75D30118Q67839.pdf
PDF 963 KB Posted
- Attached to
- Active Surveillance Among School Children Federal contract opportunity
- Solicitation number
- 75D301-18-R-67839
About this file
Solicitation
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Responses_to_Questions_67839.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGES
15A. NAME
AND
ADDRESS
OF
OFFEROR
SEC. PAGE(S) SEC. PAGE(S)
(Date) (Hour)
CALENDAR DAYS
14. ACKNOWLEDGMENT OF AMENDMENTS
(The offeror acknowledges receipt of amend-ments to the SOLICITATION for offerors and related documents numbered and dated:
(Type or Print)
SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 700)
RATING
PAGE OF
1 52
2. CONTRACT NO.
3. SOLICITATION NO.
75D301-18-R-67839
4. TYPE OF SOLICITATION
SEALED BID (IFB)
X NEGOTIATED (RFP)
5. DATE ISSUED
07/02/2018
6. REQUISITION/PURCHASE
NO.
00HCVLEE-2018-24118
7. ISSUED BY CODE 2536 8. ADDRESS OFFER TO (If other than Item 7)
Centers for Disease Control and Prevention
Acquisition and Assistance Branch 1
2920 Brandywine Road, MS E-15
Atlanta, GA 30341-5539
Approved as to Form and Legality: _____________________________
NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”
SOLICITATION
9. Sealed offers in original and copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in until 10AM ET local time 08/10/2018
CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR INFORMATION
CALL:
A. NAME
Germaine Mullins
B. TELEPHONE (NO COLLECT CALLS)
AREA CODE NUMBER: EXT:
(770) 488-1938
C. E-MAIL ADDRESS
GMULLINS@CDC.GOV
11. TABLE OF CONTENTS
(x) DESCRIPTION (x) DESCRIPTION
PART I – THE SCHEDULE PART II – CONTRACT CLAUSES
X A SOLICITATION/CONTRACT FORM 1 X I CONTRACT CLAUSES 32
X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X C DESCRIPTION/SPECS./WORK STATEMENT 4 X J LIST OF ATTACHMENTS 38
X D PACKAGING AND MARKING Erro r!
Book mark not defi ned.
PART IV – REPRESENTATIONS AND INSTRUCTIONS
X E INSPECTION AND ACCEPTANCE 16 REPRESENTATIONS, CERTIFICATIONS, AND
X F DELIVERIES OR PERFORMANCE 17 X K OTHER STATEMENTS OF OFFERORS 39
X G CONTRACT ADMINISTRATION DATA 21 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 43
X H SPECIAL CONTRACT REQUIREMENTS 24 X M EVALUATION FACTORS FOR AWARD 49
OFFER (Must be fully completed by offeror)
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52-232-8)
10 CALENDAR DAYS
20 CALENDAR DAYS
30 CALENDAR DAYS
AMENDMENT NO. DATE AMENDMENT NO. DATE
CODE FACILITY 16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER
15B. TELEPHONE NO.
AREA CODE NUMBER EXT.
15C. CHECK IF REMITTANCE ADDRESS
IS DIFFERENT FROM ABOVE - ENTER
SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE
18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
21. ACCOUNTING AND APPROPRIATION
10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( )
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
24. ADMINISTERED BY (If other than Item 7) CODE 2536 25. PAYMENT WILL BE MADE BY CODE 434
Centers for Disease Control and Prevention
Acquisition and Assistance Branch 1
2920 Brandywine Road, MS E-15
Atlanta, GA 30341-5539
Centers for Disease Control and Prevention (FMO)
PO Box 15580 404-718-8100
Atlanta, GA 30333-0080
26. NAME OF CONTRACTING OFFICER (Type or print)
27. UNITED STATES OF AMERICA
(Signature of Contracting Officer)
28. AWARD DATE
IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 33 (REV. 9-97)
PREVIOUS EDITION IS UNUSABLE Prescribed by GSA
FAR (48 CFR) 53.214©
K
Section B - Supplies Or Services And Prices/Costs
ITEM SUPPLIES / SERVICES QTY /
UNIT
UNIT PRICE EXTENDED
PRICE
0001 Active Surveillance Among School Children the National
Center for Emerging and Zoonotic Infectious Diseases
(Firm Fixed Price)
Non-Severable Services
Period of Performance: September 1, 2018 through August
31, 2021
1 Job
The Government anticipates a Firm Fixed Price requirement.
Performance-Based Payments Milestone Schedule
The Offeror shall propose performance based payments for Contract Line Item Number 0001
Task Number Milestone
Proposed Amount
Task 2 Summary and Evaluation of Past Chronic Disease Surveillance
Task 3 Train Nurse Workforce Data Champions
Task 4 Procure optimal platform for surveillance data
Task 5 Support enhanced surveillance data collection activities in 1 or more demonstration jurisdictions
Task 6.1 National Nurse Workforce Engagement Plan
Task 6.2 Support enhanced surveillance data collection nationwide
Task 7 Provide education to nurses about chronic illness conditions including ME/CFS and POTS
Task 8 Provide education to nurses about resources and best practices to support the educational success of students with chronic illnesses
Task 9 Evaluate the active surveillance system for chronic conditions using published resources
Task 10.1 In-person meeting with CDC Technical monitor and other invited staff
Task 10.2 Disseminate information regarding the process of implementing national active surveillance in schools
Task 11.1 Disseminate findings and lessons learned from the implementation of national active surveillance
Task 11.2 Disseminate findings and lessons learned from the implementation of national active surveillance
Reporting
Requirements (I)
Progress Report
Reporting
Requirements (II)
Final Report
Section C - Description/Specification/Work Statement
STATEMENT OF WORK
ACTIVE SURVEILLANCE AMONG SCHOOL CHILDREN FOR CHRONIC CONDITIONS
Background and Need
Myalgic encephalomyelitis/chronic fatigue syndrome (ME/CFS) is a complex, chronic, debilitating disease that involves several body systems. ME/CFS is characterized by reduced ability to perform pre-illness activities that lasts for more than 6 months and is accompanied by profound fatigue, which is not improved by rest. A hallmark of
ME/CFS is that symptoms can worsen after physical, mental, or emotional effort, a manifestation known as post-exertional malaise (PEM). Patients with ME/CFS also have unrefreshing sleep. Other common manifestations include orthostatic intolerance, cognitive impairment, and pain. Secondary psychological symptoms such as depression and anxiety may also be present in some patients with ME/CFS, as can be observed in people with other long-term chronic illnesses.
Currently, there is neither a diagnostic biomarker nor a cure for ME/CFS. The lack of a biomarker makes estimating incidence and prevalence of ME/CFS very challenging. A clinician can make the diagnosis of ME/CFS based on a thorough medical history and physical examination and after assessment for other fatiguing illnesses with a targeted evaluation.
Adults and children, including adolescents, have been diagnosed with ME/CFS. It has been estimated ME/CFS affects more than one million persons in the United States; however, among cases identified through past active, community-based surveillance for ME/CFS, less than 20% of those meeting diagnostic criteria for illness reported having received a diagnosis from a physician. Scientists estimate that up to 2 in 100 children suffer from ME/CFS, but few studies have been conducted in this vulnerable age group.
In many children and adults, the diagnosis of ME/CFS might not be considered because few clinicians are aware of this condition or the 2015 diagnostic criteria published by the Institute of Medicine (IOM). For some pediatric patients with ME/CFS, whether they have been diagnosed formally or not, activities of daily living, education, and social engagement can result in PEM, which leaves them unable to complete assignments or other needed tasks.
Some patients with ME/CFS are home- or bed-bound due to their illness symptoms. It has been hypothesized that
ME/CFS might account for a high proportion of chronic school absenteeism and school withdrawal. More data are needed to characterize the frequency of chronic school absenteeism and school withdrawal. Identifying which clinical diagnoses are associated with children experiencing chronic school absenteeism and school withdrawal is important to defining interventions that would help ensure health and school attendance. Given that some children with ME/CFS might not receive timely or appropriate diagnoses from their primary care providers, monitoring symptoms of ME/CFS would be helpful. Educating school nurses about ME/CFS might also enable them to suggest the diagnosis to parents or guardians when students’ symptoms are possibly consistent with the 2015 IOM diagnostic criteria.
Through a needs assessment that the ME/CFS program of the Centers for Disease Control and Prevention (CDC) conducted in 2013, state epidemiologists indicated that they would like to have information about the burden of
ME/CFS in their states. In January 2017, the Chronic Fatigue Syndrome Advisory Committee (CFSAC) of the
U.S. Department of Health and Human Services (HHS) recommended that HHS “educate educators and school nurses on ME/CFS affecting children and adolescents.” Active national surveillance in schools for ME/CFS coupled with education of school nurses about ME/CFS could help improve estimates of the burden of ME/CFS in children and lead to the improvement of services to children suffering from this and other chronic health conditions. Having baseline data about other chronic conditions, including, but not limited to asthma, diabetes type
I, diabetes type II, and seizures would help inform the interpretation of future data and would also help guide interventions to help students experiencing health-related academic challenges.
Purpose https://www.cdc.gov/me-cfs/me-cfs-children/index.html https://www.cdc.gov/me-cfs/me-cfs-children/index.html
The purpose of this requirement is to educate and support school nurse workforce so that they can conduct national active surveillance among U.S. school children for chronic conditions, including myalgic encephalomyelitis/chronic fatigue syndrome (ME/CFS), and characterize the association of these chronic conditions with chronic school absenteeism and school withdrawal.
Project Objectives
The project objectives for this requirement include the following:
1. Engage the school nurse workforce at multiple levels (e.g., local, district, state, and national levels) to collect data pertaining to chronic conditions, chronic school absenteeism, and school withdrawal as well other relevant data (e.g., student population size and types of schools with reported data, characteristics of school nurse workforce at local and other levels).
2. Provide continuing nursing education (CNE) regarding ME/CFS and resources available to students with chronic conditions, using ME/CFS as an example.
3. Provide technical assistance, support, training, and data platform(s) to the school nurse workforce to facilitate the collection of active surveillance data and to facilitate analysis and dissemination of the active surveillance data.
4. Evaluate the active surveillance system for chronic conditions, including ME/CFS, using resources including the Updated Guidelines for Evaluating Public Health Surveillance Systems:
Recommendations from the Guidelines Working Group available at:
https://www.cdc.gov/mmwr/PDF/rr/rr5013.pdf
5. Disseminate information regarding the process of implementing national active surveillance in schools to interested stakeholders (including to CFSAC).
6. Disseminate findings and lessons learned from the implementation of national active surveillance in schools to interested stakeholders (including to CFSAC).
7. Develop and publish in collaboration with the funding agency at least one peer-reviewed publication related to the implementation of national active surveillance for chronic conditions, chronic school absenteeism, and school withdrawal.
Scope of Work
Independently and not as an agent of the Government, the offeror shall provide all personnel, facilities, facilities equipment, materials, and supplies to conduct the national active surveillance for chronic conditions. The offeror shall provide personnel that have demonstrated expertise and experience with working with the school nurse workforce in at least 45 states to collect and submit data pertaining to the standardized definitions for chronic illnesses and other parameters.
Technical Requirements
The offeror shall have expertise and ability to train and provide technical assistance to school nurses across the country and shall be able to provide future continuing nursing education (CNE) regarding ME/CFS and available resources to students with chronic conditions. The offeror shall perform the following specific tasks:
Task 1. Kick-off Meeting
The offeror shall participate in a kick-off meeting and provide the minutes to the Government.
Task 2. Complete a summary and evaluation of past chronic disease surveillance in U.S. schools.
The offeror shall complete a summary and evaluation of past chronic disease surveillance in U.S. schools. This document shall include the uniform definitions used in past surveillance efforts as well as other information regarding data collection and barriers encountered. Discussion shall include activities needed to strengthen surveillance as identified through evaluation.
Task 3. Conduct training for nurse workforce data champions.
The offeror shall provide training for the nurse workforce data champions. The training address topics including data fidelity, data-sharing agreements, and messaging to local and other school nurses regarding initiating or continuing engagement with data collection and other surveillance efforts.
Task 4. Identify and procure the most optimal data platform to facilitate the collection, cleaning, analysis and dissemination of surveillance data related to chronic conditions, chronic school absenteeism, and school withdrawal.
The offeror shall identify and procure the most optimal data platform to facilitate the collection, cleaning, analysis, and dissemination of surveillance data related to chronic conditions, chronic school absenteeism, and school withdrawal. This process can be informed by the evaluation efforts identified as Task 2.
Task 5. Support the conduct of enhanced surveillance data collection activities in one or more demonstration jurisdictions
The offeror shall support the conduct of data collection activities in one or more demonstration jurisdictions in which some or all of the following conditions exist: uniformity of software available to state nurse workforce, known or pre-existing efforts in public health, clinical, or advocacy communities to increase awareness of
ME/CFS, or known or improving availability of area clinicians with expertise in the diagnosis and management of
ME/CFS.
Task 6. Support the conduct of surveillance data collection activities by the school nurse workforce nationwide.
The offeror shall provide technical assistance to the school nurse workforce nationwide. To facilitate this process, the offeror shall develop a National Nurse Workforce Engagement Plan. The Engagement plan shall be informed by a needs assessment. Technical assistance might be provided directly or through “train-the-trainer” support of nurse workforce data champions or others. This technical assistance might include activities such as statistical or data management support.
Task 7. Provide education to nurses about chronic illness conditions including ME/CFS and postural orthostatic tachycardia syndrome (POTS)
The offeror shall provide education to nurses about chronic illness conditions including ME/CFS and postural orthostatic tachycardia syndrome (POTS). Initial education might be informal to facilitate the kick-off of surveillance for these chronic conditions and other causes of chronic absenteeism and early withdrawal. However, an enduring webinar or other program that offers at least one unit of Continuing Nursing Education (CNE) is required to complete this task. This shall be made available as a first priority to nurses participating in the active surveillance effort, but may also be made more widely available to nurses in private and other school settings.
Task 8. Provide education to nurses about resources and best practices to support the educational success of students with chronic illnesses, using a case vignette or similar tool featuring ME/CFS.
The offeror shall provide education to nurses about resources and best practices to support the educational success of students with chronic illnesses, using a case vignette or similar tool featuring ME/CFS. A webinar or other program that offers at least one unit of Continuing Nursing Education is required to complete this task. This shall be made available as a first priority to nurses participating in the active surveillance effort, but may also be made more widely available to nurses in private and other school settings.
Task 9. Evaluate the active surveillance system for chronic conditions using published resources.
The offeror shall evaluate the active surveillance system for chronic conditions using resources including the
Updated Guidelines for Evaluating Public Health Surveillance Systems: Recommendations from the Guidelines
Working Group available at: https://www.cdc.gov/mmwr/PDF/rr/rr5013.pdf Additional resources include chapter 8 of Principles and Practice of Public Health Surveillance (3rd ed).
Task 10. Disseminate information regarding the process of implementing national active surveillance in schools to interested stakeholders (including, but not limited, to CFSAC).
The offeror shall provide information regarding the process of implementing national active surveillance in schools to interested stakeholders (including to CFSAC). The offeror shall have at least one (1) in-person meeting every 12 months at CDC in Atlanta, Georgia.
Task 11. Disseminate findings and lessons learned from the implementation of national active surveillance in schools to interested stakeholders (including, but not limited, to CFSAC).
The offeror shall disseminate findings and lessons learned from the implementation of national active surveillance in schools to interested stakeholders (including to CFSAC). This task includes preparation of at least one (1) manuscript jointly authored with CDC for publication in a peer-reviewed journal and at least one (1) webinar, which shall be posted on a website available to both the school nurse workforce and the general public.
Government Furnished Property
The tasks listed in the Statement of Work do not require the offeror to have access to Government IT resources.
HHSAR Provision, 352.239-73: Electronic and Information Technology Accessibility Notice
(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of
1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT)
Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.
(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at http://www.hhs.gov/web/508. The complete text of the
Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.
(c) The Section 508 accessibility standards applicable to this contract are: 1194.
205 WCAG 2.0 Level A & AA Success Criteria
302 Functional Performance Criteria
502 Inoperability with Assistive Technology
503 Applications
504 Authoring Tools
602 Support Documentation
603 Support Services
In order to facilitate the Government's determination whether proposed EIT supplies meet applicable Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and documentation detail - whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues.
http://www.hhs.gov/web/508 http://www.access-board.gov/sec508/standards.htm
Instructions for preparing the HHS Section 508 Evaluation Template are available under Section 508 policy on the
HHS Web site http://hhs.gov/web/508.
In order to facilitate the Government's determination whether proposed EIT services meet applicable Section 508 accessibility standards, offerors must provide enough information to assist the Government in determining that the
EIT services conform to Section 508 accessibility standards, including any underway remediation efforts addressing conformance issues.
(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If a offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the
Government, i.e., after award of a contract or order, that supplies or services delivered do not conform to the accessibility standards, remediation of the supplies or services to the level of conformance specified in the contract will be the responsibility of the Contractor at its expense.
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of
“information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal Information
Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
http://hhs.gov/web/508
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information
Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information
Security Program security requirements, outlined in the HHS Information Security and Privacy Policy
(IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or
Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R.
2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed.
Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information
Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal
Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
4) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB
Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
5) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor.
Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with
HHS and CDC policies. Unauthorized disclosure of information will be subject to the HHS/CDC sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
6) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB
Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .
7) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport
Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the
HTTPS is not required, but it is highly recommended.
8) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
See Appendix D for baseline deliverables.
9) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements.
Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including
PII).
d. Verify that the encryption solutions in use have been validated under the Cryptographic Module
Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR [CDC-provided delivery date].
e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC Office of Chief
Information Security Officer (OCISO).
10) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the
Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
See Appendix C for the HHS Contractor Non-Disclosure Agreement.
11) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the
CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security
Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awarness Training
(SAT) and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within
60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant
Security Responsibilities Memorandum.
All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed
ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act
(FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable
Information” (03 January 2017) states:
Definition of an Incident:
An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach:
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses
PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII” .
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
2) All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.
4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and without unreasonable delay, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team
(US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center
(CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at cdc@csirt.gov or telephone at 866-655-2245, whether the response is positive or negative.
5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.
6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response
Plan and to assist with responding to a breach.
7) Cloud service providers shall use guidance provided in the FedRAMP Incident Communications
Procedures when deciding when to report directly to US-CERT first or notify CDC first.
8) Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the
HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so instructed by the
Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC-approved notifications to affected individuals; and,
9) Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.
E. Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal
Regulations (CFR).
The requiring activity representative, in conjunction with Personnel Security, shall use the OPM Position
Sensitivity Designation automated tool (https://www.opm.gov/investigations/) to determine the sensitivity designation for background investigations. After making those determinations, include all applicable position sensitivity designations.
F. Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential
Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors;
OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS
HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO by the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted immediately upon change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
G. Contract Initiation and Expiration
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS
Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology and in accordance with the HHS
Contract Closeout Guide (2012).
https://www.opm.gov/investigations/ https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-
64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for
Media Sanitization.
4) Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO before an employee stops working under this contract.
5) Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or CDC policies.
6) The Contractor (and/or any subcontractor) shall perform and document the actions identified in the CDC
Out-Processing Checklist (http://intranet.cdc.gov/od/hcrmo/pdfs/hr/Out_Processing_Checklist.pdf) when an employee terminates work under this contract. All documentation shall be made available to the CO and/or COR upon request.
H. Records Management and Retention
The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order
13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS policies and shall not dispose of any records unless authorized by
HHS.
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS policies.
HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html http://intranet.cdc.gov/od/hcrmo/pdfs/hr/Out_Processing_Checklist.pdf
Section D - Packaging And Marking
There are no clauses/provisions included in this section.
Section E - Inspection And Acceptance
E.1 FAR 52.246-4 Inspection of Services—Fixed-Price (Aug 1996)
(a) Definition. “Services,” as used in this clause, includes services performed, workmanship, and material furnished or utilized in the performance of services.
(b) The Contractor shall provide and maintain an inspection system acceptable to the Government covering the services under this contract. Complete records of all inspection work performed by the Contractor shall be maintained and made available to the Government during contract performance and for as long afterwards as the contract requires.
(c) The Government has the right to inspect and test all services called for by the contract, to the extent practicable at all times and places during the term of the contract. The Government shall perform inspections and tests in a manner that will not unduly delay the work.
(d) If the Government performs inspections or tests on the premises of the Contractor or a subcontractor, the
Contractor shall furnish, and shall require subcontractors to furnish, at no increase in contract price, all reasonable facilities and assistance for the safe and convenient performance of these duties.
(e) If any of the services do not conform with contract requirements, the Government may require the Contractor to perform the services again in conformity with contract requirements, at no increase in contract amount. When the defects in services cannot be corrected by reperformance, the Government may—
(1) Require the Contractor to take necessary action to ensure that future performance conforms to contract requirements; and
(2) Reduce the contract price to reflect the reduced value of the services performed.
(f) If the Contractor fails to promptly perform the services again or to take the necessary action to ensure future performance in conformity with contract requirements, the Government may—
(1) By contract or otherwise, perform the services and charge to the Contractor any cost incurred by the Government that is directly related to the performance of such service; or
(2) Terminate the contract for default.
(End of clause)
Section F - Deliveries Or Performance
F.1 FAR 52.242-15 Stop-Work Order (Aug 1989)
(a) The Contracting Officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either—
(1) Cancel the stop-work order; or
(2) Terminate the work covered by the order as provided in the Default, or the Termination for Convenience of the
Government, clause of this contract.
(b) If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if—
(1) The stop-work order results in an increase in the time required for, or in the Contractor’s cost properly allocable to, the performance of any part of this contract; and
(2) The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage;
provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.