36C77620Q0042-018.pdf
PDF Posted
- Attached to
- R408--National Data Systems (NDS) Federal contract opportunity
- Solicitation number
- 36C77620Q0042
About this file
This standard operating procedure outlines the process for provisioning access to National Data Systems (NDS) Healthcare Operations data sources. It describes responsibilities for reviewing and processing access requests, provisioning different data sources including the Clinical Data Warehouse, VSSC systems, mainframe files, and OEF/OIF/OND rosters. The procedure details creating tickets for approved, returned, and rejected requests in the Alexsys system and notifying requestors. It also provides templates for provisioning mainframe access through the Austin Information Technology Center and notifying staff about OEF/OIF/OND roster requests. Appendices include step-by-step processes for provisioning specific data sources, inactivating accounts, and handling CAPRI/VistAWeb access according to the separate SOP for those systems.
The related federal contract opportunity is solicitation number 36C77620Q0042 for the National Data Systems contract. As no further detail is provided, the type of products or services required under the contract cannot be determined from this information.
36C77620Q0042 S02 - Attachment J - WRO0000.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C77620Q0042-0001000.docx | DOCX document | |
| 36C77620Q0042-008.pdf | ||
| 36C77620Q0042-010.pdf | ||
| 36C77620Q0042-019.pdf | ||
| 36C77620Q0042-017.pdf | ||
| 36C77620Q0042-016.pdf | ||
| 36C77620Q0042-014.pdf | ||
| 36C77620Q0042-013.pdf | ||
| 36C77620Q0042-012.pdf | ||
| 36C77620Q0042-009.pdf | ||
| 36C77620Q0042-015.pdf | ||
| 36C77620Q0042-011.pdf | ||
| 36C77620Q0042-007.docx | DOCX document |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Monday, December 14, 2015
STANDARD OPERATING PROCEDURE
Processing NDS Healthcare Operations Access
Requests
March 2015
Revision History
Document Title: STANDARD OPERATING PROCEDURE for processing NDS
Healthcare Operations Access Requests
Date Version Author Revision Description
10/15/2013 V.2 Tesa Kochie /
Mark Molloy
Added text for SAS Grid provisioning notification (#3). Removed the requirement to attach form to notification email (#4). When returning the request, changed it where you copy the email to the ticket (#10).
11/6/2013 V.3 Mark Molloy Added text to address how to process duplicate requests (#22). Modified Returned Request process based on changes made in Alexsys
(#14).
02/03/2014 V.4 Mark Molloy Added text to address adding returned reasons for each returned ticket.
9/3/2014 V.5 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Armando, Aaron, Lynn, Irma)
9/15/2014 V.6 Linda Hudock Updated SOP to include CDW Special Project data
11/14/2014 V.7 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Lynn, Irma)
11/25/2014 V.8 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Lynn, Irma)
12/4/14 V.9 Mark Molloy Incorporated ePAS to the SOP.
3/4/15 v.10 Cindy Wamsley, Abigail
Churchman, Tesa
Kochie
Cleaned up content and formatting
3/25/2015 V. 11 Tesa Kochie Added CDW Authorization SOP
5/11/2015 V. 12 Tesa Kochie Updated contact info for OEF/OIF/OND and
Alexsys Field Modifications.
12/14/2015 V. 13 Abigail
Churchman
Updates throughout
Table of Contents Revision History
PURPOSE
RESPONSIBILITIES
PROCEDURES
1. Review Electronic Permissions Access System (ePAS) Request Form
2. Provision Access According to Data Source Selected
3. Send Approval/Notification Email:
4. Create Alexsys Ticket
5. Approve/Return/Reject ePAS form
Appendix A - Provisioning Access Processes
A. CDW Processing Steps
Edit Existing Customer
Add New Customer
Add Customer Event
Inactivating a CDW Account
B. VSSC Processing Steps
Add New Customer
Edit Existing Customer
Inactivate NSSD Account
C. Mainframe Processing Steps
D. OEF/OIF/OND Processing Steps
E. CAPRI/VistAWeb Processing Steps
STANDARD OPERATING PROCEDURE
Processing NDS Healthcare Operations Access Requests
PURPOSE
This SOP establishes the process/procedure for processing National Data Systems (NDS)
Healthcare Operations access requests. There will always be exceptions to the standards set forth in this SOP. These situations should be handled in a manner that is suitable for the particular situation and with advice and guidance from appropriates sources (i.e., senior staff or management) as necessary.
RESPONSIBILITIES
NDS
• NDS staff will review submitted requests for accuracy and completeness.
• NDS staff will process each request.
• NDS staff will send a notification email when the request has been processed.
• NDS staff will forward mainframe SAS data requests to the AITC for processing.
• NDS staff will forward OEF/OIF/OND data access requests to OPH for processing.
• NDS staff will enter an Alexsys ticket for each request received.
Austin Information Technology Center (AITC)
• AITC help desk staff will create a ticket and assign the ticket to provision mainframe data access for the requestor.
Office of Public Health (OPH)
• OPH will approve and provision OEF/OIF/OND roster access to the requestor.
Office of the Inspector General (OIG)
• OIG staff will ensure that all OIG requests for access are signed by an OIG ISO.
PROCEDURES
1. Review Electronic Permissions Access System (ePAS) Request Form
When an ePAS form is ready for review, an ePAS notification is send directly to a reviewer’s form VA email account and to NDS.OperationalAccessRequests@va.gov.
You can access the ePAS from via the ePAS link and view all entries under ‘Approval’ for your queue at https://epas.r02.med.va.gov/ or by opening the ePAS form by clicking the link in the automated email alert.
Review the ePAS form for the following:
• Full Legal Name*
• Job Title*
• Email Address *
• Active Directory Name with Domain*
• Work Number*
• Employee Agency
• Employee Type
• Contractor Name (if applicable)
• Contractor Business Address (if applicable)
• Station Number
• Supervisor Name and Email
• ISO Name and Email
• Purpose of Use (as selected)
• Data Sources (as selected)
• Duration of Access
• Duration of Access Termination Date (if applicable)
• Acknowledgement
• If Mainframe access is being requested, verify that the requestor (1) has a valid
CUPS/TSO account that (2) displays the Functional Task Codes (FTCs) requested in the ePAS access request form.
• Signatures: Ensure ePAS form is signed by the appropriate personnel*
• “Vital Status – Scrambled”: When selected, ensure that the “Vital Status Rules of
Behavior” tab is completed. The Rules of Behavior page must not be separated from the ePAS form.
* Denotes auto-populated though the Active Directory look-up.
NOTE: NDS Ops Staff should not process any VHA NDS ePAS forms for OIG Staff unless one of the following four individuals has signed as the Information Security
Officer (ISO):
• Jim Laky, OIG ISO
• Jeremy Shifflett, OIG Deputy ISO
• Mick Vu, OIG Deputy CIO
• Justin Black, OIG CIO
2. Provision Access According to Data Source Selected.
Steps for provisioning access to the following are located in Appendix A.
A. CDW Provisioning Steps
B. VSSC Provisioning Steps
C. Mainframe Processing Steps
D. OEF/OIF/OND Processing Steps https://epas.r02.med.va.gov/
E. CAPRI/VistAWeb Processing Steps
3. Send Approval/Notification Email:
• Respond to the ePAS email notification notifying the requestor, supervisor, and
ISO that access has been authorized. (To correctly format the text go to Format
Text tab and select HTML, instead of Plain Text)
• Choose the correct email template below to populate the body of the email, based on the data sources that were requested.
• Email is copied into Alexsys ticket
VSSC email Template
This operational access request has been authorized by National Data Systems for
VSSC per your attached ePAS request.
If you have any difficulty obtaining protected data in any VSSC/DSS web product, contact the VSSC help desk at https://help.vssc.med.va.gov (choose Data Access as the
Program Area). Neither NDS nor the AITC help desk provides help desk support for
VSSC/DSS products.
CDW email Template
This operational access request has been authorized by National Data Systems for CDW per your ePAS request.
For further instructions for CDW access, follow the link to the CDW Support site then click
“CDW Guide: Introduction and Policies” under Guides in the left-hand navigation pane.
Please allow several hours for the changes to update throughout the network before requesting
CDW Support (although it may not take that long to update). After reviewing the CDW support web link, if more immediate action in necessary, please contact the Austin National
Service Desk via telephone at 855-NSD-HELP (855-673-4357), option 5, or via this web link http://vaww.aac.va.gov/servicedesk.
VINCI Staff: [Requestor Name] is authorized use of the SAS Grid.
NOTE: If SAS Grid Application is requested, add matt.s.smith@va.gov to the email string.
**Please see Mainframe and OEF/OIF/OND Roster section for appropriate email thread.
4. Create Alexsys Ticket
To create an Alexsys ticket:
1. Login to Alexsys at: http://vhahachiaprod/teamweb/teamweb.dll/
2. Login with VA network username and password
3. Click the New tab
Returned and Rejected Tickets
For returned (including rejections) requests, select the NDS Healthcare Operation
Returned Request form on the Select Work Request Type window and complete the following required fields:
• Title field to include requestor Last name, First name
• Station Number
• ePAS ID Number
• Reason for Return
• Copy the entire returned/termination ePAS reason and paste into the Description section of Alexsys.
• If Rejecting the ePAS request, select the Rejected check box
• If creating a return ticket, change status to Open and put yourself as owner.
Change status to Returned once you have received the correctly modified form
(and relate the NDS ops ticket to the returned ticket). If the form must be returned multiple times, keep the ticket open until the form has been corrected and include a note every time the form is returned.
• Select the reason for Return
• Select the Data Sources that were requested
• *Date Form Submitted to NDS (Date the ISO Signed the Request)
• Click the Save icon
• Click Close to close the Alexsys ticket
Approved requests
For approved requests, select NDS Healthcare Operations on the Select Work Request
Type window and complete the following fields:
• Title field – Requestor’s Last Name, First Name
• *Station Number
• Employee Type
• *AD Domain/Username
• *ePAS ID Number
• *Purpose of Use
• *Date Form Submitted to NDS (Date the ISO Signed the Request)
• Enter in the appropriate data sources requested for the submission
• Close Date (This field will auto populate when to the *Status field is Completed and the ticket is saved.)
• Open Date (This field auto populates when the ticket is opened.)
Commented [RMG1]: This should be step 5
1.Email is received in outlook mailbox from ePAS 2.If the request has CAPRI/VistAWeb processor will need to select “yes” or “No” to indicate whether it will be going for additional NDS authorization (to Angel)
3.Access is provisioned 4.Email notification is sent to requester
5.Amy approves in ePAS
6.Abagail enters Alexsys ticket
-On occasion a request in ePAS may be closed a day after the email notification is sent. The Alexsys ticket is only closed after the notification is sent and the request is closed in ePAS. The
Close Date of the Alexsys ticket will always be the date it was closed in ePAS.
http://vhahachiaprod/teamweb/teamweb.dll/
• *Mainframe ID (if applicable)
• *Local CUPS POC email (If Mainframe selected)
• Duration of Access (choose only one)
• Date Access Terminated (if applicable)
• Copy the entire approval email should be pasted into the Description section of
Alexsys including the
• Click the Save icon
• Click Close to close the Alexsys ticket
5. Approve/Return/Reject ePAS form
Approving ePAS Form
• Select Approve in the header or footer of the form
• Sign the form with your network credentials or PIV badge
Returning ePAS Form
• Select Send the Document Back in the header of the form
• Select to whom the form should be returned
• Enter the reason the form should be returned
NOTE: Request forms are returned/sent back if additional information is required or something within the form needs to be changed prior to authorization.
NOTE: OIG forms are returned if they are not signed by one of the above individuals. Email should be sent to jim.laky@va.gov and Jeremy.shifflett@va.gov. OIG staff are exempt from verifying training requirements per OIG Access policy.
Rejecting ePAS Form
• Select Reject in the header or footer of the form
• Provide a reason for rejecting the ePAS form
NOTE: Request forms are rejected if the ticket is a duplicate request, form was submitted by someone other than the requestor or access is not permitted based on purpose of use provided.
Commented [RMG2]: This should be Step 4 1.Email is received in outlook mailbox from ePAS 2.If the request has CAPRI/VistAWeb processor will need to select “yes” or “No” to indicate whether it will be going for additional NDS authorization (to Angel)
3.Access is provisioned
4.Email notification is sent to requester
5.Amy approves in ePAS
6.Abagail enters Alexsys ticket
-On occasion a request in ePAS may be closed a day after the email notification is sent. The Alexsys ticket is only closed after the notification is sent and the request is closed in ePAS. The
Close Date of the Alexsys ticket will always be the date it was closed in ePAS.
https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/jim.laky@va.gov https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/Jeremy.shifflett@va.gov
Appendix A - Provisioning Access Processes
A. CDW Processing Steps
Login to the CDW BaseCamp:
https://vaww.app.dev.dwh.cdw.portal.va.gov/BaseCampWeb/
1. Search for the customer in the database by selecting Manage Customers and then filtering your search by Last Name from the drop down. You can also search by AD
Account or email address.
2. If the customer is found in the database, review the entry and Edit Existing Customer as needed. If customer is not found then Add Customer
Edit Existing Customer
1. Search for Customer in BaseCamp and click ‘Edit’ link to the left of the customer name
NOTE: If the Customer exists with a different AD Account names, be sure to select the correct customer. Create a New customer entry if the AD information on the ePAS form is different from the existing CDW BaseCamp entry. If a previous account needs to be inactivated, please see Inactivating an Account below.
2. Click the Details tab on the screen that appears
3. Review fields to ensure they are correct. If a correction needs to be made, make corrections, then click Save at the bottom of the screen.
Add New Customer
1. Select the add customer link
2. Complete the following fields in the Add a new Customer Record box:
• AD Account* (AD Domain\Username)
• Email Address*
• First Name*
• Last Name*
• Station #
• Phone
• Indicate if the customer is a Contractor by selecting yes or no
• Comment (Use as needed. Enter comments when inactivating an account)
• ePAS
• Click Save Changes
Add Authorizations
1. Click the Authorizations tab
2. Answer the “Are you using CDW data question by selecting yes or
3. Check one or more of the following authorizations and include the corresponding ePAS number:
• CDW_Full (Basic Read Access) *See note below.
• CDW_SPatient (Privileged Read Patient Access)
• CDW_SStaff (Staff Real SSN Access)
• CDW_DSS (DSS Access)
• CDW_VitalStatus (Vital Status Files)
• CDW_SASData (Medical SAS Files)
• CDW_nonCDWNonPHI (Non CDW Data that does not contain PHI)
• CDW_nonCDWPHI (Non CDW Data)
4. If the requester selected a termination date in ePAS, enter the expiration date in the
Expiration Date field.
5. Select the Save button at the bottom of the screen.
NOTE: SAS Grid will appear in the customer’s CDW BaseCamp record as SAS_Users and
VHAVINCI_Users when added to the profile by VINCI staff. matt.s.smith@va.gov is copied on the approval email if SAS Grid is selected for access.
Additional Resource:
CDW Authorization SOP
CDW_Authorization_ SOP_ver 3.pdf
Inactivating a CDW Account
1. If a customer has two (or more) accounts in CDW and one (or more) of them is from a previous position/organization/AD domain, notify CDW that the account(s) should be inactivated.
2. Send a message to OIT BISL team at CDW Project Support mail group cdwprojectsupport@va.gov requesting that the old account(s) be inactivated.
3. Annotate Comment field in the customer’s Details tab with the following text:
4. Per customer's (or other notifying authority) email of (date), this account should be inactivated. BISL staff notified via email on (date).
5. A copy of the inactivate e-mail is stored in the CDW/VSSC Account Inactivation folder in the NDS Operational Access Requests mailbox.
6. Replies from BISL Staff, stating that the account has been inactivated, will also be stored in the CDW/VSSC Account Inactivation folder in the NDS Operational Access Requests mailbox.
B. VSSC Processing Steps
1. Log into the National Security SSN Level Access Data Mart Systems (NSSD) https://secure.vssc.med.va.gov/natsec/
2. Select Add and Edit Existing user access https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/matt.s.smith@va.gov
3. Search for the Customer’s last name or active directory username in the search box and click Find User
Add New Customer
1. Click New User
2. Enter the following information from the ePAS form:
• Last Name
• First Name
• VISN
• Facility (If the Facility selected on the form is not available select NA)
• Active Directory Domain (Will auto-populate when VISN is selected, but can also be edited)
• Active Directory UserName
• Application Name – Highest Level of Access
• Workload
• DSS
• Sunset Date: Enter a Sunset Date if applicable
• Sunset Date would be entered if a date is entered on the ePAS form stating the
‘Access is only required for duration of the position’.
• If a date exists in the NSSD Database but no date is entered in ePAS, remove the
Sunset Date in NSSD.
• Click Insert this User when finished updating the record.
Edit Existing Customer
1. If user is found, click the Edit button next to the customer’s name and make appropriate changes to the customer’s NSSD entry. Update the following information, as necessary:
• Last Name
• First Name
• VISN
• Facility
• Active Directory Domain
• Active Directory UserName
• Application Name – Highest Level of Access
• Workload – Update accordingly as needed
• DSS – Update accordingly as needed
• Sunset Date: Enter a Sunset Date if applicable
• Sunset Date would be entered if a date is entered on the ePAS form stating the
‘Access is only required for duration of the position’.
• If a date exists in the NSSD Database but no date is entered in ePAS, remove the
Sunset Date in NSSD.
• Click Update this User when finished updating the record
NOTE: If a customer has two (or more) accounts in NSSD and one (or more) of them is from a previous position/organization/AD domain, the old record/account must be inactivated by NDS
Operational staff and a new record/account created. NEVER delete the previous NSSD record.
Inactivate NSSD Account
1. Find user and select Edit
2. Change Application Level of access to None (5-none) for both Workload and DSS
3. Select Update this User
C. Mainframe Processing Steps
1. Send an email to AITC Help Desk cdco-nsd@va.gov using the approved template below. NDS ensures the requestor and other individuals who were on the original request email (including the ISO and local CUPS POC) are in the Cc: line.
2. AITC National Service Desk (NSD) has a 24-hour turnaround time to create an SDM ticket using the request category SOC.SW.9957 and route it to AITC Access
Management
3. AITC Access Management will provision the access and notify the requestor, requestor’s supervisor, ISO & CUPS POC by e-mail that approved data access has been provisioned.
Email Template for Submission to AITC for Data Access Request Provisioning
By receiving this email the National Service Desk has been tasked with creating an
SDM request using the following request category: SIC.SW.9957
Service Desk please fill in the request fields as annotated below:
Requester Supervisor:
Affected End User:
Summary:
NDS APPROVAL
NDS has authorized the following access to mainframe files for (Operational) purposes.
Name of supervisor of individual receiving access
Name of individual receiving access
Active Directory Username of individual receiving access
Active Directory Domain of individual receiving access
TSO – Account ID – of user receiving access
ISO
CUPS POC – Name (Phone #)
Files Authorized:
(NDS should remove any that do not apply)
110JJ02 – BIRLS Real SSN
110TT01 – MedSAS National Real SSN VetsNet files
110TT05 – MedSAS VISN Real SSN
110NN06 – Vital Status Scrambled SSN
110TT20 – Vital Status Real SSN Crosswalk File
AITC when access has been provisioned please notify all named individuals
(Individual receiving the access, Individual’s Supervisor, ISO & CUPS POC) that access is ready for use.
D. OEF/OIF/OND Processing Steps
1. Send the ePAS notification email to Dr. Robert Bossarte, Robert.Bossarte@va.gov requesting approval and processing of the request. Ensure that the Requester and Supervisor are in the Cc: line for transparency
Email to Office of Public Health
Good afternoon Dr. Bossarte, [Requestor Name] is authorized by NDS to apply for access to the OEF/OIF/OND
Access Roster for Operational Purposes.
Thank you,
2. Include the following in the notification email sent to the requester, supervisor and ISO.
Email to the requestor
Your request to access the OEF/OIF/OND Roster is approved by NDS and a notice has been sent to the Office of Public Health notifying them of the approval. Be advised that the Office of Public Health operates independently from NDS, and has an independent timeline for internal approval/provisioning of the OEF/OIF/OND Roster requests.
For questions pertaining to request approval, data fulfillment and provisioning please contact Dr. Ishii at the Office of Public Health if you have questions regarding the status of your OEF/OIF/OND request. Please allow for an initial 3 week processing time.
E. CAPRI/VistAWeb Processing Steps
Please visit the following link for information on processing CAPRI/VistAWeb:
mailto:Robert.Bossarte@va.gov https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/BusinessOperation/Standard_Operating_
Procedures(SOP)/FINAL%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx
File details come from the government source that posted it. Updated .