36C77620Q0042-018.pdf

PDF Posted

Attached to
R408--National Data Systems (NDS) Federal contract opportunity
Solicitation number
36C77620Q0042
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This standard operating procedure outlines the process for provisioning access to National Data Systems (NDS) Healthcare Operations data sources. It describes responsibilities for reviewing and processing access requests, provisioning different data sources including the Clinical Data Warehouse, VSSC systems, mainframe files, and OEF/OIF/OND rosters. The procedure details creating tickets for approved, returned, and rejected requests in the Alexsys system and notifying requestors. It also provides templates for provisioning mainframe access through the Austin Information Technology Center and notifying staff about OEF/OIF/OND roster requests. Appendices include step-by-step processes for provisioning specific data sources, inactivating accounts, and handling CAPRI/VistAWeb access according to the separate SOP for those systems.

The related federal contract opportunity is solicitation number 36C77620Q0042 for the National Data Systems contract. As no further detail is provided, the type of products or services required under the contract cannot be determined from this information.

36C77620Q0042 S02 - Attachment J - WRO0000.pdf

View the file

Other files for this federal contract opportunity

Other files attached to R408--National Data Systems (NDS), newest first.
File Type Posted
36C77620Q0042-0001000.docx DOCX document
36C77620Q0042-008.pdf PDF
36C77620Q0042-010.pdf PDF
36C77620Q0042-019.pdf PDF
36C77620Q0042-017.pdf PDF
36C77620Q0042-016.pdf PDF
36C77620Q0042-014.pdf PDF
36C77620Q0042-013.pdf PDF
36C77620Q0042-012.pdf PDF
36C77620Q0042-009.pdf PDF
36C77620Q0042-015.pdf PDF
36C77620Q0042-011.pdf PDF
36C77620Q0042-007.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Monday, December 14, 2015

STANDARD OPERATING PROCEDURE

Processing NDS Healthcare Operations Access

Requests

March 2015

Revision History

Document Title: STANDARD OPERATING PROCEDURE for processing NDS

Healthcare Operations Access Requests

Date Version Author Revision Description

10/15/2013 V.2 Tesa Kochie /

Mark Molloy

Added text for SAS Grid provisioning notification (#3). Removed the requirement to attach form to notification email (#4). When returning the request, changed it where you copy the email to the ticket (#10).

11/6/2013 V.3 Mark Molloy Added text to address how to process duplicate requests (#22). Modified Returned Request process based on changes made in Alexsys

(#14).

02/03/2014 V.4 Mark Molloy Added text to address adding returned reasons for each returned ticket.

9/3/2014 V.5 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Armando, Aaron, Lynn, Irma)

9/15/2014 V.6 Linda Hudock Updated SOP to include CDW Special Project data

11/14/2014 V.7 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Lynn, Irma)

11/25/2014 V.8 Linda Hudock Updated SOP per comments of NDS staff to date (Linda, Lynn, Irma)

12/4/14 V.9 Mark Molloy Incorporated ePAS to the SOP.

3/4/15 v.10 Cindy Wamsley, Abigail

Churchman, Tesa

Kochie

Cleaned up content and formatting

3/25/2015 V. 11 Tesa Kochie Added CDW Authorization SOP

5/11/2015 V. 12 Tesa Kochie Updated contact info for OEF/OIF/OND and

Alexsys Field Modifications.

12/14/2015 V. 13 Abigail

Churchman

Updates throughout

Table of Contents Revision History

PURPOSE

RESPONSIBILITIES

PROCEDURES

1. Review Electronic Permissions Access System (ePAS) Request Form

2. Provision Access According to Data Source Selected

3. Send Approval/Notification Email:

4. Create Alexsys Ticket

5. Approve/Return/Reject ePAS form

Appendix A - Provisioning Access Processes

A. CDW Processing Steps

Edit Existing Customer

Add New Customer

Add Customer Event

Inactivating a CDW Account

B. VSSC Processing Steps

Add New Customer

Edit Existing Customer

Inactivate NSSD Account

C. Mainframe Processing Steps

D. OEF/OIF/OND Processing Steps

E. CAPRI/VistAWeb Processing Steps

STANDARD OPERATING PROCEDURE

Processing NDS Healthcare Operations Access Requests

PURPOSE

This SOP establishes the process/procedure for processing National Data Systems (NDS)

Healthcare Operations access requests. There will always be exceptions to the standards set forth in this SOP. These situations should be handled in a manner that is suitable for the particular situation and with advice and guidance from appropriates sources (i.e., senior staff or management) as necessary.

RESPONSIBILITIES

NDS

• NDS staff will review submitted requests for accuracy and completeness.

• NDS staff will process each request.

• NDS staff will send a notification email when the request has been processed.

• NDS staff will forward mainframe SAS data requests to the AITC for processing.

• NDS staff will forward OEF/OIF/OND data access requests to OPH for processing.

• NDS staff will enter an Alexsys ticket for each request received.

Austin Information Technology Center (AITC)

• AITC help desk staff will create a ticket and assign the ticket to provision mainframe data access for the requestor.

Office of Public Health (OPH)

• OPH will approve and provision OEF/OIF/OND roster access to the requestor.

Office of the Inspector General (OIG)

• OIG staff will ensure that all OIG requests for access are signed by an OIG ISO.

PROCEDURES

1. Review Electronic Permissions Access System (ePAS) Request Form

When an ePAS form is ready for review, an ePAS notification is send directly to a reviewer’s form VA email account and to NDS.OperationalAccessRequests@va.gov.

You can access the ePAS from via the ePAS link and view all entries under ‘Approval’ for your queue at https://epas.r02.med.va.gov/ or by opening the ePAS form by clicking the link in the automated email alert.

Review the ePAS form for the following:

• Full Legal Name*

• Job Title*

• Email Address *

• Active Directory Name with Domain*

• Work Number*

• Employee Agency

• Employee Type

• Contractor Name (if applicable)

• Contractor Business Address (if applicable)

• Station Number

• Supervisor Name and Email

• ISO Name and Email

• Purpose of Use (as selected)

• Data Sources (as selected)

• Duration of Access

• Duration of Access Termination Date (if applicable)

• Acknowledgement

• If Mainframe access is being requested, verify that the requestor (1) has a valid

CUPS/TSO account that (2) displays the Functional Task Codes (FTCs) requested in the ePAS access request form.

• Signatures: Ensure ePAS form is signed by the appropriate personnel*

• “Vital Status – Scrambled”: When selected, ensure that the “Vital Status Rules of

Behavior” tab is completed. The Rules of Behavior page must not be separated from the ePAS form.

* Denotes auto-populated though the Active Directory look-up.

NOTE: NDS Ops Staff should not process any VHA NDS ePAS forms for OIG Staff unless one of the following four individuals has signed as the Information Security

Officer (ISO):

• Jim Laky, OIG ISO

• Jeremy Shifflett, OIG Deputy ISO

• Mick Vu, OIG Deputy CIO

• Justin Black, OIG CIO

2. Provision Access According to Data Source Selected.

Steps for provisioning access to the following are located in Appendix A.

A. CDW Provisioning Steps

B. VSSC Provisioning Steps

C. Mainframe Processing Steps

D. OEF/OIF/OND Processing Steps https://epas.r02.med.va.gov/

E. CAPRI/VistAWeb Processing Steps

3. Send Approval/Notification Email:

• Respond to the ePAS email notification notifying the requestor, supervisor, and

ISO that access has been authorized. (To correctly format the text go to Format

Text tab and select HTML, instead of Plain Text)

• Choose the correct email template below to populate the body of the email, based on the data sources that were requested.

• Email is copied into Alexsys ticket

VSSC email Template

This operational access request has been authorized by National Data Systems for

VSSC per your attached ePAS request.

If you have any difficulty obtaining protected data in any VSSC/DSS web product, contact the VSSC help desk at https://help.vssc.med.va.gov (choose Data Access as the

Program Area). Neither NDS nor the AITC help desk provides help desk support for

VSSC/DSS products.

CDW email Template

This operational access request has been authorized by National Data Systems for CDW per your ePAS request.

For further instructions for CDW access, follow the link to the CDW Support site then click

“CDW Guide: Introduction and Policies” under Guides in the left-hand navigation pane.

Please allow several hours for the changes to update throughout the network before requesting

CDW Support (although it may not take that long to update). After reviewing the CDW support web link, if more immediate action in necessary, please contact the Austin National

Service Desk via telephone at 855-NSD-HELP (855-673-4357), option 5, or via this web link http://vaww.aac.va.gov/servicedesk.

VINCI Staff: [Requestor Name] is authorized use of the SAS Grid.

NOTE: If SAS Grid Application is requested, add matt.s.smith@va.gov to the email string.

**Please see Mainframe and OEF/OIF/OND Roster section for appropriate email thread.

4. Create Alexsys Ticket

To create an Alexsys ticket:

1. Login to Alexsys at: http://vhahachiaprod/teamweb/teamweb.dll/

2. Login with VA network username and password

3. Click the New tab

Returned and Rejected Tickets

For returned (including rejections) requests, select the NDS Healthcare Operation

Returned Request form on the Select Work Request Type window and complete the following required fields:

• Title field to include requestor Last name, First name

• Station Number

• ePAS ID Number

• Reason for Return

• Copy the entire returned/termination ePAS reason and paste into the Description section of Alexsys.

• If Rejecting the ePAS request, select the Rejected check box

• If creating a return ticket, change status to Open and put yourself as owner.

Change status to Returned once you have received the correctly modified form

(and relate the NDS ops ticket to the returned ticket). If the form must be returned multiple times, keep the ticket open until the form has been corrected and include a note every time the form is returned.

• Select the reason for Return

• Select the Data Sources that were requested

• *Date Form Submitted to NDS (Date the ISO Signed the Request)

• Click the Save icon

• Click Close to close the Alexsys ticket

Approved requests

For approved requests, select NDS Healthcare Operations on the Select Work Request

Type window and complete the following fields:

• Title field – Requestor’s Last Name, First Name

• *Station Number

• Employee Type

• *AD Domain/Username

• *ePAS ID Number

• *Purpose of Use

• *Date Form Submitted to NDS (Date the ISO Signed the Request)

• Enter in the appropriate data sources requested for the submission

• Close Date (This field will auto populate when to the *Status field is Completed and the ticket is saved.)

• Open Date (This field auto populates when the ticket is opened.)

Commented [RMG1]: This should be step 5

1.Email is received in outlook mailbox from ePAS 2.If the request has CAPRI/VistAWeb processor will need to select “yes” or “No” to indicate whether it will be going for additional NDS authorization (to Angel)

3.Access is provisioned 4.Email notification is sent to requester

5.Amy approves in ePAS

6.Abagail enters Alexsys ticket

-On occasion a request in ePAS may be closed a day after the email notification is sent. The Alexsys ticket is only closed after the notification is sent and the request is closed in ePAS. The

Close Date of the Alexsys ticket will always be the date it was closed in ePAS.

http://vhahachiaprod/teamweb/teamweb.dll/

• *Mainframe ID (if applicable)

• *Local CUPS POC email (If Mainframe selected)

• Duration of Access (choose only one)

• Date Access Terminated (if applicable)

• Copy the entire approval email should be pasted into the Description section of

Alexsys including the

• Click the Save icon

• Click Close to close the Alexsys ticket

5. Approve/Return/Reject ePAS form

Approving ePAS Form

• Select Approve in the header or footer of the form

• Sign the form with your network credentials or PIV badge

Returning ePAS Form

• Select Send the Document Back in the header of the form

• Select to whom the form should be returned

• Enter the reason the form should be returned

NOTE: Request forms are returned/sent back if additional information is required or something within the form needs to be changed prior to authorization.

NOTE: OIG forms are returned if they are not signed by one of the above individuals. Email should be sent to jim.laky@va.gov and Jeremy.shifflett@va.gov. OIG staff are exempt from verifying training requirements per OIG Access policy.

Rejecting ePAS Form

• Select Reject in the header or footer of the form

• Provide a reason for rejecting the ePAS form

NOTE: Request forms are rejected if the ticket is a duplicate request, form was submitted by someone other than the requestor or access is not permitted based on purpose of use provided.

Commented [RMG2]: This should be Step 4 1.Email is received in outlook mailbox from ePAS 2.If the request has CAPRI/VistAWeb processor will need to select “yes” or “No” to indicate whether it will be going for additional NDS authorization (to Angel)

3.Access is provisioned

4.Email notification is sent to requester

5.Amy approves in ePAS

6.Abagail enters Alexsys ticket

-On occasion a request in ePAS may be closed a day after the email notification is sent. The Alexsys ticket is only closed after the notification is sent and the request is closed in ePAS. The

Close Date of the Alexsys ticket will always be the date it was closed in ePAS.

https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/jim.laky@va.gov https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/Jeremy.shifflett@va.gov

Appendix A - Provisioning Access Processes

A. CDW Processing Steps

Login to the CDW BaseCamp:

https://vaww.app.dev.dwh.cdw.portal.va.gov/BaseCampWeb/

1. Search for the customer in the database by selecting Manage Customers and then filtering your search by Last Name from the drop down. You can also search by AD

Account or email address.

2. If the customer is found in the database, review the entry and Edit Existing Customer as needed. If customer is not found then Add Customer

Edit Existing Customer

1. Search for Customer in BaseCamp and click ‘Edit’ link to the left of the customer name

NOTE: If the Customer exists with a different AD Account names, be sure to select the correct customer. Create a New customer entry if the AD information on the ePAS form is different from the existing CDW BaseCamp entry. If a previous account needs to be inactivated, please see Inactivating an Account below.

2. Click the Details tab on the screen that appears

3. Review fields to ensure they are correct. If a correction needs to be made, make corrections, then click Save at the bottom of the screen.

Add New Customer

1. Select the add customer link

2. Complete the following fields in the Add a new Customer Record box:

• AD Account* (AD Domain\Username)

• Email Address*

• First Name*

• Last Name*

• Station #

• Phone

• Indicate if the customer is a Contractor by selecting yes or no

• Comment (Use as needed. Enter comments when inactivating an account)

• ePAS

• Click Save Changes

Add Authorizations

1. Click the Authorizations tab

2. Answer the “Are you using CDW data question by selecting yes or

3. Check one or more of the following authorizations and include the corresponding ePAS number:

• CDW_Full (Basic Read Access) *See note below.

• CDW_SPatient (Privileged Read Patient Access)

• CDW_SStaff (Staff Real SSN Access)

• CDW_DSS (DSS Access)

• CDW_VitalStatus (Vital Status Files)

• CDW_SASData (Medical SAS Files)

• CDW_nonCDWNonPHI (Non CDW Data that does not contain PHI)

• CDW_nonCDWPHI (Non CDW Data)

4. If the requester selected a termination date in ePAS, enter the expiration date in the

Expiration Date field.

5. Select the Save button at the bottom of the screen.

NOTE: SAS Grid will appear in the customer’s CDW BaseCamp record as SAS_Users and

VHAVINCI_Users when added to the profile by VINCI staff. matt.s.smith@va.gov is copied on the approval email if SAS Grid is selected for access.

Additional Resource:

CDW Authorization SOP

CDW_Authorization_ SOP_ver 3.pdf

Inactivating a CDW Account

1. If a customer has two (or more) accounts in CDW and one (or more) of them is from a previous position/organization/AD domain, notify CDW that the account(s) should be inactivated.

2. Send a message to OIT BISL team at CDW Project Support mail group cdwprojectsupport@va.gov requesting that the old account(s) be inactivated.

3. Annotate Comment field in the customer’s Details tab with the following text:

4. Per customer's (or other notifying authority) email of (date), this account should be inactivated. BISL staff notified via email on (date).

5. A copy of the inactivate e-mail is stored in the CDW/VSSC Account Inactivation folder in the NDS Operational Access Requests mailbox.

6. Replies from BISL Staff, stating that the account has been inactivated, will also be stored in the CDW/VSSC Account Inactivation folder in the NDS Operational Access Requests mailbox.

B. VSSC Processing Steps

1. Log into the National Security SSN Level Access Data Mart Systems (NSSD) https://secure.vssc.med.va.gov/natsec/

2. Select Add and Edit Existing user access https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/matt.s.smith@va.gov

3. Search for the Customer’s last name or active directory username in the search box and click Find User

Add New Customer

1. Click New User

2. Enter the following information from the ePAS form:

• Last Name

• First Name

• VISN

• Facility (If the Facility selected on the form is not available select NA)

• Active Directory Domain (Will auto-populate when VISN is selected, but can also be edited)

• Active Directory UserName

• Application Name – Highest Level of Access

• Workload

• DSS

• Sunset Date: Enter a Sunset Date if applicable

• Sunset Date would be entered if a date is entered on the ePAS form stating the

‘Access is only required for duration of the position’.

• If a date exists in the NSSD Database but no date is entered in ePAS, remove the

Sunset Date in NSSD.

• Click Insert this User when finished updating the record.

Edit Existing Customer

1. If user is found, click the Edit button next to the customer’s name and make appropriate changes to the customer’s NSSD entry. Update the following information, as necessary:

• Last Name

• First Name

• VISN

• Facility

• Active Directory Domain

• Active Directory UserName

• Application Name – Highest Level of Access

• Workload – Update accordingly as needed

• DSS – Update accordingly as needed

• Sunset Date: Enter a Sunset Date if applicable

• Sunset Date would be entered if a date is entered on the ePAS form stating the

‘Access is only required for duration of the position’.

• If a date exists in the NSSD Database but no date is entered in ePAS, remove the

Sunset Date in NSSD.

• Click Update this User when finished updating the record

NOTE: If a customer has two (or more) accounts in NSSD and one (or more) of them is from a previous position/organization/AD domain, the old record/account must be inactivated by NDS

Operational staff and a new record/account created. NEVER delete the previous NSSD record.

Inactivate NSSD Account

1. Find user and select Edit

2. Change Application Level of access to None (5-none) for both Workload and DSS

3. Select Update this User

C. Mainframe Processing Steps

1. Send an email to AITC Help Desk cdco-nsd@va.gov using the approved template below. NDS ensures the requestor and other individuals who were on the original request email (including the ISO and local CUPS POC) are in the Cc: line.

2. AITC National Service Desk (NSD) has a 24-hour turnaround time to create an SDM ticket using the request category SOC.SW.9957 and route it to AITC Access

Management

3. AITC Access Management will provision the access and notify the requestor, requestor’s supervisor, ISO & CUPS POC by e-mail that approved data access has been provisioned.

Email Template for Submission to AITC for Data Access Request Provisioning

By receiving this email the National Service Desk has been tasked with creating an

SDM request using the following request category: SIC.SW.9957

Service Desk please fill in the request fields as annotated below:

Requester Supervisor:

Affected End User:

Summary:

NDS APPROVAL

NDS has authorized the following access to mainframe files for (Operational) purposes.

Name of supervisor of individual receiving access

Name of individual receiving access

Active Directory Username of individual receiving access

Active Directory Domain of individual receiving access

TSO – Account ID – of user receiving access

ISO

CUPS POC – Name (Phone #)

Files Authorized:

(NDS should remove any that do not apply)

110JJ02 – BIRLS Real SSN

110TT01 – MedSAS National Real SSN VetsNet files

110TT05 – MedSAS VISN Real SSN

110NN06 – Vital Status Scrambled SSN

110TT20 – Vital Status Real SSN Crosswalk File

AITC when access has been provisioned please notify all named individuals

(Individual receiving the access, Individual’s Supervisor, ISO & CUPS POC) that access is ready for use.

D. OEF/OIF/OND Processing Steps

1. Send the ePAS notification email to Dr. Robert Bossarte, Robert.Bossarte@va.gov requesting approval and processing of the request. Ensure that the Requester and Supervisor are in the Cc: line for transparency

Email to Office of Public Health

Good afternoon Dr. Bossarte, [Requestor Name] is authorized by NDS to apply for access to the OEF/OIF/OND

Access Roster for Operational Purposes.

Thank you,

2. Include the following in the notification email sent to the requester, supervisor and ISO.

Email to the requestor

Your request to access the OEF/OIF/OND Roster is approved by NDS and a notice has been sent to the Office of Public Health notifying them of the approval. Be advised that the Office of Public Health operates independently from NDS, and has an independent timeline for internal approval/provisioning of the OEF/OIF/OND Roster requests.

For questions pertaining to request approval, data fulfillment and provisioning please contact Dr. Ishii at the Office of Public Health if you have questions regarding the status of your OEF/OIF/OND request. Please allow for an initial 3 week processing time.

E. CAPRI/VistAWeb Processing Steps

Please visit the following link for information on processing CAPRI/VistAWeb:

mailto:Robert.Bossarte@va.gov https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/BusinessOperation/Standard_Operating_

Procedures(SOP)/FINAL%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx https://vaww.vha.vaco.portal.va.gov/sites/HDI/HIA/Support%20and%20Administration/Standard%20Operating%20Procedures%20(SOPs)/FY15%20SOPs/SOP%20for%20CAPRI%20VISTAWEB_FINAL.docx

File details come from the government source that posted it. Updated .