Attachment_J.17_HCQIS_CFE_Guidelines_and_Requirements.docx

DOCX document 59 KB Posted

Attached to
BFCC-QIO IDIQ Federal contract opportunity
Solicitation number
75FCMC18R0034
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

J.17 HCQIS CFE Guidelines

View the file

Other files for this federal contract opportunity

Other files attached to BFCC-QIO IDIQ, newest first.
File Type Posted
BFCC_Pre-solicitation_Recording_Webex.docx DOCX document
May_15_BFCC_registered_participants_list.xlsx XLSX spreadsheet
2018-05-15_BFCC_Pre-Solicitation_Conference_Agenda.pdf PDF
2018-05-15_BFCC_Pre-Solicit_Conf_FINAL-508_Final.pptx PPTX presentation
Attachment_J.3-C_TO_0002_Evaluation_Measures_Table.docx DOCX document
Attachment_J.2-F_TO_0001_Business_Proposal_Instructions_BFCC_NCORC.docx DOCX document
Attachment_J.11_Small_Business_Subcontracting_Plan.doc DOC document
Attachment_J.15_VPAT.doc DOC document
Attachment_J.1_BFCC_IDIQ_Statement_of_Work.docx DOCX document
Attachment_J.16_VDI_Onboarding.pdf PDF
Attachment_J.3-G_TO_0002_Task_Order_Terms_and_Conditions.docx DOCX document
Attachment_J.3-F_TO_0002_Business_Proposal_Instructions_Case_Review.docx DOCX document
SF-33_75FCMC18R0034.pdf PDF
Attachment_J.8_ServiceNow_CMS_Asset_and_Procurement_User_Guide.docx DOCX document
Attachment_J.2-C_TO_0001_Evaluation_Measures_Table_BFCC_NCORC.docx DOCX document
Attachment_J.12_565_Report_of_Accountable_Property.pdf PDF
BFCC_RFP_75FCMC18R0034.docx DOCX document
Attachment_J.4_Contractor_Business_Ethics_COI_and_Compliance_Program_Requirements.docx DOCX document
Attachment_J.2-B_TO_0001_Schedule_of_Deliverables_BFCC_NCORC.docx DOCX document
Attachment_J.14_Question_Submission_Format_Sample.xlsx XLSX spreadsheet
Attachment_J.9_Information_Systems_Security_Requirements.docx DOCX document
Attachment_J.2-G_TO_0001_Task_Order_Terms_and_Conditions.docx DOCX document
Attachment_J.2-A_TO_0001_Statement_of_Work_BFCC_NCORC.docx DOCX document
Attachment_J.5_Personal_Conflicts_of_Interest_Financial_Disclosure.docx DOCX document
Attachment_J.3-D_TO_0002_Proposal_Instructions_and_Eval_Criteria_BFCC_Case_Review.docx DOCX document
Attachment_J.3-E_TO_0002_Business_Proposal_Forms_Case_Review_.xlsx XLSX spreadsheet
Attachment_J.10_Consent_to_Subcontract.docx DOCX document
Attachment_J.7_Compliance_Program_Guidance.pdf PDF
Attachment_J.2-E_TO_0001_Business_Proposal_Forms.xlsx XLSX spreadsheet
Attachment_J.3-B_TO_0002_Case_Review_SOD.docx DOCX document
Attachment_J.6_BFCC_Glossary_Terms_and_Acronyms.docx DOCX document
Attachment_J.3-H_LOE_by_Case.xlsx XLSX spreadsheet
Attachment_J.2-D_TO_0001_Proposal_Instructions_and_Eval_Criteria_BFCC_NCORC.docx DOCX document
Attachment_J.3-A_TO_0002_Case_Review_SOW.docx DOCX document
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CMS XLC

Health Care Quality Information Systems (HCQIS) Contractor-Furnished Equipment (CFE) Guidelines and Requirements Version 1.0 04/17/2018

Introduction In response to end-user requests and to support the ever-increasing computing demands of the Health Care Quality Information Systems (HCQIS), the Center for Clinical Standards and Quality (CCSQ) offers its users the ability to use corporate-furnished equipment (CFE) in place of the currently provided Centers for Medicare & Medicaid Services (CMS) government-furnished equipment (GFE).

This enables organizations to select and right-size the computer hardware used to access the HCQIS environment through a Virtual Desktop Infrastructure (VDI) or Virtual Private Network (VPN) that best satisfies the CCSQ contract (all computer hardware must comply the VDI or VPN access and security requirements). Organizations should first consider the use of VDI. Users who cannot complete their job functions over VDI will then be considered for VPN use. Appropriate justification must be provided to CMS prior to any user being approved for VPN access.

This HCQIS CFE Guidelines and Requirements document provides details on the access and security requirements for both VDI and VPN, along with the onboarding requirements.

Use of the VPN constitutes agreement with all requirements in this HCQIS CFE Guidelines and Requirements document.

CFE Overview As an alternative to GFE, CCSQ offers its users the ability to select and right-size the computer hardware used to access the HCQIS environment.

By choosing to use CFE, through either a VDI and/or VPN, the contractor agrees to the CFE requirements in Section 2.1.

Note: Additional requirements specific to VDI and VPN are captured in sections below.

General CFE Requirements and User Responsibilities The following list identifies general CFE requirements and user responsibilities:

Personal laptops, computers, smartphones, etc. are not authorized to connect to the HCQIS network in any fashion, including charging a smartphone via your connected laptop’s Universal Serial Bus (USB) port.

“Connect to the HCQIS network” in this context means logging into the HCQIS network via a successful VPN instance. VPN connections to the HCQIS network are allowed only via CFE, VPN connections via personal assets are strictly prohibited.

Users are authorized to connect to the HCQIS VDI or VPN environments while physically in the U.S. or its territories. Connection attempts from locations other than these will result in the connection begin refused, and the behavior will be logged as a security violation.

While connected to the HCQIS VPN, split-tunneling will be disabled. As a result, non-VPN traffic may be blocked by the VPN client when connected to the HCQIS VPN.

HCQIS VDI or VPN users shall not store CMS-sourced Personally Identifiable Information (PII) and Personal Health Information (PHI) on their local hard drives or removable media (U.S. Health Insurance Portability and Accountability Act (HIPAA) of 1996, The Privacy Act of 1974 for PHI and PII definitions). No CMS data shall be stored on unencrypted storage devices, such as flash drives.

CMS data shall only be stored on hard drives or removable media that complies with CMS encryption requirements.

1. “CMS data” in this context means:

Data sent to CMS by providers, business partners, government entities, health plans, etc. for use in government programs Any data not available to the general public (and/or containing PHI/PII) supplied by CMS for programmatic use under contract Any data derived by CMS from data submitted to the government that is not created for public display Computer system software, designs, and configurations built for government use Any information supplied by CMS marked as sensitive or for official use only (FOUO) Encrypt all sensitive federal data and information (e.g., PII, PHI, proprietary information, etc.) in transit (e.g., email, network connections, etc.) and at rest (e.g., servers, storage devices, mobile devices, backup media, etc.) with Federal Information Processing Standards (FIPS) 140-2 validated encryption solution.

Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The contractor shall provide a written copy of the validation documentation to the Contracting Officer’s Representative (COR) and/or Government Task Lead (GTL) upon request.

If any CMS data is stored on the device, it shall not be taken out of the continental United States (CONUS) unless said CMS data has been removed.

Verify you have access to a fully functioning and reliable internet connection.

Verify that you (or your corporate information technology (IT) department) have rights to install software on your local machine, for any client software needed.

Use of the HCQIS VDI/VPN requires a Symantec Validation and ID Protection (VIP) soft token for two-factor authentication (TFA). Soft tokens must be registered and activated (Homeland Security Presidential Directive 12 (HSPD-12)).

1. The token (i.e., Symantec VIP client software) can reside on the CFE laptop or on a user’s mobile device, but must be properly registered for use on the HCQIS network.

VDI requires the use of the VMware Horizon Client application. The VMware Horizon Client must be installed on the user’s personal computer (PC) before a connection to the VDI environment is possible.

Contractors connecting to the HCQIS environment in any manner shall monitor and adhere to all IT policies, standards, procedures, directives, templates, and guidelines that govern the CMS Information Security program. CMS IT Security Policy documents (such as the Acceptable Risk Safeguards (ARS), Information Systems Security and Privacy Policy (IS2P2), and the Risk Management Handbook (RMH)) can be accessed at http://www.cms.gov/informationsecurity.

IT Support Contractors can obtain support for issues related to VDI or VPN access by calling the QualityNet Help Desk, but first must determine that the problem is not related to the computer hardware, operating system (OS), non-CMS software, required patches and antivirus (AV) updates, and/or network connectivity. If your organization’s IT service professional determines that a particular problem is not related to your hardware or software, and is directly related to CMS application access or functionality, your organization’s IT service professional should contact the QualityNet Help Desk for assistance.

VDI Overview In a traditional environment, a user manipulates data on a PC or laptop using preloaded software and applications. By leveraging VDI, users can communicate with local file, print, and database (DB) servers within the organization’s physical network infrastructure or with data elsewhere in the HCQIS network using a remote connection. VDI uses applications running in a remote image (hence the virtual desktop) and data stored in the HCQIS data center, rather than locally run applications and locally stored data.

All the typical icons, folders, toolbars, widgets, etc. that an individual is used to seeing on his/her desktop, appears within the VDI session. It will appear as if the resources being used are local to the user’s desk; however, they are housed in the data center.

A VDI environment enables users to access HCQIS resources without the need for the VPN tunnel via an external facing website (note that VDI may also be used in conjunction with VPN). Once connected to this website and authenticated using TFA, the user can perform all work-related tasks in a virtual environment using corporate or personal assets. CMS reserves the right to change this policy if the security posture of VDI changes.

VDI has the following benefits:

No need to use GFE No requirement to connect via a VPN client No need to load standard software/applications used to perform contract work on one’s PC or laptop No need to worry about local software patches and updates being downloaded and installed over the VPN connection VDI Access Requirements The following list presents VDI access requirements:

Use of the VDI system does not constitute a connection, so there is no restriction on the CFE used, other than it must run a supported browser and any related client software.

Connecting via VDI to the HCQIS network using public machines (e.g., library computers, kiosks, hotel computers, etc.) is strictly prohibited.

All VDI users must successfully complete the HCQIS VDI request process.

VDI users must be approved to use HCQIS VDI services on CFE per the VDI Onboarding User Guide.

VPN Overview VPN software allows the user to create an encrypted tunnel from his/her CFE to the HCQIS network. This allows secure access to HCQIS data via one’s Internet Service Provider (ISP), a hotel internet connection, etc. After a VPN connection is established, the user has the same capabilities, permissions, and access levels one would have if physically located at a CMS location or within an organization’s CMSnet-connected office building.

VPN Access Requirements Other than GFE, VPN connections to the HCQIS network are allowed only via CFE (i.e., laptops). VPN connections via personal assets are strictly prohibited. All VPN users must successfully complete the HCQIS VPN request process and receive approval to use HCQIS VPN services on CFE.

VPN Software Requirements For VPN use, it is recommended that any other VPN client software be removed from the target machine before installing the HCQIS Cisco VPN client. The contractor assumes responsibility for any conflicts related to the non-HCQIS VPN clients being installed.

The following additional software requirements relate to the use of the HCQIS VPN:

Microsoft Windows 8.1, Windows 10, or a currently supported version of the Mac OS must be used. Although Windows 7 is technically supported for compatibility, users are strongly urged to use Windows 8.1 or Windows 10.

AV software must be present, running, and current. The most current versions of the software and the signature file should be used, unless otherwise advised to be incompatible with the current HCQIS environment. A full AV scan shall be completed within 24 hours prior to connecting to the HCQIS VPN.

All current Microsoft or Apple service packs, hot fixes, and patches must be installed.

All installed software (e.g., MS Word, Chrome, Safari, Java, Adobe products, etc.) must be current with security patches.

VPN Security Configuration The following security requirements must be met for the machine being used to connect to the HCQIS VPN:

Federally-mandated USGCB or DISA STIG configuration settings must be adhered to as specified in CMS’s Acceptable Risk Safeguards (ARS) document.

The hard drive(s) of the machine used for a VPN connection must be encrypted using software that is compliant with FIPS 140-2 requirements. In addition, the system must encrypt any data transferred to removable media (also via FIPS 140-2 compliant encryption software).

After 15 minutes of inactivity, the CFE screen must auto-lock.

For Windows machines, the Enhanced Mitigation Experience Toolkit (EMET) v5.5 or later must be installed, and Internet Information System (IIS) must not be installed on the system.

All local accounts on the machine must have a password set.

A standard user account (i.e. not an account with admin rights) should be used when connected to the HCQIS VPN.

For Windows machines, local volumes (i.e., hard drives) must be formatted with New Technology File System (NTFS).

Federal Information Security Management Act (FISMA)/United States Government Configuration Baseline (USGCB)/Defense Information System Agency (DISA) Security Technical Implementation Guide (STIG) requirements must be met for all local administrator-level accounts and any accounts used to log into the machine prior to making a VPN connection to HCQIS.

Note: CMS retains the right to request that a contractor computer be inspected by CMS, or an authorized representative, and pass requirements verification. As part of the inspection, it will be verified that all hardware, software, and security requirements are met. In addition, all machines connected to the HCQIS VPN will be scanned for vulnerabilities while connected, and if any serious issues are found and communicated, the user agrees to remove the machine from the VPN and remediate the issue(s) before reconnecting.

VPN Security Posture Assessment The Cisco Identity Service Engine (ISE) provides the ability to check security requirements on client computers and laptops. The AnyConnect ISE Posture Module will be installed on the computer during the client installation to facilitate communication with the ISE on the CMS VPN network. The ISE automatically updates itself daily to ensure client machines are checked against the most recent hot fixes and virus signature files. The ISE evaluates all requirements to determine whether access should be granted.

If a machine attempting to connect fails an ISE posture check, the user will be notified of the deficient posture reason, and access to the HCQIS network will be denied. The user is responsible for obtaining updated software from their CFE provider before attempting to connect again.

Attachment J.17

Acronyms

Acronym
Definition
ARS
Acceptable Risk Safeguards
AV
Antivirus
CCSQ
Center for Clinical Standards and Quality
CFE
Contractor-Furnished Equipment
CMS
Centers for Medicare & Medicaid Services
CONUS
Continental United States
COR
Contract Officer’s Representative
DB
Database
DEP
Data Execution Prevention
DISA
Defense Information Systems Agency
DoD
Department of Defense
EMET
Enhanced Mitigation Experience Toolkit
FIPS
Federal Information Processing Standards
FISMA
Federal Information Security Management Act
FOUO
For Official Use Only
GFE
Government-Furnished Equipment
GTL
Government Task Lead
HCQIS
Health Care Quality Information Systems
HIDS
HCQIS Infrastructure and Data Center Support
HIPAA
Health Insurance Portability and Accountability Act
HSPD
Homeland Security Presidential Directive
IIS
Internet Information System
IS2P2
Information Systems Security and Privacy Policy
ISE
Cisco Identity Service Engine
ISP
Internet Service Provider
IT
Information Technology
LAN
Local Area Network
LM
LAN Manager
NTFS
New Technology File System
NTLM
Network LAN Manager
OS
Operating System
PC
Personal Computer
PHI
Personal Health Information
PII
Personally Identifiable Information
RMH
Risk Management Handbook
ROB
Rules of Behavior
SAM
Security Account Manager
SEHOP
Structured Exception Handling Overwrite Protection
SID
Security Identifier
SP
Service Pack
STIG
Security Technical Implementation Guide
TFA
Two-Factor Authentication
USB
Universal Serial Bus
USGCB
United States Government Configuration Baseline
VDI
Virtual Desktop Infrastructure
VIP
Validation and ID Protection
VPN
Virtual Private Network
WinRM
Windows Remote Management
XLC
Expedited Life Cycle

Referenced Documents Table 3: Referenced Documents

Document Name
Document Location and/or URL
Issuance Date
CMS Acceptable Risk Safeguards
https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/CIO-Directives-and-Policies/CIO-IT-Policy-Library-Items/STANDARD-ARS-Acceptable-Risk-Safeguards.html
11/21/2017
CMS Information Security and Privacy Overview
http://www.cms.gov/informationsecurity
04/26/2016
Rules of Behavior (ROB) for Use of HHS Information Resources
https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/rules-of-behavior-for-use-of-hhs-information-resources/index.html
07/24/2013

File details come from the government source that posted it.