36C77620Q0042-009.pdf

PDF Posted

Attached to
R408--National Data Systems (NDS) Federal contract opportunity
Solicitation number
36C77620Q0042
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This performance work statement outlines requirements for National Data Systems Health Information Access Services to be provided to the Department of Veterans Affairs. The contractor shall perform tasks including managing VHA user access, supporting data access requests and help desk functions, assisting with data sharing agreements and business associate agreement support. The contractor must adhere to all applicable VA policies and regulations regarding security, privacy, and information technology standards. The base period of performance is 12 months with four 12-month option periods. The contractor shall provide deliverables such as monthly status reports and Section 508 compliance test results.

36C77620Q0042 S02 - Attachment A PWS _HIG20-25 NDS HIA Services.pdf

View the file

Other files for this federal contract opportunity

Other files attached to R408--National Data Systems (NDS), newest first.
File Type Posted
36C77620Q0042-0001000.docx DOCX document
36C77620Q0042-015.pdf PDF
36C77620Q0042-011.pdf PDF
36C77620Q0042-007.docx DOCX document
36C77620Q0042-010.pdf PDF
36C77620Q0042-019.pdf PDF
36C77620Q0042-008.pdf PDF
36C77620Q0042-018.pdf PDF
36C77620Q0042-017.pdf PDF
36C77620Q0042-016.pdf PDF
36C77620Q0042-014.pdf PDF
36C77620Q0042-013.pdf PDF
36C77620Q0042-012.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PerformanceWorkStatementTemplate_FEB_21_2018

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Office of Health Informatics (OHI)

Health Information Governance (HIG) National Data Systems (NDS)

National Data Systems (NDS) Health Information Access (HIA) Services

HIG20-25

Date: 11/14/2019 PWS Version Number: 1.3

NDS HIA Services

Contents

1.0 BACKGROUND

2.0 APPLICABLE DOCUMENTS

3.0 SCOPE OF WORK

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

4.2 PLACE OF PERFORMANCE

4.3 TRAVEL

5.0 SPECIFIC TASKS AND DELIVERABLES

5.1 VHA User Access Management and Support

Data Access Requests Help Desk Support (OPTIONAL TASK)

Data Sharing Agreements (OPTIONAL TASK)

Historical/Projected Workload Data:

5.2 Business Associate Agreement (BAA) Support

5.3 Reporting Requirements

6.0 GENERAL REQUIREMENTS

6.1 KEY PERSONNEL

6.2 ENTERPRISE AND IT FRAMEWORK

ONE-VA TECHNICAL REFERENCE MODEL

FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT

(FICAM)

INTERNET PROTOCOL VERSION 6 (IPV6)

TRUSTED INTERNET CONNECTION (TIC)

STANDARD COMPUTER CONFIGURATION

VETERAN FOCUSED INTEGRATION PROCESS (VIP)

PROCESS ASSETT LIBRARY (PAL)

6.3 SECURITY AND PRIVACY REQUIREMENTS

POSITION/TASK RISK DESIGNATION LEVEL(S)

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

6.4 METHOD AND DISTRIBUTION OF DELIVERABLES

6.5 PERFORMANCE METRICS

6.6 FACILITY/RESOURCE PROVISIONS

6.7 GOVERNMENT FURNISHED PROPERTY

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM

SECURITY/PRIVACY LANGUAGE................................. Error! Bookmark not defined.

1.0 BACKGROUND

National Data Systems (NDS) is responsible for ensuring that access to health information is managed in accordance with VA policy and Federal law, including the Privacy Act of 1974, http://www.justice.gov/opcl/privstat.htm and the Health Insurance Portability and Accountability Act (HIPAA) http://www.hhs.gov/ocr/privacy/. NDS is located within Veterans Health Administration (VHA) Office of Informatics Health Informatics (OHI) Health Information Governance (HIG). NDS manages the development and implementation of policy, regulation, and training around individuals accessing health information.

NDS manages all national health information data access requests as well as data queries and supports the reporting of VHA health information access, file extracts, Data Use Agreements (DUAs), Business Associate Agreements (BAAs) and other related data access agreements. http://www2.va.gov/directory/guide/division_flsh.asp?dnum=1

NDS responds to multiple requests for access to many of VHA’s health information systems, including Electronic Health Records (EHRs), national databases, and extracted datasets. The goal of NDS is to provide those who serve Veterans, proper access to the informational resources they need, while always maintaining the privacy and security of Veterans’ health information. Access may be required on a temporary or long-term basis.

NDS is the central program for managing, tracking and approving all VHA data access requests to many of VHA’s health information resources. NDS approves user access to national data which contains Personal Health Information (PHI) to include the Veteran’s social security number. NDS fulfills requests from VHA health information resources to various Government customers including, but not limited to, clinicians, program offices, researchers, government oversight organizations. Non-Government customers include but are not limited to Veteran Service Organizations (VSO) access in order to advocate for Veterans with their claims for benefits. NDS is involved in data access activities and initiatives which manage the development and implementation of policy, regulation, training and the evaluation and monitoring of trending, and reporting on data access performance.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. “Federal Information Security Modernization Act of 2014”

2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

3. FIPS Pub 199. Standards for Security Categorization of Federal Information and Information Systems, February 2004

4. FIPS Pub 200, Minimum Security Requirements for Federal Information and Information Systems, March 2016

5. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

6. 10 U.S.C. § 2224, "Defense Information Assurance Program"

7. Carnegie Mellon Software Engineering Institute, Capability Maturity Model®

Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information

Technology Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

12. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

14. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility

Standards,” July 1, 2003

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)”

17. An Introductory Resource Guide for Implementing the Health Insurance

Portability and Accountability Act (HIPAA) Security Rule, October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7,

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “Managing Information Security Risk: VA Information

Security Program,” September 20, 2012

21. VA Handbook 6500, “Risk Management Framework for VA Information

Systems – Tier 3: VA Information Security Program,” March 10, 2015

22. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

23. VA Handbook 6500.2, “Management of Breaches Involving Sensitive

Personal Information (SPI)”, July 28, 2016

24. VA Handbook 6500.3, “Assessment, Authorization, And Continuous

Monitoring of VA Information Systems,” February 3, 2014

25. VA Handbook 6500.5, “Incorporating Security and Privacy in System

Development Lifecycle”, March 22, 2010

26. VA Handbook 6500.6, “Contract Security,” March 12, 2010

27. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs

28. OI&T Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

32. VA Handbook 6510, “VA Identity and Access Management”, January 15,

33. VA Directive 6300, Records and Information Management, February 26,

34. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

35. NIST SP 800-37, Guide for Applying the Risk Management Framework to

Federal Information Systems: A Security Life Cycle Approach, June 10,

36. NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations, January 22, 2015

37. OMB Memorandum, “Transition to IPv6”, September 28, 2010

38. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, October 26, 2015

39. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12)

Program, March 24, 2014

40. OMB Memorandum M-06-18, Acquisition of Products and Services for

Implementation of HSPD-12, June 30, 2006

41. OMB Memorandum 04-04, E-Authentication Guidance for Federal Agencies, December 16, 2003

42. OMB Memorandum 05-24, Implementation of Homeland Security

Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

43. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3,

44. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

45. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

46. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008

47. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

48. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, Digital Identity Guidelines, June 2017 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx

49. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014

50. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile

Devices (Draft), October 2012

51. Draft National Institute of Standards and Technology Interagency Report

(NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

52. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland

Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

53. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

54. VA Memorandum “Mandate to meet PIV Requirements for New and Existing Systems” (VAIQ# 7712300), June 30, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

55. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

56. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

57. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

58. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

59. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

60. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

61. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015

62. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

63. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

64. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

65. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote

Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

66. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

67. VA Memorandum, “Implementation of Federal Personal Identity Verification

(PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

68. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

69. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;

https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

70. “Veteran Focused Integration Process (VIP) Guide 2.0”, May 2017, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

71. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

72. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

73. VA Memorandum “Use of Personal Email (VAIQ #7581492)”, April 24, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

74. VA Memorandum “Updated VA Information Security Rules of Behavior (VAIQ #7823189)”, September, 15, 2017,

3.0 SCOPE OF WORK

The Contractor shall provide all labor, supervision and other resources required to deliver professional and technical services, to the NDS Program Office. These services include support for VHA health information user access management, and support for the Business Associate Agreement program.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The period of performance shall be a twelve (12) month base period, with four (4) twelve (12) month option periods.

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).

There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

If any of the above falls on a Saturday, then Friday shall be observed as a holiday.

Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

4.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed at Contractor facilities.

Work may be performed at government site with prior approval of the Program Manager and Contracting Officer. Government onsite space is limited to one space at VACO in Washington, DC.

a) Hours of service - Contractor shall provide service during normal business hours from 8:00 A.M. to 4:30 P.M. local time, Monday through Friday.

In addition, TDY to a Government facility within the effort doesn’t change the Place of Performance to the Government Site.

4.3 TRAVEL

Occasional travel shall be required. Travel costs shall be included as a separate, direct reimbursable, “not to exceed” line item.

The contractor must obtain written approval from the VA PM (or the designated back-up when the VA PM is out of the office) before any travel begins, utilizing Attachment N, Travel Authorization Request in Section D of solicitation. Travel and per diem expenses shall be approved and paid on an actual expenditure’s basis in accordance with Federal Travel Regulations and FAR 31.205-46. Travel that occurs without written pre-approval shall NOT be reimbursed. The contractor MUST use Attachment N for travel pre-approval. Other documents or e-mails shall NOT be accepted as pre-approval.

In order to be paid for travel, the contractor shall submit supporting documentation as required by Federal Travel Regulations with invoices. Federal Travel Regulations require receipts for travel expenditures of $75.00 or more. Expenses for subsistence and lodging shall be approved and paid to the contractor only to the extent where an overnight stay is necessary and authorized by Federal Travel Regulations in effect at the time of the stay for the specific location. Additional information can be found at:

http://www.gsa.gov/portal/category/21287 http://www.gsa.gov/portal/category/21287

An estimation of travel requirements is listed below. This estimation should be used in developing the travel price quote by the contractor. Please note that locations may be subject to change.

Travel detail Base

Location trips staff

East Coast VAMCs (Bay Pines, FL) 1 1

Austin Info Tech Center (Austin, TX) 1 1

2 2

Travel detail Option Yr. 1

East Coast VAMCs (Bay Pines, FL) 1 1

Travel detail Option Yr. 2

East Coast VAMCs (Bay Pines, FL) 1 1

Travel detail Option Yr. 3

East Coast VAMCs (Bay Pines, FL) 1 1

Travel detail Option Yr. 4

East Coast VAMCs (Bay Pines, FL) 1 1

Contractor travel within the local commuting area will not be reimbursed.

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the mandatory tasks and provide the specific deliverables described below within the performance period stated in this Performance Work

Statement. If for any reason, any deliverable cannot be delivered on time according to the below schedule, the Contractor shall provide a written explanation to the Program Manager, Contracting Officer Representative and Contracting Officer as soon as discovered, but not later than three days prior to deliverable due date. This written transmittal shall include a firm commitment of when the work shall be completed. This transmittal shall cite the reasons for the delay, and the impact on the overall project.

5.1 VHA User Access Management and Support

The Contractor shall manage regional (Veteran Integrated Service Networks – VISNs) and national access to VHA health information resources. These services include: data access requests, help desk support, data access process support, and data sharing agreements.

NDS customers include, but are not limited to, clinicians, researchers, peer reviewers, legal reviewers, GAO, Veteran Service Organizations (VSO).

The Contractor shall be involved in information gathering and documentation development related to VHA data access. The Contractor shall assist with continuous improvement of existing processes and tools for VHA data access on a quarterly basis.

The Contractor shall assist NDS in managing new initiatives or innovations that improve how VA processes VHA Data Access requests, which is driven by customer need. At a minimum, supervisory and/or lead Contractor staff shall regularly participate in all designated weekly, monthly, and ad hoc staff, workgroup, and access-related meetings and/or conference calls.

Data Access Requests (An option CLIN with additional quantities will be included in the schedule).

The contractor shall review all data access requests to ensure all required paperwork has been submitted and meets VHA policy requirements for data access approval. The Contractor shall be responsible for all processes in the provisioning of access to VHA data based on the data sources requested and enter the requests into a VA developed tracking system. All data access requests shall involve customer service-based interaction, with timely feedback to end users about status of request, missing documentation, and when the researcher may expect data after request is approved. Contractor must complete all requests within three business days from the date of receipt and comply with the standard operating procedures (SOP).

Refer to the associated standard operating procedures for additional detail.

Reference Attachments:

Attachment B - SOP BAA Management 2018 Attachment C – BAA Management Checklist Attachment D - DUA Template Non-Federal Protected Attachment E - DUA Template Federal Protected Attachment F - DUA Template LDS Federal

Attachment G - DUA Template LDS Non-Federal Attachment H - SOP Healthcare Operations Access (HOA) Requests 7.2018 Attachment I - SOP Power of Attorney (POA) 3.2015 Attachment J - SOP Research Requests DART 7.24.15

In support of ensuring adherence to NDS User Access Management processes, the Contractor shall conduct a quality assurance review daily to ensure appropriate access administration was completed accurately and in accordance with standard operating procedures.

The contractor shall be required to compile monthly, quarterly, and annual statistics of user demographics and frequency of requests seeking special access to VA health information resources. The Contractor shall track all open, closed and pending actions taken in existing VA system or platform under this task.

Help Desk Support (OPTIONAL TASK)

This task is identified as an optional task and contingent upon the availability of funding.

The contractor shall provide second-tier help desk support assistance to the established Enterprise Service Desk (ESD) for managed access. The contractor shall do the following immediately upon receipt but not to exceed one business day:

- Log help-desk tickets into the appropriate existing workload management tracking system.

- Respond to email and phone inquiries from the ESD Helpdesk or customer.

- Provide user training associated with access applications (Training is typically regarding how to complete the request form and/or step-by-step instructions for logging in to use requested access, once granted. This is typically adhoc and PowerPoint driven.)

Second Tier Support includes software troubleshooting Examples of Support Tickets:

Tier Two Support Tickets:

• CAPRI Mailbox inquiries

• CAPRI upgrade

• Connectivity Issues

• Modify Menus in CLAIMS (CAPRI)

• Modify Security Key(s) in CLAIMS (CAPRI)

• Invalid Pointer Operation (via CAPRI)

Data Sharing Agreements (OPTIONAL TASK)

This task is identified as an optional task and contingent upon the availability of funding.

VHA has the need to create various data sharing agreements with external organizations to enable the sharing of data both by VHA receiving and providing data.

NDS serves as a centralized collection point for all data sharing agreements and assists with the process of creating the agreement by consulting with the VHA business unit.

The contractor shall review documentation, consult with customers, and monitor VHA data sharing agreements between VHA data owners and data users that require specific data sets to complete a final data sharing agreement. This will be accomplished by referring to and following established policy, practices, and templates. The tracking of the agreements will be done with VA provided tools and systems. The VA will provide current templates for the sharing agreements upon award. Refer to attachments D, E, F, and G (DUA Handbook, DUA Template Non-Federal Protected, DUA Template Federal Protected, DUA Template LDS Federal, DUA Template LDS Non-Federal) as samples.

The types of data sharing agreements are as follows:

Name Description

Data Use Agreement

(DUA)

DUAs govern the sharing of sensitive data between a Data Owner and a Requestor external to the VA. This written agreement establishes the specific terms for VA and non-VA Requestor uses, and provides a means to transfer liability for the protection of the information to an outside party.

Data Use and Reciprocal Support Agreement

(DURSA)

A comprehensive, multi-party trust agreement that will be signed by all Nationwide Health Information Network (NHIN) Health Information Exchanges (NHIE), both public and private, wishing to participate in the Nationwide Health Information Network. The DURSA provides the legal framework governing participation in the NHIN, by requiring the signatories to abide by a common set of terms and conditions. These common terms and conditions support the secure, interoperable exchange of health data between and among numerous NHIEs across a diverse set of public and private entities across the country.

Memorandum of Agreement (MOA)

A written agreement between parties to cooperatively work together on an agreed upon project, or to meet or accomplish an agreed objective.

The purpose of an MOA is to have a written understanding of the agreement between parties.

Memorandum of Understanding (MOU)

A document established between two or more parties to define their respective responsibilities in accomplishing a particular goal or mission.

MOUs are generally recognized as binding, even if no legal claim could be based on the rights and obligations outlined in these agreements.

Standing Written Request Letter (SWRL)

A written request to VHA from specific agencies, such as public law enforcement, public health departments, state cancer registries, and other agencies which require information disclosure from VHA, based on established statute (some statutes require mandatory reporting).

Standing Written Request Letters are updated every three years

Historical/Projected Workload Data:

Provided below is a chart identifying projected data of volume of requests for each task 1 workload category. This information is based on reporting matrix within the organization.

This information is provided as data to be utilized for information purpose only. Some contract staff below are cross utilized within multiple workload categories.

NDS Workload Projections

PoP Contract Resource

Workload Category PoP May 2019– Apr 2020 (in progress)

Base Year Projections Option Year 1 Projections

.5 HealthCare Ops 5700 6000 6300

.5 CAPRI/Joint Legacy Viewer 2600 2700 2800

.5 Power of Attorney 24000 23000 23000

1 Research 2340 2500 2550

.5 Helpdesk Support

(designated as an Optional Task)

Data Sharing Agreements

(designated as an Optional Task)

Deliverables 5.1:

Contractor shall provide a monthly status report of VHA User Access Management tasks and documentation support to include the quantities for each workload category. This report shall contain:

• NDS User Access Management Status of open, closed and pending requests for each workload type

• All open, closed and pending actions taken during the Quality Assurance Review

• All open, closed, and pending actions on Help Desk Support items

• Tracking of VHA Data Sharing Agreements

• Status of pending and completed VHA data sharing agreements

• Log of attended meetings/conference calls Deliverable 5.1.1 (Quantities for each):

A. Healthcare Ops Access requests B. CAPRI/Joint Legacy Viewer C. Power of Attorney D. Research

Deliverable 5.1.2 Optional (Quantities):

A. Helpdesk Support (Tier 2 tickets only)

Deliverable 5.1.3 Optional (Quantities):

A. Data Sharing Agreements

Due Date: Monthly for twelve (12) months from date of award

5.2 BUSINESS ASSOCIATE AGREEMENT (BAA) SUPPORT (AN OPTION

CLIN WITH ADDITIONAL QUANTITIES WILL BE INCLUDED IN THE

SCHEDULE).

The Contractor shall provide administrative support to the VHA Business Associate PM.

The Contractor shall provide the updated status in response to email and telephone inquiries regarding the progression of each Business Associate Agreements (BAA) action. These actions include the initial vendor questionnaire step, scoring the risk analysis worksheet, acquiring appropriate signatures (Business Associate and VHA), scanning completed agreements and archiving (upload into database). The contractor shall assist with managing and updating the BAA databases. Reference Section D, Attachment B, SOP BAA Management. NDS currently has approximately 365 active BAAs in the database.

The contractor shall attend weekly BAA status meetings via phone with the VHA Business Associate Agreement PM.

Task 5.2 Historical/Projected Data:

Based on historical data, the Government estimates that one (1) FTE can support the following BAA transactions. Note: During the Period of Performance (PoP) March 2017 through February 2018 the following transactions were completed. This historical data is based on available PoP data with the understanding that transactions can fluctuate.

BAA Transaction Description

PoP May 2019 – Apr 2020

Base Year Projection

Totals

Option Year 1 Projection

Totals

BAAs Reviewed 180 200 210

BAAs Executed 15 15 20

BAAs Terminated 10 10 10

Deliverables 5.2:

Contractor shall provide a monthly status report of BAA Support to include the quantities for each BAA action. The Business Associate PM will review and validate data input against information contained in the BAA Tracker. This report shall contain:

A. BAAs Reviewed (quantities) B. BAAs Executed (quantities) C. BAAs Terminated (quantities)

Support for each BAA transaction includes the following administrative tasks and are consistent for each BAA transaction:

• Emailing clients with attachments to include Business Associate Profile Questionnaires, draft BAAs, final BAAs, partially executed Business Associate Agreement Termination Letters and fully executed Business Associate Termination Letters

• Follow up status emails to clients

• Emailing Business Associate Agreement PM with attachments to include Business Associate Profile Questionnaires, draft BAAs, final BAAs, partially executed Business Associate Agreement Termination Letters and fully executed Business Associate Termination Letters

• Phone calls to clients for status updates

• Scoring the Business Associate Risk Analysis Worksheet

• Updating the BAA Tracker

• Updating the network drive BAA folders

Due Date: Monthly for twelve (12) months from date of award.

5.3 Reporting Requirements

The Contractor shall provide the PM and COR with Monthly Progress Reports in electronic form in Microsoft Word. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved.

If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The Contractor shall monitor performance against the PWS and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues. The contractor shall notify the PM, COR, and CO in writing if problems arise that could adversely impact the performance of the task order.

The contractor shall take minutes of all formal conference calls and/or meetings held with the PM. Copies of these minutes shall be attached to the monthly progress report.

Monthly progress reports shall contain, but are not limited to, the following:

• Status summary

• Change request status (new, open, closed since last report)

• Issue status (new, open, closed since last report)

• Schedule status

• Minutes of status meetings

• Contractor staff roster (providing updates as they occur, including personnel and security requirements)

• Status of required background investigations

Deliverables 5.3:

Monthly Progress Report. Due the fifth (5th) business day of each month

6.0 GENERAL REQUIREMENTS

6.1 KEY PERSONNEL

The following minimum standards shall apply for personnel performing under this contract and shall be maintained throughout the life of the contract.

A. Program Assistant Functional Responsibilities:

Provide administrative support to the VHA Business Associate Program Manager. Provide the updated status in response to email and telephone inquiries regarding the progression of each Business Associate Agreements (BAA) action. These actions include sending and receiving profile questionnaires, scoring the risk analysis worksheet, drafting BAAs, acquiring appropriate signatures (Business Associate and VHA), annotating communications between VHA and business associate. The contractor shall assist with managing and updating the BAA databases.

Minimum Experience/Education:

Possess at least a 2-year degree in business, administration, office automation or healthcare related fields, with preferred background and/or training in the Health Insurance Portability and Accountability Act (HIPAA) business associate provisions.

B. Program Analyst Functional Responsibilities:

Possess and be able to apply expert level knowledge of research, the use of data for research, and research methodologies to the review and approval process for applicable VHA data access requests. Using analytical ability, provide professional and thorough written and/or verbal communications in response to email and telephone inquiries regarding the approval process and any identified deficiencies that may exist within a request. These actions include collaborating with other entities identified in the approval process;

reviewing submitted documentation and applying scrutiny in accordance with applicable policy, procedures, and guidance; acquiring appropriate approvals;

and annotating communications and status within identified applications. The contractor shall assist with managing, updating, and identifying business requirements for the applicable tools used in the approval process.

Minimum Experience/Education:

Possess at least a 2-year degree in business, administration, office automation or healthcare related fields, with a minimum of 2 years’ experience in the Health Insurance Portability and Accountability Act (HIPAA) and Privacy Act of 1974.

6.2 ENTERPRISE AND IT FRAMEWORK

ONE-VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (One-VA TRM). One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications.

One-VA TRM includes the Standards Profile and Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and Design (ASD) has overall responsibility for the One-VA TRM.

FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M- 05-24, and M-11-11 can be found at:

http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11- 11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems.

https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846

2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2005/m05-22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet), the Technical Infrastructure for USGv6 Adoption (http://www-x.antd.nist.gov/usgv6/index.html), and the NIST SP 800 series applicable compliance (http://csrc.nist.gov/publications/PubsSPs.html) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g.

web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.

STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Microsoft Office 2010. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Office 365 ProPlus and Windows 10. However, Office 365 ProPlus and Windows 10 are not the VA standard yet and are currently approved for limited use during their rollout, we are in-process of this rollout and making them the standard by OI&T. Upon the release approval of Office 365 ProPlus and Windows 10 individually as the VA standard, Office 365 ProPlus and Windows 10 will supersede Office 2010 and Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet https://www.nist.gov/programs-projects/usgv6-technical-basis-next-generation-internet http://www-x.antd.nist.gov/usgv6/index.html http://www-x.antd.nist.gov/usgv6/index.html http://csrc.nist.gov/publications/PubsSPs.html https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

VETERAN FOCUSED INTEGRATION PROCESS (VIP)

The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products

PROCESS ASSETT LIBRARY (PAL)

The Contractor shall utilize PAL, the OI&T-wide process management tool that assists in the execution of an IT project (including adherence to VIP standards). PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards or guides to assist project teams in facilitating their VIP compliant work.

6.3 SECURITY AND PRIVACY REQUIREMENTS

It has been determined that protected health information may be disclosed or accessed and a signed Business Associate Agreement (BAA) shall be required. The Contractor shall adhere to the requirements set forth within the BAA, referenced in Section D of the contract, and shall comply with VA Directive 6066.

POSITION/TASK RISK DESIGNATION LEVEL(S)

https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number Tier1 / Low Risk Tier 2 / Moderate Risk

Tier 4 / High Risk

5.1

5.2

5.3

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

b. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .