36C77620Q0042-017.pdf

PDF Posted

Attached to
R408--National Data Systems (NDS) Federal contract opportunity
Solicitation number
36C77620Q0042
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This standard operating procedure outlines the process for approving requests in the Data Access Request Tracker system. Initial reviewers check documentation for completeness and determine required detailed reviews by privacy, security, and subject matter experts. Final reviewers verify all reviews are complete. Upon final approval, provisioning notifications are issued to authorize data access.

The related federal contract opportunity is for National Data Systems to provide continued support and maintenance of the Data Access Request Tracker and overall data access management program. Services include initial and final reviews, provisioning approvals, system administration, and coordinating with subject matter experts. The one-year base period of performance runs from 2020 to 2021 with option periods extending to 2025.

36C77620Q0042 S02 - Attachment I SOP for DART_Updated 08302018.pdf

View the file

Other files for this federal contract opportunity

Other files attached to R408--National Data Systems (NDS), newest first.
File Type Posted
36C77620Q0042-0001000.docx DOCX document
36C77620Q0042-008.pdf PDF
36C77620Q0042-018.pdf PDF
36C77620Q0042-010.pdf PDF
36C77620Q0042-019.pdf PDF
36C77620Q0042-016.pdf PDF
36C77620Q0042-014.pdf PDF
36C77620Q0042-013.pdf PDF
36C77620Q0042-012.pdf PDF
36C77620Q0042-009.pdf PDF
36C77620Q0042-015.pdf PDF
36C77620Q0042-011.pdf PDF
36C77620Q0042-007.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

August 2018

STANDARD OPERATING PROCEDURE

Processing Requests in the Data Access Request

Tracker

Revision History

Document Title: STANDARD OPERATING PROCEDURE

Processing Requests in the Data Access Request Tracker (DART)

Date Version Author Revision Description

10/29/2015 1 Kochi, Churchman, Wamsley

Initial Version

08/23/2018 2 Mark Molloy Updated Approval process and DART link

Table of Contents Revision History

PURPOSE

DEFINITIONS

RESPONSIBILITIES

PROCEDURES

1. Accessing DART Reviews

2. Initial Requests

3. Change Requests

4. Amendments

5. Sending for Additional Reviews

6. Complete NDS Final Review

7. Provisioning Access

STANDARD OPERATING PROCEDURE (SOP)

Processing Requests in the Data Access Request Tracker

PURPOSE

This Standard Operating Procedure (SOP) establishes the process/procedure for approving Data Access

Request Tracker (DART) Requests.

DEFINITIONS

• DART: Data Access Request Tracker (DART) application is a workflow application that guides data users through the process of requesting access to data and guides reviewers through the review process. It gathers and retains required information and documents, submitted by the requestor and makes them available to the appropriate reviewers. Reviewers receive notifications with links to the request to be reviewed and can approve them or request additional information or actions from projects. Email notices from reviewers are sent automatically to the requestor at each stage of the review process.

• Initial Review: Data Access Request Tracker (DART) controls the work flow needed to ensure that requests have been submitted with correct documentation and can be moved on to detailed review.

• Detailed Review: Data Access Request Tracker (DART) controls the process for obtaining detailed reviews/approvals from representatives from the following areas: VHA Security, VHA

Privacy, Office of Research and Development, Office of Public Health, Office of Research &

Development (ORD), Homeless Registry and CAPRI/Joint Legacy Viewer (JLV).

• Final Review: Data Access Request Tracker (DART) controls the work flow needed to ensure that requests have been approved by detailed review an can be given final approval and moved on to provisioning of the access or data.

RESPONSIBILITIES

❖ VHA National Data Systems (NDS):

• NDS will perform initial review and approve.

• NDS will determine requirements and need for detailed review(s).

• NDS will perform final review and approve.

• NDS will approve/authorize provisioning of access by AITC to mainframe files.

• NDS will provision access of CAPRI/JLV after HIG Authorization received

❖ VINCI Data Managers

• VINCI Data Managers will provide a data extract upon notification that NDS has given final approval.

PROCEDURES

1. Accessing DART Reviews

1. Log into DART: https://dart.vha.med.va.gov/vinci_dart_client/dart9/dashboard.html

2. Click on your “To-Do-List”

• NDS initial reviewer will utilize the DART NDS “To-Do List” for selecting which requests to attend to first. NDS reviews requests on a “First come first serviced” basis.

https://dart.vha.med.va.gov/vinci_dart_client/dart9/dashboard.html

2. Initial Requests

1. Once you click on the link to the request, under the “Information” tab, check the IRB expiration date and the End Date.

2. Click on the “History” Icon at the top right of the screen to review if the request has ever been seen by an NDS Initial reviewer.

• If it has, and was sent back to the submitter for changes, click on the

“Communication” Icon to see what changes were requested and if the submitter included additional information or asked questions.

3. Navigate to the “Participants” tab to review:

• Name and # of participants (this information will need to be cross checked against required documentation)

• Whether the participant is listed for Notifications only, Data Access or both

• The number of locations involved in the study

4. Navigate to the “Data” tab to review:

• The data sources being selected (this information will need to be cross checked against required documentation)

• Note storage location. If storing locally, a Security review is required

• If Real SSN is selected, note that an ORD review is required

• If Yes is selected for “Will data be transferred external to the VHA?” (DUA is required), note that a Security review is required.

• MCA, VSSC and Mainframe access (provisioned by NDS Initial Reviewer when the final request is approved)

• If CAPRI/JLV is selected (and new CAPRI request forms are included in the

‘Documents’ tab), a Privacy, ORD, and CAPRI/JLV review is required.

• If Homeless Registry is selected, Homeless Registry review is required.

5. Navigate to the “Documents” tab to review:

• Review all documents submitted and identify any deficiency using the DART “Add

Note” communication tool associated with each document. BE AS SPECIFIC AS

YOU CAN. For example, Requestors do not always know acronyms. Spell them out.

• Reviewer will set the “Review Status” to “Pending, Under Review, Waiting for

Information, or Complete” as appropriate.

• For each document, the Reviewer will need to look for the following:

• Research Request Memo

1. Check data sources to ensure they match those listed on the data sources tab in the DART application

2. Check to ensure that the participants listed match those listed on the

Participants tab requiring Data Access (remember, those only listed for notifications are not required to be listed)

i. Ensure participants are designated as VA Employees, WOC or

Contractors

ii. If requiring mainframe access, mainframe ID, NT user accounts and domain name are needed to provision access

iii. If Requiring VSSC and/or MCA Web Reports, NT username and domain are needed to provision access

3. Ensure the Description has been completed as to why they are requesting access.

4. Make sure security questions are answered for Security Review. These questions are required if the Requestor will be storing the data outside of the VINCI environment locally.

5. Check signatures. Ensure the following have signed

i. Principal Investigator

ii. Supervisor

6. Note any deficiencies using the DART “Add Note” communication tool

• Research Study Institutional Review Board (IRB) Approval letter

1. Check expiration date (Note: if data on memo is within the year, it is okay). If the IRB date is close to expiration, you can send the requestor a note as an FYI to be sure they come back and upload a new IRB letter.

2. Note any deficiencies using the DART “Add Note” communication tool

• Research and Development (RD) Committee Approval Letter

1. Check document is uploaded and no expiration date is indicated.

• IRB Approval of Waiver of HIPAA – Compliant Authorization

1. Check to ensure proper document is loaded

2. If CAPRI/JLV is a data source:

i. Determine if a mention of CAPRI is present and/or required.

Waivers that indicate specific data sources (like CDW) must also indicate the need for CAPRI/JLV access. Waivers without specific data sources do not. However, CAPRI/JLV must be mentioned in either the Waiver or Protocol if specific language is not mentioned in the HIPAA Waiver of Authorization

3. Note any deficiencies using the DART “Add Note” communication tool

*Multisite studies can go through the Central IRB, but it is not required.

• Research Protocol

1. Search the document to locate data sources being requested

2. If CAPRI/JLV is a data source:

i. If CAPRI/JLV is not mentioned in the Waiver, make sure it is mentioned in the protocol.

3. Note any deficiencies using the DART “Add Note” communication tool

• CDW Domain Checklist

1. Check to ensure the Checklist has either CDW Production or CDW

Raw domains selected. Those selected must match those on the checked on the data sources tab in the DART application.

2. Note any deficiencies using the DART “Add Note” communication tool

• Real SSN Access Request

1. Ensure correct document is loaded

2. Note any deficiencies using the DART “Add Note” communication tool

• Study Participants Documentation

1. Vital Status Rules of Behavior (VS ROB)

i. Ensure document is loaded.

ii. Make sure document is signed by the participant. Note: All participants must sign a VS ROB regardless of individual need for Vital Status data as this information is rolled up into the

VINCI extract file.

2. EHR Access Request Form

i. Ensure a document is loaded.

ii. If they do not require CAPRI/JLV access a document stating

“No access required” must be uploaded.

iii. Ensure the EHR forms are signed by the Requester, Principal

Investigator and Approving Authority.

iv. In signature blocks 22 and 23, note that these need to be completed by the Facility Chief of Staff or the ACOS of

Research

3. Note any deficiencies using the DART “Add Note” communication tool

6. Responding to Requestor with Changes

• NDS initial reviewer will notify the requestor of any deficiencies in the documentation and what changes are required by using the “Request Changes” function in DART.

Notes from the review should be copied and pasted into the “Request Changes” communication box.

3. Change Requests Requests that come back can either be Initial Reviews or Amendments

1. Review the Information on the “Information” tab

2. Review the communications and amendment narrative

3. Review the history tab

4. Check that all changes have been made that were requested

Note: Call individuals who have open requests for long periods of time to assist.

4. Amendments

1. Amendment Narrative needs to contain information on new staff, and other changes being requested

2. Check IRB expiration and make sure documents match

3. Look at participants tab

4. Look at Data tab

5. Documents – scroll to ensure all are complete. If something is marked as no status, review. If good, mark complete

i. Updated Memo

ii. If requesting Vital Status and/or CAPRI/JLV – additional documentation

6. Send to Privacy. If new CAPRI/JLV requests are included Send to ORD and CAPRI/JLV review as well

Note: Call individuals who have open requests for long periods of time to assist.

5. Sending for Additional Reviews Upon satisfactory initial review NDS initial reviewer will determine what detailed reviews are required and select the appropriate review on the “NDS Decision” Tab of DART and approve the initial review.

Please see DART Review Flow Chart on Appendix A for additional information.

New and Change requests:

• Privacy – Always reviews

• Security – If storage location is outside VINCI or DUA is required

• ORD – If Real SSN is requested

• OEF/OIF/OND - If Requested

• Homelessness - If requested

Amendments:

• Privacy – Always reviews

• Security – If storage location is outside VINCI or DUA is required and Security has not approved a previous amendment

• ORD – If Real SSN is requested and ORD has not approved a previous amendment

• OEF/OIF/OND - If Requested

• Homelessness - If requested

6. Complete NDS Final Review

1. NDS final reviewer will utilize the DART NDS “To-Do List” for selecting which requests to attend to first. NDS reviews requests on a “First come first serviced” basis.

2. NDS final reviewer will verify that all detailed reviews have been completed using the

“History” function of DART.

3. NDS final reviewer will re-review any documents that have been replaced as indicated by a change of the status associated with each document.

4. NDS final reviewer will notify the requestor of any deficiencies in the documentation using the “Request Changes” function in DART.

5. NDS final reviewer will obtain the signature of approving VHA NDS Official on the Data

Use Agreement, store the signed document on the NDS K: drive under Data Use Agreements using the Tracking Number and Last name of the Principal Investigator followed by DUA as the file name (ex 2013-01-001 Doe DUA).

6. NDS final reviewer will upload the signed copy into DART using the Admin Documents Tab in DART.

7. Provisioning Access

1. DART issues messages to the provisioning parties for CDW access however it does not send a provisioning message to the AITC for provisioning access to the mainframe.

2.

3. NDS final reviewer must send approving e-mail to the AITC authorizing the provisioning of the access. Details of the construct of this message are still in flux due to the implementation of the AITC ePAS system. NDS Final Reviewer must also provision access for and NSSD

(VSSC and MCA Web Reports).

4. Vinci Data Managers receive a DART generated message that final approval has been given.

They work with the requestor to generate a data extract that complies with the approval received. The extract can be used in the VINCI environment or on VA servers that are behind the VA firewall.

File details come from the government source that posted it. Updated .