REV 75D301-20-R-68023_MS_Word_Tracked Changes_12.17.19 .doc

DOC document 2 MB Posted

Attached to
National Prevention Information Network (NPIN) Federal contract opportunity
Solicitation number
75D301-20-R-68023
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This is a pre-solicitation notice for a multiple award indefinite delivery indefinite quantity contract set aside for small businesses to provide information technology and communication services to support the National Prevention Information Network program administered by the Centers for Disease Control and Prevention. Services will include information and communication technology support, health communication, and health education. The period of performance is 60 months with an anticipated maximum value of $48 million to be awarded across multiple contracts. The solicitation request for proposal will be released on or about July 18, 2019 via http://www.fbo.gov and is for services in the NAICS code 519130 with a small business size standard of 1,000 employees. Interested parties should monitor the website for additional procurement documents.

View the file

Other files for this federal contract opportunity

Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION, OFFER AND AWARD

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

RATING

PAGE OF

2. CONTRACT NO.

3. SOLICITATION NO.

75D301-20-R-68023

4. TYPE OF SOLICITATION

X

NEGOTIATED (RFP)

5. DATE ISSUED

10/02/2019

6. REQUISITION/PURCHASE NO.

7. ISSUED BY
CODE
8219
8. ADDRESS OFFER TO (If other than Item 7)

Centers for Disease Control and Prevention (CDC)

Office of Acquisition Services (OAS)

2900 Woodcock Blvd, MS TCU-4

Atlanta, GA 30341-4004

Liubov A. Kriel

Approved as to Form and Legality: _____________________________

NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”

SOLICITATION

9. Sealed offers in original and 6 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in 2900 Woodcock Blvd, Atlanta, GA 30341 until 2pm EST local time 01/22/2020 CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME

Liubov Kriel

B. TELEPHONE (NO COLLECT CALLS)

AREA CODE NUMBER: EXT:

(770) 488-2856

C. E-MAIL ADDRESS

vyh1@cdc.gov

11. TABLE OF CONTENTS

(x)

DESCRIPTION

(x)

DESCRIPTION

PART I – THE SCHEDULE
PART II – CONTRACT CLAUSES
X
A
SOLICITATION/CONTRACT FORM
1
X
I
CONTRACT CLAUSES
51
X
B
SUPPLIES OR SERVICES AND PRICES/COSTS
2
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X
C
DESCRIPTION/SPECS./WORK STATEMENT
5
X
J
LIST OF ATTACHMENTS
63
X
D
PACKAGING AND MARKING
21
PART IV – REPRESENTATIONS AND INSTRUCTIONS

X

E
INSPECTION AND ACCEPTANCE
22

REPRESENTATIONS, CERTIFICATIONS, AND

X
F
DELIVERIES OR PERFORMANCE
23
X
K
OTHER STATEMENTS OF OFFERORS
64
X
G
CONTRACT ADMINISTRATION DATA
24
X
L
INSTRS., CONDS., AND NOTICES TO OFFERORS
72
X
H
SPECIAL CONTRACT REQUIREMENTS
31
X
M
EVALUATION FACTORS FOR AWARD
84

OFFER (Must be fully completed by offeror)

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52-232-8)

10 CALENDAR DAYS

20 CALENDAR DAYS

30 CALENDAR DAYS

AMENDMENT NO.
DATE
AMENDMENT NO.
DATE

CODE

FACILITY

16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER

15B. TELEPHONE NO.

AREA CODE NUMBER EXT.

15C. CHECK IF REMITTANCE ADDRESS

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE

18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED

20. AMOUNT

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

21. ACCOUNTING AND APPROPRIATION

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

(4 copies unless otherwise specified)

ITEM

24. ADMINISTERED BY (If other than Item 7)
CODE
8219
25. PAYMENT WILL BE MADE BY
CODE
434

Centers for Disease Control and Prevention (CDC)

Office of Acquisition Services (OAS)

2900 Woodcock Blvd, MS TCU-4

Atlanta, GA 30341-4004

Centers for Disease Control and Prevention (FMO)

PO Box 15580 404-718-8100

Atlanta, GA 30333-0080

26. NAME OF CONTRACTING OFFICER (Type or print)

27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION

STANDARD FORM 33 (REV. 9-97)

PREVIOUS EDITION IS UNUSABLE

Prescribed by GSA

FAR (48 CFR) 53.214©

Section B - Supplies Or Services And Prices/Costs

ITEM
SUPPLIES / SERVICES
QTY / UNIT
UNIT PRICE
EXTENDED PRICE
0001
National Prevention Information Network (NPIN) as described in Section C and per task order.

Task Orders to be issued as needed and funds to be obligated separately.

Period of Performance (POP):

April 23, 2020 – April 22, 2025

MAXIMUM VALUE see B.6
5 years
NTE $48M

B.1 Purpose

The purpose of this contract is to provide services that fall within the scope of the work specified in Section C for the project entitled, “National Prevention Information Network (NPIN).” The Contracting Officer (CO) will request the work through the issuance of task orders during the ordering period as specified in Section I of the contract.

B.2 Contract Type and Services

This is a competitive TOTAL Small Business Set-Aside procurement. A small business concern means a small business concern that appears on the Small Business Concerns list maintained by the Small Business Administration (13 CFR 126.103).

This acquisition is being competed in accordance with FAR Part 15 - Contracting by Negotiation. The NAICS Code is 519130 "Internet Publishing and Broadcasting and Web Search Portals," with a small business size standard of 1,000 employees.

This is an Indefinite- Delivery Indefinite- Quantity contract (IDIQ) utilizing individual task orders to provide Information and Communication Technology and Communication and Education services. The Government will issue task orders that are Firm-Fixed-Price (FFP) or a hybrid type, that is firm-fixed-price (FFP) with an additional time-and-materials (T&M) CLIN or a T&M type contract. .

Obligation of funds will be done by the issuance of individual task orders by the Contracting Officer in accordance with the clause titled “Award of Task Orders” in Section H and FAR clause 52.216-18 titled “Ordering” in Section I. The Contractor shall not exceed the amount negotiated for each individual task order without prior written approval of the Contracting Officer.

In addition, the Contractor shall not commence work until a task order or other written notification for a specific assignment is issued by the Contracting Officer. Only a CDC Contracting Officer is authorized to issue a task order request to the Contractor or issue finalized task orders under this contract. The Government is not obligated to reimburse the Contractor for any costs that it incurs before issuance of a task order or other written notification by the Contracting Officer.

The Government intends to issue one or more basic contract awards for this IDIQ contract The intent is to issue two task orders (see Attachments J5 and J6 and Section L herein) upon award of this IDIQ. Task orders will be issued with specific performance periods.

B.3 Performance-Based Preference

Pursuant to FAR 37.102(a) (1), the Contracting Officer will use performance-based acquisition methods to the maximum extent practicable.

B.4 Minimum and Maximum Ordering Amounts

Minimum Order Amount: $1,000

Maximum Order Amount: $5,000,000 B.5 Minimum Guarantee

This contract guarantees that task order(s) amounting to a minimum of one thousand dollars ($1,000) will be issued during the contract period. In the event the contractor receives obligations of less than this minimum over the five year period of performance, the Government will fund the difference between the actual obligation and the guaranteed minimum. Once a task order is issued for $1,000 or more, the government has satisfied its minimum guarantee.

B.6 Maximum Contract Value

The aggregate maximum value of all combined awards made under this solicitation shall not exceed $48,000,000.00. The overall aggregate maximum value for ALL contracts cumulatively will be $48,000,000.00. If the Government's requirements for services set forth in the solicitation do not result in orders in the amounts described as “maximum," the event shall not constitute the basis for an equitable price adjustment under this contract.

B.7 Task Order Pricing

Task orders issued under this contract may be Time and Materials, Firm-Fixed-Price or a hybrid type, that is firm-fixed-price with an additional time-and-materials CLIN.

B.7.1 Firm Fixed Price (FFP)

Pursuant to FAR 15.4, Pricing, and FAR 16.2, Fixed-Price Contracts, the Firm-Fixed Price for each task order will be negotiated based on the price to complete the work. After acceptance of a fixed price task order by the Contractor, the task order price will only be adjusted to reflect changes in scope or conditions.

B.7.2 Time and Materials/Labor-Hour (T&M/LH)

The basic contract shall provide loaded hourly labor rates for T&M and LH type orders. When labor-hour or T&M type task orders are used, the fair and reasonable pricing will be determined in accordance with FAR 15.4, Pricing, and FAR 16.601, Time and Materials Contracts.

B.8 Travel Pricing

Travel will be reimbursed at actual cost in accordance with the limitations set forth in FAR 31.205-46. Fee/ profit shall not be applied to travel costs. Contractors may apply G&A to travel in accordance with the Contractor’s usual accounting practices consistent with FAR 31.2. Travel expenses may be identified under a separate CLIN which will be a cost reimbursable CLIN on the specific task order.

B.9 Place of Work and Government-Furnished Equipment

Work under the contract may be performed on-site at CDC locations in Atlanta, Georgia or may be conducted off-site at Contractor locations. On-site meetings with CDC staff may be required. Each task order will specify the location requirements.

If the work is to be performed primarily on-site at a CDC location, due to the nature of the work, CDC will provide IT equipment (i.e., desktop computer), telephone, and other office equipment and supplies as needed for the Contractor to perform required tasks.

If the work is to be performed primarily off-site at the Contractor’s locations, where the Contractor needs to access CDC’s network, the CDC will not provide IT equipment. The computers used by Contractor personnel shall meet CDC’s standard software and security configuration before logging onto CDC’s network.

B.10 Non-Personal Services Contract Statement

This is a non-personal services contract as defined in Federal Acquisition Regulation (FAR) 37.101. The Government will evaluate the quality of support services provided but the Contractor retains control over its employees or agents. The Contractor is solely responsible and liable for and expressly agrees to indemnify the Government with respect to any liability producing acts or omissions by it or by its employees.

B.11 Service Contract Act

The NPIN contract labor categories are considered bona fide information technology and professional labor and generally exempt from the Service Contract Act. However, each task order will be reviewed for applicability.

B.12. Contract Structure The basic contract will establish the general scope and ordering period for task orders to be issued against this contract. The term of this IDIQ contract is 60 months. It is anticipated that multiple task orders will be issued to the contractors to work in areas identified in this Scope of Work. Each task order shall have a discrete period of performance independent of the basic contract and no task order shall extend more than twelve (12) months beyond the expiration date of the basic contract.

Individual task orders exceeding $3,500 will be competed in accordance with the fair opportunity process described in FAR 16.505(b)(1) unless an exception to fair opportunity is documented in accordance with FAR 16.505(b)(2). All task orders will be solicited by email. Contractors will have a minimum of 10 business days to respond.

Section C - Description/Specification/Work Statement

Performance Work Statement (PWS)

Title: National Prevention Information Network Domain Basic IDIQ Contract

C.1 BACKGROUND AND NEED

The National Center for HIV/AIDS, Viral Hepatitis, STD, and TB Prevention (NCHHSTP) is part of the Centers for Disease Control and Prevention (CDC), an agency of the U.S. Department of Health and Human Services (HHS). It is one of three national centers housed within CDC’s Office of Infectious Diseases (OID).

The National Center for HIV/AIDS, STD, and TB Prevention (NCHSTP) was established in 1994 to bring together most of CDC’s HIV prevention activities under a single organizational home with Sexually Transmitted Disease (STD) Prevention and Tuberculosis (TB) Elimination Programs. In 2006, CDC’s Division of Viral Hepatitis (DVH) was added, and the Center was renamed the National Center for HIV/AIDS, Viral Hepatitis, STD, and TB Prevention.

The diseases addressed by NCHHSTP share a number of commonalities. They have similar or overlapping at-risk populations—including racial and ethnic minorities, men who have sex with men (MSM), and injection drug users (IDUs). These diseases also have important interactions. Those who are infected with certain STDs, such as syphilis or gonorrhea, are at greater risk for HIV infection. Likewise, those who are infected with HIV are far more susceptible to TB disease because their immune systems are weakened.

These diseases also share similar social determinants, including poor access to health care, stigma, discrimination, homophobia, and poverty. In the area of prevention and control, effective, science-based interventions exist to reduce the burden of TB, Viral Hepatitis, most STDs, and HIV.

C.1.2 Partnerships

NCHHSTP works in collaboration with governmental and nongovernmental partners at community, state, national, and international levels with a goal of creating and strengthening mutually beneficial strategic relationships with other individuals, organizations, and networks that strengthen HIV/AIDS, Viral Hepatitis, STD, and TB prevention and control by producing solutions that no individual entity working independently can accomplish.

NCHHSTP provides leadership and strengthens related efforts of other Federal agencies without duplicating efforts. NCHHSTP coordinates its efforts with several other agencies within Health Human Service (HHS). For example, the Health Resources and Services Administration (HRSA) is authorized under the Ryan White HIV/AIDS Treatment Modernization Act to support treatment programs for people living with HIV and AIDS, and HRSA uses data from NCHHSTP’s surveillance systems to guide funding for these programs. NCHHSTP HIV/AIDS surveillance data are also used to guide funding for the U.S. Department of Housing and Urban Development’s (HUD’s) Housing Opportunities for People with AIDS program.

NCHHSTP supports prevention efforts, demonstration projects, capacity-building efforts, and surveillance activities in state, local, and territorial health departments, as well as community-based organizations (CBOs) and national organizations. In addition to supporting traditional public health activities, NCHHSTP works with stakeholders in network partnerships and collaborative partnerships. As defined by NCHHSTP, network partnerships include individuals, groups, and organizations that routinely exchange ideas and information for mutual benefit about HIV, Viral Hepatitis, STDs, and Tuberculosis. Collaborative partnerships are mutually beneficial collaborations to prevent, care for, and/or treat HIV, Viral Hepatitis, STDs, and Tuberculosis, with a particular focus on reducing health disparities. These collaborations can be formal agreements or informal arrangements and are generally characterized by goal sharing, agreeing to explicit commitments, and promoting horizontal communication.

C.1.3 NPIN Program

NCHHSTP’s primary mechanism for supporting network partnerships is the National Prevention Information Network (NPIN). NPIN, at its inception as the CDC National AIDS Clearinghouse, was designed to facilitate the sharing of information and resources among individuals, organizations, and networks working in HIV prevention, treatment, and support services. Today, NPIN remains an important source of CDC and partner evidence-based information and resources, serving professionals dedicated to the prevention of HIV, viral hepatitis, STDs, and TB, through digital media channels. Most NPIN products services are accessible to the general public.

NPIN has the following objectives:

a) To support CDC and NCHHSTP efforts to provide timely information and resources to prevention partners through innovative approaches to knowledge/information transfer.

b) To connect partners in public health through collaborative communication, innovative technology solutions, and customer service.

c) To provide Web-based online databases, information resources, and technical assistance via online support.

d) To support and apply innovation using digital channels to enhance connection among and engagement with prevention partners and stakeholders to maximize health impact of NCHHSTP’s programs.

Early efforts were clearly “demand-driven” as NPIN and its predecessor, the CDC National AIDS Clearinghouse, was responsive to all legitimate information needs and the resulting pressures of increasing demand during the height of the AIDS epidemic. In recent years, the growth of digital channels, including web, social media, and mobile media, which offer new ways to disseminate information and additional sources of information expanded the services and products of NPIN, accelerating the need to be responsive to current and emerging user needs, and to take advantage of evolving technology. In addition, the importance of curating the best resources to and among partner organizations has been heightened, requiring increased sophistication in selecting and promoting health information relevant to NCHHSTP program efforts.

NPIN is congressionally mandated by the Health Omnibus Extension of 1988 which, “Authorizes the Secretary, through the Director of the CDC, to establish a clearinghouse to make information on AIDS available to Federal agencies, States, public and private entities, and the general public. The Health Omnibus Extension of 1988 allows the clearinghouse to: (1) develop and obtain educational materials, model curricula, and methods regarding reducing the transmission of the etiologic agent; (2) provide instruction and support for individuals who provide instruction regarding prevention of AIDS; and (3) conduct evaluations of such materials, curricula, and methods.”

C.2 PURPOSE

The purpose of this contract is to provide services that fall within the scope of the work specified in Section C for the project entitled, “National Prevention Information Network (NPIN)” administered by the Centers for Disease Control and Prevention (CDC), Division of the National Center for HIV/AIDs, Viral Hepatitis, Sexually Transmitted Diseases (STD), and Tuberculosis (TB) Programs - (NCHHSTP).

C.3 SCOPE OF WORK

The services to be acquired under this contract provide a mechanism for various information technology, health communication, and health education professional services tasks, studies, and projects to be performed for NCHHSTP for NPIN. Services to be performed will be non-personal and not inherently governmental services in nature. As an independent organization and not as an agent of the Government, the contractor shall furnish all necessary personnel, facilities, supplies, and equipment, to provide NCHHSTP with required scientific, technical, and operational services, within the general work parameters set forth in this Performance Work Statement. Contractor’s performance and all resulting deliverables must adhere to all federal, HHS, and/or CDC IT security policies and procedures. All resource materials produced or maintained under this contract, including databases, all information products, all data, mailing lists, websites, telephone protocols (Intellectual Property), etc., are the property of the Government.

C.4 TECHNICAL REQUIREMENTS

The Contractor shall provide support services to NCHHSTP for NPIN through two Domains: Domain 1- Information and Communication Technology and Domain 2- Communication and Education. The following are representative examples of tasks, which may be ordered through the issuance of individual task orders under this contract. This listing provides the types of tasks, which may be conducted and is not represented as being complete or all-inclusive. This Statement of Work shall function as a Performance Work Statement.

C.4.1 Domain 1: Information and Communication Technology

Task Area A: Digital Media Channel Development, Web Content Management System (WCMS), Digital Media Metrics (web analytics), and Enhancement includes: Managing NPIN’s products, websites and services via a fully interactive, dynamic web-based platform, which addresses the best practices in site architecture, quality assurance, web posting, web maintenance, web evaluation, reporting, web content management and usability/user experience. The contractor shall use the Drupal (the web content management system of record) to manage a software system that provides website authoring, collaboration, and administrative tools designed to allow users with little knowledge of web programming languages or markup languages to create and manage website content with relative ease. The Contractor shall also make periodic improvements on all properties (websites, widgets, databases) and channels as defined by task order.

Task Area B: Database Development, Analysis, and Management includes: Providing database administrators to manage functional database needs and provide consolidated database servers where customers do not have system administrator privileges - currently, NPIN manages more than 16,000 records.

Task Area C: Special Data Products includes: Recommending appropriate fields and provide access to all Resources and Services Database records and all HIV testing/campaign widgets location records via the NPIN Website. The Contractor shall leverage and optimize the use of the existing and future NPIN partner database and related data assets to support the priorities and activities of NCHHSTP and prevention partners.

Task Area D: Accessibility Review and Remediation includes: Providing support and certification for remediation of applications, files, pages and websites, utilizing best practices, approved checklists, guidance documents, approved repair tools, and standard techniques that are provided by CDC for NPIN.

Task Area E: Usability and User Experience includes: Providing services and technical assistance for usability and user-centered design activities, based upon user experience methodologies in support of NPIN. The Contractor shall make recommendations for designs for websites and applications that are measurably easier to learn, remember, and use. The research-based usability methodologies and best practices shall guide these efforts. CDC websites and applications must comply with CDC standards, web governance and all existing laws, regulations, and policies governing federal websites for content, usability, and accessibility, CDC Web policy and template standards.

C.4.2 Domain 2: Communication and Education

Task Area A: Kick Off Meeting: Includes Planning and execution of a meeting with the government within 3-4 weeks of the award. The contractor shall also create meeting notes.

Task Area B: Marketing and Outreach for the NPIN Program includes: Development of a strategic communication plan for the NPIN program including an assessment of the existing communication and marketing activities. A preliminary assessment of existing communication (via web, mobile and social media) and marketing activities and feature recommendations regarding how to increase awareness and utilization of NPIN products and services among internal and external stakeholders. The Contractor shall routinely update promotion/marketing materials each contract year.

Task Area C: Health Communication Support and Technical Assistance includes: Providing communication support around designated events (awareness days/months, data and guidelines releases, and other scientific releases), graphics design, social media, web content, marketing and promotion via NPIN communication channels and providing evaluation /metrics of all web properties, social media platforms, email distribution lists and all other health communication activities.

Task Area D: Partner Communication Services includes: Maintaining and updating NPIN email distribution lists, creating new distribution lists, developing and disseminating content for use on pre-existing custom curated email distribution lists.

Task Area E: Partner Engagement Activities includes: Coordinating, facilitating and supporting partner engagement events with CDC, its stakeholders and partners (either in person, via phone, web or video conference). These events could include but are not limited to consultation meetings, national conferences, listening sessions, stakeholder meetings, and other similar event in support of NPIN.

Task Area F: NPIN Channels Content Management Includes: A review of the current Web Content Management System (WCMS) across all of NPIN platforms and development and implementation of a content strategy to increase utilization of all NPIN products and services. The Contractor shall also develop content and publish health communication content for NPIN channels and platforms.

Task Area G: Training and Technical Assistance includes: Providing in-person training and technical assistance in accessing and utilizing webinar and other video platforms in support of NPIN. These may be group or one-on-one sessions and may take place in settings such as CDC grantee/stakeholder meetings; key conferences (e.g. STD Prevention Conference, National HIV Prevention Conference, American Public Health Association Conference, National Conference on Health Communication Marketing and Media); and on-site at CDC facilities Task Area H: Scanning and Implementation of New Technologies and Best Practices for NPIN includes: Supporting the incorporation of best and promising practices and trends in emerging technologies into government program services and support.

Task Area I: Program Evaluation includes: Utilizing quantitative and/or qualitative methods to evaluate health communication programs and efforts in support of NPIN. The contractor shall prepare and deliver comprehensive oral and written reports.

C.5

REPORTING SCHEDULE

In addition to specific reporting requirements defined in each Task Order issued, the Contractor shall furnish quarterly progress reports detailing current status of each Task Order awarded under the IDIQ. The report shall be narrative in form and shall include a summary of progress toward completion of each Task Order and any problems encountered to date, including the Contractor’s assessment of the specific impact of such problems on scheduled date of completion of milestones. This report shall be delivered to the CO and the IDIQ COR. Weekly, Monthly, Semi-Annual and Final Reports will be stated at the task order level.

C.6. SPECIAL REQUIREMENTS

CDC Implementation of HHS Security and Privacy Language for Information and Information

Technology Procurements Language, Version 1.0 Procurements Requiring Information Security and/or Physical Access Security

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [ X ] Low [ ] Moderate [ ] High

Integrity: [ X ] Low [ ] Moderate [ ] High

Availability: [ X ] Low [ ] Moderate [ ] High

Overall Risk Level: [ ] Low [ ] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ X ] No PII [ ] Yes PII

Complete this section using the information obtained from the Security and Privacy Checklist in Appendix A, parts A and B.

4) Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ X ] Low [ ] Moderate [ ] High

5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .

9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

10) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

See Appendix D for baseline deliverables.

11) Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.

e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC Office of Chief Information Security Officer (OCISO).

12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

See Section H of the RFP for the Contractor Non-Disclosure Agreement.

13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.

a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.

All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

D. Incident Response

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:

Definition of an Incident:

An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Definition of a Breach:

The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

It further adds:

A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.

The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.

Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:

1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.

2) All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.

4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.

5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.

6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.

7) Cloud service providers shall use guidance provided in the FedRAMP Incident Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.

8) Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC- approved notifications to affected individuals; and,

9) Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.

E. Position Sensitivity Designations

All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR).

The requiring activity representative, in conjunction with Personnel Security, shall use the OPM Position Sensitivity Designation automated tool (https://www.opm.gov/investigations/) to determine the sensitivity designation for background investigations. After making those determinations, include all applicable position sensitivity designations.

F. Homeland Security Presidential Directive (HSPD)-12

The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.

For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presidential-directive-12)

Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO by the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted immediately upon change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.

If the employee is filling a new position, the Contractor shall provide a position description and the employees’ resume.

G. Contract Initiation and Expiration

1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012).

HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html

CDC EPC Requirements: https://www2a.CDC.gov/CDCup/library/other/eplc.htm

2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.

3) Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .