36E77618Q0067-002.pdf

PDF 274 KB Posted

Attached to
LV38 Infsuion pump upgrade Federal contract opportunity
Solicitation number
36E77618Q0067
Issued by
Department of Veterans Affairs Office of Information Service Center

About this file

36E77618Q0067 ATTACHMENT 1 - Final PWS - LV38 Infusion Pumps v6.1 - 6.4.18.pdf

View the file

Other files for this federal contract opportunity

Other files attached to LV38 Infsuion pump upgrade, newest first.
File Type Posted
-14242.docx DOCX document
36E77618Q0067-A00001000.docx DOCX document
36E77618Q0067-003.pdf PDF
36E77618Q0067-004.pdf PDF
36E77618Q0067-001.docx DOCX document
36E77618Q0067-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PerformanceWorkStatementTemplate_APR_28_2017

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

VA Eastern Colorado Health Care System

LV38 – Infusion Pumps and Pump Server Upgrade

Date: June 4, 2018 PWS Version Number: v6.1

Contents

1.0 BACKGROUND

2.0 APPLICABLE DOCUMENTS

3.0 SCOPE OF WORK

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

4.2 PLACE OF PERFORMANCE

4.3 TRAVEL

5.0 SPECIFIC TASKS AND DELIVERABLES

5.1 Infusion Pump Guardrail Software (JSN: U0021)

5.2 Alaris PC Units (JSN: M4266B), Model #8015LS, Quantity: 240 units

5.3 Volume Infusion Pump (IV) Module (JSN: M4266), Model #8100, Quantity: 358 units

5.4 Installation Services

5.5 Training Requirement

5.6 Operation and Maintenance Manuals

5.7 Ongoing Operations and Maintenance Services

6.0 GENERAL REQUIREMENTS

6.1 General Conditions (Delivery)

6.2. ENTERPRISE AND IT FRAMEWORK

6.3. SECURITY AND PRIVACY REQUIREMENTS

6.4. METHOD AND DISTRIBUTION OF DELIVERABLES

6.5. PERFORMANCE METRICS

6.6. FACILITY/RESOURCE PROVISIONS

6.7. GOVERNMENT FURNISHED PROPERTY

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

1.0 BACKGROUND

This acquisition is in support of the initial outfitting and activation of the new Denver VA Medical Center being constructed in Aurora, CO.

The Veteran Affairs Eastern Colorado Health Care System (VA ECHCS), Denver, CO., requires a software upgrade and hardware refresh of the Alaris Carefusion infusion pump selected modules. The Alaris system is utilized for drug delivery for patients throughout the medical center. The system has software for the updates to the drug formulary or library, pump module maintenance, and for quality reporting for pump and system statuses.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”

2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements

For Cryptographic Modules”

3. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,”

August 2013

4. 10 U.S.C. § 2224, "Defense Information Assurance Program"

5. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for

Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

7. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

8. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/

9. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs

10. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

11. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1,

12. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

13. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services

(CHAMPUS)”

14. An Introductory Resource Guide for Implementing the Health Insurance Portability and

Accountability Act (HIPAA) Security Rule, October 2008

15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the

Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998

16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

17. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,”

September 20, 2012 http://www.va.gov/vapubs/ http://www.va.gov/vapubs http://www.va.gov/vapubs

18. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015

19. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

20. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information

(SPI)”, July 28, 2016

21. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA

Information Systems,” February 3, 2014

22. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development

Lifecycle”, March 22, 2010

23. VA Handbook 6500.6, “Contract Security,” March 12, 2010

24. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

25. OI&T ProPath Process Methodology (Transitioning to Process Asset Library (PAL) (reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp

26. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.aspx)

27. National Institute Standards and Technology (NIST) Special Publications (SP)

28. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact

Assessment,” October 15, 2014

29. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact

Assessment,” July 30, 2015

30. VA Directive 6300, Records and Information Management, February 26, 2009

31. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

32. OMB Memorandum, “Transition to IPv6”, September 28, 2010

33. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015

34. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014

35. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of

HSPD-12, June 30, 2006

36. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive

(HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

37. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011

38. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

39. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

40. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008

41. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

42. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013

43. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014 http://www.va.gov/PROPATH/Maps.asp http://www.va.gov/PROPATH/Templates.asp http://www.va.gov/trm/TRMHomePage.aspx

44. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012

45. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

46. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

47. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

48. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

55. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated

March 19, 2015

56. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

57. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

58. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

61. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV)

Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

63. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;

https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

64. “Veteran Focused Integration Process (VIP) Guide 1.0”, December, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

65. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411

66. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

3.0 SCOPE OF WORK

The Contractor shall provide all the equipment and services required to provide the VA Eastern Colorado Health Care System (VA ECHCS) with a software upgrade and hardware refresh of the Alaris CareFusion Infusion Pump and selected modules. The Contractor shall also provide the professional services, training, and operations and maintenance services detailed in Section 5 to ensure successful installation and configuration of the required equipment.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

Equipment: Delivery 60 days after receipt of order (ARO)

Period of Performance (Operations and Maintenance Services):

Base Period: 12 months from date of award Option Period One (1): 12 months Option Period Two (2): 12 months Option Period Three (3): 12 months Option Period Four (4): 12 months

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).

There are ten (10) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412

Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

4.2 PLACE OF PERFORMANCE

Installation and configuration tasks under this PWS shall be performed at VA facilities located in Aurora, CO. Work may be performed at remote locations with prior concurrence from the Contracting Officer’s Representative (COR).

Operations and Maintenance tasks under this PWS for the base and option periods shall be performed at the Contractor’s facilities.

4.3 TRAVEL

The Government does not anticipate travel under this effort to perform the tasks associated with the effort.

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall provide the following:

VA ECHCS requires a software upgrade and hardware refresh of the Alaris CareFusion infusion pump selected modules. The Alaris system is utilized for drug delivery for patients throughout the medical center. The system has software for the updates to the drug formulary or library, pump module maintenance, and for quality reporting for pump and system statuses.

The Contractor shall upgrade the server software from current versions referenced in Table 1.

Contractor shall provide the operating system and SQL for the upgrades as well. This upgrade and migration shall be to VA provided hardware for virtual machine (VM) environment.

Software Current Version Operating System Windows Server 2008 R2, SP 1 Database SQL Server 2008 R2 CareFusion Alaris Guardrails CQI Reporter v9.8 CareFusion Alaris System Maintenance v.9.8.1 CareFusion Alaris Guardrails Editor v9.8

Table 1: Infusion Pump Software

Based on the approved deployment work schedule, the Contractor shall provide all labor necessary to install, deploy, and configure the requirements detailed in this PWS.

The Contractor shall install Alaris PC units and Volume IV module and upgrade of the Infusion Pump server at the existing Denver VA facility.

The Contractor shall unpack and install all equipment in the designated area to be provided by the Government. The Contractor shall dispose of all trash offsite as there are no adequate onsite trash disposal facilities.

5.1 Infusion Pump Guardrail Software (JSN: U0021)

5.1.1 The contractor shall upgrade and migrate the existing CareFusion Infusion Pump Guardrail server to the new Virtualized Machine (VM) environment. The hardware to house the VM will be provided by the VA ECHCS.

5.1.2 All software shall be compatible with the following devices currently in service at the facility to include:

• Alaris 8015 PC units

• Alaris 8015LS PC units

• Alaris 8100 Large Volume Pump modules

• Alaris 8110 Syringe modules

• Alaris 8120 PCA modules

• Alaris 8300 EtCO2 modules

5.1.3 The latest version of the Alaris Guardrail shall be approved on the VA Office of Information and Technology (OI&T) Technical Reference Model (TRM) portal and allow user access through the VA OI&T workstation computer.

5.1.4 The Contractor shall complete the VA 6550 Pre-Procurement Assessment form for each software type.

5.1.5 The software shall be upgraded with the noted functionalities

5.1.6 All reports, data, documents, content, and plans created or otherwise generated from the software delivered hereunder shall be the property of the VA.

5.1.6.1 CareFusion Alaris Guardrails Editor

• Used for editing drug formulary/library

• Provide access controlled by usernames to limit access to approved pharmacy staff only to edit drug listings.

• Have the capability to pull current library and previous library into a table format or to be exported into a spreadsheet format.

• Allow for date and time stamp of the drug library to note when put into clinical use.

• Capability to provide wireless updates through the OI&T Wireless network. This push must be Federal Information Processing Standard (FIPS) 140-2 compliant in terms of encryption and security for the data transfer.

5.1.6.2 CareFusion Alaris Guardrails CQI Reporter

• Provide report generation and quality improvement measurements.

• Allow for access control for nursing, pharmacy, and biomedical engineering staff for report generation.

• Capability to provide pre-generated reports that include: error codes, alarms activated, pump programming.

• Ability to produce self-generated reports with fields determined by department users.

• Capability of running reports in table, graph, or chart format or have the capability to be exported in a data type to allow for table, graph, or chart generation.

5.1.6.3 CareFusion Alaris System Maintenance

• To be used by biomedical engineering staff for maintenance of infusion pumps and devices.

• Shall have configurable profiles for quick upload of technical information to the device.

• Shall have step-by-step procedures and testing of devices and prompt staff for data values and information to complete the Preventative Maintenance (PM) report.

• Software shall be able to connect to the device to interrogate for alarms, error logs, or other information related to PM.

5.2 Alaris PC Units (JSN: M4266B), Model #8015LS, Quantity: 240 units

5.2.1 Basis of Design: Alaris PC(LS) unit 8015LS

5.2.2 The PC units are replacement items for the earlier generation of Alaris PC units currently in use at the facility. The Contractor shall migrate the current 237 term licenses for the existing PC units to the newly purchased Alaris 8015(LS) PC devices.

5.2.3 The Contractor shall also provide three (3) additional new PC unit term licenses for a total of 240 licenses.

5.2.4 The Contractor shall include in their pricing the trade in value of 237 PC units model 8015. The Contractor shall be responsible for removing items and returning items to necessary warehouse facilities.

5.3 Volume Infusion Pump (IV) Module (JSN: M4266), Model #8100, Quantity: 358 units

5.3.1 Basis of Design: Alaris Unit Model 8100

5.3.2 The IV modules are replacement items for the earlier generation of Alaris IV modules currently in use at the facility. The Contractor shall migrate the 358 term licenses for the existing IV units to the newly purchased Alaris Unit Model 8100s.

5.3.3 The Contractor shall include in their pricing the trade in value of 360 PC Unit model 8100. The Contractor shall be responsible for removing items and returning items to necessary warehouse facilities.

5.4 Installation Services

Project Estimate Time Line

Phase I Project Kickoff Estimated Start Date: Immediately upon contract award

Phase II System Upgrade and Migration Immediately upon Phase I completion

Phase III Hardware Installation and Testing Immediately upon Phase II completion

Phase IV Verification and Validation Immediately upon Phase III completion

5.4.1 The Contractor shall provide an Implementation Plan and schedule and implementation meeting within two (2) weeks of order shipment. The Contractor shall identify specific deployment tasks and milestones in the Implementation Plan.

5.4.2 The Contractor shall provide and maintain an accurate, detailed Inventory List of the Contractor installed equipment and software including serial numbers, Government provided Equipment Entry (EE) Tag Numbers, version release, and licenses.

5.4.3 The Contractor shall perform all installation and configuration necessary to complete the requirements detailed in this PWS. The Contractor shall also perform technical service checks to ensure the product is fully operational in accordance with the manufacturer’s operating standards.

5.4.4 The Contractor shall provide an Excel version cut sheet that includes the serial number for each piece of equipment installed as well as the IP addresses and MAC addresses for all equipment that attaches to the network by IDF.

5.5 Training Requirement

5.5.1 The Contractor shall provide, at a minimum, system administrator training for three (3) VA ECHCS Biomedical Engineering Staff.

5.5.2 The Contractor shall provide onsite pump controller user level training for a minimum of two (2) business days for a maximum of 250 VA staff located at the Denver facility.

5.5.3 Training shall be held as small group instruction and include, at a minimum, end user roles and responsibilities and instruction on how to safely operate the system.

5.5.4 The Contractor shall provide access to online education videos for continued training for VA staff.

5.6 Operation and Maintenance Manuals

5.6.1 The Contractor shall deliver a compilation of the manufacturer recommended maintenance schedule(s) and operation manual(s) packaged in binders to the onsite point of contact upon completion of delivery.

5.6.2 Binders – Quantity of two (2) for each of the items identified in section 5

5.6.3 Digital Copies – Quantity of one (1) for each of the items identified in Section 5

5.7 Ongoing Operations and Maintenance Services

The Contractor shall provide a Software Management Service Agreement that will upgrade the existing Alaris server software programs to the most current version at the time of award. The Software Management Service Agreement shall include telephone support from 8:00 a.m. – 5:00 p.m. (Mountain) and shall include the upgrade and update of all CareFusion modules that the facility owns at the time of contract award.

5.7.1 Base Period: Operations and Management Services as described in Section 5.7 for the period of 12 months from the date of award.

Option Period One (1): Operations and Management Services as described in Section 5.7 for the period of 12 months from the date the base period ends.

Option Period Two (2): Operations and Management Services as described in Section 5.7 for the period of 12 months from the date the first option period ends.

Option Period Three (3): Operations and Management Services as described in Section 5.7 for the period of 12 months from the date the second option period ends.

Option Period Four (4): Operations and Management Services as described in Section 5.7 for the period of 12 months from the date the third option period ends.

5.7.1.1 Inventory to be covered by this agreement:

5.7.1.1.1 Alaris 8015LS PC Units (Quantity: 248)

5.7.1.1.2 Alaris 8100 Large Volume Pump modules (Quantity: 358)

5.7.1.1.3 Alaris 8110 Syringe modules (Quantity: 25)

5.7.1.1.4 Alaris 8120 PCA modules (Quantity: 35)

5.7.1.1.5 Alaris 8300 EtCO2 modules (Quantity: 45)

6.0 GENERAL REQUIREMENTS

6.1 GENERAL CONDITIONS (DELIVERY)

6.1.1 This acquisition is part of the initial outfitting and activation of the new Denver VA Medical Center being constructed in Aurora, CO. Delivery will be coordinated after award of the order.

The Contractor shall contact the Technical Onsite Point of Contact (POC) to schedule a pre-delivery meeting to be conducted approximately 30 days before the initial award delivery date for verification of delivery dates. Technical Onsite POC for this requirement is:

Lauren Hill (W) – (720) 857-5935 (C) – (407) 233-7054

Email: Lhill@MartekGlobal.com

6.1.2. The Contractor may be required to adjust the delivery date from the date specified in the purchase order due to situations beyond the Government’s control. The Government reserves the right to adjust the delivery date specified in the award for up to 90 days at no additional cost to the Government.

6.1.3. Requirements

6.1.3.1. Onsite assembly and installation of items and performance of the services identified in this SOW will take place during normal business hours that have been identified as: 0700 to 1600 (7:00 mailto:Lhill@MartekGlobal.com a.m. to 4:00 p.m.) Mountain Time; Monday through Friday; excluding Federal Holidays. See section 4.1 of this PWS.

6.1.3.2. Secure storage is limited at the Denver VA Replacement Facility. If secure storage is required, the Contractor shall make arrangements locally at no additional cost to the Government.

6.1.3.3. The Contractor shall provide all tools, labor, and materials to complete assembly and installation of the required equipment detailed in this PWS.

6.1.3.4. The Contractor shall have available an Onsite Representative to serve as the primary interfae with the Denver VA Medical Center and VA ECHCS during the duration of assembly and installation of the required equipment detailed in this PWS.

6.1.3.5. The VA will provide a staging area for the equipment to be staged before deployment.

6.1.3.6. Delivery Location:

6.1.3.6.1. The Contractor shall deliver all equipment to:

VA Eastern Colorado Health Care System Loading Dock 1700 North Wheeling Street Aurora, CO 80045

6.1.3.7. Delivery Markings

6.1.3.7.1. The Contractor shall deliver items in the Original Equipment Manufacturer (OEM)’s original sealed containers with the OEM’s name clearly marked thereon.

6.1.3.7.2. The Contractor shall deliver all items marked with the IFCAP Purchase Order Number (ex:

259C70000) and the Award Document Purchase Order Number (ex: VA701-17-P-0000).

6.1.3.8. Delivery Coordination

6.1.3.8.1. All deliveries shall be coordinated with the Onsite POC identified in section 6.1.1.1.

Deliveries that are not properly coordinated will be rejected.

6.1.3.9. Site Delivery Conditions

6.1.3.9.1. There shall be no eating, drinking, or smoking inside the construction site at any time.

6.1.3.9.2. All delivery personnel shall comply with all posted safety requirements to include the wearing of Personal Protection Equipment (PPE). Minimum PPE requirements are: Hard hat, over-the-ankle boots, reflective safety vest, eye protection, and gloves.

6.1.4. Use of Premises

6.1.4.1. Requirements

6.1.4.1.1. During the performance of this contract, all work shall be conducted at the VA Denver Replacement Hospital. The Contractor shall perform all work in a manner that will cause minimal interference with VA ECHCS operations and the operation of other Contractors on the premises.

6.1.4.2. The Contractor shall coordinate and cooperate with VA ECHCS’s General Contractor and Construction Manager during delivery and installation activities. All coordination with the General Contractor shall be coordinated through the Technical Onsite POC.

6.1.4.3. The Denver Replacement Facility is currently an active construction site. The Contractor shall assume all responsibility for taking precautions for the Contractor’s (and any associated Subcontractors) employees, agents, licensees, and permittees.

6.1.4.4. Prior to commencing work, the Contractor and associated personnel (including Subcontractors) shall be required to attend a VA Construction and Facilities Management Site Safety Training Program.

6.1.4.5. Clean up and disposal: There are no trash disposal facilities or dumpsters available for Contractor use at the Denver VA Replacement Facility for the disposal of material. The Contractor shall clean up all debris and discard at the Contractor’s expense.

6.1.4.6. The removal of waste and/or excess material shall be conducted through the loading area.

Delivery trucks and/or other Contractor vehicles shall not be permitted to remain in the loading area. Vehicles shall be brought back to the area if required to remove any waste, tool, or excess materials.

6.1.5. Protection of Property

6.1.5.1. Requirements

6.1.5.1.1. The Contractor shall conduct an inspection walk-through of the building(s) and ground with the Technical Onsite POC before commencing any work.

6.1.5.1.2. The Contractor shall protect all items from damage during delivery. The Contractor shall take all precaution to protect against damage to the building(s), grounds, and furnishings.

The Contractor shall be responsible for the repair and replacement of any items related to the building(s) and grounds damaged (whether accidentally or on purpose), due to action by the Contractor or their representative.

6.1.5.1.3. The Contractor shall be responsible for repairing and replacing any items, components, building(s), and grounds damaged due to negligence and/or actions taken by the Contractor or its employees or representatives. The source of all repairs beyond simple surface cleaning is the Facility Construction Contractor (or appropriate Subcontractor) so that building warranty is maintained. Concurrence for the VA Facilities Management POC and Technical Onsite POC is required before the Contractor may perform any significant repair work. In all cases, repairs shall utilize materials of the same quality, size, texture, grade, and color to match adjacent existing work.

6.1.5.1.4. The Contractor shall be responsible for securing all items, their work, tools, and equipment used during delivery and installation.

6.2. ENTERPRISE AND IT FRAMEWORK

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (One-VA TRM). One-VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. One-VA TRM includes the Standards Profile and Product List that collectively serves as a VA technology roadmap. Architecture, Strategy, and Design (ASD) has overall responsibility for the One-VA TRM.

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are PIV-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems are compliant with VA Identity Management Policy (VAIQ# 7011145), Continued Implementation of Homeland Security Presidential Directive 12 (VAIQ#7100147), and VA IAM enterprise identity management requirements (IAM Identity Management Business Requirements Guidance document), located at https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514. The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with NIST Special Publication 800-63, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of Personal Identity Verification (PIV) and/or Common Access Card (CAC), as determined by the business need. Assertion based authentication must include a SAML implementation. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST 800-63 guidelines. Trust based authentication must include authentication/account binding based on trusted HTTP headers. The Contractor solution shall conform to the specific Identity and Access Management PIV requirements set forth in OMB Memoranda M-04-04, M-05-24, M-11-11, as well as the National Institute of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) 201-2, and supporting NIST Special Publications. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04- 04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05- 24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11- 11.pdf respectively. The identity authentication Level of Assurance (LOA) requirement for this specific effort is LOA-4.

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05- 22.pdf) and September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf). IPv6 technology, in accordance with the USGv6 Profile (NIST Special Publication (SP) 500- 267 (http://www-x.antd.nist.gov/usgv6/index.html), the Technical Infrastructure for USGv6 Adoption (http://www.nist.gov/itl/antd/usgv6.cfm), and the NIST SP 800 series applicable compliance http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp http://www.techstrategies.oit.va.gov/enterprise_dp.asp https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf http://www-x.antd.nist.gov/usgv6/index.html http://www.nist.gov/itl/antd/usgv6.cfm

(http://csrc.nist.gov/publications/PubsSPs.html) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack IPv6 IPv4 connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack IPv6 IPv4 users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack IPv6 IPv4 operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08- 05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08- 23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Microsoft Office 2010. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Office 2013 and Windows 8.1. However, Office 2013 and Windows 8.1 are not the VA standard yet and are currently not approved for use on the VA Network, but are in-process for future approval by OI&T. Upon the release approval of Office 2013 and Windows 8.1 individually as the VA standard, Office 2013 and Windows 8.1 will supersede Office 2010 and Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) specific to the particular client operating system being used.

The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products http://csrc.nist.gov/publications/PubsSPs.html https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://s3.amazonaws.com/sitesusa/wp-content/uploads/sites/482/2015/04/TIC_Ref_Arch_v2-0_2013.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

The Contractor shall utilize ProPath (PAL), the OI&T-wide process management tool that assists in the execution of an IT project (including adherence to VIP standards). PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards or guides to assist project teams in facilitating their VIP compliant work.

6.3. SECURITY AND PRIVACY REQUIREMENTS

There are no additional security and privacy requirements applicable to this requirement.

6.3.1. POSITION/TASK RISK DESIGNATION LEVEL(S)

The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number Tier1 / Low Risk Tier 2 / Moderate Risk Tier 4 / High Risk

5.4 5.5 5.7

6.1.1

The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

6.3.2. CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

b. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the ProPath (PAL) template. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background

Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor shall coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form

e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

f. The Contractor employee shall certify and release the e-QIP document, print and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC.

These documents shall be submitted to the COR within 3 business days of receipt of the e- QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-QIP).

g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

h. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook

6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.

i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.

6.4. METHOD AND DISTRIBUTION OF DELIVERABLES

The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include: MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).

6.5. PERFORMANCE METRICS

The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.

Performance Objective Performance Standard Acceptable Levels of Performance

A. Technical / Quality of Product or Service

1. Demonstrates understanding of requirements

2. Efficient and effective in meeting requirements

3. Meets technical needs and mission requirements

4. Provides quality services/products

Satisfactory or higher

B. Project Milestones and Schedule

1. Established milestones and project dates are met

2. Products completed, reviewed, delivered in accordance with the established schedule

3. Notifies customer in advance of potential problems

Satisfactory or higher

C. Cost & Staffing 1. Currency of expertise and staffing levels appropriate

2. Personnel possess necessary knowledge, skills and abilities to perform tasks

Satisfactory or higher

D. Management 1. Integration and coordination of all activities to execute effort

Satisfactory or higher

The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.

6.6. FACILITY/RESOURCE PROVISIONS

The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

6.7. GOVERNMENT FURNISHED PROPERTY

There is no Government Furnished Equipment (GFE) that will be provided for the completion of this requirement.

ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED

VA Maintenance/Installation Contracts

*Reference: VA Handbook 6500.6 Appendix C – VA Information and Information System Security/Privacy Language for Inclusion to Contracts, as appropriate

1. VA INFORMATION CUSTODIAL LANGUAGE

Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data

- General, FAR 52.227-14(d) (1).

2. SECURITY INCIDENT INVESTIGATION

The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

3. LIQUIDATED DAMAGES FOR DATA BREACH

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

(1) Notification;

(2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

(3) Data breach analysis;

(4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.