A19 - RFQ_75D301-23-Q-77070 Amendment 00001.doc
DOC document 455 KB Posted
- Attached to
- TBTC Clinical Trial Management System Federal contract opportunity
- Solicitation number
- 75D301-23-Q-77070
About this file
This is a combined synopsis/solicitation from the Centers for Disease Control and Prevention seeking a firm-fixed-price contract for a clinical trial management system to support tuberculosis research. Key details include developing a system to manage two TB clinical trials through electronic data capture, monitoring, participant randomization, and data visualization capabilities. The system must be accessible internationally and meet CDC security requirements. The performance period is September 2023 through September 2025. Responses are due by early September 2023, and the award will be set aside 100% for small business. The contract type will be firm-fixed-price with milestone-based payments.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A19 - RFQ_75D301-23-Q-77070 Amendment 00002.doc | DOC document | |
| A19 - RFQ_75D301-23-Q-77070 Amendment 00001 QandA Attachment 1.docx | DOCX document | |
| RFQ_75D301-23-Q-77070_CSS.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
1. CONTRACT ID CODE
PAGE OF PAGES
2. AMENDMENT/MODIFICATION NO.
00001
3. EFFECTIVE DATE
09/05/2023
4. REQUISITION/PURCHASE REQ. NO.
5. PROJECT NO. (If applicable)
| 6. ISSUED BY |
| CODE |
| 7. ADMINISTERED BY (If other than Item 6) |
| CODE |
Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS)
2900 Woodcock Blvd, MS TCU-4
Atlanta GA 303414004
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
X
9A. AMENDMENT OF SOLICITATION NO.
75D301-23-Q-77070 9B. DATED (See Item 11) 08/28/2023
10A. MODIFICATION OF CONTRACT/ORDER NO.
10B. DATED (See Item 13)
| CODE |
| FACILITY CODE |
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers _ is extended, X is not extended.
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
(a) By completing Items 8 and 15, and returning 1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEGMENT
TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT
IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
N/A
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
A.
THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN
B.
THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C.
THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D.
OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
The purpose of this amendment to the solicitation is to do the following:
1. Provide answers to the questions submitted in response to the solicitation. See Attachment 1.
2. Revise the milestone payment schedule in the solicitation. See page 2 for revised solicitation. All changes are highlighted in yellow.
Offerors are to acknowledge receipt of this Amendment with quote submission. See Block 11 of this Amendment.
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
16A. NAME OF CONTRACTING OFFICER
Denedra D. Threatt
15B. CONTRACTOR/OFFEROR
(Signature of person authorized to sign)
15C. DATE SIGNED
16B. UNITED STATES OF AMERICA
BY ___________________________________________
(Signature of Contracting Officer)
16C. DATE SIGNED
NSN 7540-01-152-8070
STANDARD FORM 30 (REV. 10-83)
PREVIOUS EDITION UNUSABLE
30-105 Prescribed by GSA
FAR (48 CFR) 53.243
Combined Synopsis/Solicitation
Solicitation Number: 75D301-23-Q-77070 Trial Management System for TB Clinical Research
This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in Federal Acquisition Requirements (FAR) Subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotes are being requested, and a written solicitation will not be issued.
The solicitation number for this requirement is 75D301-23-Q-77070 and is hereby issued as a Request for Quote (RFQ) using FAR Subpart 13.1 Simplified Acquisition Procedures.
This solicitation document and incorporated provisions and clauses are those in effect through the Federal Acquisition Circular (FAC) 2020-06.
This acquisition will be Set-Aside 100% for Small Business. The North American Industry Classification System (NAICS) code is 541990. A Firm-Fixed-Price purchase order will be issued in writing to the successful offeror. To be eligible to receive an award resulting from this solicitation, contractor must be registered in the System for Award Management.
The Centers for Disease Control and Prevention (CDC) intends to award a firm-fixed-price contract for the acquisition of items listed in Section B - Contract Line Items (CLINS). The CDC will select the quote that is technically acceptable and offers the lowest evaluated priced. Please either fill in the dollar amounts or provide a separate excel spreadsheet containing the same information including a list of line item number(s) and items, quantities, units of measure, and options, if applicable.
TABLE OF CONTENTS
SECTION B - CONTRACT LINE ITEMS
SECTION C - STATEMENT OF WORK
SECTION D - SIMPLIFIED ACQUISITION TERMS AND CONDITIONS
SECTION E - QUOTE SUBMISSION INSTRUCTIONS
SECTION B. CONTRACT LINE ITEMS
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 0001 |
| TBTC Trial Management System |
This is a firm-fixed price line item.
This is a non-severable line item.
Period of Performance: 9/25/2023 – 9/24/2025
| 1/Each |
| $ |
| $ |
Total: _________________
Schedule of Milestones for Performance-Based Payments In accordance with FAR 52.232.32, Performance Based Payments (April 2012), upon successful completion of an event, the contractor may request performance based payments. The determination of eligibility for receipt of payment will be made by the Contracting Officer upon written certification from the COR that the performance milestone has been met. It is anticipated that each milestone payment will approximate the estimated timeline listed below but variation is anticipated and eligibility for payment could occur sooner or later depending upon the time of completion of the designated milestone. Milestone payments are subject to the terms of FAR 52.232-32 incorporated in Section I of this contract.
performance period: 12 months
| milestone event |
| eSTIMATED tIMELINE |
| Payment % |
| Provide plans and timelines (Task 1) |
| Within 30 days of award |
| 5% |
| Development of base system (Task 5 & 6) |
| Within60 days of award |
| 50% |
| Development of monitoring module (Task 5) |
| Within 60 days of award |
| 10% |
| System access (Task 4) |
| Within 60 days of award |
| 10% |
| Training (Task 2 & 3) |
| Within 60 days of award |
| 10% |
| Transfer of data (Task 7) |
| Within 90 days of award |
| 10% |
| TOTAL |
| 100% |
SECTION C. STATEMENT OF WORK
Title: Trial Management System for TB Clinical Research
SECTION 1 – BACKGROUND
Since the late 1940s the U.S. Public Health Service (USPHS), and the Department of Veterans Affairs have conducted studies of anti-TB medications. In the 1960’s, the U.S. TB control and clinical research programs were transferred from their original location in Washington DC to the National Communicable Disease Center (now CDC) in Atlanta. In the 1980s, when funding for TB control was declining, support for TB drug trials also diminished. With the resurgence of TB, strong federal support for TB control was restored in 1992. CDC renewed its engagement with TB clinical trials in 1993; an open competition funded a group of trial-capable sites for a period of 5 years (1993–1998). Among site characteristics sought were access to significant numbers of TB patients, experience in the conduct of clinical trials, the presence of a highly qualified clinical team, and a credible plan for recruitment, management, and follow-up of trial participants. This trial, initially named USPHS Study 22, enrolled 1,075 TB participants from sites in the U.S. and Canada.
In 1997 CDC and the investigators from these sites decided to reorganize their activities, creating the TB Trials Consortium, or TBTC. TBTC is based in the Clinical Research Branch (CRB) of CDC’s Division of Tuberculosis Elimination (DTBE). The CRB includes medical officers, epidemiologists, health scientists, clinical research specialists, laboratorians, data analysts, data managers, statisticians, and contract specialists.
Formal by-laws for TBTC were adopted in 1998, establishing a central Steering Committee, made up of one representative from each site and one from CDC, as well as several executive committees: Core Science Group (CSG); Implementation and Quality Committee (IQC); Publications and Presentations committee (P&P); and Advocacy and External Relations (AER). The purpose of the Steering Committee was to develop a long-term comprehensive scientific agenda for the TBTC. An Executive Affairs Group (EAG), composed of committee chairs and CRB leadership, was to serve as the executive arm of the Steering Committee, and was responsible for day-to-day decision-making.
It is the intent of the DTBE that TBTC continue its efforts to conduct therapeutic, diagnostic, and preventive research in support of the CDC goal of TB elimination. An improved system will provide TBTC clinical trials with a faster, more comprehensive, and responsive system for data intake, trial monitoring, and drug management, enhancing the TB control program of the United States and the mission of domestic TB elimination.
SECTION 2 – PURPOSE/OBJECTIVE
To develop a clinical trial monitoring system specifically for intake, analysis, and monitoring of TB clinical trial data.
SECTION 3 – SCOPE OF WORK
The contractor shall provide a clinical trial management system to be used by the Tuberculosis Trials Consortium (TBTC). TBTC trial management is currently done through a custom-built system. The objective of the new project is to enhance the current process by creating a system with the capabilities to continue to perform electronic data capture processes as well as additional tasks. The contractor will be responsible for creating a system to manage two TBTC clinical trials (Study 37/ASTERoiD and Study 38/CRUSH). This system must include electronic data capture, monitoring, participant randomization, integrated MedDRA and WHO Drug Dictionary coding, data visualization, data collected in compliance with Clinical Data Acquisition Standards Harmonization (CDASH) and the management of study sites, Institutional Review Board (IRB) data and users. The contractor will provide training to Clinical Research Branch (CRB) staff on the sue of the system. The system is required to be accessible internationally at all TBTC sites while meeting CDC security requirements. This scope of work includes the creation of a trial management system and all labor, materials, and equipment required for system development.
SECTION 4 – TASKS TO BE PERFORMED
Task 1: The Contractor shall prepare a plan for a timeline and provide scheduled status updates for the development of the Trial Management System for two (2) TB clinical research trials (Study 37 and Study 38).
1.1 Training plan for CRB staff
a. Deliver detailed explanation of approach for providing appropriate training to CRB staff
1.2 Timeline for development of study 37 management system
1.3 Status updates for study 37
i. Deliver detailed update on progress via virtual meeting or email, as determined by program
ii. Deliver email to follow up if in virtual meeting 1.4 Timeline for development of study 38 management system
b. Status updates for study 38
i. Deliver detailed update on progress via virtual meeting or email, as determined by program
ii. Deliver email to follow up if in virtual meeting Task 2: The Contractor shall provide training to Clinical Research Branch (CRB) staff on the use of the system. The Training shall be via virtual meeting. The training shall include all necessary documentation
Task 3: The Contractor shall provide training to CRB staff to aid in future system builds and modifications. The training shall be via virtual meeting. The training shall include all necessary documentation Task 4: The Contractor shall develop a Trial Management System that can be easily accessed by all international sites participating in TBTC studies (Canada, Uganda, Benin, South Africa, Australia, Haiti, and Vietnam). The Trial Management system must comply with international accessibility.
4.1 The Contractor shall develop or provide training materials to assist in the training of trial site staff on the use of the system Task 5: The Contractor shall develop a Trial Management System for two (2) TB clinical research trials (Study 37 and Study 38).
5.1 The Contractor shall be responsible for developing the following for Study 37:
a. Randomization of participants and generation of participant schedules.
b. Integrated drug management system that functions with system randomization.
c. Collection of site user information, including trainings, contact information, roles and relevant trials for each user which can be used for site and role specific email generation
d. Collection of site-specific information, including active studies, site contact information, Institutional Review Board (IRB) information, and Laboratory information.
e. Collection of study IRB information, including the tracking of IRB Actions.
f. Inclusion of a Quality Assurance or test site to assess system development before changes are released to production.
g. Monitoring module which includes monitoring of all participants and active studies with the ability to make comments and queries on participant forms which can then be addressed by clinical trial sites and monitors.
h. Data visualization capabilities, including the ability to create or integrate dynamic data visualizations into the trial management system which can be accessed by clinical trial sites.
5.2 The Contractor shall be responsible for developing the following for Study 38:
i. Randomization of participants and generation of participant schedules.
j. Integrated drug management system that functions with system randomization.
k. Collection of site user information, including trainings, contact information, roles and relevant trials for each user which can be used for site and role specific email generation
l. Collection of site-specific information, including active studies, site contact information, Institutional Review Board (IRB) information, and Laboratory information.
m. Collection of study IRB information, including the tracking of IRB Actions.
n. Inclusion of a Quality Assurance or test site to assess system development before changes are released to production.
o. Monitoring module which includes monitoring of all participants and active studies with the ability to make comments and queries on participant forms which can then be addressed by clinical trial sites and monitors.
p. Data visualization capabilities, including the ability to create or integrate dynamic data visualizations into the trial management system which can be accessed by clinical trial sites.
Task 6: The Contractor shall ensure Trial Management System serves as an electronic data capture (EDC) system for two (2) TB clinical research trials (Study 37 and Study 38).
6.1 The EDC must be developed to include the following:
a. Case Report Forms (CRFs) customizable to TBTC studies to capture clinical trial data
b. CRFs which can be edited throughout the study
c. Ability to export data from the EDC as needed, as frequently as daily
d. Data collected and exported satisfying Clinical Data Acquisition Standards Harmonization (CDASH) compliance
e. Protocol deviation tracking
f. Participant summary reports to generate PDF of all entered participant information from the EDC
g. Integrated Medical Dictionary for Regulatory Activities (MedDRA) and WHO Drug Dictionary into Case Report Form data collection.
Task 7: The Contractor shall transfer existing study data for Studies 37 and 38 to new system with the ability for trial sites to view previously collected study data in the new system within new system CRFs.
Task 8: The Contractor shall provide on-going technical support, as needed, throughout the contract period.
SECTION 5 – GOVERNMENT FURNISHED PROPERTY
None.
SECTION 6 – PLACE OF PERFORMANCE
This contract may be performed entirely off site.
SECTION 7 – DELIVERABLES/REPORTING SCHEDULE
| Task |
| Deliverable |
| Quantity/Format |
| Due Date |
| Deliver To |
| Task 1 |
| Estimated time for use of Study 37 & Study 38 in the new system -- The Contractor shall prepare and submit information on when the new system is available for use |
| electronically via Word document |
| Within 7 calendar days of contract award |
| COR |
| Task 1 |
| Estimated time for the transfer of study data to the new system -- -- The Contractor shall prepare and submit information on when the study data are available in the new system |
| electronically via Word document |
| Within 7 calendar days of contract award |
| COR |
| Task 1 |
| Training plan: The Contractor shall prepare and submit information on how the staff will learn to use the new system |
| electronically via Word document |
| Within 7 calendar days of contract award |
| COR |
| Task 1 |
| Training timeline: the Contractor shall provide a detailed written timeline of when the training of staff on the new system will take place |
| electronically via Word document |
| Within 7 calendar days of contract award |
| COR |
| Tasks 2 & 3 |
| Virtual training: The Contractor shall prepare at least one virtual training to prepare CRB staff to use the new system. The training(s) will be comprehensive to the degree that all staff in attendance are able to use the system. |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Tasks 2 & 3 |
| The Contractor shall prepare documents to supplement the virtual training to prepare CRB staff to use the new system. The training materials will be easy to reference and understand in their relationship to the new system. |
| provide electronically in MS Word or other appropriate material format |
| Within 60 calendar days of award |
| COR |
| Task 4 |
| The Contractor shall prepare documents to supplement the trainings provided CRB staff to orient clinical trial site staff to the new system. The training materials will be easy to reference and understand in their relationship to the new system. The training materials should explain how to access new system. |
| provide electronically in MS Word or other appropriate material format |
| Within 60 calendar days of award |
| COR |
| Task 5 |
| Test of system: The Contractor shall prepare a Quality Assurance or test site to assess system development before changes are released to production |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall prepare a system with the ability to randomize study participants based on CRB provided randomization table and criteria for both clinical trials |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall provide an integrated drug management system that functions with the system randomization to manage study drugs for both clinical trial sites. |
| provide electronically online |
| Within 90 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall create a module for the collection of site user information, including trainings, contact information, roles and relevant trials for each user which can be used for site and role specific email generation |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall create a module for the collection of information, including active studies, site contact information, Institutional Review Board (IRB) information, and Laboratory information. |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall create a module which includes monitoring of all participants and active studies with the ability to make comments and queries on participant forms which can then be addressed by clinical trial sites and study monitors |
| provide electronically online |
| Within 90 calendar days of award |
| COR |
| Task 5 |
| The Contractor shall create a study management system with data visualization capabilities, including the ability to create or integrate dynamic data visualizations into the trial management system which can be accessed by clinical trial sites. |
| provide electronically online |
| Within 90 calendar days of award |
| COR |
| Task 6 |
| Electronic Case Report Forms (eCRFs) customizable to TBTC studies: The Contractor shall create eCRFs which are customizable to TBTC studies and based on the business rules and requirements required for each study |
| provide electronically online |
| Within 60 calendar days of award |
| COR |
| Task 6 |
| eCRFs which can be edited throughout the study – -- The Contractor shall create eCRFs which can be edited throughout the study by the Clinical Research Branch (CRB) Data Management Team (DMIT), as needed based on study requirements. |
| provide electronic online forms |
| Within 60 calendar days of award |
| COR |
| Task 6 |
| The Contractor shall export all eCRF study data from the EDC, as needed, as frequently as daily. Exported data shall be in the CDASH format. |
| provide electronically in clinical trial management system |
| Within 60 calendar days of award |
| COR |
| Task 6 |
| The Contractor shall provide a method for protocol deviation tracking which allows protocol deviations to be tracked across participants and across studies. Deviations need to have the ability to be linked to multiple participants within one clinical trial site |
| provide electronically in clinical trial management system |
| Within 60 calendar days of award |
| COR |
| Task 6 |
| The Contractor shall generate PDF reports of all entered participant information from eCRF data which can be generated by CRB staff, as needed, based on the requirements provided by DMIT. |
| provide electronically in clinical trial management system |
| Within 90 calendar days of award |
| COR |
| Task 7 |
| The Contractor shall transfer existing study data for Study 38 to new system with the ability for trial sites to view previously collected study data in the new system within new system CRFs. |
| provide electronically in clinical trial management system |
| Within 90 days of award |
| COR |
| Task 7 |
| The Contractor shall transfer existing study data for Study 37 to new system with the ability for trial sites to view previously collected study data in the new system within new system CRFs. |
| provide electronically in clinical trial management system |
| Within 120 days of award |
| COR |
SECTION 10 – ADDITIONAL REQUIREMENTS
The created trial management system must comply with FDA clinical trial regulations for electronic data capture (21 CFR Part 11). The system must meet CDC security requirements per NCHHSTP Information Systems Security Office (ISSO). The system should integrate CDC Secure Access Management System (SAMS).
Information Security and Privacy Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
Protect government information and information systems in order to ensure:
Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
Availability, which means ensuring timely and reliable access to and use of information.
Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
Comply with the Privacy Act requirements and tailor FAR clauses as needed.
Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality:
[X] Low [ ] Moderate [ ] High
Integrity:
Availability:
Overall Risk Level:
[X] Low [ ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[x] No PII [ ] Yes PII
Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.
Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
marked appropriately;
disclosed to authorized personnel on a Need-To-Know basis;
protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and returned to HHS control, destroyed when no longer needed, or held until otherwise directed. Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:
18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6). .
Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
Standard for Encryption. The Contractor (and/or any subcontractor) shall:
Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC Office of Chief Information Security Officer (OCISO).
Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
Training
Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
Role-based Training.
All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
Training Records.
The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
Rules of Behavior
The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
Incident Response
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:
Definition of an Incident:
An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach:
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
All contractors and subcontractors shall participate in regular training on how to identify and report a breach.
All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.
All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.
All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.
Cloud service providers shall use guidance provided in the FedRAMP Incident Communications Procedures when deciding when to report directly to US-CERT first or notify CDC first.
Identify roles and responsibilities, in accordance with HHS/CDC Breach Response Policy and the HHS/CDC Breach Response Plan. To this end, the Contractor shall NOT notify affected individuals unless and until so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, all notifications must be pre-approved by the appropriate CDC officials, consistent with HHS/CDC Breach Response Plan, and the Contractor shall then send CDC- approved notifications to affected individuals; and, Acknowledge that CDC will not interpret report of a breach, by itself, as conclusive evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.
Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR).
Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR and/or CO by the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted immediately upon change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
Contract Initiation and Expiration
General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HHS EPLC framework and methodology and in accordance with the HHS Contract Closeout Guide (2012).
System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or COR and system ISSO before an employee stops working under this contract.
Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or CDC policies.
The Contractor (and/or any subcontractor) shall perform and document the actions identified in the CDC Out-Processing Checklist (http://intranet.cdc.gov/od/hcrmo/pdfs/hr/Out_Processing_Checklist.pdf) when an employee terminates work under this contract. All documentation shall be made available to the CO and/or COR upon request.
Records Management and Retention
The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS policies and shall not dispose of any records unless authorized by HHS.
In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS policies.
Data Right and Source Code
As required by the Federal Source Code Policy set out in OMB Memo M-16-21, all computer software first produced in the performance of this contract shall be open source software and shall be available for Government-wide use and for use by the public with data use rights under FAR 52.227-14 Rights in Data - General, unless otherwise specified in writing by the contract officer. The Contractor (and/or any subcontractor) shall maintain, at all times, a working, current and fully-documented copy of all project or activity custom-developed source code in a repository from the CDC Recognized List of Source Code Repositories.
Secure Coding Practices
The Contractor (and/or any subcontractor) shall follow secure coding best practice requirements, as directed by the United States Computer Emergency Readiness Team (US-CERT) specified standards and the Open Web Application Security Project (OWASP) that will limit system software vulnerability exploits.
Section 508 Compliance
Electronic and Information Technology Accessibility Notice
(a) Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 and the Architectural and Transportation Barriers Compliance Board Electronic and Information (EIT) Accessibility Standards (36 CFR part 1194), require that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency.
(b) Accordingly, any offeror responding to this solicitation must comply with established HHS EIT accessibility standards. Information about Section 508 is available at http://www.hhs.gov/web/508. The complete text of the Section 508 Final Provisions can be accessed at http://www.access-board.gov/sec508/standards.htm.
(c) The Section 508 accessibility standards applicable to this contract are:
In order to facilitate the Government's determination whether proposed EIT supplies meet applicable Section 508 accessibility standards, offerors must submit an HHS Section 508 Product Assessment Template, in accordance with its completion instructions. The purpose of the template is to assist HHS acquisition and program officials in determining whether proposed EIT supplies conform to applicable Section 508 accessibility standards. The template allows offerors or developers to self-evaluate their supplies and documentation detail - whether they conform to a specific Section 508 accessibility standard, and any underway remediation efforts addressing conformance issues. Instructions for preparing the HHS Section 508 Evaluation Template are available under Section 508 policy on the HHS Web site http://hhs.gov/web/508.
(d) Respondents to this solicitation must identify any exception to Section 508 requirements. If an offeror claims its supplies or services meet applicable Section 508 accessibility standards, and it is later determined by the Government, i.e., after award of a contract…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .