business Associate of Covered Entity.
“Subcontractor” shall have the same meaning as the term is defined at 45 C.F.R.
§ 160.103. For the purposes of this Agreement, Subcontractor shall refer to a contractor of any person or entity, other than Covered Entity or Business Associate, that creates, receives, maintains, or transmits PHI under the terms of this Agreement.
Terms and Conditions. Covered Entity and Business Associate agree as follows:
1. Ownership of PHI. PHI is and remains data owned by Covered Entity as long as
Business Associate creates, receives, maintains, or transmits PHI, regardless of whether a compliant Business Associate Agreement is in place.
2. Use and Disclosure of PHI by Business Associate. Unless otherwise provided, Business Associate:
A. May not use or disclose PHI other than as permitted or required by this Agreement, or in a manner that would violate the HIPAA Privacy Rule if done by Covered Entity, except that it may use or disclose PHI:
(1) As required by law or to carry out its legal responsibilities;
(2) For the proper management and administration of Business Associate; or
(3) To provide Data Aggregation services relating to the health care operations of Covered Entity.
B. Must use or disclose PHI in a manner that complies with Covered Entity’s minimum necessary policies and procedures.
C. May de-identify PHI created or received by Business Associate under this Agreement, provided that the de-identification conforms to the requirements of the HIPAA Privacy Rule and that such de-identified information is used solely for purposes of providing or improving Business Associate’s services for Covered Entity or for another lawful purpose approved in advance and in writing by Covered Entity. Business Associate shall not sell or market de-identified data sets created from Covered Entity’s PHI.
3. Obligations of Business Associate. In connection with any Use or Disclosure of PHI, Business Associate must:
A. Consult with Covered Entity before using or disclosing PHI whenever Business Associate is uncertain whether the Use or Disclosure is authorized under this Agreement.
B. Implement appropriate administrative, physical, and technical safeguards and controls to protect PHI and document applicable policies and procedures to prevent any Use or Disclosure of PHI other than as provided by this Agreement.
C. Provide satisfactory assurances that PHI created or received by Business Associate under this Agreement is protected to the greatest extent feasible.
D. Notify Covered Entity no later than twenty-four (24) hours after Business Associate’s discovery (as described in (1) below) of any incident, such as a potential access, acquisition, use, disclosure, modification, or destruction of either secured or unsecured PHI in violation of this Agreement “that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of VA information or a VA information system” accessible by VA users “or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies,” per the Federal Information Security Management Act, 44 USC 3501-3518.
(1) For purposes of this notification, an incident as described above will be treated as discovered by Business Associate when such event is known to any employee, officer, or other agent (other than the individual who committed the incident) of Business Associate or, by exercising reasonable diligence, would have been known to an employee, officer, or other agent of Business Associate.
(2) Notification shall be sent to the <Insert local VHA Privacy Officer’s name(s) and email address(es)> and to the VHA Health Information Access Office, Business Associate Program Manager by email at VHABAAIssues@va.gov.
(3) Absent Covered Entity’s request or approval, Business Associate shall not directly notify individuals or the Department of Health and Human Services of incidents involving PHI created or received by Business Associate as an agent of Covered Entity.
E. Provide a written report to Covered Entity of any potential access, acquisition, use, disclosure, modification, or destruction of either secured or unsecured PHI in violation of this Agreement, including any Breach of PHI, within ten (10) business days of the initial notification to the Covered Entity.
(1) The written report of an incident as described above will document the following:
mailto:VHABAAIssues@va.gov
(a) The identity of each Individual whose PHI has been, or is reasonably believed by Business Associate to have been, accessed, acquired, used, disclosed, modified, or destroyed;
(b) A description of what occurred, including the date of the incident and the date of the discovery of the incident (if known);
(c) A description of the types of secured or unsecured PHI that was involved;
(d) A description of what is being done to investigate the incident, to mitigate further harm to Individuals, and to protect against future Security Incidents;
and
(e) Any other information as required by 45 C.F.R. §§ 164.404(c) and 164.410.
(2) The written report shall be addressed to:
<Insert local VHA Privacy Officer’s name(s) and facility address> and submitted by email to <Insert local VHA Privacy Officer’s email address(es)> and to the VHA Health Information Access Office, Business Associate Program Manager at VHABAAIssues@va.gov.
F. To the greatest extent feasible, mitigate any harm due to a Use or Disclosure of PHI by Business Associate in violation of this Agreement that is known or, by exercising reasonable diligence, should have been known to Business Associate.
G. To the extent feasible, use only agents and Subcontractors that are physically located within a jurisdiction subject to the laws of the United States or its Territories.
H. Enter into Business Associate Agreements with contractors and Subcontractors as appropriate under the HIPAA Rules and this Agreement. In doing so, Business Associate:
(1) Must ensure that the terms of any Agreement between Business Associate and a contractor or Subcontractor are at least as restrictive as Business Associate Agreement between Business Associate and Covered Entity.
(2) Must ensure that contractors and Subcontractors agree to the same restrictions and conditions that apply to Business Associate and obtain satisfactory written assurances from them that they agree to those restrictions and conditions.
(3) Unless approved by Covered Entity in advance and in writing, may not amend any terms of such Agreement, in any way to make them inconsistent with mailto:VHABAAIssues@va.gov the obligations of Business Associate or any contractors or Subcontractors in connection with or in consideration of the HIPAA Rules or this Agreement.
I. Within five (5) business days of a written request from Covered Entity:
(1) Make available information for Covered Entity to respond to an Individual’s request for access to PHI about him/her.
(2) Make available information for Covered Entity to respond to an Individual’s request for amendment of PHI about him/her and, as determined by and under the direction of Covered Entity, incorporate any amendment to the
PHI.
(3) Make available PHI for Covered Entity to respond to an Individual’s request for an accounting of Disclosures of PHI about him/her.
J. Business Associate shall not take any action in response to an individual’s request for access, amendment, or accounting and shall direct the individual to contact the VHA Privacy Office at 1-877-461-5038.
K. To the extent Business Associate is required to carry out Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the provisions that apply to Covered Entity in the performance of such obligations.
L. Provide to the Secretary of Health and Human Services and to Covered Entity records related to Use or Disclosure of PHI, including its policies, procedures, and practices, for the purpose of determining Covered Entity’s, Business Associate’s, or a Subcontractor’s compliance with the HIPAA Rules.
M. Upon completion or termination of the applicable contract(s) or agreement(s), return or destroy all PHI and other VA data created or received by Business Associate during the performance of the contract(s) or agreement(s). No such information will be retained by Business Associate unless retention is required by law or specifically permitted by Covered Entity. If return or destruction is not feasible, Business Associate shall continue to protect the PHI in accordance with the HIPAA Rules or this Agreement and use or disclose the information under this Agreement only for the purpose of making the return or destruction feasible, as required by law, or as specifically permitted by Covered Entity. Business Associate shall provide written assurance that either all PHI has been returned or destroyed, or any information retained will be safeguarded and used and disclosed only as permitted under this paragraph.
N. Be liable to Covered Entity for civil or criminal penalties imposed on Covered Entity, in accordance with 45 C.F.R. §§ 164.402 and 164.410, and with the HITECH Act, 42 U.S.C. §§ 17931(b), 17934(c), for any violation of the HIPAA Rules or this Agreement by Business Associate.
4. Obligations of Covered Entity. Covered Entity agrees that it:
A. Will not request Business Associate to make any Use or Disclosure of PHI in a manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if made by Covered Entity, except as permitted under Section 2 of this Agreement.
B. Will promptly notify Business Associate in writing of any restrictions on Covered Entity’s authority to use or disclose PHI that may limit Business Associate’s Use or Disclosure of PHI or otherwise affect its ability to fulfill its obligations under this Agreement.
C. Has obtained or will obtain from Individuals any authorization necessary for Business Associate to fulfill its obligations under this Agreement.
D. Will promptly notify Business Associate in writing of any change in Covered Entity’s Notice of Privacy Practices, or any modification or revocation of an Individual’s authorization to use or disclose PHI, if such change or revocation may limit Business Associate’s Use and Disclosure of PHI or otherwise affect its ability to perform its obligations under this Agreement.
5. Amendment. Business Associate and Covered Entity agree to enter into good faith negotiations to amend this Agreement, as necessary, for Covered Entity and Business Associate to comply with the requirements of the HIPAA Rules or other applicable law.
6. Termination.
A. Automatic Termination. This Agreement will automatically terminate upon completion of Business Associate’s duties under all underlying Agreements or by termination of such underlying Agreements.
B. Termination Upon Review. This Agreement may be terminated by Covered Entity, at its discretion, upon review as provided by Section 9 of this Agreement.
C. Termination for Cause. In the event of a material breach of this Agreement by Business Associate, Covered Entity:
(1) Will provide Business Associate written notice of the material breach and an opportunity for Business Associate to cure the breach or end the violation within the reasonable time specified by Covered Entity and;
(2) May terminate this Agreement if Business Associate does not cure the breach or end the violation within the reasonable time specified by Covered Entity.
D. Effect of Termination. Termination of this Agreement will result in cessation of activities by Business Associate involving PHI under this Agreement.
E. Survival. The obligations of Business Associate under Section 3 above shall survive the termination of this Agreement as long as Business Associate creates, receives, maintains, or transmits PHI, regardless of whether a compliant Business Associate Agreement is in place.
7. No Third-Party Beneficiaries. Nothing expressed or implied in this Agreement confers any rights, remedies, obligations, or liabilities whatsoever upon any person or entity other than Covered Entity and Business Associate, including their respective successors or assigns.
8. Other Applicable Law. This Agreement does not abrogate any responsibilities of the parties under any other applicable law.
9. Review Date. The provisions of this Agreement will be reviewed by Covered Entity every two years from Effective Date to determine the applicability and accuracy of the Agreement based on the circumstances that exist at the time of review.
10. Effective Date. This Agreement shall be effective on the last signature date below.
Department of Veterans Affairs COMPANY/ORGANIZATION Veterans Health Administration <Insert Facility Name>
By: By:
Name: Name:
Title: Title:
Date: Date:
File details come from the government source that posted it. Updated .