A19. 75D301-22-Q-75404 amendment 1.doc
DOC document 271 KB Posted
- Attached to
- Evidenced-Based Care Guidelines Subscription Federal contract opportunity
- Solicitation number
- 75D301-22-Q-75404
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 75D301-22-Q-75404 final.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
REQUEST FOR QUOTATIONS
(THIS IS NOT AN ORDER)
THIS RFQ
PAGE OF PAGES
1. REQUEST NO.
75D301-22-Q-75404
2. DATE ISSUED
08/04/2022
3. REQUISITION/PURCHASE REQUEST NO.
0000HCCP-2022-68724
4. CERT. FOR NAT. DEF.
UNDER BDSA REG. 2
AND/OR DMS REG. 1
RATING
5a. ISSUED BY
Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS)
2900 Woodcock Blvd, MS TCU-4
Atlanta GA 303414004
6. DELIVERY BY (Date)
5b. FOR INFORMATION CALL (No collect calls)
| NAME |
| TELEPHONE NUMBER |
| AREA CODE |
| NUMBER |
| Martin F. Nemec |
| (404) |
| 498-5605 x |
| 8. TO: |
| 9. DESTINATION |
| a. NAME |
| b. COMPANY |
| a. NAME OF CONSIGNEE |
| c. STREET ADDRESS |
| b. STREET ADDRESS |
| c. CITY |
| d. CITY |
| e. STATE |
| f. ZIP CODE |
| d. STATE |
| e. ZIP CODE |
10. PLEASE FURNISH QUOTATIONS TO
THE ISSUING OFFICE IN BLOCK 5a ON
OR BEFORE CLOSE OF BUSINESS (Date)
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State and local taxes)
ITEM NO.
(a)
SUPPLIES/SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e)
AMOUNT
(f)
This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Federal Acquisition Requirements (FAR) Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested, and a written solicitation will not be issued.
| 12. DISCOUNT FOR PROMPT PAYMENT |
| a. 10 CALENDAR DAYS |
b. 20 CALENDAR DAYS
c. 30 CALENDAR DAYS
d. CALENDAR DAYS
| NUMBER |
| PERCENTAGE |
NOTE: Additional provisions and representations
| 13. NAME AND ADDRESS OF QUOTER |
| 14. SIGNATURE OF PERSON AUTHORIZED TO |
SIGN QUOTATION
15. DATE OF
QUOTATION
a. NAME OF QUOTER
| b. STREET ADDRESS |
| 16. SIGNER |
| a. NAME (Type or print) |
| b. TELEPHONE |
c. COUNTY
AREA CODE
| d. CITY |
| e. STATE |
| f. ZIP CODE |
| c. TITLE (Type or print) |
| NUMBER |
AUTHORIZED FOR LOCAL REPRODUCTION
STANDARD FORM 18 (REV. 6-95)
Previous edition not usable
Prescribed by GSA
FAR (48 CFR) 53.215-1(a)
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 0001 |
| Evidenced Based, Care Guidelines Subscription for up to 5 users performing 800-900 case reviews a year. |
Firm Fixed-Price; Severable Line Item Period of Performance: 9/1/2022 through 8/31/2023
1 Lot
Option 1001 Option Year 1 Items:
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 1001 |
| Evidenced Based, Care Guidelines Subscription for up to 5 users performing 800-900 case reviews a year. |
Firm Fixed-Price; Severable Line Item Period of Performance: 9/1/2023 through 8/31/2024
1 Lot
Option 2001 Option Year 2 Items:
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 2001 |
| Evidenced Based, Care Guidelines Subscription for up to 5 users performing 800-900 case reviews a year. |
Period of Performance: 9/1/2024 through 8/31/2025
1 Lot
Option 3001 Option Year 3 Items:
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 3001 |
| Evidenced Based, Care Guidelines Subscription for up to 5 users performing 800-900 case reviews a year. |
Period of Performance: 9/1/2025 through 8/31/2026
1 Lot
Option 4001 Option Year 4 Items:
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 4001 |
| Evidenced Based, Care Guidelines Subscription for up to 5 users performing 800-900 case reviews a year. |
Period of Performance: 9/1/2026 through 8/31/2027
1 Lot
SECTION C – STATEMENT OF WORK
Title: World Trade Center (WTC) Health Program Evidence Based Care Guidelines
SECTION 1 – BACKGROUND
On January 2, 2011, the President signed Public Law No. 111-347, the James Zadroga 9/11 Health and Compensation Act of 2010 (Zadroga Act). Title I of the Zadroga Act amended the Public Health Service Act to add Title XXXIII establishing the World Trade Center (WTC) Health Program within the Department of Health and Human Services. Title I is codified at 42 U.S.C. §§ 300mm – 300mm-61. The Zadroga Act can be found at: https://www.govinfo.gov/content/pkg/PLAW-111publ347/pdf/PLAW-111publ347.pdf. In addition to the statutory requirements for the Program codified in 42 U.S.C. §§ 300mm – 300mm-61, the WTC Program Administrator has also promulgated regulations governing the administration of the Program at 42 C.F.R. pt. 88.
On December 18, 2015, the Zadroga Act was amended to provide authority and funding and for the WTC Health Program to continue through 2090. See Pub. L. 114-113 (Dec. 18, 2015), “Consolidated Appropriations Act, 2016,” Div. O, Title III (“James Zadroga 9/11 Health and Compensation Reauthorization Act”). As of March 31, 2020, the WTC Health Program had 104,000 members enrolled, including 78,534 general responders and 25,484 survivors. Current WTC Health Program statistics and reports can be found at https://www.cdc.gov/wtc/ataglance.html#enrollmentWTC.
The WTC Health Program provides monitoring and treatment for survivors and responders (referred to as Members) of the 9/11 terrorist attacks in NYC, the Pentagon, and near Shanksville, Pennsylvania. The WTC Health Program is a limited health benefit program, meaning that treatment is only covered for health condition(s) for which exposure to airborne toxins, hazards, or any other adverse conditions resulting from the September 11, 2001, terrorist attacks. In order to receive treatment, members must be both enrolled in the Program and certified for any qualifying condition(s). Both program eligibility and certification decisions are made by the National Institute for Occupational Safety and Health (NIOSH) enrollment and certification specialists. This data is maintained by the Health Program Support (HPS) contractor and transferred to the pharmacy benefits manager (PBM) based on a pre-determined schedule. The Zadroga Act encompasses a myriad of responsibilities associated with the administration and performance needed to enroll, initially evaluate, medically monitor, and manage covered health conditions for eligible individuals through diagnostic and treatment services.
Care is administered to members in the New York City (NYC) metropolitan area through the Clinical Centers of Excellence (CCEs) and for those members living outside of the NYC metropolitan area, through a Nationwide Provider Network (NPN), all of which are managed by contracts with the Program. In addition to these contracts, the Program also contracts with an HPS contract that processes medical claims, manages the Program’s call center, processes enrollment and certification applications (as previously mentioned), manages the provider network, and maintains eligibility data for the Program.
The Program is implementing a Utilization Management (UM) time-limited pilot Program to conduct concurrent review of a sample of members during the care they receive during hospitalizations, emergency room stays, or urgent care encounters in order to determine medical necessity. The goal of this Program is to ensure members are receiving the right level of care in the right setting for the right length of time. Concurrent review during this UM pilot also ensures the member progresses to the appropriate next level of care and/or discharge, optimizes member outcomes, and contributes to cost containment. By conducting his pilot, the Program will be able to determine if and how UM can be implemented Program-wide.
SECTION 2 – PURPOSE
The Centers for Disease Control & Prevention (CDC), NIOSH, WTC Health Program is seeking a subscription to nationally recognized evidence-based care guidelines to facilitate the utilization management review process.
SECTION 3 – SCOPE OF WORK
The vendor shall provide WTC Health Program access to the nationally-recognized evidence-based care guidelines that use the Progression of Care criteria and include inpatient and surgical care criteria, general recovery care criteria, and behavioral health care criteria. Evidence-based guidelines are essential in developing an efficient Utilization Management program to assist in supporting clinical decision making, documentation, and assessing efficient transition of care settings.
SECTION 4 – TASKS TO BE PERFORMED
1. System Set-Up, Implementation, and Training
Within 7 business days of contract award, vendor shall be prepared to meet with appropriate stakeholders for a virtual kickoff meeting to discuss and agree upon:
a) User access to the system
b) Organization structures for distribution of work and reporting
c) Communications materials and training
d) Plan for providing technical support and integration of systems into NIOSH process and workflows.
2. UM Clinical Guidelines Database
System access shall be provided to a pre-identified number of users, based on their assigned areas and “need to know”. Prior to receiving their credentials, all users shall be required to attend a brief web-based orientation (training).
The subscription shall include the following characteristics:
a. Aligned with industry standards of major healthcare payers’ practices
b. Customizable to accommodate WTC Health Program’s limited-benefit plan requirements
c. Readily available technical support within 24 hours by a designated account manager
d. Customized training for all users consisting of online and instructor-led learning opportunities; additional trainings upon request
e. Administratively accessible by up to five (5) designated WTC staff
f. Readily available job aids and processes for utilizing the system
g. Available webinars and ongoing trainings sessions to keep abreast of current healthcare trends to address the needs of our membership
h. Prevalent in major hospitals and healthcare systems within the New York Metropolitan Area (NYMA)
i. Available outlines for determining levels of care, alternatives to admission, and readiness for discharge
SECTION 5 – GOVERNMENT FURNISHED MATERIALS
N/A
SECTION 6 – PERIOD OF PERFORMANCE
The estimated period of performance for these tasks will be:
Base Period:
9/1/2022 through 8/31/2023
Option Period 1:
9/1/2023 through 8/31/2024
Option Period 2:
9/1/2024 through 8/31/2025 Option Period 3:
9/1/2025 through 8/31/2026 Option Period 4:
9/1/2026 through 8/31/2027
SECTION 7 – DELIVERABLES/REPORTING SCHEDULE
| Items |
| Description |
| Delivery Date |
| Deliver To |
| Introductory Call |
| Call with WTC Health Program Staff and Vendor Staff to discuss implementation. |
| Within 7 business days after award |
| COR |
Program Staff
| Implementation and Support Plan |
| Plan outlining how the system will be integrated into NIOSH process and workflows and how technical support will be provided to the Program. |
| Within 7 business days after award |
| COR |
Program Staff
| Access to Software System |
| Vendor will ensure WTC Health Program employees have access to the software systems |
| Within 14 business days after award |
| COR |
Program Staff
| Implementation training, education, and other support services as necessary |
| Vendor shall provide education and training to the authorized users. |
| Within 30 business days after award |
| COR |
Program Staff
| Customer Support |
| Technical and Training Support for the WTC Health Program Staff. |
| As needed (on a 24/7 basis) |
| COR |
Program Staff
SECTION 8 – IT SECURITY/SPECIAL CONSIDERATIONS
Information Type and Impact Level Assessment Categorize the requestedinformationtechnology and/orinformationby completingthe table perthe instructions listed below.
· Information Type: Use the National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories (https://csrc.nist.gov/publications/).
· Impact Levels (Confidentiality/Integrity/Availability): Rate the risks for each Information Type. The NIST-defined risk ratings may be changed to reflect the actual risk to the CDC and/or C/I/Omission.
· Overall Risk: This is equal to the highest risk rating in its specific column for all of the Information Types listed.
Information Types and Security Objective Impact Levels
| Item # |
| Information Type |
| Confidentiality |
| Integrity |
| Availability |
| 1 |
| D.14.2 Population Health Management and Consumer Safety Information Type |
| Low |
| Moderate |
| Low |
| 2 |
| C.3.5.7 Information Management Information Type |
| Low |
| Moderate |
| Low |
| 3 |
| C.2.8.9 Personal Identity and Authenticatio Infromation Type |
| Moderate |
| Moderate |
| Moderate |
| Overall Risk |
| Moderate |
| Moderate |
| Moderate |
Position Sensitivity Designations The ISSO in coordination with the requiring activity representative and Personnel Security Offices, determine the applicable position designations using OPM’s Position Sensitivity Designation Automated Tool (https://www.opm. gov/investigations/). The following are position sensitivity levels that may apply to this solicitation/contract:
| Investigation |
| Position Requirement |
NAC
Tier 1 Tier 2s (with subject interview) National Agency Check
Low-Risk Non-Sensitive, including HSPD-12 Credentialing
Moderate-Risk Public Trust (MRPT)
| Tier 3 |
| Non-CriticalSensitive,NationalSecurity, includingSecretand“L”access eligibility |
| Tier 4 |
| High-Risk Public Trust |
| Tier 5 |
| Critical Sensitive and Special Sensitive, National Security, including TopSecret, SCI, and “Q” access eligibility |
| Not Applicable |
| No Requirement |
Covered Contractor Information System Deliverables
The following table details a listing of possible deliverables that may be completed by the contractor (at a minimum) and included in the Schedule of Deliverables. These should be added to the existing schedule and not in a separate security deliverable schedule.
| Deliverable Title/Description |
| Due Date |
| Roster |
| By effective date of this contract. |
| Contractor Employee Non-Disclosure Agreement (NDA). |
| Prior to performing any work on behalf of HHS. |
| Copy of training records for all mandatory training. |
| In conjunction with contract award and annually thereafter or upon request. |
| Signed Rules of Behavior (ROB) for all employees. |
| Initiation of contract and at least annually thereafter. |
| Incident Report (as incidents or breaches occur). |
| As soon as possible and without reasonable delay and no later than 1 hour of discovery. |
| List of Personnel with defined roles and responsibilities. |
| Prior to performing any work on behalf of HHS. |
| Off-boarding documentation, equipment and badge when leaving contract. |
| Within 7 days of contractor departure and at contract expiration. |
| Onboarding documentation when beginning contract. |
| Prior to performing any work on behalf of HHS. |
If the procurement involves a system or cloud service, Disposition/Decommission Plan.
At contract expiration.
| Develop, document, and periodically update System Security Plans (SSPs). Develop and implement Plan of Action and Milestones (POA&M) designed to correct deficiencies and reduce or eliminate vulnerabilities. |
| Every 365 days /as requested by CDC/NIOSH. |
| Retirement Checklist, all deliverables and data/records retained in accordance with Records Management and other requirements, Device sanitization documentation, Destruction documentation for all other CDC data/information (soft/hard copy). |
| Prior to system retirement/decommissioning. |
| POA&M updates; Revised security documentation/Agreements. |
| Monthly/as requested by CDC/NIOSH. |
| Incident reports (as needed) Incident Response Plan. |
| As requested by CDC/NIOSH. |
| Computer software, including the source code, if applicable. |
| Prior to performing any work on behalf of HHS. |
| Other source code, if applicable. |
| Prior to performing any work on behalf of HHS. |
| Syslog-ng: daily audit logs. |
| Daily at minimum/as requested by CDC/NIOSH. |
Standard Language Covered Contractor Information System A Covered Contractor Information System is defined as “an information system that is owned and operated by a contractor and all sub-contractors that processes, stores, or transmits Federal contract information.”
1) Adequate Security
Definition of Adequate Security: Adequate security is defined as protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Contractor (and/or any subcontractor) shall provide adequate security on all covered contractor information systems for protecting the confidentiality of Controlled Unclassified Information (CUI). Contractor shall implement, at a minimum, the following information security protections:
a. The covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” in effect at the time the solicitation is issued or as authorized by the Contracting Officer. To document implementation of NIST SP 800-171 Rev.2, the Contractor shall provide the following system documentation to CDC/NIOSH to demonstrate implementation or planned implementation of the security requirements:
i. System Security Plan (SSP) – Contractor shall develop, document, and annually update System Security Plans (SSPs). The system security plan describes system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. Contractor must ensure that the required information in [SP 800-171 Requirement] 3.12.4 is conveyed in those plans. Contractor must document the system security plan using the NIST suggested template.
ii. Plan of Action and Milestones (POA&M) – Contractor shall develop and implement Plan of Action and Milestones designed to correct deficiencies and reduce or eliminate vulnerabilities in their systems. Contractor must document the POA&M using NIST suggested template.
b. The Contractor shall implement NIST SP 800-171 Rev 2. The Contractor shall notify the NIOSH Information System Security Officer/Delegate, and the Contract Officer within 30 days of contract award, of any security requirements specified by NIST SP 800-171 Rev 2 not implemented at the time of contract award.
i. The Contractor shall submit requests to vary from NIST SP 800-171 Rev 2 in writing to the Contracting Officer, for consideration by the ISSO to determine if requests are applicable and if an alternative security measures are equally effective.
ii. If CDC/NIOSH has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the NIOSH Office of the Director of Information Technology (OD-IT) when requesting its recognition under this contract.
iii. If the Contractor intends to use an external cloud service provider to store, process, or transmit any controlled unclassified information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline and that the cloud service provider complies with requirements in this contract for cyber incident reporting, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
c. Apply other information systems security measures when the Contractor reasonably determines that information systems security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., medical devices) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
Cyber Incident Reporting Requirement Definition of an Incident: “Cyber incident” means actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
When the Contractor discovers a cyber incident that affects a covered contractor information system residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the Contractor shall —
1. Conduct a review for evidence of compromise of controlled unclassified information.
2. All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery to the NIOSH Security Team and the Contracting Officer. NIOSH Security Team will coordinate and escalate reported incidents to CSIRT CDC – Computer Security Incident Response Team as soon as possible and without reasonable delay. NIOSH Security Operations: NIOSHINFOSECOperations@cdc.gov Cyber Incident Report
Tracking and documenting system security incidents includes maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics, evaluating incident details, trends, and handling. The cyber incident report shall be treated as information created by or for CDC/NIOSH and shall include, at a minimum, the required elements.
Contact Information for the Incident Reporter and Handler
· Name.
· Role.
· Organizational unit (e.g., agency, department, division, team) and affiliation.
· Email address.
· Phone number.
· Location (e.g., mailing address, office room number).
Incident Details
· Status change date/timestamps (including time zone): when the incident started, when the incident was discovered/detected, when the incident was reported, when the incident was resolved/ended, etc.
· Physical location of the incident (e.g., city, state).
· Current status of the incident (e.g., ongoing attack).
· Source/cause of the incident (if known), including hostnames and IP addresses.
· Description of the incident (e.g., how it was detected, what occurred).
· Description of affected resources (e.g., networks, hosts, applications, data), including systems’ hostnames, IP addresses, and function.
· If known, incident category, vectors of attack associated with the incident, and indicators related to the incident (traffic patterns, registry keys, etc.).
· Prioritization factors (functional impact, information impact, recoverability, etc.).
· Mitigating factors (e.g., stolen laptop containing sensitive data was using full disk encryption).
· Response actions performed (e.g., shut off host, disconnected host from network).
· Other organizations contacted (e.g., software vendor).
Media Preservation and Protection
Definition of Media: “Media” is defined as the physical devices or writing surfaces including, but is not limited to, magnetic tapes, optical disks, magnetic disks, large-scale integration memory chips, and printouts onto which covered defense information is recorded, stored, or printed within a covered contractor information system.
When a Contractor discovers a cyber incident has occurred, the Contractor shall preserve and protect images of all known affected information systems and all relevant monitoring/packet capture data for at least 1 year from the submission of the cyber incident report to allow CDC/NIOSH to request the media or decline interest. Per the NIOSH Enhanced Based Security Controls, CDC/NIOSH requires audit records to be retained for 7 Years, this timeframe provides support for after-the-fact investigations of security incidents and to meet regulatory and CDC/NIOSH information retention requirements.
Audit and Accountability
The Contractor shall meet the information security requirements for Audit and Accountability (AU) to ensure audit records meet the following minimum requirements pertaining to AU and other privacy requirements:
· Audit Records Reporting: Provide audit logs for NIOSH to review for NIOSH specific data for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
· Anonymize Non-NIOSH associated data and PII: Where feasible and within the limits of technology, locates and removes/redacts vendor specific non-NIOSH associated data and PII and/or uses anonymization and de-identification techniques to permit use of all NIOSH retained data while reducing its sensitivity and the risk resulting from disclosure.
· Right to Receive Logs: NIOSH shall have the right to receive NIOSH-specific application logs at a minimum of daily. Daily audit records shall be sent to the NIOSH Technical Operations (TechOps) group via a Syslog-ng. The point of contact to configure Syslog-ng will be provided to the Contractor upon the contract award. If Syslog-ng is not feasible or technically possible, an alternative option for receiving audit records may be considered as agreed upon by the Contractor and NIOSH Office of the Director of Information Technology (OD-IT). CDC/NIOSH requires audit records to be retained for 7 Years, this timeframe provides support for after-the-fact investigations of security incidents and to meet regulatory and CDC/NIOSH information retention requirements.
Information Security Continuous Monitoring
The Contractor shall ensure an assessment of the controls is conducted at least annually to determine the implemented security and privacy controls are operating as intended and producing the desired results (this may involve penetration testing conducted by the agency or independent third-party). In addition, review all relevant documentation (SSP, POA&M, etc.) and provide updates by specified due date. NIOSH shall have the right to conduct a third-party audit. This audit shall assure appropriate safeguard of NIOSH information and compliance with the agreed security standards and procedures.
Access to Additional Information or Equipment Necessary for Forensic Analysis
Definition of Forensic Analysis: “Forensic analysis” means the practice of gathering, retaining, and analyzing computer-related data for investigative purposes in a manner that maintains the integrity of the data.
Upon request, the Contractor shall provide access to additional information or equipment that is necessary to conduct a forensic analysis.
Cyber Incident Damage Assessment Activities
If CDC/NIOSH elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance to A. 4. Media Preservation and Protection.
CDC/NIOSH Safeguarding and Use of Contractor Attributional/Proprietary Information
The CDC/NIOSH shall protect against the unauthorized use or release of information obtained from the contractor (or derived from information obtained from the contractor) that includes contractor attributional/proprietary information. To the maximum extent practicable, the Contractor shall identify and mark attributional/proprietary information. In making an authorized release of such information, CDC/NIOSH will implement appropriate procedures to minimize the contractor attributional/proprietary information that is included in such authorized release, seeking to include only that information that is necessary for the authorized purpose(s) for which the information is being released. Use and release of contractor attributional/proprietary information not created by or for CDC/NIOSH
Definition of Contractor attributional/proprietary information: “Contractor attributional/proprietary information” means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Information that is obtained from the contractor (or derived from information obtained from the contractor) under this contract that is not created by or for CDC/NIOSH is authorized to be released outside of CDC/NIOSH —
1. To entities with missions that may be affected by such information.
2. To entities that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents,
3. To Government entities that conduct counterintelligence or law enforcement investigations.
4. To a support services contractor (“recipient”) that is directly supporting CDC/NIOSH activities, Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information.
Use and release of contractor attributional/proprietary information created by or for CDC/NIOSH
Information that is obtained from the contractor (or derived from information obtained from the contractor) under this contract that is created by or for CDC/NIOSH of this contract is authorized to be used and released outside of CDC/NIOSH for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and policy based restrictions on the Government’s use and release of such information.
Other applicable laws and regulations
The Contractor shall conduct activities that includes this contract in accordance with applicable laws and regulations on the interception, monitoring, access, use, and disclosure of electronic communications and data.
Other Safeguarding or Reporting Requirements
The safeguarding and cyber incident reporting required by this contract in no way abrogates the Contractor’s responsibility for other safeguarding or cyber incident reporting pertaining to its unclassified information system as required by other applicable requirements of this contract, or as a result of other applicable U.S. Government statutory or regulatory requirements.
Subcontracts
The Contractor shall —
1. Include this clause, including this paragraph (A.14. Subcontracts), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve controlled unclassified information, including subcontracts for commercial items, without alteration, except to identify the parties. The Contractor shall determine if the information required for subcontractor performance retains its identity as controlled unclassified information and will require protection under this contract, and, if necessary, consult with the Contracting Officer; and
2. Require subcontractors to —
a) Notify the prime Contractor (or next higher-tier subcontractor) when submitting a request to vary from a NIST SP 800-171 security requirement to the Contracting Officer.
b) Provide the incident report number, automatically assigned by CDC/NIOSH, to the prime Contractor (or next higher-tier subcontractor) as soon as practicable, when reporting a cyber incident to CDC/NIOSH as required in A.3. Cyber Incident Report of this contract.
HIPAA Compliance and Business Associate Agreement (Section 13)
The WTC Health Program, including any other NIOSH, CDC, or HHS components to the extent that they assist in administering the WTC Health Program involving protected health information (PHI), is treated as a Covered Entity for purposes of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The PBM is a business associate of the WTC Health Program as that term is defined in the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. pts. 160, 162, and 164). To the extent that the PBM performs functions or activities on behalf of, or provides certain services to, the WTC Health Program where the PBM creates, receives, maintains, or transmits “protected health information” (PHI), the following “HIPAA provisions” apply: the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104–191; 42 U.S.C. § 1320d); the Health Information Technology for Economic and Clinical Health (HITECH) Act[1] (Pub. L. 111-5; 42 U.S.C. §§ 300jj et seq.); the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. pts. 160, 162, and 164); and HHS HIPAA policies.
The PBM shall require its providers, as applicable, and any and all agents and subcontractors to comply with all applicable provisions of HIPAA and shall document in writing the policies and procedures that will be used to meet such obligations. The PBM shall provide the WTC Program Administrator with a copy of their Notice of Use and Disclosures of Protected Health Information required by the HIPAA Privacy rule for review and approval and ensure in that notice that the members are aware the WTC Program Administrator will have access to the member’s protected health information for purposes of the treatment provided by and administration of the WTC Health Program established under the James Zadroga 9/11 Health and Compensation Act. Furthermore, the PBM’s Operations Manual shall provide the details of how the PBM will meet the obligations and activities of a Business Associate of the WTC Health Program.
Attachment #3 contains the WTC Health Program Business Associate Agreement which describes the detailed legal obligations and requirements of the Business Associate and the Covered Entity, including reporting of potential breaches. Any potential offeror shall submit an executed Business Associate Agreement with their proposal. This document shall later be incorporated into the successful awardees’ subsequent contract. At all times throughout the duration of this contract and until the PBM fulfills its obligations under this contract and the BAA, the PBM is subject to and shall comply with all applicable HIPAA provisions regarding business associates, as well as any updates to those provisions.
As a Business Associate of the WTC Health Program, the PBM is directly liable under HIPAA for the following violations:[3]
· Impermissible uses and disclosures of PHI;
· Failure to provide breach notification to the Covered Entity;
· Failure to provide access to a copy of electronic PHI to either the Covered Entity, the individual, or the individual’s designee, as specified in the Business Associate Agreement;
· Failure to disclose PHI where required by the Secretary of HHS to investigate or determine the Business Associate’s compliance with HIPAA;
· Failure to maintain and provide an accounting of disclosures to the Covered Entity and
· Failure to comply with the requirements of the Security Rule.
Secure Data Transfer Language
Files Transmission There are two (2) options for electronic submission of documents/deliverables; CDC SFTP Site or Secure Access Management Services (SAMS) are the two (2) approved methods of transmission.
· Secure File Transfer Protocol (SFTP) site is used for downloading and uploading files from or to the CDC network.
· SAMS is the CDC’s electronic authentication (E-Auth) provider to support access for external partners. E-Auth systems protect CDC by authenticating a user and authorizing that person to use specific IT resources.
COVID-19 Language
HHS reserves the right to exercise priorities and allocations authority with respect to this contract, to include rating this order in accordance with 45 CFR Part 101, Subpart A—Health Resources Priorities and Allocations System.
SECTION D – CLAUSES
D.1 FAR 52.252-2 Clauses Incorporated By References (Feb 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:
https://www.ecfr.gov/current/title-48
| SOURCE |
| TITLE AND DATE |
FAR
| 52.204-13 |
| System for Award Management Maintenance (Oct 2018) |
| 52.204-18 |
| Commercial and Government Entity Code Maintenance (Aug 2020) |
| 52.212-4 |
| Contract Terms and Conditions- Commercial Items (Nov 2021) |
| 52.232-39 |
| Unenforceability of Unauthorized Obligations (Jun 2013) |
| 52.232-40 |
| Providing Accelerated Payments to Small Business Contractors (Nov 2021) |
HHSAR
| 352.222-70 |
| Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015) |
D.2 Full Text:
FAR 52.212-5 -- Contract Terms and Conditions Required To Implement Statutes or Executive Orders—Commercial Products and Commercial Services. (May 2022)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Nov 2021) (Section 1634 of Pub. L. 115-91).
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment . (Nov 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015).
(5) 52.233-3, Protest After Award (Aug 1996) ( 31 U.S.C. 3553).
(6) 52.233-4, Applicable Law for Breach of Contract Claim (Oct 2004) (Public Laws 108-77 and 108-78 ( 19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
[Contracting Officer check as appropriate.]
(1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Jun 2020), with Alternate I (Nov 2021) ( 41 U.S.C. 4704 and 10 U.S.C. 2402).
__ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Nov 2021) ( 41 U.S.C. 3509)).
__ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub. L. 111-5). (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009.)
x (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Jun 2020) (Pub. L. 109-282) ( 31 U.S.C. 6101 note).
__ (5) [Reserved].
(6) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
__ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
x (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment . (Nov 2021) ( 31 U.S.C. 6101 note).
(9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) ( 41 U.S.C. 2313).
__ (10) [Reserved].
__ (11) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Sep 2021) ( 15 U.S.C. 657a).
x (12) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Sep 2021) (if the offeror elects to waive the preference, it shall so indicate in its offer ) ( 15 U.S.C. 657a).
__ (13) [Reserved]
__ (14) (i) 52.219-6, Notice of Total Small Business Set-Aside (Nov 2020) ( 15 U.S.C. 644).
__ (ii) Alternate I (Mar 2020) of 52.219-6.
__ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (Nov 2020) ( 15 U.S.C. 644).
__ (ii) Alternate I (Mar 2020) of 52.219-7.
(16) 52.219-8, Utilization of Small Business Concerns (Oct 2018) ( 15 U.S.C. 637(d)(2) and (3)).
__ (17) (i) 52.219-9, Small Business Subcontracting Plan (Nov 2021) ( 15 U.S.C. 637(d)(4)).
__ (ii) Alternate I (Nov 2016) of 52.219-9.
__ (iii) Alternate II (Nov 2016) of 52.219-9.
__ (iv) Alternate III (Jun 2020) of 52.219-9.
__ (v) Alternate IV (Sep 2021) of 52.219-9.
__ (18) (i) 52.219-13, Notice of Set-Aside of Orders (Mar 2020) ( 15 U.S.C. 644(r)).
__ (ii) Alternate I (Mar 2020) of 52.219-13.
__ (19) 52.219-14, Limitations on Subcontracting (Sep 2021) ( 15 U.S.C. 637s).
__ (20) 52.219-16, Liquidated Damages—Subcontracting Plan (Sep 2021) ( 15 U.S.C. 637(d)(4)(F)(i)).
__ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Sep 2021) ( 15 U.S.C. 657f).
x (22) (i) 52.219-28, Post Award Small Business Program Rerepresentation (Sep 2021) ( 15 U.S.C. 632(a)(2)).
__ (ii) Alternate I (Mar 2020) of 52.219-28.
__ (23) 52.219-29, Notice of Set-Aside for, or Sole-Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Sep 2021) ( 15 U.S.C. 637(m)).
__ (24) 52.219-30, Notice of Set-Aside for, or Sole-Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Sep 2021) ( 15 U.S.C. 637(m)).
__ (25) 52.219-32, Orders Issued Directly Under Small Business Reserves (Mar 2020) ( 15 U.S.C. 644(r)).
__ (26) 52.219-33, Nonmanufacturer Rule (Sep 2021) ( 15U.S.C. 637(a)(17)).
x (27) 52.222-3, Convict Labor (Jun 2003) (E.O.11755).
__ (28) 52.222-19, Child Labor-Cooperation with Authorities and Remedies (Jan 2022) (E.O.13126).
x (29) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
x (30) (i) 52.222-26, Equal Opportunity (Sep 2016) (E.O.11246).
__ (ii) Alternate I (Feb 1999) of 52.222-26.
(31) (i) 52.222-35, Equal Opportunity for Veterans (Jun 2020) ( 38 U.S.C. 4212).
__ (ii) Alternate I (Jul 2014) of 52.222-35.
x (32) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jun 2020) ( 29 U.S.C. 793).
__ (ii) Alternate I (Jul 2014) of 52.222-36.
(33) 52.222-37, Employment Reports on Veterans (Jun 2020) ( 38 U.S.C. 4212).
(34) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).
x (35) (i) 52.222-50, Combating Trafficking in Persons (Nov 2021) ( 22 U.S.C. chapter 78 and E.O. 13627).
__ (ii) Alternate I (Mar 2015) of 52.222-50 ( 22 U.S.C. chapter 78 and E.O. 13627).
(36) 52.222-54, Employment Eligibility Verification (May 2022) . (Executive Order 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial products or commercial services as prescribed in FAR 22.1803.)
__ (37) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA–Designated Items (May 2008) ( 42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
__ (ii) Alternate I (May 2008) of 52.223-9 ( 42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
__ (38) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O. 13693).
__ (39) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (Jun 2016) (E.O. 13693).
__ (40) (i) 52.223-13, Acquisition of EPEAT®-Registered Imaging Equipment (Jun 2014) (E.O.s 13423 and 13514).
__ (ii) Alternate I (Oct 2015) of 52.223-13.
__ (41) (i) 52.223-14, Acquisition of EPEAT®-Registered Televisions (Jun 2014) (E.O.s 13423 and 13514).
__ (ii) Alternate I (Jun2014) of 52.223-14.
__ (42) 52.223-15, Energy Efficiency in Energy-Consuming Products (May 2020) ( 42 U.S.C. 8259b).
__ (43) (i) 52.223-16, Acquisition of EPEAT®-Registered Personal Computer Products (Oct 2015) (E.O.s 13423 and 13514).
__ (ii) Alternate I (Jun 2014) of 52.223-16.
x (44) 52.223-18, Encouraging Contractor Policies to Ban Text Messaging While Driving (Jun 2020) (E.O. 13513).
__ (45) 52.223-20, Aerosols (Jun 2016) (E.O. 13693).
__ (46) 52.223-21, Foams (Jun2016) (E.O. 13693).
__ (47) (i) 52.224-3 Privacy Training (Jan 2017) (5 U.S.C. 552 a).
__ (ii) Alternate I (Jan 2017) of 52.224-3.
__ (48) 52.225-1, Buy American-Supplies (Nov 2021) ( 41 U.S.C. chapter 83).
__ (49) (i) 52.225-3, Buy American-Free Trade Agreements-Israeli Trade Act (Nov 2021) ( 41 U.S.C.chapter83, 19 U.S.C. 3301 note, 19 U.S.C. 2112 note, 19 U.S.C. 3805 note, 19 U.S.C. 4001 note, Pub. L. 103-182, 108-77, 108-78, 108-286, 108-302, 109-53, 109-169, 109-283, 110-138, 112-41, 112-42, and 112-43.
__ (ii) Alternate I (Jan 2021) of 52.225-3.
__ (iii) Alternate II (Jan 2021) of 52.225-3.
__ (iv) Alternate III (Jan 2021) of 52.225-3.
__ (50) 52.225-5, Trade Agreements (Oct 2019) ( 19 U.S.C. 2501, et seq., 19 U.S.C. 3301 note).
x (51) 52.225-13, Restrictions on Certain Foreign Purchases (Feb 2021) (E.O.’s, proclamations, and statutes administered by the Office of Foreign Assets Control of the Department of the Treasury).
__ (52) 52.225-26, Contractors Performing Private Security Functions Outside the United States (Oct 2016) (Section 862, as amended, of the National Defense Authorization Act for Fiscal Year 2008; 10 U.S.C. 2302Note).
__ (53) 52.226-4, Notice of Disaster or Emergency Area Set-Aside (Nov2007) ( 42 U.S.C. 5150).
__ (54) 52.226-5, Restrictions on Subcontracting Outside Disaster or Emergency Area (Nov2007) ( 42 U.S.C. 5150).
(55) 52.229-12, Tax on Certain Foreign Procurements (Feb 2021).
__ (56) 52.232-29, Terms for Financing of Purchases of Commercial Products and Commercial Services (Nov 2021) ( 41 U.S.C. 4505, 10 U.S.C. 2307(f)).
__ (57) 52.232-30, Installment Payments for Commercial Products and Commercial Services (Nov 2021) ( 41 U.S.C. 4505, 10 U.S.C. 2307(f)).
x (58) 52.232-33, Payment by Electronic Funds Transfer-System for Award Management (Oct 2018) ( 31 U.S.C. 3332).
__ (59) 52.232-34, Payment by Electronic Funds Transfer-Other than System for Award Management (Jul 2013) ( 31 U.S.C. 3332).
__ (60) 52.232-36, Payment by Third Party (May 2014) ( 31 U.S.C. 3332).
__ (61) 52.239-1, Privacy or Security Safeguards (Aug 1996) ( 5 U.S.C. 552a).
__ (62) 52.242-5, Payments to Small Business Subcontractors (Jan 2017) ( 15 U.S.C. 637(d)(13)).
__ (63) (i) 52.247-64, Preference for Privately Owned U.S.-Flag Commercial Vessels (Nov 2021) ( 46 U.S.C. 55305 and 10 U.S.C. 2631).
__ (ii) Alternate I (Apr 2003) of 52.247-64.
__ (iii) Alternate II (Nov 2021) of 52.247-64.
(c) The Contractor shall comply with the FAR clauses in this paragraph (c), applicable to commercial services, that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
[Contracting Officer check as appropriate.]
__ (1) 52.222-41, Service Contract Labor Standards (Aug 2018) ( 41 U.S.C. chapter67).
__ (2) 52.222-42, Statement of Equivalent Rates for Federal Hires (May 2014) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).
(3) 52.222-43, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (Multiple Year and Option Contracts) (Aug 2018) ( 29 U.S.C. 206 and 41 U.S.C. chapter 67).
__ (4) 52.222-44, Fair Labor Standards Act and Service Contract Labor Standards-Price Adjustment (May 2014) ( 29U.S.C.206 and 41 U.S.C. chapter 67).
__ (5) 52.222-51, Exemption from Application of the Service Contract Labor Standards to Contracts for Maintenance, Calibration, or Repair of Certain Equipment -Requirements (May 2014) ( 41 U.S.C. chapter 67).
__ (6) 52.222-53, Exemption from Application of the Service Contract Labor Standards to Contracts for Certain Services-Requirements (May 2014) ( 41 U.S.C. chapter 67).
__ (7) 52.222-55, Minimum Wages for Contractor Workers Under Executive Order 14026 (Jan 2022).
__ (8) 52.222-62, Paid Sick Leave Under Executive Order 13706 (Jan 2022) (E.O. 13706).
__ (9) 52.226-6, Promoting Excess Food Donation to Nonprofit Organizations (Jun 2020) ( 42 U.S.C. 1792).
(d) Comptroller General Examination of Record. The Contractor shall comply with the provisions of this paragraph (d) if this contract was awarded using other than sealed bid, is in excess of the simplified acquisition threshold , as defined in FAR 2.101, on the date of award of this contract , and does not contain the clause at 52.215-2, Audit and Records-Negotiation.
(1) The Comptroller General of the United States, or an authorized representative of the Comptroller General, shall have access to and right to examine any of the Contractor ’s directly pertinent records involving transactions related to this contract.
(2) The Contractor shall make available at its offices at all reasonable times the records, materials , and other evidence for examination, audit, or reproduction, until 3 years after final payment under this contract or for any shorter period specified in FAR subpart 4.7, Contractor Records Retention, of the other clauses of this contract . If this contract is completely or partially terminated, the records relating to the work terminated shall be made available for 3 years after any resulting final termination settlement. Records relating to appeals under the disputes clause or to litigation or the settlement of claims arising under or relating to this contract shall be made available until such appeals, litigation, or claims are finally resolved.
(3) As used in this clause, records include books, documents, accounting procedures and practices, and other data , regardless of type and regardless of form. This does not require the Contractor to create or maintain any record that the Contractor does not maintain in the ordinary course of business or pursuant to a provision of law.
(e) (1) Notwithstanding the requirements of the clauses in paragraphs (a), (b), (c), and (d) of this clause, the Contractor is not required to flow down any FAR clause, other than those in this paragraph (e)(1) in a subcontract for commercial products or commercial services. Unless otherwise indicated below, the extent of the flow down shall be as required by the clause-
(i) 52.203-13, Contractor Code of Business Ethics and Conduct (Nov 2021) ( 41 U.S.C. 3509).
(ii) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .