Solicitation - 75FCMC25RJ003.pdf
PDF 1 MB Posted
- Attached to
- Recovery Audit Contractor (RAC) Regions 3, 4, & 5 Federal contract opportunity
- Solicitation number
- 75FCMC25RJ003
About this file
This is a Standard Form 1449 (SF-1449) Solicitation/Contract document for Recovery Audit Contractor (RAC) services for Regions 3, 4, and 5, issued by the Centers for Medicare & Medicaid Services (CMS). The solicitation number is 75FCMC25RJ003.
CMS anticipates awarding three firm-fixed contingency fee contracts to review Medicare Fee-for-Service claims submitted to A/B Medicare Administrative Contractors. The base period is 8.5 years (May 1, 2025 to October 30, 2033) with an 18-month administrative/appeals option period (October 31, 2033 to April 30, 2035). Contractors will be paid only from recovered overpayments, with payment allowed after claims exit the second level appeals process or after 120 days if no appeal is filed. Key personnel requirements include Project Manager, Contractor Medical Director, Medical Review Manager, Chief Information Officer, and System Security Officer. Contractors must maintain Joint Operating Agreements with Medicare contractors and CMS partners. The work involves reviewing claims, adjusting claims based on findings, supporting appeals processes, and reporting status updates through the RAC Data Warehouse. Region 5 specifically covers Durable Medical Equipment, Prosthetics, Orthotics, and Supply claims and Home Health/Hospice claims.
View the file
Other files for this federal contract opportunity
Show all 23
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER PAGE 1 OF
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. TELEPHONE NUMBER (No collect calls)
8. OFFER DUE DATE/
LOCAL TIME
9. ISSUED BY
13b. RATING
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO 16. ADMINISTERED BY CODE
18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ IFB RFP
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF. OFFER
DATED . . YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED
31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
10. THIS ACQUISITION IS UNRESTRICTED OR
NAICS:
SIZE STANDARD:
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
SET ASIDE: % FOR:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
ARE ARE NOT ATTACHED
ARE ARE NOT ATTACHED
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
8 (A)
EDWOSB
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SMALL BUSINESS
75FCMC25RJ003
Solicitation/Contract Form
Supplies or Services and Prices/Cost
Additional Information/Notes
The Government anticipates award of three firm fixed contingency fee contracts. This contingency fee type contract will be established in accordance with Section 1893(h) of the Social Security Act as added by the Tax Relief and Heath Care Act of 2006. This section states, "Under the Contracts: (A) payment shall be made to such a contractor only from amounts recovered;
(B) from such amounts recovered, payment, (i) shall be made on a contingent basis for collecting overpayments(...)."
B.1 Continuation of Block 11
DELIVERABLES
All deliverables required under this contract:
Task N umber
Deli ver able No.
Deliverable Due Date
Task 1 1 Initial Meeting Two weeks from date of award
Task 2 2 Project Plan, ATO status, JOAs
Draft w/in two weeks after the initial meeting with CMS
Subsequent Project Plans due by COB on the fifth business day following the end of each month.
Task 14 3 Conference Calls Weekly, and as needed
Task 15 4
Monthly Reports (subsequent project plans, Administrative, Appeals, Review Topics, Mandatory Training records)
Monthly- by COB on the fifth business day following the end of the month
Task 4.D 5 Annual Case File Submissions
Annually, and w/in 15 business days prior to the end of the Administrative Period of the contract
Require ment
III.B
6 SSAE 18 Type II Audit A final report from the CPA firm must be submitted to CMS annually, by the award anniversary date
Admi nistrati ve Period
& Cl oseout
7 Draft Final Report Within six weeks prior to the end of the Administrative Period of the contract.
Admi nistrati ve Period
& Cl oseout
8 Final Report Within two weeks prior to the end of the
Administrative Period of the contract.
B.2 Continuation of Block 18a
SCHEDULE OF PAYMENTS
The contractor shall be paid in accordance with their firm fixed contingency fee as described below. The RAC shall not receive any payments for the mere identification of improper overpayments. There are specific statutory timeframes for filing appeals at each level. The RAC may invoice for the appliable firm fixed contingency fee when all required claim elements are input into the RAC Data Warehouse (RACDW) and either: (1) the improperly paid claims have successfully exited (adjudication in favor of the RAC) the second level of the appeals process (QIC level) in the event an appeal is filed; or (2) if no appeal has been filed within the initial 120 days that a provider has to appeal, the RAC may then invoice for their firm fixed contingency fee payment.
The firm fixed contingency fee will be calculated by applying the applicable percentage to the underpayments refunded and the overpayments collected, without subtracting or netting out the underpayments. Amount attributed to interest owed by or charged to the provider will not be included in overpayments or underpayments when calculating the contingency fee.
If a Provider files an appeal disputing the overpayment determination and the appeal is adjudicated in the prover's favor at ANY level, the RAC shall repay Center for Medicaid and Medicare Services (CMS) the contingency payment it received for that recovery. Repayments to CMS will be subtracted from the next applicable invoice, e.g. offset, or may be the subject of a demand pursuant to FAR Subpart 32.6
B.3 Continuation of Blocks 19-24
SCHEDULE OF SUPPLIES/SERVICES
In order to be compliant with CMS systems, funding has been included during this time of award. The amount of funding that is obligated to this contract is not guaranteed to the contractor. The RAC payments process is identified in Section B.2. The obligated amount for this contract is $TBD. It is the contractor's responsibility to notify the Contracting Officer (CO) and Contracting Officer Representative (COR) when the contractor expects the balance of obligated funds to be at or less than $3,000,000. Delay in this notice will delay payments until a modification is completed.
The firm fixed contingency fee percentage that will be applied to all categories of claims is (TBD)%. Any changes to an Offeror's contingency fee must be negotiated and changed by contract modification.
The period of performance (POP)s for the RAC Region (TBD) contract will include an 8.5-year "Active Recovery Auditing" base period and an 18-month "Closeout and Reconciliation; Administrative and Appeals" option period. During option period 1, CMS will continue to recoup overpayments from providers, allow the RAC to invoice for recoupments received, require the RACs to support the appeal process and allow CMS to recoup payment attributable to overturned appeals from the RAC. CMS reserves the right to extend the contract pursuant to 42 CFR 421, "Medicare Integrity Program", the Contracting Officer may unilaterally renew this contract annually by giving the Contractor written notice, within 15 days of the expiration date of this contract (after exercise of all option or renewal years), of its intent to do so.
Item Supplies/Service Dates Quantity Unit Unit Price Amount
Base Period (8.5 years)
Severability: Yes Firm Fixed Price
Period of Performance From
01 MAY
To
30 OCT
8.5 Years
(Option Period 1)
Administrative and Appeals Option (18 months)
Severability: Yes Firm Fixed Price
Period of Performance From
31 OCT
To
30 APR
18.0 Months
Description/Specifications/Statement of Work
Requirements
See Attachment J.1 Statement of Work (SOW)
Packaging and Marking
None; not applicable
Inspection and Acceptance
See Addenda to FAR 52.212-4 CONTRACT TERMS AND CONDITIONS - COMMERCIAL ITEMS (NOV 2023)
Deliveries or Performance
Delivery Schedule
Period of Performance From
01 MAY 2025
To
30 OCT 2033
0002 (Option Period
1) Delivery Schedule
Period of Performance From
31 OCT 2033
To
30 APR 2035
Additional Regulation or Supplement Clauses Incorporated by Full Text
CMS_POP PERIOD OF PERFORMANCE Jan 2014
The period of performance of this contract is May 1, 2025 through October 30, 2033.
This contract includes the following Option Period: October 31, 2033 through April 30, 2035.
Contract Administration Data
Department of Health and Human Services Acquisition Regulations (HHSAR) Clauses Incorporated by Reference
This contract incorporates one or more clauses by reference, with the same force and effect as if they were provided in full text. Upon request, the Contracting Officer will provide the information in full text. The full text of a clause is also available electronically at . http://www.hhs.gov/policies/hhsar/
Number Title Effective Date 352.232-71 Electronic Submission of Payment Requests Feb 2022
Additional Regulation or Supplement Clauses Incorporated by Full Text
CMS_PIR PAYMENTS - INVOICES (Reconciled Contracts) Sep 2024
PAYMENTS - INVOICES - ( September 2024 )
a. GENERAL: Effective August 31, 2020, the Contractor/ Vendor shall create an invoice within t he Invoice Processing Platform (IPP), a secure Web-based service for federal agencies and their vendors to manage government invoicing from purchase order (PO) through payment notification. Note: All invoice terms and conditions are contract specific and may vary from contract to contract.
5 Payment Documentation and Process, provides the required content for a b. CONTENT OF INVOICE: FAR 32.90 proper invoice. In addition to the requirements of FAR 32.905 , the following items shall also be included on the invoice to be considered proper:
• Line item number (i.e. CLIN/SLIN as applicable) ;
• Contractor /Vendor 's Unique Entity Identifier (UEI) Number;
• Period of Performance (PoP) or delivery date of goods or services provided;
• Attachments and applicable support documentation requested by the CO ;
• The first page of the PDF invoice or PDF SF-1034 shall include :
1. Contractor /Vendor name and address;
2. Bill to: CMS, P.O. Box 7520, Baltimore, MD 21207;
3. Full CMS contract number and task order number;
4. Summary of charges by CLIN/SLIN (if applicable) with a grand total. CLIN/SLIN( S) on the PDF shall be identical to what is entered in IPP;
5. Invoice number shall be identical to what is entered in IPP. Each Contractor/Vendor invoice number must be unique across all CMS contracts awarded to the Contractor/Vendor. For example, If Contractor /Vendor A has 5 CMS contracts, Contractor /Vendor A cannot use the same invoice number on any of the 5 contracts they have with CMS. If using a dash in IPP then the dash must be used on the PDF. IPP does not allow any special characters (i.e.*, # , _ );
6. Within IPP, the " Bill Period Start " and "Bill Period End " dates should align with the " Service From " and " Service To " dates (this is not the entire POP dates );
http://www.hhs.gov/policies/hhsar/
7. Date of Delivery or Service dates shown on the PDF should: ( i ) F all within the contract POP (unless contract indicates otherwise) ( ii ) Align with the " Bill Period Start " and "Bill Period End " dates and " Service From " and " Service To " dates, and ( iii ) Note when the work was performed;
8. Date invoice was prepared;
9. The total invoice amount on the first page of the invoice or SF-1034 must be a debit. A credit may be shown on the first page of the invoice or SF-1034 if the credit falls within the Period Of Performance and is for the same CLIN as the debit. CMS does not accept credit vouchers or process refunds in IPP or the Invoice Submission Box .
Credits in excess of $5.01 must be submitted via Pay.gov (For questions surrounding Pay.gov, contact pay.gov.
clev@clev.frb.org or 1-800-624-1373 (Option 2)). Credits sent to Pay.gov shall be copied to the CO, CS and COR .
Credits valued at or less than $5.01 must be submitted via Credit Gateway; however, it is preferred that the Contractor/Vendor wait until a dollar amount is accumulated in order to submit the refund through Pay.gov (For questions surrounding Credit Gateway, contact customer.care@usbank.com or 1-877-815-1206 ) ;
• When an invoice has been resubmitted, an "R" should be added after the invoice number on the PDF and in IPP;
this will ensure that the original invoice number is not duplicated in IPP. If a resubmitted invoice is rejected again, each subsequent resubmission requires an additional "R" added after the invoice number (i.e. "RR" );
• The " final " designation should only be used when the contract is being closed out by OAGM. Do not use for the end of POP or Option Year ;
• Contractor/ Vendor must maintain active registration in SAM .gov . If your SAM account is about to expire, wait until it is updated before submitting your invoice ; and,
• Banking or address changes must be submitted via email to CCRchanges@cms.hhs.gov .
: The Contractor/ Vendor shall create an invoice from the Purchase Order (PO)/Contract via c. INVOICE SUBMISSION the IPP website http://www.ipp.gov/ . For questions, call IPP Customer Support at (866) 973-3131 or email the IPP Customer Support at IPPCustomerSupport@fiscal.treasury.gov. Only one PDF invoice per submission is allowed in IPP .
: The Government shall make payment of all proper invoices in accordance with the following clauses , d. PAYMENTS as applicable and included in the respective TO/PO/contract :
• FAR 52.232-33 Payments by Electronic Funds Transfer - System for Award Management,
• FAR 52.232-1 Payments
• FAR 52.212-4 Contract Terms and Conditions - Commercial Items (If applicable)
• FAR 52.216-7 Allowable Cost and Payment
• FAR 52.232-7 Payments under Time-and-Materials and Labor-Hour Contracts
Payment shall be made upon acceptance by the Contracting Officer's Representative (COR) in accordance with the applicable FAR Inspection and Acceptance clause and the Contracting Officer's approval, as appropriate.
Reimbursement for invoices submitted under this contract shall be made no later than 30 calendar days after receipt of a proper invoice from the Contractor requested at the paying office designated above . Contracts with a 15- day payment term are not subject to interest payments until after day 30.
: The Prompt Payment Act, Public Law 97-177 (96 Stat.85.31 U.S.C. 1801) e. INTEREST ON OVERDUE PAYMENT is applicable to payments under this contract and requires the payment of interest on payments made more than 30 calendar days after receipt of a proper invoice in IPP . Determinations of interest due will be made in accordance with the provisions of the Prompt Payment Act and 5 CFR 1315.
CMS_CWP CONTRACTOR WORK PERFORMED OUTSIDE THE UNITED STATES AND ITS TERRITORIES Jan
Contractor Work Performed Outside the United States and its Territories (January 2021)
To comply with requirements of Homeland Security Presidential Directive -12 (HSPD-12) and Personal Identity Verification (PIV) of Federal Employees and Contractors, CMS must achieve appropriate security assurance for multiple CMS information systems by efficiently verifying the claimed identity of individuals working on the contract. The Contractor and its subcontractor(s) shall not perform any activities under this contract, including the transmission of data or other information, outside of the United States (U.S.) and its Territories without the prior written approval of the Contracting Officer. If work must be performed outside the U.S., the Contractor shall submit a request to the Contracting Officer, in writing, at least 45 calendar days prior to the work beginning.
The Contracting Officer will consider the following factors in making a decision whether to authorize the performance of work outside the U.S. and its Territories:
1. The necessity of the work to be performed outside the United States and its territories;
2. The Statement of Work under contract that will be performed outside the U.S. and its Territories;
3. Total projected dollar value of the work to be performed outside the U.S.;
4. Total projected number of labor hours and length of time to be performed for each individual employee working outside the U.S.;
5. The desired country/location where the work will be performed;
6. FAR Part 25, Foreign Acquisitions, and all other laws and regulations applicable to the performance of work outside the U.S.;
7. The contractor and/or its subcontractor(s) plans to adequately protect and secure CMS data, as well as abide by all applicable laws and regulations when work is performed outside of the U.S. and its Territories. Plans shall include -
a. Adequate contract terms regarding system security;
b. Adequate contract terms regarding the confidentiality and privacy requirements for information and data protection;
c. Adequate contract terms that are otherwise relevant, including the requirements of the Statement of Work;
d. The Contractor’s corporate compliance plan and internal policies and procedures designed to prevent and detect violations of applicable law, regulations, rules and ethical standards by employees, agents and others; and,
8. The necessity of Government Furnished Equipment (GFE) or Contractor Owned/Contractor Operated (COCO) devices to be used outside the U.S. and verification of a secure VPN access.
9. Compliance with Executive Order 13940 Aligning Federal Contracting and Hiring Practices With the Interests of American Workers. Determine if approval will reduce opportunities for the United States contractor workers performing in the United States and if this would cause any potential effects to national security.
10. Conformance with Section 889 “Prohibition on Certain Telecommunications and Video Surveillance Services or Equipment”, of Public Law115-232.
11. Determination that approval is in best interest of the Government.
The Contractor’s request for authorization to perform work outside the U.S. shall include supplemental information to demonstrate that the performance of the work outside the U.S. satisfies all of the above factors. Contracting Officer approval to perform work outside the U.S. may require additional Statement of Work requirements, additional contract terms and conditions and/or Federal Acquisition Regulation (FAR) clauses to be incorporated into the contract.
CMS_CPP CONTRACTOR PERFORMANCE EVALUATION Oct 2014
CONTRACTOR PAST PERFORMANCE EVALUATION(S) (OCT 2014)
a. General:
In accordance with Federal Acquisition Regulation (FAR) 42.15, Contractor Performance Information, past performance evaluations shall be prepared at least annually and at the time the work under a contract or order is completed. Additional interim performance evaluations may be prepared at Contracting Officer discretion, as necessary.
CMS will utilize the Contractor Performance Assessment Reporting System (CPARS), the Government-wide evaluation reporting tool for all past performance reports on contracts and orders, as appropriate. CPARS is a secure Internet website located at https://www.cpars.
.gov
b. CPARS Process:
1. Contractors may obtain CPARS training material and register for on-line training .CPARS Training: https://www.cpars.gov
2. CMS is responsible for registering the contract in CPARS within 30 calendar days of contract Post-Award Contract Registration:
award. The Contractor shall:
i. Designate at least one (1) point of contact that will be responsible for serving as the Contractor’s Representative (CR). Additional CRs may also be identified; and,
ii. Provide the CMS Contract Specialist with the name(s) and email address(es) of the CPARS point(s) of contact.
Once CMS registers the contract in CPARS, the CR(s) will receive an automated CPARS email message that contains User IDs and instructions for creating a password for future past performance evaluation processing.
3. Interim, Annual and Final Past Performance Evaluation Reports:
a. Once the CMS Assessing Official (AO) issues an evaluation to the Contractor in CPARS, the CR(s) will Issuing the Evaluation:
receive an email instructing them to login to CPARS to review the evaluation.
b. The CR has the option to provide comments on the evaluation, indicate if they concur or do not concur Contractor Comments:
with the evaluation, sign, and then return the evaluation to the AO. The CR has a total of 60 days following the AO’s evaluation signature date to submit comments. If the CR submits comments within the first 14 days following the AO’s signature date and the AO closes the evaluation, the evaluation will become available in CPARS within 1 day.
On day 15 following the AO’s evaluation signature date, the evaluation will become available in CPARS with or without CR comments and whether or not it has been closed by the AO. If no CR comments have been sent and the evaluation has not been closed, it will be marked as “Pending” in CPARS.
If the CR sends comments at any time prior to 61 days following the AO’s evaluation signature date, those comments will be reflected in CPARS within 1 day. On day 61 following the AO’s evaluation signature date, the CR will be "locked out" of the evaluation and may no longer send comments.
CMS_GRR GOVERNMENT REPRESENTATIVES AND RESPONSIBILITIES Nov 2024
G.X GOVERNMENT REPRESENTATIVES AND RESPONSIBILITIES (NOV 2024)
Following are the Government Representatives and their respective roles and responsibilities on this contract:
a. Contracting Officer
As defined in Federal Acquisition Regulation (FAR)2.101, Definitions, and in accordance with FAR 1.602-1, Authority, "Contracting officers have authority to enter into, administer, and/or terminate contracts and make related determinations and findings." There is no other authorized representative or any other Administrative Contracting Officer assigned to this contract to carry out a Contracting Officer's duties, except for technical direction assigned to the Contracting Officer's Representative, if applicable.
The Contracting Officer is:
Centers for Medicare & Medicaid Services
Office of Acquisition & Grants Management
Acquisition Support Group
Division of Program Integrity & Financial Management Contracts
ATTN: Nicole Hoey
Mail-stop: B3-30-03
7500 Security Blvd.
Baltimore, MD 21244-1850 https://www.cpars.gov https://www.cpars.gov https://www.cpars.gov
Phone: 410-786-0489
Email Address: Nicole.Hoey@cms.hhs.gov
b. Contract Specialist
Notwithstanding any of the other provisions of this Contract, the Contract Specialist will assist the Contracting Officer with his/her responsibilities as defined in the FAR.
The Contract Specialist is:
Centers for Medicare & Medicaid Services
Office of Acquisition & Grants Management
Acquisition Support Group
Division of Program Integrity & Financial Management Contracts
ATTN: Tracy Amos
7500 Security Blvd.
Mail-stop: B3-30-03
Baltimore, MD 21244-1850
Phone: 667-290-9676
Email Address: Tracy.Amos1@cms.hhs.gov
c. Contracting Officer's Representative
The Contracting Officer's Representative (COR), as defined in FAR 2.101, Definitions, is:
Centers for Medicare & Medicaid Services
Center for Program Integrity
Provider Compliance Group
Division of Recovery Audit Operations
ATTN: To Be Determined (TBD)
7500 Security Blvd.
Mail-stop: TBD
Baltimore, MD 21244-1850
Phone: TBD
Email Address: TBD
In accordance with FAR 1.602-2(d), Responsibilities, the COR's delegated responsibilities are identified in the Contracting Officer's appointment memorandum, a copy of which will be furnished to the contractor.
The COR will serve as the primary liaison between the Contractor and the Contracting Officer and perform duties within the limitations of the COR's responsibilities in accordance with FAR 1.602-2(d).
Technical direction must be within the general scope of the work stated in the contract. The term "technical direction" is defined to include, without limitation, the following:
(1) Directions to the Contractor which direct the contract effort, shift work emphasis between work areas or tasks, require pursuit of certain lines of inquiry, fill in details or otherwise serve to accomplish the contractual technical requirements as identified in the Statement of Work or Performance Work Statement; or
(2) Provision of information to the Contractor, which assists in the interpretation of drawings, specifications, or technical portions of the work description.
Technical direction within the scope of the contract, shall be "in writing" whenever possible and routed through the CO prior to release to the Contractor. If technical direction is verbally communicated, the COR must immediately confirm its direction in writing. Where doubt exists as to whether proposed technical direction is within or outside the scope of the contract, the CO shall be contacted.
If, in the opinion of the Contractor, any instruction or direction issued by a Government representative constitutes a change to the contract or constitutes a "Change Order" as defined in FAR 2.101, Definitions, the Contractor shall follow the instructions identified in FAR 52.243-7 Notification of Changes.
The COR "has no authority to make any commitments or changes that affect price, quality, quantity, delivery, or other terms and conditions of the contract nor in any way direct the contractor or its subcontractors to operate in conflict with the contract terms and conditions." See FAR1.
602-2(d)(5). The COR's authority is not re-delegable and the COR may be personally liable for unauthorized acts in accordance with FAR 1.602- (d)(7)(iv) and (v). For example, the COR does not have the authority to:
1. Make changes to contract terms and conditions;
2. Direct the contractor to perform work or make deliveries not specifically required under the contract;
3. Waive or relax the Government's rights with regard to the Contractor's compliance with the specifications, price, delivery or any other terms or conditions of the contract;
4. Make any commitments or approve any actions that would create any financial obligation on the part of the Government; or
5. Issue direction that constitutes a "change" as defined in:
FAR 52.243-1, Changes – Fixed Price;
FAR 52.243-2, Changes – Cost-Reimbursement;
FAR 52.243-3, Changes – Time-and-Materials or Labor-Hours;
FAR 52.243-4, Changes; or, FAR 52.243-5, Changes and Changed Conditions.
In addition to the above responsibilities, the COR and/or Contractor shall immediately notify the Contracting Officer of any contractual concerns related to the following:
1. Personal Services: FAR37.104(a) provides that, "[a] personal services contract is characterized by the employer-employee relationship it creates between the Government and the contractor's personnel. The Government is normally required to obtain its employees by direct hire under competitive appointment or other procedures required by the civil service laws. Obtaining personal services by contract, rather than by direct hire, circumvents those laws unless Congress has specifically authorized acquisition of the services by contract."
Under this contract, the services to be performed do not require the Contractor or the Contractor's personnel to exercise personal judgement and discretion on behalf of the Government. Rather, the Contractor's personnel will act and exercise personal judgement and discretion on behalf of the Contractor. The services to be performed under this contract are not for personal services as defined by FAR 37.104.
Both the Government and the Contractor have a responsibility to monitor contract activities. The CO must be notified immediately if at any time during contract performance the interaction between the Government representative and Contractor personnel constitutes or is perceived to constitute personal services. Both the Government and Contractor personnel must exercise caution to ensure that service contracts not personal in nature avoid even the appearance of a personal services contract.
2. Inherently Governmental Functions: The agency shall not use contractors for the performance of inherently governmental functions unless issued under statutory authority See FAR 7.5 Inherently Governmental Functions. As defined in FAR 2.101, "Inherently Governmental Function" means, as a matter of policy, a function that is so intimately related to the public interest as to mandate performance by Government employees. An inherently governmental function includes activities that require either the exercise of discretion in applying Government authority, or the making of value judgments in making decisions for the Government. Inherently governmental functions DO NOT normally include gathering information for or providing advice, opinions, recommendations, or ideas to Government officials.
FAR 7.503(c) provides a list of examples of functions considered to be inherently governmental functions or which shall be treated as such.
To this effect, during contract performance, care should be taken to ensure that any change or expansion in scope of the requirement does not include inherently governmental functions. Further, due to the nature of a given requirement, there is a potential for close working relationships to develop between Government and Contractor personnel; however, care should be taken to ensure that any familiarity established between the Government and Contractor personnel never promotes or fosters an environment that allows for the assignment of inherently governmental functions to contractor employee(s).
3. Unauthorized Commitments: In carrying out your duties, you are reminded that in accordance with FAR (d)(5), the COR 1.602-2 "[h]as no authority to make any commitments or changes that affect price, quality, quantity, delivery, or other terms and conditions of the contract, or in any way direct the Contractor, or its Subcontractors, to operate in conflict with the contract terms and conditions." Doing so constitutes an "unauthorized commitment." The Contracting Officer is the only individual with the authority to enter into an agreement on behalf of the Government. An unauthorized commitment is defined as "an agreement that is not binding solely because the Government representative who made it lacked the authority to enter into that agreement on behalf of the Government." FAR 1-602-3(a). Examples of unauthorized commitments include, but are not limited to, the following:
• Orders placed with a Contractor without a valid contractual instrument in place.
• Directing any Contractor to do additional work, in excess of the contract value, or work beyond the Period of Performance.
• Authorize new work to a contract without notifying the Contracting Officer (CO) or Contract Specialist(CS) and having a modification in place for the new work.
• Directing the Contractor, in any way that could change the terms and conditions of the contractual instrument or be deemed outside the Scope of the Statement of Work.
Unauthorized commitments are a serious matter and may result in personal liability on the part of the employee who committed the unauthorized commitment. Ratification, is "the act of approving an unauthorized commitment by an official who has the authority to do so." FAR 1.602-3(a).
https://www.acquisition.gov/far/part-1
Special Contract Requirements
Department of Health and Human Services Acquisition Regulations (HHSAR) Clauses Incorporated by Full Text
352.204-71 Information and Information Systems Security Feb 2024 Deviation
(a) As used in this clause—Definitions.
means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where—Breach
(1) A person other than an authorized user accesses or potentially accesses personally identifiable information, or
(2) An authorized user accesses personally identifiable information for an other than authorized purpose.
(see 45 CFR 160.103), except as provided in paragraph (2) of this definition, business associate means, with respect to a covered Business associate entity, a person who -
(1) On behalf of such covered entity or of an organized health care arrangement (as defined in this clause) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this contract or agreement, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at , billing, benefit management, practice 42 CFR 3.20 management, and repricing; or
(2) Provides, other than in the capacity of a member of the workforce of such covered entity, legal, actuarial, accounting, consulting, data aggregation (as defined in 45 CFR section ), management, administrative, accreditation, or financial services to or for such covered entity, or to or for an 164.501 organized health care arrangement in which the covered entity participates, where the provision of the service involves the disclosure of protected health information from such covered entity or arrangement, or from another business associate of such covered entity or arrangement, to the person.
(3) A covered entity may be a business associate of another covered entity.
(4) includes the following: Business associate
(i) A Health Information Organization, E-prescribing Gateway, or other person that provides data transmission services with respect to protected health information to a covered entity and that requires access on a routine basis to such protected health information.
(ii) A person that offers a personal health record to one or more individuals on behalf of a covered entity.
(iii) A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate.
(5) does not include: Business associate
(i) A health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual.
(ii) A plan sponsor, with respect to disclosures by a group health plan (or by a health insurance issuer or HMO with respect to a group health plan) to the plan sponsor, to the extent that the requirements of 45 CFR apply and are met. 164.504(f)
(iii) A government agency, with respect to determining eligibility for, or enrollment in, a government health plan that provides public benefits and is administered by another government agency, or collecting protected health information for such purposes, to the extent such activities are authorized by law.
(iv) A covered entity participating in an organized health care arrangement that performs a function or activity as described by paragraph (1)(i) of this definition for or on behalf of such organized health care arrangement, or that provides a serviceas described in paragraph (1)(ii) of this definition to or for such organized health care arrangement by virtue of such activities or services.
means the agreement, or other arrangement, as dictated by the HIPAA Privacy Rule (45 CFR 160), between an HHS Business associate agreement covered entity and a business associate, which must be entered into in addition to the underlying contract for services and before any disclosure (see 45 CFR 160.103) of PHI can be made to the business associate, in order for the business associate to perform certain functions or activities on behalf of an HHS entity.
means information that laws, regulations, or Government-wide policies require to have safeguarding or Controlled unclassified information (CUI) dissemination controls, excluding classified information.
means a component or combination of components of a hybrid entity designated by the hybrid entity in accordance with 45 Healthcare component CFR 164.105(a)(2)(iii)(D) (see 45 CFR 164.103). The Secretary of HHS has designated HHS as a covered entity (further designated as a “hybrid entity”), and has also designated four HHS divisions as healthcare components under HIPAA, including —
(1) The Centers for Medicare and Medicaid Services (CMS), insofar as it operates the fee-for-service Medicare program;
https://www.ecfr.gov/current/title-42/chapter-I/subchapter-A/part-3/subpart-A/section-3.20 https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.501 https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504#p-164.504(f)
(2) The Program Support Center (PSC), Division of Commissioned Personnel, insofar as it operates a health plan for Commissioned Corps officers;
(3) The World Trade Center (WTC) Health Program; and,
(4) The Indian Health Service (IHS), insofar as it operates a health plan and a program providing healthcare that uses electronic transactions.
means a set of HHS rules that describes the responsibilities and expected behavior of users HHS Information Technology General Rules of Behavior of HHS information or information systems.
means all HHS data, on any storage media or in any form or format, which requires confidentiality, integrity, and HHS sensitive information availability protection due to the risk of harm that could result to interests of HHS, other agencies or entities, or individuals from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes—
(1) Information where the improper use or disclosure could adversely affect the ability of HHS to accomplish its mission, i.e., HHS proprietary information;
(2) Records about individuals requiring protection under laws and regulations such as the E-Government Act, Privacy Act and the HIPAA Privacy Rule, or based on a data use agreement or a promise or assurance of confidentiality; and
(3) Information that would be exempt from disclosure if requested under the Freedom of Information Act. Examples of HHS sensitive information include—
(i) Individually-identifiable medical, benefits, and personnel information;
(ii) Financial, budgetary, research, quality assurance, confidential commercial, critical infrastructure, security-sensitive, procurement-sensitive, investigatory, and law enforcement information;
(iii) Controlled unclassified information;
(iv) Information that would be confidential and privileged in litigation such as information protected by the deliberative process privilege, attorney work-product privilege, and the attorney-client privilege; and
(v) Other information which, if released, could result in a violation of law or agreement, could cause harm or unfairness to any individual or group, or could adversely affect the national interest or the conduct of Federal programs.
means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and part 164. HIPAA Rules
Incident means an occurrence that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information systems; or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable policies.
means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or Information system disposition of information.
means a formal document that provides an overview of the security requirements for an information system or an Information system security plan information security program and describes the security controls in place or planned for meeting those requirements.
(see FAR 2.101) also means Information and Communication Technology (ICT).Information technology means those contracts that include services (including support services), and related resources for Information technology-related contracts information technology.
(see 45 CFR 160.103) means:Organized health care arrangement
(1) A clinically integrated care setting in which individuals typically receive health care from more than one health care provider;
(2) An organized system of health care in which more than one covered entity participates and in which the participating covered entities:
(i) Hold themselves out to the public as participating in a joint arrangement; and
(ii) Participate in joint activities that include at least one of the following:
(A) Utilization review, in which health care decisions by participating covered entities are reviewed by other participating covered entities or by a third party on their behalf;
(B) Quality assessment and improvement activities, in which treatment provided by participating covered entities is assessed by other participating covered entities or by a third party on their behalf; or
(C) Payment activities, if the financial risk for delivering health care is shared, in part or in whole, by participating covered entities through the joint arrangement and if protected health information created or received by a covered entity is reviewed by other participating covered entities or by a third party on their behalf for the purpose of administering the sharing of financial risk.
(3) A group health plan and a health insurance issuer or HMO with respect to such group health plan, but only with respect to protected health information created or received by such health insurance issuer or HMO that relates to individuals who are or who have been participants or beneficiaries in such group health plan;
(4) A group health plan and one or more other group health plans each of which are maintained by the same plan sponsor; or
(5) The group health plans described in paragraph (4) of this definition and health insurance issuers or HMOs with respect to such group health plans, but only with respect to protected health information created or received by such health insurance issuers or HMOs that relates to individuals who are or have been participants or beneficiaries in any of such group health plans.
means the HHS official(s) with responsibility for implementing and oversight of privacy related policies and practices that impact a Privacy officer given HHS acquisition.
(b) . Contractors, subcontractors, their employees, third-parties, and business associates with access to HHS information, information systems, General or information technology (IT) or providing and accessing IT-related goods and services, shall adhere to the HHS Cybersecurity Program and the directives and handbooks, complete HHS security training prior to accessing HHS information (including HHS sensitive information and information systems security and privacy) and on an annualbasis thereafter, as well as those set forth in the contract specifications, statement of work, or performance work statement. These include, but are not limited to, HHS , which establishes HHS Personnel Security and Suitability Program procedures, responsibilities, and processes for complying with current Federal law, Executive Orders, policies, regulations, standards, and guidance for protecting HHS information, information systems (see 302.101, Definitions) security and privacy, and adhering to personnel security requirements when accessing HHS information or information systems.
(c) . Access to HHS information and HHS information systems
(1) Contractors are limited in their request for logical or physical access to HHS information or HHS information systems for their employees, subcontractors, third parties and business associates to the extent necessary to perform the services or provide the goods as specified in the contracts, agreements, task, delivery, or purchase orders.
(2) All Contractors, subcontractors, third parties, and business associates working with HHS information are subject to the same investigative requirements as those of HHS appointees or employees who have access to the same types of information. The level and process of background security investigations for Contractors to access HHS information and HHS information systems shall be in accordance with HHS Personnel Security
. and Suitability Program
(3) Contractors, subcontractors, third parties, and business associates who require access to national security programs must have a valid security clearance.
(4) The Contractor (and/or any subcontractor) must comply with , Executive Order 13556 Controlled Unclassified Information, (implemented at 3 part 2002 when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term "handling" refers to "…any use of CUI, including but not CFR, ) limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information." 81 Fed. Reg. 63323. The requirements below apply only to nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, must be –
(i) Marked appropriately;
(ii) Disclosed to authorized personnel on a need-to-know basis;
(iii) Protected in accordance with NIST SP 800-53, applicable baseline if Security and Privacy Controls for Information Systems and Organizations handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal if handled by internal Contractor system; andInformation Systems and Organizations
(iv) Returned to HHS control, destroyed when no longer needed, or held until otherwise directed. Information and/or data must be disposed of in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
(5) HIPAA . Under the HIPAA Privacy and Security Rules (see 45 CFR 164), pursuant to 45 CFR 164.502(e)(1), a business associate agreements covered entity may disclose protected health information to a business associate and may allow a business associate to create, receive, maintain, or transmit protected health information on its behalf, if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information. A covered entity is not required to obtain such satisfactory assurances from a business associate that is a subcontractor of a covered entity’s business associate. Additionally, a business associate may disclose protected health information to a business associate that is a subcontractor and may allow the subcontractor to create,receive, maintain, or transmit protected health information on its behalf, if the business associate obtains satisfactory assurances, in accordance with 45 CFR , that the subcontractor will appropriately safeguard the 164.504(e)(1)(i) information. The satisfactory assurances required by 45 CFR 45 CFR 164.504(e)(1) of this section shall be documented through a written contract or other written agreement or arrangement with the business associate that meets the applicable requirements of 45 CFR . The contracts shall 164.504(e) also include breach reporting policies and procedures for suspected or confirmed breaches of protected health information. The contract shall impose a duty to cooperate with the healthcare component and/or HHS breach investigation and response and must require all subcontractors to comply with the same HIPAA Rules requirements as a condition of receiving government data.
(i) Contractors or entities required to execute business associate agreements for contracts and other agreements become HHS business associates.
Business associate agreements are issued by HHS or may be issued by other HHS programs in support of HHS. The HIPAA Privacy Rule requires HHS to execute compliant business associate agreements with persons or entities that create, receive, maintain, or transmit HHS PHI or that will store, generate, access, exchange, process, or utilize such PHI in order to perform certain activities, functions or services to, for, or on behalf of HHS. There may be other HHS components or staff offices which also provide certain services and support to HHS and must receive PHI in order to do so. If https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504#p-164.504(e)(1)(i) https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504#p-164.504(e) these components award contracts or enter into other agreements, purchase/delivery orders, modifications and issue governmentwide purchase card transactions to help in the delivery of these services to HHS, they will also fall within the requirement to obtain a satisfactory assurance from these contractors by executing a business associate agreements.
(ii) A prime contractor required to execute a business associate agreement shall also Business associate agreement flow down to subcontractors.
obtain a satisfactory assurance, in the form of a business associate agreement, of its subcontractors who will also create, receive, maintain, or transmit PHI or that will store, generate, access, exchange, process, or utilize such PHI will comply with HIPAA Rules requirements to the same degree as the Contractor. A contractor employing a subcontractor who creates, receives, maintains, or transmits PHI or that will store, generate, access, exchange, process, or utilize such PHI under a contract or agreement is required to execute a business associate agreement with each of its subcontractors which also obligates the subcontractor (i.e., also a business associate) to provide the same protections and safeguards and agree to the same disclosure restrictions to PHI that is required of the covered entity and the prime contractor.
(d) Custom software development and outsourced operations must be located in the U.S. to the Contractor operations required to be in United States.
maximum extent practicable. If such services are proposed to be performed outside the continental United States, and are not otherwise disallowed by other Federal law, regulations or policy, or other HHS policy or other mandates as stated in the contract, specifications, statement of work or performance work statement (including applicable business associate agreements), the Contractor/subcontractor must state in its proposal where all non-U.S. services are provided.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .