RFQ_75D301-19-Q-70517_07182019.pdf
PDF 887 KB Posted
- Attached to
- Tuberculosis Trials Consortium Study 35 Federal contract opportunity
- Solicitation number
- 75D301-19-Q-70517
About this file
Solicitation
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_00002.pdf | ||
| TBTC_35_Clarifying_Questions_and_Answers_080719.pdf | ||
| Amendment_00001.pdf | ||
| TBTC_35_Questions_and_Answers_Final_080219_revised.pdf | ||
| Attachment_4_Past_Performance_Survey.pdf | ||
| Attachment_1_Appendix_A_FDA_RBM.pdf | ||
| Attachment_3_Consent_Letter.docx | DOCX document | |
| Attachment_2_Appendix_B_S35_Summary.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
REQUEST FOR QUOTATIONS
(THIS IS NOT AN ORDER)
THIS RFQ IS X IS NOT A SMALL BUSINESS SET-ASIDE.
PAGE OF PAGES
1 66
1. REQUEST NO.
75D301-19-Q-70517
2. DATE ISSUED
3. REQUISITION/PURCHASE REQUEST NO.
00HCVJEE-2019-36755
4. CERT. FOR NAT. DEF.
UNDER BDSA REG. 2
AND/OR DMS REG. 1
RATING
5a. ISSUED BY
Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS)
2900 Woodcock Blvd, MS TCU-4
Atlanta GA 303414004
6. DELIVERY BY (Date)
8/13/2019, 5PM EST
5b. FOR INFORMATION CALL (No collect calls)
NAME TELEPHONE NUMBER
AREA CODE NUMBER
Timothy Barnes (770) 488-2883 x
8. TO: 9. DESTINATION
a. NAME b. COMPANY a. NAME OF CONSIGNEE
c. STREET ADDRESS b. STREET ADDRESS
c. CITY
d. CITY e. STATE f. ZIP CODE d. STATE e. ZIP CODE
10. PLEASE FURNISH QUOTATIONS TO
THE ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS (Date)
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services.
Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State and local taxes)
ITEM NO.
(a)
SUPPLIES/SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e)
AMOUNT
(f)
“See Continuation Page”
12. DISCOUNT FOR PROMPT PAYMENT
a. 10 CALENDAR DAYS
b. 20 CALENDAR DAYS
c. 30 CALENDAR DAYS
d. CALENDAR DAYS
NUMBER PERCENTAGE
NOTE: Additional provisions and representations are are not attached.
13. NAME AND ADDRESS OF QUOTER 14. SIGNATURE OF PERSON AUTHORIZED TO
SIGN QUOTATION
15. DATE OF
QUOTATION
a. NAME OF QUOTER
b. STREET ADDRESS 16. SIGNER
a. NAME (Type or print) b. TELEPHONE
c. COUNTY AREA CODE
d. CITY e. STATE f. ZIP CODE c. TITLE (Type or print) NUMBER
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 18 (REV. 6-95)
Previous edition not usable Prescribed by GSA FAR (48 CFR) 53.215-1(a)
7. DELIVERY
FOB
DESTINATION
OTHER
(See Schedule)
SUPPLIES/SERVICES
Line Items
Base Year: Period of Performance – 9/1/2019 - 8/31/2020
ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE
0001 TBTC Study 35 On Site Monitoring
This is a fixed price CLIN
1 Job
0002 Travel
This is a cost reimbursement CLIN subject FAR 52.232-20 Limitation of
Cost
Note: The quantity/unit will be considered 1 Job. Therefore, your Unit Price will be the same as the Extended Price
Option Year 1: Period of Performance – 9/1/2020 - 8/31/2021
ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE
1001 TBTC Study 35 on Site Monitoring
This is a fixed price CLIN
1002 Travel
This is a cost reimbursement CLIN subject FAR 52.232-20 Limitation of
Cost
Note: The quantity/unit will be considered 1 Job. Therefore, your Unit Price will be the same as the Extended Price
Statement of Work
Title: TBTC Study 35 On-Site Monitoring
C.1 BACKGROUND
The Tuberculosis Trials Consortium (TBTC) is a domestic and international network of clinical research sites conducting programmatically relevant research on the treatment and prevention of tuberculosis disease. The TBTC was formally organized in 1997. Recompetition for research sites occurred in 1999 and 2009. The Data & Coordinating Center (DCC) of the TBTC is based within the US Centers for Disease Control and Prevention’s Division of Tuberculosis
Elimination. The TBTC DCC team includes medical officers, epidemiologists, data analysts, data managers, statisticians, data clerks, and various support staff. CDC is the sponsor for Study
35 and for all TBTC trials.
As this trial is conducted under Investigational New Drug (IND) authorization and is partially funded by Unitaid (an international organization that invests in innovations to prevent, diagnose and treat HIV/AIDS, tuberculosis and malaria more quickly, affordably and effectively) it has the potential to be audited by the US Food & Drug Administration and/or European Medicines
Agency. It is the first trial of the study product administered to children. Because this study involves young children (by definition, a vulnerable population), CDC is especially concerned to assure safety and minimize risks to participants.
The following will be required for this trial:
On-site initiation visits for all participating sites prior to first enrollment;
On-site periodic monitoring visits;
On-site close out visits;
Tracking of monitoring activities and deficiencies; and
Reports of monitoring findings.
This trial will be conducted only in South Africa, in Johannesburg and Cape Town, at a minimum of three clinical research sites. Enrollment is expected to begin in July of 2019 and continue until December of 2020. All children are followed for 24 weeks post-enrollment. Total enrollment is expected to be 72 children.
SUBSECTION A – DEFINITIONS
TBTC Tuberculosis Trials Consortium
DCC Data & Coordinating Center of the TBTC, housed within CDC’s Division of TB
Elimination
Study 35 a Phase I/II Dose Finding and Safety Study of Rifapentine and Isoniazid in HIV-
Infected and HIV-Uninfected Children with Latent Tuberculosis Infection
IND Investigational new drug
CRO Contract research organization
PK Pharmacokinetics
PD Pharmacodynamics
PG Pharmacogenomics
TBTC2 TBTC’s custom-designed, web-based, study management system used for electronic data capture, study product management and accountability, site information reporting, and dissemination of quality assurance reports
C.2 PURPOSE
The purpose of this requirement is to provide on-site monitoring of the clinical research sites, pharmacies, and laboratories participating in TBTC Study 35, following FDA Guidance and requirements, direction and guidance from the TBTC (DCC) project lead(s). This on-site monitoring will include, at a minimum, regulatory document review, source document verification, study product accountability, and laboratory compliance visits.
This requirement announcement proposes to award a contract research organization to conduct on-site monitoring for TBTC Study 35, a Phase I/II dose finding and safety study of rifapentine and isoniazid in HIV-infected and HIV-uninfected children with latent tuberculosis infection.
C.3 SCOPE OF WORK
The scope of this requirement is to provide on-site monitoring of clinical research sites, pharmacies, and laboratories participating in clinical trial TBTC Study 35. Study 35 is a Phase
I/II dose finding and safety study of rifapentine and isoniazid in HIV-infected and HIV-uninfected children with latent tuberculosis infection. The monitor will follow FDA Guidance for Industry on Oversight of Clinical Investigations – A Risk-Based Approach to Monitoring
(https://www.fda.gov/downloads/Drugs/.../Guidances/UCM269919.pdf ) (Appendix A). This guidance will ensure clinical trial quality and participant safety, adherence to U.S. and international standards of good clinical practice, data collection and reporting, regulatory compliance, accurate protocol implementation, internal quality management and study product accountability. An overview of the study can be found in Appendix B.
To support the on-site monitoring, the TBTC Data & Coordinating Center housed within CDC's
Division of TB will provide to the successful offeror:
Access to and training for the TBTC2 study management system;
Protocol and case report form training;
Guidance on protocol implementation;
Input into the Study 35 monitoring plan incorporating principles of risk based monitoring;
Documentation of obligations transferred from sponsor to the successful offeror (contract research organization, or CRO);
Central monitoring of Study 35 data and activities;
Quality assurance of Study 35 data; and
Pre-site visit reports and information prioritizing tasks at on-site visits.
C.4 TASKS TO BE PERFORMED
The contractor shall, as an independent organization and not as an agent of the Government, furnish all necessary services, qualified personnel, material, equipment, and facilities to conduct on-site monitoring for the TBTC Study 35. The expected duration of this contract is two-years.
Specific requirements and tasks include the following:
a. Draft Monitoring Plan
b. Visit types. The CRO shall conduct three types of visits as described below
1. Initiation visits
i. Will occur at least two (2) weeks before planned study start;
ii. Visit is expected to last two (2) to four (4) days; and
iii. Activities to include: regulatory review, pharmacy visit, PK laboratory visit, and assessment of quality implementation and training needs.
2. Periodic visits Will occur after the first two (2) study participants are enrolled or no later than six (6) months after the initiation visit;
i. Two (2) to three (3) visits will occur annually at each site;
ii. Each visit is expected to last two (2) to five (5) days; and
iii. Activities to include: regulatory review, pharmacy visit, study medication accountability audit;
iv. PK laboratory visit, informed consent verification, complete review of first two participant charts; essential data source document verification, directly observed therapy observation, follow-up of sponsor-identified issues, follow-up of previous monitoring findings, and assessment of quality implementation and training needs.
3. Close out visit
i. Will occur once after all participants have completed the study;
ii. Visit is expected to last two (2) to four (4) days; and
iii. Activities to include regulatory review, pharmacy visit, PK laboratory visit, informed consent verification, essential data source document verification, study medication reconciliation, follow-up of sponsor-identified issues, and follow-up of previous monitoring findings.
c. Visit preparation. At least 30 days prior to a planned visit, the CRO shall Notify DCC, in writing, via email of upcoming monitoring visit, including
i. Planned activities;
ii. Length of visit; and
iii. Name of monitor(s);
d. Visit activities.
1. Regulatory review – Review of essential documents and the investigator files as required per US Human Subjects Protection and FDA regulations, ICH GCP, and
South African regulatory requirements.
2. Informed consent verification - 100% of all informed consent and assent documents must be reviewed
3. Complete review of first two participant charts - 100% source document verification for all data and results within the first two participant charts.
4. Essential data source document verification - 100% of sponsor-identified essential data must be verified against source documents. Essential data include, but are not limited to, data on
i. Eligibility;
ii. Targeted review of serious adverse events;
iii. Targeted review of suspected tuberculosis events; and
iv. Data and results that will be used to evaluate primary and secondary study end-points.
e. Pharmacy visit – observation and monitoring to ensure compliance with study procedures;
1. Study medication accountability audit – accounting of study medication requested, received, dispensed, and returned, including accounting for destruction as applicable;
2. Directly observed therapy observation – observation of therapy administration from pharmacy dispensing to ingestion by study participant;
3. PK laboratory visit – observation and monitoring to ensure compliance with study procedures;
4. Follow-up on sponsor-identified issues – as applicable, and per requirements from sponsor;
5. Follow-up on previous monitoring findings – as applicable from previous visits; and
6. Assessment of quality of study implementation and training needs
f. Documentation of findings, reports, and communication. During or following each monitoring visit, the CRO shall:
1. Communicate immediately with DCC team if an urgent issue or question arises during an on-site visit;
2. Within 3 business days of completion of visit, send email to the DCC team with high-level, preliminary structured summary of visit findings;
3. Within 10 business days of completion of visit, send a draft monitoring report to
DCC team, following agreed upon report format and communication method
4. Within 30 business days of completion of visit, send a final monitoring report to
DCC team, following agreed upon report format and communication method;
5. Within 10 days of monitor’s review of the resolution or corrective action of any deficiencies noted during the monitoring visit, send a monitoring follow-up report;
6. Document participant-specific monitoring findings in the TBTC2 study management system at the time of the site visit;
7. Respond to any requests for clarification from summary email or monitoring report within 3 business days of receipt;
8. Maintain a log of findings from site visits;
9. Communicate with study site teams to document resolution of any findings; and
10. Maintain a log of participant charts reviewed.
C.5 – GOVERNMENT FURNISHED MATERIALS/PROPERTY
None.
This contract will not provide government furnished property.
C.6 – PERIOD OF PERFORMANCE
Base Year: September 1, 2019 – August 31, 2020
Option Year One: September 1, 2020 – August 31, 2021
C.7 – PLACE OF PERFORMANCE
Work under this contract will be performed at the following places:
Contractor’s facility;
Stellenbosch University; Cape Town, Republic of South Africa (RSA);
o Desmond Tutu TB Centre, Francie van Zijl Avenue, Clinical Building, K Floor, Tygerberg Hospital, Cape Town, RSA o Brooklyn Chest Hospital, Stanberry Street, Ysterplaat, Cape Town, RSA o KIDCRU, Francie van Zijl Avenue, Ward J8, Tygerberg Hospital, Cape Town, RSA
C.8 – DELIVERABLES/REPORTING SCHEDULE
Items Task # Description Quantity or No. of
Copies
Delivery Date Deliver To
Constance Henderson, csh1@cdc.gov, and the email listed below
Draft
Monitoring
Plan
C.4.a. Plan that provides a detailed description of the monitoring plan electronic copy
30 days after contract award tbtcresearchadmin@cdc.gov
Monitoring visit notification
C.4.b. Notification of upcoming monitoring visit electronic copy
30 days prior to planned monitoring visit tbtcresearchadmin@cdc.gov
Preliminary structured summary of monitoring visit
Findings
C.4.f.2 High level summary of the monitoring visit to include any major issues noted electronic copy
3 business days after completion of monitoring visit tbtcresearchadmin@cdc.gov
Draft site monitoring report
C.4.f.3. Summary of the monitoring visit electronic copy
Within 10 business days of completion of monitoring visit tbtcresearchadmin@cdc.gov
Final Site monitoring report
C.4.f.4. Finalized summary of the monitoring visit electronic copy
30 days after completion of monitoring visit tbtcresearchadmin@cdc.gov
Site monitoring follow-up report
C.4.f.5. Summary of the resolution/corrective action that was implemented to address issues noted during the monitoring visit electronic copy
10 days after the monitor’s review of the resolution/corrective action tbtcresearchadmin@cdc.gov
C.9 – TRAVEL
Travel to implementing clinical sites, research pharmacies, and PK analysis laboratories in South
Africa will be required to complete work in this contract.
C.10 – SPECIAL REQUIREMENTS
1. If the CRO plans to sub-contract this work CDC must approve of the sub-contractor prior to the award of the contract.
2. The contractor will need to utilize TBTC2, which is the web application that is used for data management of TBTC’s clinical research studies. Requests for access to TBTC2 must be sent to TBTCStudy35@cdc.gov at least one week prior to planned site visits.
mailto:TBTCStudy35@cdc.gov
C.11 – MINIMUM QUALIFICATION
At least 5 years of experience in the last 10 years performing on-site monitoring for clinical research sites in South Africa conducting pharmacokinetic trials in children.
Contract Administration Data
1. Contract Communications/Correspondence (Jul 1999)
The Contractor shall identify all correspondence, reports, and other data pertinent to this contract by imprinting thereon the contract number from Page 1 of the contract.
(End of Clause)
2. Contracting Officer (Jul 1999)
(a) The Contracting Officer is the only individual who can legally commit the Government to the expenditure of public funds. No person other than the Contracting Officer can make any changes to the terms, conditions, general provisions, or other stipulations of this contract.
(b) No information, other than that which may be contained in an authorized modification to this contract, duly issued by the Contracting Officer, which may be received from any person employed by the United States Government, or otherwise, shall be considered grounds for deviation from any stipulation of this contract.
3. CDC0_G008 Contracting Officer’s Representative (COR) (Jul 2017)
Performance of the work hereunder shall be subject to the technical directions of the designated
COR for this contract.
As used herein, technical directions are directions to the Contractor which fill in details, suggests possible lines of inquiry, or otherwise completes the general scope of work set forth herein.
These technical directions must be within the general scope of work, and may not alter the scope of work or cause changes of such a nature as to justify an adjustment in the stated contract price/cost, or any stated limitation thereof.
In the event that the Contractor believes full implementation of any of these directions may exceed the scope of the contract, he or she shall notify the originator of the technical direction and the Contracting Officer, immediately or as soon as possible, in a letter or e-mail separate of any required report(s). No technical direction, nor its fulfillment, shall alter or abrogate the rights and obligations fixed in this contract.
The Government COR is not authorized to change any of the terms and conditions of this contract. Contract changes shall be made only by the Contracting Officer by properly written modification(s) to the contract.
The Government will provide the Contractor with a copy of the COR delegation memorandum upon request.
4. Payment by Electronic Funds Transfer (Feb 2018)
(a) The Government shall use electronic funds transfer to the maximum extent possible when making payments under this contract. FAR 52.232-33, Payment by Electronic Funds Transfer –
System for Award Management, in Section I, requires the contractor to designate in writing a financial institution for receipt of electronic funds transfer payments.
(b) In the case that EFT information is not within the System of Award Management, FAR
52.232-34 requires mandatory submission of Contractor’s EFT information directly to the office designated in this contract to receive that information (hereafter: “designated office”); see below.
The contractor shall submit the EFT information within the form titled “ACH
Vendor/Miscellaneous Payment Enrollment Form” to the address indicated below. Note: The form is either attached to this contract (see Section J, List of Attachments) or may be obtained by contacting the Contracting Officer or the CDC Office of Financial Resources at 678-475-4510.
(c) In cases where the contractor has previously provided such information, i.e., pursuant to a prior contract/order, and been enrolled in the program, the form is not required unless the designated financial institution has changed.
(d) The completed form shall be mailed after award, but no later than 14 calendar days before an invoice is submitted, to the following address:
The Centers for Disease Control and Prevention
Office of Financial Resources (OFR)
P.O. Box 15580
Atlanta, GA 30333
Or – Fax copy to: 404-638-5342
5. CDC42.0002 Evaluation of Contractor Performance Utilizing CPARS (Apr 2015)
In accordance with FAR 42.15, the Centers for Disease Control and Prevention (CDC) will review and evaluate contract performance. FAR 42.1502 and 42.1503 requires agencies to prepare evaluations of contractor performance and submit them to the Past Performance
Information Retrieval System (PPIRS). The CDC utilizes the Department of Defense (DOD) web-based Contractor Performance Assessment Reporting System (CPARS) to prepare and report these contractor performance evaluations. All information contained in these assessments may be used by the Government, within the limitations of FAR 42.15, for future source selections in accordance with FAR 15.304 where past performance is an evaluation factor.
The CPARS system requires a contractor representative to be assigned so that the contractor has appropriate input into the performance evaluation process. The CPARS contractor representative will be given access to CPARS and will be given the opportunity to concur or not-concur with performance evaluations before the evaluations are complete. The CPARS contractor representative will also have the opportunity to add comments to performance evaluations.
The assessment is not subject to the Disputes clause of the contract, nor is it subject to appeal beyond the review and comment procedures described in the guides on the CPARS website.
Refer to: www.cpars.gov for details and additional information related to CPARS, CPARS user access, how contract performance assessments are conducted, and how Contractors participate.
Access and training for all persons responsible for the preparation and review of performance assessments is also available at the CPARS website.
The contractor must provide the CDC contracting office with the name, e-mail address, and phone number of their designated CPARS representative who will be responsible for logging into CPARS and reviewing and commenting on performance evaluations. The contractor must maintain a current representative to serve as the contractor representative in CPARS. It is the contractor’s responsibility to notify the CDC contracting office, in writing (letter or email), when their CPARS representative information needs to be changed or updated. Failure to maintain current CPARS contractor representative information will result in the loss of an opportunity to review and comment on performance evaluations.
[End of Clause]
6. CDCA_G001 – Invoice Submission (Jul 2017)
(a) The Contractor shall submit the original contract invoice/voucher to the address shown below:
The Centers for Disease Control and Prevention
Office of Financial Resources (OFR)
P.O. Box 15580
Atlanta, GA 3033
Or – The Contractor may submit the original invoice via facsimile or email:
Fax: 404-638-5324
Email: FMOAPINV@CDC.GOV
NOTE: Submit to only one (1) of the above locations.
(b) The contractor shall submit 2 copies of the invoice to the cognizant contracting office previously identified in this contract. These invoice copies shall be addressed to the attention of the Contracting Officer.
(c) The Contractor is , is not required to submit a copy of each invoice directly to the
Contracting Officer’s Representative (COR) concurrently with submission to the Contracting
Officer.
http://www.cpars.gov/ mailto:FMOAPINV@CDC.GOV
(d) In accordance with 5 CFR part 1315 (Prompt Payment), CDC's Office of Financial
Resources is the designated billing office for the purpose of determining the payment due date under FAR 32.904.
(e) The Contractor shall include (as a minimum) the following information on each invoice:
(1) Contractor’s Name & Address
(2) Contractor’s Tax Identification Number (TIN)
(3) Purchase Order/Contract Number and Task Order Number, if Appropriate
(4) Invoice Number
(5) Invoice Date
(6) Contract Line Item Number and Description of Item
(7) Quantity
(8) Unit Price & Extended Amount for each line item
(9) Shipping and Payment Terms
(10) Total Amount of Invoice
(11) Name, title and telephone number of person to be notified in the event of a defective invoice
(12) Payment Address, if different from the information in (c)(1).
(13) DUNS + 4 Number
(14) Electronic funds transfer (EFT) banking information
Special Contract Requirements
1. CDC37.0001 Non-Personal Services (April 2015)
(a) Personal services shall not be performed under this contract. Although the Government may provide sporadic or occasional instructions within the scope of the contract, the Contractor is responsible for control and supervision of its employees. If the Contractor (including its employees) believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the
Contractor shall promptly notify the Contracting Officer of this communication or action.
(b) The contractor shall comply with, and ensure their employees and subcontractors comply with, CDC Policy titled “Identification of Contractors' Employees and Safeguarding Government
Information.” No Contractor employee shall hold him or herself out to be a Government employee, agent, or representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as
Contractor employees and specify the name of the company for which they work. . The contractor is limited to performing the services identified in the contract statement of work and shall not interpret any communication with anyone as a permissible change in contract scope or as authorization to perform work not described in the contract. All contract changes will be incorporated by a modification signed by the Contracting Officer.
(c) The Contractor shall ensure that all of its employees and subcontractor employees working on this contract are informed of the substance of this clause. The Contractor agrees that this is a non-personal services contract; and that for all the purposes of the contract, the Contractor is not, nor shall it hold itself out to be an agent or partner of, or joint venture with, the Government.
The Contractor shall notify its employees that they shall neither supervise nor accept supervision from Government employees. The substance of this clause shall be included in all subcontracts at any tier.
(d) Nothing in this clause shall limit the Government's rights in any way under any other provision of the contract, including those related to the Government's right to inspect and accept or reject the services performed under this contract.
2. Special Security Requirements
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter
“contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission.
In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal Information
Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal
Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS
Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS
Information Security Program security requirements, outlined in the HHS Information Security and
Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for
Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each
Security Objective and the Overall Risk Level, which is the highest watermark of the three factors
(Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [ X ] Low [ ] Moderate [ ] High
Integrity: [ X ] Low [ ] Moderate [ ] High
Availability: [ X ] Low [ ] Moderate [ ] High
Overall Risk Level: [ X ] Low [ ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[ X ] No PII [ ] Yes PII
4) Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB)
Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.”
Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [ ] Low [ ] Moderate [ ] High
5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or
Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R.
2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed.
Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information
Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal
Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor
(and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor
(and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor.
Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with
HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB
Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .
9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport
Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
10) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
11) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use have been validated under the Cryptographic Module
Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC
Office of Chief Information Security Officer (OCISO).
12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the
CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
See Appendix C for the Contractor Non-Disclosure Agreement.
13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-
22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the
CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information
Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security
Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with
Significant Security Responsibilities Memorandum.
All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act
(FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:
Definition of an Incident:
An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach:
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as
“a suspected or confirmed incident involving PII”.
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
2) All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.
4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency
Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer
Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within
24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.
5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.
6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach
Response Plan and to assist with responding to a breach.
7) Cloud service providers shall use guidance provided in the FedRAMP Incident Communications
Procedures when deciding when to report directly to US-CERT first or notify CDC first.
8) Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the
HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC-approved notifications to affected individuals; and,
9) Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.
E. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR).
The requiring activity representative, in conjunction with Personnel Security, shall use the OPM Position
Sensitivity Designation automated tool (https://www.opm.gov/investigations/) to determine the sensitivity designation for background investigations. After making those determinations, include all applicable position sensitivity designations.
F. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security
Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO by the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted immediately upon change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the
G. Contract Initiation and Expiration
NOTE: Capital Planning and Investment Control (CPIC) is an integral part of the Agency’s strategic planning initiative. In accordance with the CPIC process and Clinger-Cohen Act, Contractor shall follow the HHS EPLC framework and provide complete, reliable, consistent, and timely life-cycle information, to include development and cost information; and systematic measurement of performance.
https://www.opm.gov/investigations/ https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12
• Contractor(s) must furnish data to ensure that any new system developed as part of this contract is added to the Enterprise Systems Catalog (ESC), and any IT costs associated with those systems, or existing (DSNS 1811, 12528, 1776, 2016) systems are captured in the
Enterprise Systems Catalog as part of the Capital Planning process.
• CDC Enterprise Architecture (EA) Requirements -- General The Contractor shall ensure that new Information Technology (IT) products and services are aligned with the vision and guidance of the CDC’s Enterprise Target Architecture. IT projects must produce, maintain and make available a standard set of documentation that describes the IT Systems and their respective information flows at a sufficient level of detail. A minimum set of documentation guidelines may be found from the CDC Enterprise Architecture online site or can be requested via email at EA@CDC.GOV.
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology and in accordance with the HHS
Contract Closeout Guide (2012).
HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html
CDC EPC Requirements: https://www2a.CDC.gov/CDCup/library/other/eplc.htm
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP
800-64, Security Considerations in the System…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.