75FCMC22R0035_0001.pdf
PDF 706 KB Posted
- Attached to
- National Correct Coding Initiative (NCCI) Federal contract opportunity
- Solicitation number
- 75FCMC22R0035
About this file
This is a solicitation for National Correct Coding Initiative (NCCI) program services. The Centers for Medicare and Medicaid Services (CMS) seeks proposals from eligible 8(a) small businesses to maintain NCCI correct coding edits, manuals, and edit files that promote Medicare and Medicaid program integrity and reduce improper payments. The firm fixed price contract includes a one-year base period, three one-year option periods, a ten-month option period, and a 90-day transition period. Offerors must have the ability to provide guidance, edits, and methodologies ensuring consistent coding and payment policies. Interested 8(a) sources may directly submit proposals by the response date specified on the federal contracting website, with no other submission methods accepted.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| E.2 NCCI Questions_CMS Response.docx | DOCX document | |
| J.2 - Contractor_Offeror Conflict of Interest Template.docx | DOCX document | |
| E.1 - NCCI Business Proposal Template.xlsx | XLSX spreadsheet | |
| E.6 - Past Performance Questionnaire.docx | DOCX document | |
| J.1 - NCCI SOW.docx | DOCX document | |
| E.8 -508 Checklist Instructions.docx | DOCX document | |
| SF-33-75FCMC22R0035 NCCI RFP.pdf | ||
| E.3 - Responsibility Questionnaire.docx | DOCX document | |
| E.5 - Consent to Subcontract.docx | DOCX document | |
| E.2 - NCCI Questions Submission Template.docx | DOCX document | |
| E.4 - Prime Proposal Checklist.docx | DOCX document | |
| E.7 - Scenario C Edits.docx | DOCX document |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
(x)
75FCMC22R0035
x x copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE
RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR
OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
x
ASG - DPIFMC
BALTIMORE MD 21244-1850
7500 SECURITY BLVD., MS: B3-30-03
CMS,OAGM,ASG,DPIFMC
11/01/20220001
13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing
The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
FACILITY CODE CODE
10B. DATED (SEE ITEM 13)
10A. MODIFICATION OF CONTRACT/ORDER NO.
9B. DATED (SEE ITEM 11)
9A. AMENDMENT OF SOLICITATION NO.
CODE
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY
PAGE OF PAGES
4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)
1. CONTRACT ID CODE
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
10/20/2022
CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority) appropriation data, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
E. IMPORTANT: Contractor is not is required to sign this document and return __________________ copies to the issuing office.
ORDER NO. IN ITEM 10A.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
The purpose of this amendment is to provide responses to relevant questions received and to incorporate the following changes, identified in red text throughout the Solicitation:
1. Correct the Period of Performance start date in F.2. to February 3, 2023;
2. Updated the text in L.6 (4)(B) to include a maximum of three overall past performance submissions for the Prime;
3. Remove the reference to “All” from L.6 (4)(b)(1 & 2);
3. Updated the text in L.6 (4)(B) to include no more than three (Prime)/ two (Significant
Subcontractor) Past Performance Questionnaire (PPQ); and
4. Incorporate an updated Exhibit E.2, which includes responses to relevant questions received.
Continued ...
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)
15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED
(Signature of person authorized to sign) (Signature of Contracting Officer)
Jennifer J. Kuhn
STANDARD FORM 30 (REV. 11/2016)
Prescribed by GSA FAR (48 CFR) 53.243
Previous edition unusable
Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
NAME OF OFFEROR OR CONTRACTOR
2 63
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
75FCMC22R0035/0001
Please note this Solicitation is subject to the availability of funds. All other terms and conditions remain unchanged.
NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)
Sponsored by GSA
FAR (48 CFR) 53.110
RFP-75FCMC22R0035_0001 National Correct Coding Initiative
PART I – THE SCHEDULE
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
B.1 DESCRIPTION OF SERVICES
The contractors shall support the Centers for Medicare & Medicaid Services (CMS) National Correct Coding Initiative (NCCI) program by maintaining and further expanding all of the NCCI correct coding edits and other methodologies to ensure that consistent coding and adjudication of Medicare and Medicaid claims lead to consistent payments to providers in accordance with the payment policies of those programs; and enable CMS and states to meet the Medicaid program requirements as outlined in section 6507 of the Patient Protection and Affordable Care Act
(PPACA).
The work to be performed is described in detail in the National Correct Coding Initiative (NCCI) Statement of Work, provided as Attachment J.1.
B.2 TYPE OF CONTRACT
The contract is Firm Fixed Price (FFP). A contract line item number (CLIN) is established for the base period and each optional period.
B.3 SCHEDULE OF SERVICES
The total estimated cost of this contract is $TBD.
CLIN / SLIN # Description PSC Accounting Classification
Unit of Measure
Firm Fixed Price
Funded Period of Performance
CLIN 0001 Base Period R499 See Section G.1 Dollars
02/03/2023 – 02/02/2024 SLIN 0001AA Medicare
SLIN 0001AB Medicaid
CLIN 0002 Option Period 1
02/03/2024 – 02/02/2025 SLIN 0002AA Medicare
SLIN 0002AB Medicaid
CLIN 0003 Option Period 2
02/03/2025 – 02/02/2026 SLIN 0003AA Medicare
SLIN 0003AB Medicaid
CLIN 0004 Option Period 3
02/03/2026 – 02/02/2027 SLIN 0004AA Medicare
SLIN 0004AB Medicaid
CLIN 0005A Option Period 4 R499 See Section G.1 Dollars
02/03/2027 – 12/02/2027 SLIN 0005AA Medicare
SLIN 0005AB Medicaid
CLIN 0006 Optional Transition Out R499 See Section G.1 Dollars 11/03/2027 –
02/02/2028
B.4 PAYMENT MILESTONE SCHEDULE (will be updated annually) The Contractor shall invoice for payment in accordance with the instructions provided in Section G.2 of this contract. The Contractor shall bill upon completion and Government acceptance of the following.
Payment
Deliverable % Amount
Medicare
SLIN
0001AA
Medicaid
SLIN
0001AB
Total
1 1.1 Project Management Plan (PMP) - Initial Year
3%
2 1.1 PMP - Subsequent Years 3%
3 3.1 NCCI Coding Policy Manuals for Medicare & Medicaid - Final
7%
4 3.2 NCCI Correspondence Language Manuals for Medicare & Medicaid - Final
7%
5 3.3 Technical Guidance Manual for Medicaid - Final
7%
6 4.0 (12) Monthly Activity Report .25% each
7 4.1 Quarterly Edit Files for Medicare & Medicaid (PTP, MUE, and AOC) Test - Quarter 1
4%
8 4.1 Quarterly Edit Files for
MUE, and AOC) Final - Quarter 1
7%
9 4.2.2 Changes Report for Medicare and Medicaid (PTP, MUE, and AOC) Quarter 1
5%
10 4.1 Quarterly Edit Files for Medicare & Medicaid (PTP, MUE, and AOC) Test - Quarter 2
4%
11 4.1 Quarterly Edit Files for Medicare & Medicaid (PTP, MUE, and AOC) Final - Quarter 2
7%
12 4.2.2 Changes Report for Medicare and Medicaid (PTP, MUE, and AOC) Quarter 2
5%
13 4.1 Quarterly Edit Files for
MUE, and AOC) Test - Quarter 3
4%
14 4.1 Quarterly Edit Files for
MUE, and AOC) Final - Quarter 3
7%
15 4.2.2 Changes Report for Medicare and Medicaid (PTP, MUE, and AOC) Quarter 3
5%
16 4.1 Quarterly Edit Files for Medicare & Medicaid (PTP, MUE, and AOC) Test - Quarter 4
4%
17 4.1 Quarterly Edit Files for Medicare & Medicaid (PTP, MUE, and AOC) Final - Quarter 4
7%
18 4.2.2 Changes Report for Medicare and Medicaid (PTP, MUE, and AOC) Quarter 4
5%
19 4.2.3 Frequently Asked Questions for Medicare and Medicaid (Final)
3%
20 4.3.2 Annual Contract Year Report
3%
Total % 100%
(END OF SECTION B)
SECTION C - DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C.1 STATEMENT OF WORK
Independently and not as an agent of the Government, the contractor shall furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform the NCCI Statement of Work, Section J, Attachment J.1 attached hereto and made a part of this contract.
(END OF SECTION C)
SECTION D - PACKAGING AND MARKING
D.1 PACKAGING, MARKING AND SHIPPING
Deliverables shall be marked in accordance with the SOW Appendix A - Deliverable Schedule and Appendix E- Information Security and Privacy Language, List of Deliverables.
(END OF SECTION D)
SECTION E - INSPECTION AND ACCEPTANCE
E.1 FAR 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:
https://www.acquisition.gov/
Clause No. Title Date
52.246-4 Inspection of Services—Fixed-Price AUG 1996
E.2 INSPECTION AND ACCEPTANCE
(a) All work under this contract is subject to inspection and final acceptance by the Contracting Officer or the duly authorized representative of the Government.
(b) The Government's Contracting Officer Representative (COR) is a duly authorized representative of the Government and is responsible for inspection and acceptance of all items to be delivered under this contract.
(c) Inspection and acceptance of the contractor‘s performance shall be in accordance with the applicable FAR clauses in Section E.1 above.
(END OF SECTION E)
https://www.acquisition.gov/
SECTION F DELIVERIES OR PERFORMANCE
F.1 FAR 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:
Clause No. Title Date 52.242-15 Stop-Work Order AUG 1989
F.2 PERIOD OF PERFORMANCE (JAN 2014)
The Period of Performance for the NCCI is estimated to be February 3, 2023 to February 2, 2024.
The contract includes the following estimated Option Periods:
F.3 SCHEDULE OF DELIVERABLES
The Contractor shall submit all required deliverables in accordance with the SOW Appendix A - Deliverable Schedule and Appendix E- Information Security and Privacy Language, List of Deliverables.
(END OF SECTION F)
Option Year 1 CLIN 0002 02/03/2024 – 02/02/2025 Option Year 2 CLIN 0003 02/03/2025 – 02/02/2026 Option Year 3 CLIN 0004 02/03/2026 – 02/02/2027 Option Year 4 CLIN 0005 02/03/2027 – 12/02/2027 Option Task 6 CLIN 0006 11/03/2027 – 02/02/2028
SECTION G CONTRACT ADMINISTRATION DATA
G.1 ACCOUNTING AND APPROPRIATION DATA
(To be incorporated at time of award)
Requisition Appropriation Object Class CAN Amount
G.2 PAYMENTS - INVOICES – (AUG 2020)
a. GENERAL: Effective August 31, 2020, the contractor/vendor shall create an invoice within the Invoice Processing Platform (IPP), a secure Web-based service for federal agencies and their vendors to manage government invoicing from purchase order (PO) through payment notification. Note: All invoice terms and conditions are contract specific and may vary from contract to contract.
b. CONTENT OF INVOICE: FAR 32.905 Payment Documentation and Process, provides the required content for a proper invoice. In addition to the requirements of FAR 32.905, the following items shall also be included on the invoice to be considered proper:
• Line item number (i.e. CLIN/SLIN as applicable);
• Contractor’s UEI Number;
• Period of performance or delivery date of goods or services provided;
• Attachments
c. INVOICE SUBMISSION: The contractor/vendor shall create an invoice from the
Purchase Order (PO)/Contract via the IPP website http://www.ipp.gov/. For questions, call IPP Customer Support at (866) 973-3131 or email the IPP Customer Support at IPPCustomerSupport@fiscal.treasury.gov.
d. PAYMENTS: The Government shall make payment of all proper invoices in accordance with the following clauses, as applicable and included in the respective PO/Contract:
• FAR 52.232-33 Payments by Electronic Funds Transfer – System for Award Management,
• FAR 52.232-1 Payments
• FAR 52.212-4 Contract Terms and Conditions – Commercial Items
• FAR 52.216-7 Allowable Cost and Payment
• FAR 52.232-7 Payments under Time-and-Materials and Labor-Hour Contracts
Payment shall be made upon acceptance by the Contracting Officer’s Representative (COR)in accordance with the applicable FAR Inspection and Acceptance clause and the Contracting Officer’s approval, as appropriate.
Reimbursement for invoices submitted under this contract shall be made no later than 30 calendar days after receipt of a proper invoice from the Contractor requested at the paying office designated above. Contracts with a 15-day payment term are not subject to interest payments until after day 30.
https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2032_9.html#wp1032997 https://www.acquisition.gov/sites/default/files/current/far/html/Subpart%2032_9.html#wp1032997 http://www.ipp.gov/
e. INTEREST ON OVERDUE PAYMENT: The Prompt Payment Act, Public Law 97-
177 (96 Stat.85.31 U.S.C. 1801) is applicable to payments under this contract and requires the payment of interest on payments made more than 30 calendar days after receipt of a proper invoice in IPP.
Determinations of interest due will be made in accordance with the provisions of the Prompt Payment Act and 5 CFR 1315.
G.3 CONTRACTOR PAST PERFORMANCE EVALUATION(S) (OCT 2014)
a. General:
In accordance with Federal Acquisition Regulation (FAR) 42.15, Contractor Performance Information, past performance evaluations shall be prepared at least annually and at the time the work under a contract or order is completed. Additional interim performance evaluations may be prepared at Contracting Officer discretion, as necessary.
CMS will utilize the Contractor Performance Assessment Reporting System (CPARS), the Government-wide evaluation reporting tool for all past performance reports on contracts and orders, as appropriate. CPARS is a secure Internet website located at https://www.cpars.gov.
b. CPARS Process:
1. CPARS Training: Contractors may obtain CPARS training material and register for on-line training https://www.cpars.gov.
2. Post-Award Contract Registration: CMS is responsible for registering the contract in CPARS within 30 calendar days of contract award. The Contractor shall:
i. Designate at least one (1) point of contact that will be responsible for serving as the
Contractor’s Representative (CR). Additional CRs may also be identified; and,
ii. Provide the CMS Contract Specialist with the name(s) and email address(es) of the
CPARS point(s) of contact.
Once CMS registers the contract in CPARS, the CR(s) will receive an automated CPARS email message that contains User IDs and instructions for creating a password for future past performance evaluation processing.
3. Interim, Annual and Final Past Performance Evaluation Reports:
a. Issuing the Evaluation: Once the CMS Assessing Official (AO) issues an evaluation to the Contractor in CPARS, the CR(s) will receive an email instructing them to login to CPARS to review the evaluation.
b. Contractor Comments: The CR has the option to provide comments on the evaluation, indicate if they concur or do not concur with the evaluation, sign, and then https://www.cpars.gov/ https://www.cpars.gov/ return the evaluation to the AO. The CR has a total of 60 days following the AO’s evaluation signature date to submit comments. If the CR submits comments within the first 14 days following the AO’s signature date and the AO closes the evaluation, the evaluation will become available in CPARS within 1 day.
On day 15 following the AO’s evaluation signature date, the evaluation will become available in CPARS with or without CR comments and whether or not it has been closed by the AO. If no CR comments have been sent and the evaluation has not been closed, it will be marked as “Pending” in CPARS.
If the CR sends comments at any time prior to 61 days following the AO’s evaluation signature date, those comments will be reflected in CPARS within 1 day. On day 61 following the AO’s evaluation signature date, the CR will be “locked out” of the evaluation and may no longer send comments.
G.4 Contractor Work Performed Outside the United States and its Territories (JAN
2021)
To comply with requirements of Homeland Security Presidential Directive -12 (HSPD-
12) and Personal Identity Verification (PIV) of Federal Employees and Contractors, CMS must achieve appropriate security assurance for multiple CMS information systems by efficiently verifying the claimed identity of individuals working on the contract. The Contractor and its subcontractor(s) shall not perform any activities under this contract, including the transmission of data or other information, outside of the United States (U.S.) and its Territories without the prior written approval of the Contracting Officer. If work must be performed outside the U.S., the Contractor shall submit a request to the Contracting Officer, in writing, at least 45 calendar days prior to the work beginning.
The Contracting Officer will consider the following factors in making a decision whether to authorize the performance of work outside the U.S. and its Territories:
1. The necessity of the work to be performed outside the United States and its territories;
2. The Statement of Work under contract that will be performed outside the U.S. and its Territories;
3. Total projected dollar value of the work to be performed outside the U.S.;
4. Total projected number of labor hours and length of time to be performed for each individual employee working outside the U.S.;
5. The desired country/location where the work will be performed;
6. FAR Part 25, Foreign Acquisitions, and all other laws and regulations applicable to the performance of work outside the U.S.;
7. The contractor and/or its subcontractor(s) plans to adequately protect and secure
CMS data, as well as abide by all applicable laws and regulations when work is performed outside of the U.S. and its Territories. Plans shall include -
a. Adequate contract terms regarding system security;
b. Adequate contract terms regarding the confidentiality and privacy requirements for information and data protection;
c. Adequate contract terms that are otherwise relevant, including the requirements of the Statement of Work;
d. The Contractor’s corporate compliance plan and internal policies and procedures designed to prevent and detect violations of applicable law, regulations, rules and ethical standards by employees, agents and others; and,
8. The necessity of Government Furnished Equipment (GFE) or Contractor Owned/Contractor Operated (COCO) devices to be used outside the U.S. and verification of a secure VPN access.
9. Compliance with Executive Order 13940 Aligning Federal Contracting and Hiring Practices With the Interests of American Workers. Determine if approval will reduce opportunities for the United States contractor workers performing in the United States and if this would cause any potential effects to national security.
10. Conformance with Section 889 “Prohibition on Certain Telecommunications and Video Surveillance Services or Equipment”, of Public Law 115-232.
11. Determination that approval is in best interest of the Government.
The Contractor’s request for authorization to perform work outside the U.S. shall include supplemental information to demonstrate that the performance of the work outside the U.S. satisfies all of the above factors. Contracting Officer approval to perform work outside the U.S. may require additional Statement of Work requirements, additional contract terms and conditions and/or Federal Acquisition Regulation (FAR) clauses to be incorporated into the contract.
G.5 GOVERNMENT REPRESENTATIVES AND RESPONSIBILITIES (SEPT 2021)
Following are the Government Representatives and their respective roles and responsibilities on this contract:
a. Contracting Officer
As defined in Federal Acquisition Regulation (FAR) 2.101, Definitions, and in accordance with FAR 1.602-1, Authority, “Contracting officers have authority to enter into, administer, and/or terminate contracts and make related determinations and findings.” There is no other authorized representative or any other Administrative Contracting Officer assigned to this contract to carry out a Contracting Officer’s duties, except for technical direction assigned to the Contracting Officer’s Representative, if applicable.
The Contracting Officer is:
Centers for Medicare & Medicaid Services
Office of Acquisition & Grants Management Acquisition Support Group
Division of Program Integrity and Financial Management Contracts ATTN: Jennifer Kuhn 7500 Security Blvd.
Baltimore, MD 21244-1850
Phone: 410-786-2299 Email Address: jennifer.kuhn@cms.hhs.gov
b. Contract Specialist
Notwithstanding any of the other provisions of this Contract, the Contract Specialist will assist the Contracting Officer with his/her responsibilities as defined in the FAR.
The Contract Specialist is:
Centers for Medicare & Medicaid Services Office of Acquisition & Grants Management Acquisition Support Group Division of Program Integrity and Financial Management Contracts ATTN: Dorota Horton 7500 Security Blvd.
Baltimore, MD 21244-1850
Phone: 410-786-7403 Email Address: Dorota.Horton@cms.hhs.gov
c. Contracting Officer’s Representative
The Contracting Officer’s Representative (COR), as defined in FAR 2.101, Definitions, is:
Phone: TBD Email Address: TBD
Centers for Medicare & Medicaid Services Center for Program Integrity
ATTN: TBD
7500 Security Blvd.
Mail-stop: TBD Baltimore, MD 21244-1850
In accordance with FAR 1.602-2(d), Responsibilities, the COR’s delegated responsibilities are identified in the Contracting Officer’s appointment memorandum, a copy of which will be furnished to the contractor.
mailto:jennifer.kuhn@cms.hhs.gov mailto:Dorota.Horton@cms.hhs.gov
Technical direction must be within the general scope of the work stated in the contract. The term "technical direction" is defined to include, without limitation, the following:
(1) Directions to the Contractor which direct the contract effort, shift work emphasis between work areas or tasks, require pursuit of certain lines of inquiry, fill in details or otherwise serve to accomplish the contractual technical requirements as identified in the Statement of Work or Performance Work Statement; or
(2) Provision of information to the Contractor, which assists in the interpretation of drawings, specifications, or technical portions of the work description.
The COR does not have the authority to:
1. Make changes to contract terms and conditions;
2. Direct the contractor to perform work or make deliveries not specifically required under the contract;
3. Waive or relax the Government’s rights with regard to the Contractor’s compliance with the specifications, price, delivery or any other terms or conditions of the contract;
4. Make any commitments or approve any actions that would create any financial obligation on the part of the Government; or
5. Issue direction that constitutes a “change” as defined in:
FAR 52.243-1, Changes – Fixed Price;
FAR 52.243-2, Changes – Cost Reimbursement;
FAR 52.243-3, Changes – FAR 52.243-4, Changes; or, FAR 52.243-5, Changes and Changed Conditions.
All technical direction shall be issued in writing by the COR or, if issued verbally, shall be confirmed in writing by the COR within five (5) business days after issuance.
The Contractor shall proceed promptly with the performance of technical direction duly issued by the COR within the scope of his/her authority.
If, in the opinion of the Contractor, any instruction or direction issued by a Government representative constitutes a change to the contract or constitutes a “Change Order” as defined in FAR 2.101, Definitions, the Contractor shall follow the instructions identified in FAR 52.243-7 Notification of Changes.
G.6 SUBCONTRACT CONSENT
(a) For the purposes of this contract, consultants are considered subcontractors.
(b) To facilitate the review of a proposed subcontract, by the COR and the Contracting
Officer, the contractor shall submit the information required by the FAR Clause 52.244-2 entitled, “Subcontracts,” and FAR 52.244-5 “Competition in Subcontracting” to the Contracting Officer. The contracting officer shall review the request for subcontract approval and the COR’s recommendation and advise the contractor of his/her decision to consent to or dissent from the proposed subcontract, in writing.
(c) Consent is hereby granted to the following subcontracts:
TBD (if applicable)
(END OF SECTION G)
SECTION H SPECIAL CONTRACT REQUIREMENTS
H.1 CONFLICT OF INTEREST (OCT 2020)
a. General: The contractor and the services provided under this contract shall be free, to the greatest extent possible, of all Organizational and Personal Conflicts of Interest. Consistent with these terms and conditions, all references to Organizational and/or Personal Conflicts of Interests will be referred to individually or collectively, as Conflicts of Interest (COI). Except as defined by these terms and conditions and in accordance with FAR 9.503, the Contracting Officer shall not maintain a contract with a contractor the Contracting Officer (CO) determines has, or has the potential for, an unresolved COI.
b. Definitions:
Actual COI– The COI is either currently in existence as determined by the contractor or CMS. This form of COI will require avoidance, neutralization or mitigation acceptable to
CMS.
Affiliates –Associated business concerns or individual(s) if, directly or indirectly, either one controls or can control the other; or a third party controls or can control both.
Apparent (Perceived) COI – The COI on first observation appears to be an actual or potential COI, but may or may not be after analysis.
Avoidance – To prevent the occurrence of a COI through actions such as exclusion of sources or modification of requirements. Avoidance precludes the conflict.
Contractor – The term contractor is used synonymously with offeror.
Financial Relationships – A direct or indirect ownership or investment interest (including a stock option or non-vested interest) in any entity that exists through equity, debt, or other means and includes any indirect ownership or investment interest no matter how many levels removed from a direct interest.
Mitigation– To reduce the effects of a COI to an acceptable level of risk so that the Government’s interest with regard to fair competition and/or contract performance are not impaired. The conflict remains but action was taken that minimizes the impact of the conflict to an acceptable level of risk.
Mitigation Plan – The contractor’s written approach to mitigating a COI as documented in J.1 Section B.4.
Neutralization – To counteract, through a specific action, the effects of potential or actual COI. The conflict remains, but the impact of the conflict has been negated.
Organizational Conflict of Interest – Occurs when other activities or relationships with other persons, a person is unable or potentially unable to render impartial assistance or advice to the Government, or the person’s objectivity in performing the contract work is or might be otherwise impaired, or a person has an unfair competitive advantage.
Personal Conflicts of Interest – A situation in which a person has a financial interest, personal activity, or relationship that could impair the person’s ability to act impartially and in the best interest of the Government when performing under this contract.
Potential COI – A future situation or circumstance that would create a conflict of interest.
Three (3) Types of COIs include:
Conflict Types Definitions
Biased Ground Rules
Consists of situations where a contractor and/or its affiliate(s), as part of its performance of a Government contract, has helped (or is in a position to help) set the ground rules for another Government contract by, for example, writing the statement of work or the specifications, or establishing source-selection criteria. In these “biased ground rules” cases, the primary concern is that the entity could skew the competition, whether intentionally or not, in favor of itself and/or its affiliates.
Impaired Objectivity
Consists of situations where a contractor and/or its affiliate(s) has an interest (typically financial) that may conflict with the interest of the Government to whom the contractor has a contractual obligation, and where the entity’s work under the Government contract could give the contractor the opportunity to benefit its other business interests. If the entity is providing recommendations, judgment or advice, and its other business interests could be affected by that recommendation, judgment or advice, it’s objectivity may be impaired. An example is where the entity was evaluating itself or evaluating an affiliate or a competitor, either through an assessment of performance under another contract or an evaluation of proposals.
Unequal Access to Information
“Unfair” access to non-public information – Consists of situations where a contractor and/or its affiliate(s) has access to nonpublic information (including proprietary information and non-public source-selection information) as part of its performance of a Government contract and that information may provide the entity with a competitive advantage in a later competition for a Government contract. In these “unequal access to information” cases, the concern is limited to the risk of the contractor and/or its affiliates gaining an unfair competitive advantage; there is no issue of bias. Note: Incumbency alone does not constitute “unequal access to information.”
c. Significant Potential Conflict of Interest:
1.Nature of Conflict: Although not all inclusive, the following are considered to be an actual, potential or apparent COI with the work to be performed under this contract. The contractor shall promptly notify the CO if it is an entity, or affiliated with an entity, where any of the following circumstances exist:
a) Biased Ground rules, impaired objectivity or unequal access to information as explained in the definitions above and/or;
b) Within the three types of conflicts of interest, the CO has identified the following specific circumstances of conflicts:
o Recovery Audit Contractors (RAC); and o Providers/Suppliers and/or Provider Billing Companies or Consulting
Firms/Auditing Entities for Medicare and/or Medicaid beneficiaries.
2. Proposed Restraint on Future Contractor Activities: CMS is proposing to restrain future contractor activities as follows:
o While performing under the NCCI contract, the contractor cannot become a Recovery Audit Contractor nor have an organizational affiliation or financial relationships with the Recovery Audit Contractors; and o While performing under the NCCI contract, the contractor cannot have an organizational affiliation or financial relationship with companies or individuals that bill for, consult, audit, and/or provide medical services or supplies for Medicare and/or Medicaid beneficiaries.
d. Conflict of Interest Oversight and Mitigation Plan:
1.Conflict of Interest Oversight Program: The contractor shall maintain an effective COI Oversight Program throughout the performance of the contract which includes procedures to monitor and disclose all Organizational and Personal Conflicts of Interest. A COI oversight program should include the monitoring of personal conflicts of interest such as, but not limited to:
a) Managers or Key Personnel who would be, or are involved with, the performance of this contract;
b) Governing Body Members (e.g., Board of Directors; Trustees); and
c) Principals of the organization as defined by FAR 52.203-13, Contractor Code of Business Ethics and Conduct.
2. Mitigation Plan: At any time during the performance of the contract if an actual, potential, or apparent COI is identified whether by the CO, the contractor or otherwise, the contractor shall submit a mitigation plan (J.1 Contractor/Offeror COI Submission Template) within 30 days unless otherwise specified by the CO. It is the contractor’s responsibility under the terms and conditions to provide timely notification to the CO those COIs that are self-identified. The CO will notify the contractor regarding the specifics for submission. The Government will review the submission at which time a determination will be made whether a COI has been satisfactorily mitigated or if further action is necessary and will notify the contractor accordingly. In cases where a COI cannot be, or has not been, mitigated to the Government’s satisfaction, the Government may take the following actions (this list is not all inclusive):
a) Request a waiver in accordance with FAR 9.503 Waiver, from the Head of the Contracting Activity;
b) Make changes to the requirements of the contract;
c) Require a subcontractor change (if the conflict lies with the subcontractor); and/or
d) Terminate the contract in whole or in part.
e. Subcontractor Flow-Down Terms and Conditions: The prime contractor is responsible for avoiding, neutralizing and mitigating all actual, potential, or apparent COIs of its subcontractors, in accordance with these terms and conditions. Therefore, the prime contractor shall flow-down terms and conditions H.1 Conflict of Interest, of this contract in all subcontracts. For subcontractors, wherever the term “contractor” is used, insert “subcontractor.”
H.2 CMS INFORMATION SECURITY (OCT 2020)
All CMS information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, in order to maintain the security, confidentiality, integrity, and availability of such information. Therefore, if this contract requires the contractor to provide services (both commercial and non-commercial) for Federal Information/Data, to include any of the following requirements:
• Process any Information/Data; or
• Store any Information/Data (includes “Cloud” computing services); or
• Facilitate the transport of Information/Data; or
• Host/maintain Information/Data (including software and/or infrastructure developer/maintainers); or
• Have access to, or use of, Personally Identifiable Information (PII), including instances of remote access to, or physical removal of, such information beyond agency premises or control, The contractor shall become familiar and remain compliant with all aspects of the Statement of Work (SOW), Statement of Objectives (SOO), Performance Work Statement (PWS), which includes CMS Information Security requirements.
The contractor shall ensure that the following Federal information security standards are met for all of its CMS contracts:
• Federal Information Security Management Act (FISMA) – FISMA information can be found at https://csrc.nist.gov/projects/risk-management. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source; and,
• Federal Risk and Authorization Management Program (FedRAMP) – FedRAMP information can be found https://csrc.nist.gov/projects/risk-management at https://www.gsa.gov/technology/government-it-initiatives/fedramp. The FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.
The Contractor shall include in all awarded subcontracts the FISMA/FedRAMP compliance requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS-Security-and-Privacy- Language-for-Procurements.
H.3 HIPAA BUSINESS ASSOCIATE CLAUSE (OCT 2014)
All Protected Health Information (PHI), as defined in 45 C.F.R. §160.103, that is relevant to this Contract, shall be administered in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA," 42 U.S.C. § 1320d), as amended, as well as the corresponding implementing regulations and this HIPAA Business Associate Clause.
a. Definitions:
All terms used herein and not otherwise defined, shall have the same meaning as in HIPAA, as amended, and the corresponding implementing regulations. Non-HIPAA related provisions governing the Contractor's duties and obligations, such as those under the Privacy Act and any applicable data use agreements, are generally covered elsewhere in the Contract.
The following definitions apply to this Contract Clause:
"Business Associate'' shall mean the Contractor (and/or the Contractor’s subcontractors or agents) if/when it uses individually identifiable health information on behalf of CMS, i.e.
PHI, to carry out CMS’ HIPAA-covered functions.
"Covered Entity" shall mean the portions of CMS that are subject to the HIPAA Privacy Rule.
"Secretary" shall mean the Secretary of the Department of Health & Human Services or the Secretary's designee.
b. Obligations and Activities of Business Associate:
Except as otherwise provided in this Contract, Business Associate, as defined above, shall only use or disclose PHI on behalf of, or to provide services to, Covered Entity in accordance with this Contract and the HIPAA Privacy and Security Rules.
Business Associate shall document in writing the policies and procedures that will be used to meet HIPAA requirements. The policies and procedures shall include the following, at a minimum:
https://www.gsa.gov/technology/government-it-initiatives/fedramp https://www.gsa.gov/technology/government-it-initiatives/fedramp https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Security-and-Privacy-Language-for-Procurements https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Security-and-Privacy-Language-for-Procurements https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Security-and-Privacy-Language-for-Procurements
1. Business Associate shall not:
a. Use or disclose PHI that is created, received, maintained or transmitted by
Business Associate from, or on behalf of, Covered Entity other than as permitted or required by this Contract or as required by law;
b. Sell PHI; or,
c. Threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual for:
i.Filing a complaint under 45 CFR § 160.306;
ii.Testifying, assisting or participating in an investigation, compliance review, proceeding or hearing under 45 CFR Part 160; or iii.Opposing any act or practice that is unlawful under HIPAA, provided there is a good faith belief that the practice is unlawful, the manner of opposition is reasonable, and the opposition does not involve the disclosure of PHI in violation of subpart E of Part 164.
2. Business Associate shall:
a. Have a security official who will be responsible for development and implementation of its security policies and procedures, including workforce security measures, to ensure proper security awareness and training (including security incident response and reporting), and security incident procedures, in accordance with this Contract, including this HIPAA Business Associate Clause and the Contract’s clause entitled “CMS Information Security.”
b. Use administrative, physical and technical safeguards to prevent use or disclosure of PHI created, received, maintained or transmitted by Business Associate from, or on behalf of Covered Entity only as provided for by this Contract. In doing so, it shall implement policies and procedures to address the following and, where applicable, ensure that such policies and procedures are also in conformance with this Contract’s clause entitled “CMS Information Security:”
i. Prevent, detect, contain and correct security violations through the use of:
1. Risk analyses (including periodic technical and nontechnical evaluations);
2. Appropriate risk management strategies, including system activity review;
3. Information access procedures for approving individual’s access rights to PHI (including the implementation of workforce security measures to ensure continued appropriate role-based access to PHI), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and tracking of users) and;
4. The imposition of sanctions for violations.
ii. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.
iii. Implement policies, procedures and physical security measures that will limit access to PHI through workstations and other devices, including access through mobile devices.
iv. Implement media controls covering the movement of devices containing PHI within or outside of the Business Associate’s facility as well as the disposal and reuse of media containing PHI.
v. Implement appropriate administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability (including the use of contingency plans) of any electronic protected health information ("EPHI") it creates, receives, maintains or transmits from, or on behalf of the Covered Entity to prevent impermissible use, disclosure, maintenance or transmission of such EPHI. In the establishment of such safeguards, Business Associate shall consider its size, complexity and capabilities, as well as its technical infrastructure, and its hardware and software security capabilities.
c. Assess, and implement, where appropriate, any addressable implementation specifications associated with applicable PHI security standards.
d. Mitigate, to the extent practicable, any harmful effect that is known to Business
Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Contract.
e. Comply with the following Incident Reporting:
(a) Report to Covered Entity any security incident/breach involving unsecured PHI, of which it becomes aware, including those of its agents and subcontractors. The Business Associate shall report any violation of the terms of this contract involving PHI and any security incidents/breaches involving unsecured PHI to CMS within one (1) hour of discovery in accordance with the CMS Risk Management Handbook (RMH), specifically “RMH Vol II Procedure 7-2 Incident Handling Procedure” and “RMH Vol III Standard 7-1 Incident Handling.” These procedures can be found at http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS- Information-Technology/InformationSecurity/Information-Security- Library.html In addition, the Business Associate will also notify the CMS Contracting Officer and the Contracting Officer’s Representative (COR) by email within one (1) hour of identifying such violation or incident.
(b) Upon Covered Entity's knowledge of any material security incident/breach by Business Associate, Covered Entity will provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination clause of this Contract. See also paragraph D. Term of Clause below.
f. Ensure that any agent or subcontractor agrees through a written contract, or other legally enforceable arrangement, to the same restrictions and conditions http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Information-Security-Library.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Information-Security-Library.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Information-Security-Library.html that apply through this HIPAA Contract Clause, when creating, receiving, maintaining or transmitting PHI from, or on behalf of, Covered Entity.
g. Upon Covered Entity’s request:
i. Provide the Covered Entity or its designee with access to the PHI created, received, maintained or transmitted by Business Associate from or on behalf of the Covered Entity in the course of contract performance in order to ensure Covered Entity’s ability to meet the requirements under 45 CFR § 164.524.
ii. Amend PHI as Covered Entity directs or agrees to pursuant to 45 CFR § 164.526.
h. Make its facilities and any books, records, accounts, and any sources of PHI, including any policies and procedures, that are pertinent to ascertaining its own compliance with this contract or the Covered Entity’s compliance with the applicable HIPAA requirements, available to Covered Entity, or, in the context of an investigation or compliance review, to the Secretary for purposes of the Secretary determining Covered Entity's compliance with the various rules implementing the HIPAA.
i. Document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45
CFR § 164.528.
j. Provide to Covered Entity, or an individual identified by the Covered Entity, information collected under this Contract, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.
k. Make reasonable efforts to limit the PHI it uses, discloses or requests to the minimum necessary to accomplish the intended purpose of the permitted use, disclosure or request.
c. Obligations of Covered Entity
Covered Entity shall notify Business Associate of any:
1. Limitation(s) in its Notice of Privacy Practices in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of
PHI;
2. Changes in, or revocation of, permission by an Individual to use or disclose their PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI; and,
3. Restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.
d. Term of Clause
1. The term of this Clause shall be effective as of date of Contract award, and shall terminate when all of the PHI provided to Business Associate by the Covered Entity or a Business Associate of the Covered Entity, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity in accordance with “CMS Information Security” procedures. Business Associate shall not retain any PHI.
2. Security Incident/Breach:
Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall take action consistent with the terms of this Contract, and, as appropriate, the following:
1) Federal Acquisition Regulation (FAR) Contracts – Covered Entity may:
i. Terminate this Contract in accordance with FAR Part 49, Termination of
Contracts, if the Business Associate does not cure the security incident/breach within the time specified by Covered Entity and/or cure is not possible; or,
ii. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.
2) Other Agreements –Covered Entity shall either:
i. Provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination terms of this Contract. Covered Entity may terminate this Contract for default if the Business Associate does not cure the breach or end the violation within the time specified by Covered Entity; or,
ii. Consistent with the terms of this Contract, terminate this Contract for default if Business Associate has breached a material term of this Contract and cure is not possible; or,
iii. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.
3. Returning or Destroying PHI:
Business Associate, as defined above, which includes subcontractors or agents of the Contractor, shall:
i. Upon expiration or termination of this Contract, for any reason, return or destroy all PHI received from Covered Entity or another Business Associate of the Covered Entity, as well as any PHI created, received, maintained or transmitted from or on behalf of Covered Entity, or another Business Associate of the Covered Entity, in accordance with this contract, including the “CMS Information
Security” clause.
ii. In the event that Business Associate determines that returning or destroying the
PHI is infeasible, provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon such notice that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.
e. Miscellaneous
1. A reference in this Contract to a section in the Rules issued under HIPAA means the section as in effect or as amended.
2. The respective rights and obligations of Business Associate under paragraph D.3.b of the section entitled "Term of Clause" shall survive the termination of this Contract.
Any ambiguity in this Contract clause shall be resolved to permit Covered Entity to comply with the Rules implemented under HIPAA.
H.4 CMS SECURITY CLAUSE (MAY 2018)
a. Applicability
In accordance with OMB Memorandum M-05-24, Implementation of Homeland Security Presidential Directive 12 (HSPD-12): Policy for a Common Identification Standard for Federal Employees and Contractors, dated August 27, 2004, and Federal Information Processing…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .