Attachment A SOW LGP 01282020 (002).pdf
PDF 249 KB Posted
- Attached to
- Health Center Loan Guarantee Program Support Federal contract opportunity
- Solicitation number
- 75R60220Q00040
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 75R60220Q00040-0001.pdf | ||
| HRSA Information Security Policy.pdf | ||
| Amendment 1 75R60220Q00040.pdf | ||
| Questions and Answers - RFQ 75R60220Q00040 - Health Center Loan Guarantee Program Support 2.14.2020.pdf | ||
| HHS Information Security and Privacy Policy - 2014 Edition.pdf | ||
| SOW Attachment A LGP BPA Price Catalog 01282020.pdf | ||
| Attachment C LGP Call Order 1 - 01282020.xlsx | XLSX spreadsheet | |
| SOW Attachment C Contractor Non-Disclosure Agreement 01282020.pdf | ||
| Attachment D LGP Labor Category-loading Matrix.xlsx | XLSX spreadsheet | |
| Attachment E Past Performance Questionnaire.pdf | ||
| SOW Attachment B LGP BPA Call Order Form 01282020.xlsx | XLSX spreadsheet | |
| Attachment B Technical Evaluation Criteria.pdf | ||
| RFQ LGP 75R60220Q00040.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Title: Health Center Loan Guarantee Program Support Attachment A
Statement of Work (SOW) Health Center Loan Guarantee Program Support
January 28, 2020
I. Background
The Health Resources and Services Administration (HRSA), Bureau of Primary Health Care (BPHC) mission is to improve the health of the Nation’s underserved communities and vulnerable populations by ensuring access to comprehensive, culturally competent, quality primary health care services.
The purpose of the Health Center Program is to improve the health of the Nation’s underserved communities and vulnerable populations by assuring continued access to affordable, quality primary health care services. The Health Center Program supports patient directed public and private nonprofit organizations and urban Indian and tribal organizations that provide primary and preventive health care services to the Nation’s medically underserved.
The Health Center Program is authorized by section 330 of the Public Health Service (PHS) Act, as amended (42 U.S.C. 254b). The Health Center Program funding targets the Nation’s high need geographic areas and populations by currently supporting nearly 1,400 health centers that operate approximately 12,000 service delivery sites in every state, the District of Columbia, Puerto Rico, the Virgin Islands, and the Pacific Basin. More than 27 million patients, including medically underserved and uninsured or underinsured patients, receive accessible, affordable, quality primary health care services through the Health Center Program.
Since their inception, health centers have encountered difficulty in obtaining loans for building and equipment projects. While individual health centers across the country have taken advantage of successful local, state and national financing programs, many other health centers have not been so fortunate. To help health centers thrive so that more vulnerable and underserved people receive quality care, additional funds have been appropriated to enable health centers to access capital by partially guaranteeing loans made by non-Federal lenders.
Congress has appropriated funds that will remain available until expended for Federal guarantees of loans made by non-Federal lenders for health centers funded under section 330 of the Public Health Service (PHS) Act. These health centers, which are community controlled nonprofit or public entities, provide primary health care services for medically underserved populations. The approximately 1,400 organizations that receive section 330 funding are located in urban and rural communities throughout the Nation.
The fiscal year (FY) 1997 Appropriation authorized the provision of loan guarantees under part A of title XVI of the Public Health Service Act. The Consolidated Appropriations Act, 2018, provided additional authority to fully expend the remaining prior year appropriations from FYs 1997, 1998, and appropriated an additional $20 million to support loan guarantees.
HRSA is authorized to guarantee up to 80 percent of the principal and interest on loans made by non-Federal lenders to health centers as defined and funded under section 330 of the PHS Act
(42 U.S.C. 254b) The Loan Guarantee Program (LGP) guarantees loans secured from non- Federal lenders; these loan guarantees are not direct loans or grants.
The purpose of the HRSA Health Center Facility Loan Guarantee Program (LGP) is to facilitate access to capital funding and reduce financing costs for health centers by guaranteeing up to 80 percent of financing needed to support capital infrastructure projects. The LGP supports loans to eligible Health Center Program awardees for the construction/expansion, alteration/renovation and modernization of health center facilities. HRSA expects that loan amounts will vary and that terms and conditions will be unique for each loan or financing transaction. Therefore, the LGP does not provide maximum or minimum loan size limits or prescribe specific loan terms or conditions.
The LGP allows health centers to thrive so that more vulnerable and underserved people receive quality care. This contract will assist with the administration of the LGP, which will enable health centers to grow and modernize their facilities.
II. Purpose / General Description
The purpose of this contract is to provide transaction management for the Health Center Facility Loan Guarantee Program (LGP). This includes consultations with applicants; reviewing and processing applications to include independent evaluation of lenders’ underwriting and on-site visits to review/confirm documents; loan closing document review to insure HRSAs’ interests are protected; and program monitoring to ensure compliance with program requirements.
III. Period of Performance / Place of Performance
The period of performance shall be a 12 month base period and four 12 month option periods.
The work shall be performed primarily at the contractors facility.
IV. Tasks
Task 1: Federal Records Management
The contractor shall manage and maintain Federal records, including electronic records, ensuing from this contract in accordance with all applicable records management laws and regulations, including but not limited to:
• The Federal Records Act (44 U.S.C. Chapters. 21, 29, 31, 33); 36 CFR,
• 1236.20 “What are appropriate recordkeeping systems for electronic records?”, and
• 1236.22 “What are the additional requirements for managing electronic mail records?”
(http://www.ecfr.gov/cgi-bin/text-idx?rgn=div5&node=36:3.0.10.2.25);
file://gss-fs2/users_P-S/SScott/Loan%20Gaurantee%20Program/330%20of%20the%20Public%20Health%20Services%20Act%20(42%20U.S.C.%20254b) http://www.ecfr.gov/cgi-bin/text-idx?rgn=div5&node=36:3.0.10.2.25
• NARA Bulletin 2013-02, August 29, 2013, “Guidance on a New Approach to
Managing Email Records”
(https://www.archives.gov/records-mgmt/bulletins/2013/2013-02.html); and
• NARA Bulletin 2010-05 September 08, 2010, “Guidance on Managing Records in Cloud Computing Environments”
(http://www.archives.gov/records-mgmt/bulletins/2010/2010-05.html).
Managing the records includes, maintaining records to retain functionality and integrity throughout the records’ full lifecycle including: (1) maintenance of links between records and metadata, and (2) categorization of records to manage retention and disposal, either through transfer of permanent records to NARA or deletion of temporary records in accordance with NARA-approved retention schedules.
Task 2: Training
a. Federal Records Training: The contractor (and/or subcontractor) shall ensure that all employees having access to (1) Federal information or a Federal information system, or
(2) personally identifiable information (PII), complete the HRSA Records Management Training before performing work under this contract, and thereafter completing the annual refresher course during the life of the contract. The training can be requested by emailing the records management team at recordsmanagement3@hrsa.gov. The listing of completed training shall be included in the first progress report. Any revisions to this listing as a result of staffing changes shall be submitted with next required progress report.
Task 3: Kickoff Meeting
The contractor shall:
a. Meet in person with the Contracting Officer’s Representative (COR) and applicable HRSA staff within seven (7) days of the effective date of a Blanket Purchase Agreement (BPA). The meeting will be held at HRSA Headquarters located at 5600 Fishers Lane, Rockville, MD 20857 (5600 Fishers Lane is a secured building; allow time to get through Security). The following will be discussed:
• Tasks in statement of work;
• Project timeline submitted with the proposal;
• Schedule of deliverables;
https://www.archives.gov/records-mgmt/bulletins/2013/2013-02.html http://www.archives.gov/records-mgmt/bulletins/2010/2010-05.html
• Potential problems that might cause delays in the submission of deliverables and ways to avoid such delays; and
• Other administrative arrangements
b. Provide an electronic agenda via email to the COR three (3) days prior to the Kickoff
Meeting.
c. Take meeting minutes for submission to the COR via email within three (3) days of the Kickoff Meeting
Task 4: Project Timeline / Work Plan
a. Submit a revised project timeline/work plan to the COR via email within three (3) days of the Kickoff Meeting. The revised project timeline/work plan shall incorporate the clarifications and any minor changes discussed during the Kickoff Meeting and receive written approval from the COR for the revised timeline before work may proceed. The COR will provide approval within five (5) days of receiving all revisions. Update the work plan for any changes in the deliverables or timelines that occur during the course of contract on a monthly basis.
Task 5: LGP Transaction Monitoring and Ad Hoc Consultation
a. Program Monitoring and Notification:
1. Maintain contact with borrowers and lenders on a quarterly basis in order to monitor all outstanding LGP health center transactions.
2. Provide ongoing due diligence on health centers with outstanding HCP guarantees by reviewing loan monitoring information provided by the health center for each existing loan guarantee transaction. Due diligence activities shall include a comprehensive review of the quarterly and annual financial statements, compliance with loan covenants, management and financial review, and loan payment status. The implementation of this task shall include the receipt of required reports from LGP borrowers and lenders, compilation of relevant reporting data, and submission of semi-annual reports on individual and aggregate loans as described in Task 5.d.
b. Ad Hoc Consultation:
1. Provide ad hoc consultation to HRSA to assist with LGP application packages and existing transactions and to serve as subject matter expert to HRSA staff.
Consultations shall include verbal or written communication (estimated one per month)
c. Communication:
1. Adhere to the following communication and meeting procedures:
a) Use email and HRSA’s Electronic Handbook (EHB) system for the purpose of performing application and technical reviews.
b) Ensure COR, Program Team Lead and Staff are copied on all email communications regarding the contract and all call orders.
c) Invite LGP program staff to teleconference meetings the contractor holds with applicants.
d) Respond to all written and oral communications within a 48 hour period.
d. Semi-annual Report:
1. Provide a semi-annual report for existing transactions that contains at minimum, financial indicators for each active loan, outstanding loan balance and HRSA’s estimated guarantee exposure, and performance on financial covenants; and
a) The semi-annual report shall include a log of inquiries from existing borrowers and lenders and parties that are interested in the LGP as described in Task 5.b.
b) Begin monitoring of closed loan guarantee transactions after closing. The number of monitored transactions will be adjusted semi-annually, based on the number of transactions closed or discontinued in the previous six month period, as disclosed in the semi-annual report.
Task 6: Existing Guarantee On-site Review
a. Conduct a one-day on-site review (one day of travel before and one day of travel after) every three (3) years following closing for each active loan guarantee in order to review applicant’s compliance with the terms of the loan guarantee, as well as to carry out programmatic and financial monitoring. The contractor shall monitor the portfolio and notify HRSA of need for the three-year on-site review. During the on-site review, the following shall occur:
1. View and confirm that the guaranteed facility is still in use for the purposes for which the Loan Guarantee was provided.
2. Assess operational and financial performance of the Health Center.
a) Meet with lender(s) to discuss health center’s compliance with loan covenants;
lender changes and/or changes in internal control in terms of loan monitoring as applicable;
b) Review clinical and operating performance trends of the health center including service area and market conditions;
c) Evaluate health center’s governance structure, management and staffing make-up and identify challenges.
3. View and examine the physical assests being guaranteed to see that they are being maintained in a manner that will retain the value of those assests.
b. Submit an On-Site Review Report within fifteen (15) days of completion of the on-site review that:
1. Summarizes findings;
2. Alerts HRSA to organizational issues that might lead to loan default, specifically operating and financial performance aspects that could threaten to undermine the organization’s credit worthiness and ability to continue to service the guaranteed debt; and
3. Recommends interventions that are warranted.
Task 7: Pre-Application Consultation
a. Provide pre-application consultation (one per application), which shall include consultation with the applicant’s prospective lender(s). A consultation is specific to a health center proposed project and is initiated by a referral from HRSA. The consultation shall ensure each applicant has an understanding of the application package that will fully describe the project and include all of the loan documentation required for a complete application package. At the completion of this task, all of the information components required to submit a complete application for Task 8. shall be ready to submit.
Note that the pre-application consultation with a prospective applicant may require multiple interactions with the health center and/or its lender, and may not result in an application being submitted to the LGP (average time per consultation is eight (8) hours).
Note that the contractor may determine (with HRSA’s written concurrence) that the transaction will not result in a LGP application.
Within three (3) business days of completion of a pre-consultation session, submit to the COR either a:
1. One-page summary of the consultation session and/or guidance provided to the health center and/or lender. The summary shall include the status of:
a) Application Submission to HRSA, including expected Application Submission date.
• If the pre-application consultation will not result in a application submission, the summary shall explain why and include the conclusion date of the pre-application consultation. No further pre-application consultation shall be provided to the health center unless approved by HRSA.
b) Lender’s Commitment to borrower
c) Project Type
d) Site control
e) Financing Amount; or
2. One-page summary describing final outcome for transactions that will not proceed to
LGP application review.
Task 8: Application Review
a. Conduct comprehensive financial and operational analysis of LGP application packages.
Application Review, which shall include:
1. Application Desk Review:
Conduct a desk review to assess the lender and applicant’s organizational capacity, project viability, and operating and financial performance. Each desk review shall be completed within 10 days of assignment. The application desk review provided to HRSA shall include the following:
a) Lender Review.
• Review Lendor eligibility to ensure that the Lender is not currently disbarred/suspended from participation in a Government work or delinquent in a Government debt.
b) Lenders’ Commitment Letter Review:
• Review Lenders’ proposed terms and conditions for reasonableness in conjuction with the applicant’s operational and financial projections once the approved project site is completed.
c) Lender’s Credit Analysis and Underwriting:
• Review the depth of the Lender’s credit analysis and underwriting of the proposed financing to ensure an appropriate assessment of any risk associated with making the loan.
d) Assess Organizational Capacity and Conduct Interview with Applicant
Management and the Board at the On-site Review to Evaluate:
1) Management’s qualifications and capabilities.
Assess management’s responsiveness, credentials, length of experience and employment with the health center, stability and capacity to address leadership turnover, organizational structure and achievements, strategic planning and preparation for industry changes and level of community support and engagement.
2) Health Center governing board composition and qualifications
Review Board minutes and interview members to assess the Board’s capacity to govern, provide advisement and oversight of management, and the ability to supplement staff resources.
Assess the Board’s involvement and understanding of the proposed development of the new administrative/service delivery site project and loan obligations.
e) Assess Operating and Financial Performance:
• Examine applicants’ three years’ audited financial statements, unaudited interim statements, historical visit volume and patient services payor mix from Uniformed Data System (UDS), HRSA Onsite Visit (OSV) reports, and other operational and financial data provided in preparation for the on-site review to assess the applicant’s financial performance.
f) Assess Project Viability.
Assess applicants’ effectiveness in responding to the composition and needs of the health center’s patient population, the changing dynamics of its competitive environment, and changes in its funding environment. Reference feasibility studies submitted to the Lender for project strengths and weaknesses, risk exposure, loan repayment, and organizational capacity to sustain the new project site during and beyond the life of the loan. The contractor shall evaluate:
1. Project Development.
• Assess whether or not the applicant has site control (including length of time it may take to obtain site control).
• Review the management team’s experience with completing similar projects within budget, and whether or not there is an experienced Project Manager with the necessary qualifications to complete the project.
• Review the timeline for the project.
2. Project Sources and Uses.
• Review proposed project development budget and its underlying assumptions to determine if expenses are missing and if the budget is reasonable given the scope of the project.
• In reviewing the budget, determine the project’s funding readiness and the applicant’s ability to secure all sources of project funding, including contributions by the applicant and other funding sources, prior to the start of the project.
3. Operating and Financial Projections.
• Analyze the applicant’s projections for the project and for the organization.
• Based on the applicant’s historical performance and management’s start-up plans for the project, assess management’s ability to meet its own projections and carry the proposed debt.
4. Market Demand and Environmental Landscape.
• Review evidence of market demand for the project, evaluate competition in the market, and determine the nature and depth of the applicant’s community ties to ensure that the applicant understands the community it is proposing to serve and that the community is supportive of both the organization and the proposed project.
5. Implementation Capacity.
• Assess the likelihood of management achieving a successful start-up by reviewing the applicant’s history and its current management’s experience with implementing new facilities/services.
• Review management’s implementation plans, including clinician recruitment and patient marketing plans during the on-site review.
2. Application On-Site Review:
a) Within 10 days of application assignment, arrange a one (1) day on-site review to obtain and confirm the information from the Lender’s underwriting documentation; including the loan terms, organizational capacity, project viability and the operating and financial performance of the applicant. The on-site review should be conducted within five (5) days of completing the desk review.
b) Within two (2) days of a completed desk review, schedule a pre-on-site review conference call with the applicant and HRSA personnel to finalize plans to meet with applicant’s management team (Health Center CEO, CFO, and Board) and a lender’s representative(s) to review, schedule, and/or confirm draft on-site review meeting agenda. Within 3 days of the pre-on-site review conference call, prepare and share with HRSA the following items:
1) Draft agenda for the pre-on-site review conference call.
2) Draft agenda for the on-site review.
3) Written confirmation of site visit date, meeting address, and plans for a site tour of the proposed administrative/service delivery site/location.
4) Submit a list of required documents needed for the visit to the applicant to prepare for the on-site review.
c) Application Review Report and Recommendations:
1) Within seven (7) days of completion of the On-site review, submit a report to
HRSA that:
• Summarizes findings of the desk and on-site review; and
• Identifies key risks and recommendations associated with the proposal to inform HRSA’s decision to enter into a Loan Guarantee; and
• Perform a Technical Review of the LGP application in EHB by completing the review checklist.
• Attach/upload application review and recommendation report as part of the technical review.
Task 9: Protocol Development and Lender’s Handbook
a. During the first 12-month period, develop a protocol to assist with standardizing the monitoring of guarantees once they are in place and application review processes. The protocol shall be used as a guide for providing program oversight to health centers and lenders to ensure adherence to LGP program requirements as well as a tool for assessing and documenting an applicant’s financial viability and sustainability. In addition to the protocol, develop a Lender’s Handbook to assist lenders in utilizing the LGP program.
The handbook shall provide information about the program, the benefit of utilizing the program, application process and resources available to lenders.
1. Work with the COR during the Kickoff Meeting (as referenced in Task 3) to develop a protocol development and Lender’s Handbook review/deliverable schedule.
2. Within 180 days of contract award, provide the COR a draft protocol ready for piloting and Lender’s Handbook.
3. Within 10 months of contract award, provide the COR a final protocol and Lender’s
Handbook.
4. Provide HRSA with bi-monthly updates of this task via email until protocol development is complete.
Task 10: Loan Closing
a. As assigned by HRSA, review the loan closing documents provided by the lender to determine whether there will be changes to the risks/recommendations provided to HRSA from the application review.
b. Review the lender’s certification and loan closing documents and assess for completeness and accuracy and whether there have been changes that may impact HRSA’s risk.
1. Share deficiencies for HRSA to discuss with the lender for corrections as applicable.
c. Review the borrower’s agreement with the guarantor and loan guarantor agreement to ensure that all information are within the scope of the financing.
d. Submit a one-page summary of the Loan Closing to the COR within five (5) days of completing the review of the loan closing documents.
Task 11: Loan Assistance
a. Work with HRSA to identify and manage problem loans (including arranging calls/visits with representatives to resolve problems) and recommend strategies to resolve problems.
The level of assistance required will be determined based on a loan being in violation of covenant(s), default, and/or foreclosure.
b. Work with HRSA during the modification of the loan guarantee documents once the guarantee is in place to resolve any issues related to material amendments or modifications of a loan and associated documents and coordinate obtaining HRSA’s written approval as required in the guarantee documents. Examples include, but are not limited to, loan repayment terms, interest rates, sale/merger of the health center, or changes to collateral securing the loan.
c. Submit a one-page summary of the Loan Assistance to the COR within five (5) days of satisfactorily completing the Loan Assistance, as confirmed in writing by HRSA.
Task 12: Contract Status Reports
a. Produce monthly contract progress reports of all activities conducted under the contract, which include the following information:
1. Work performed to date, progress toward meeting the objectives of each task outlined in the SOW (to include summaries of deliverables submitted and their dates of delivery; memoranda delivered to the COR; difficulties encountered during the reporting period and those anticipated for the next reporting period; significant findings and any problems impeding progress and solutions or and proposed solutions;
2. Number of pre-application consultation sessions provided;
3. Loan financial and sustainability review performance measures such as total number of applications assigned; number of applications recommended for approval and/or rejected; date application was assigned for processing; dates of key milestones, status of applications in progress; date applications were submitted/returned to the contractor by HRSA, reasons for delays and the solution; Guarantee Commitment date, closing date, loan disbursement to date and loan payments received.
4. Status on the development of the application review protocol.
5. Submit within fifteen (15) days after the end of a month.
Task 13: Travel for On-Site Loan Assistance
a. This task item is for travel (one day of travel before and one day of travel after) for one senior professional for one day of on-site loan assistance for a health center loan guarantee client as requested by HRSA.
b. After travel is complete, contractor shall submit a one-page summary within seven (7) day after travel, verifying that the travel is complete and include the travel dates, health center name, project name, and address(es) of the projects visited.
Task 14: Legal Consultative Services
a. Provide consultation on legal and structural issues as they relate to the requirements of the LGP and specific financial transactions involving lenders and health centers, such as
(i) HRSA’s obligations under the guarantee, (ii) LGP policy considerations determined by HRSA, and (iii) specific types of financing used to support health center capital infrastructure development projects. Additionally, subsequently update and standardize LGP documents as required by this analysis. Deliverables, such as updates to LGP documents, shall be submitted via email to the COR for review and concurrence. If revisions are required, the COR will provide to the contractor for revision, resubmission and concurrence until finalized.
b. Submit a one-page summary of the Legal Consultative Services to the COR within five
(5) days of satisfactorily completing the Legal Consultative Services, as confirmed in writing by HRSA.
Task 15: Security and Privacy Requirements
a. Work with the COR for timely approval of all appropriate badging, background checks and HRSA systems access required for completing projects. Coordinate via COR’s guidance and approval, with various HRSA offices such as OIT.
b. Applicability. The requirement herein apply whether the entire contract or order
(hereafter “contract”), or portion thereof, includes either or both of the following:
1. Access (Physical or Logical to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
2. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
c. Safeguarding Information and Information Systems. In accordance with the Federal
Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
1. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
2. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
3. Adopt and implement the policies, procedures, controls, and standards required by the
HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
4. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
d. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
See the HHS Standard for the Definition of Sensitive Information, for additional information in debriefing and protecting sensitive information.
e. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor officer or employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such officer or employee can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and HRSA policies. Unauthorized disclosure of information will be subject to the HHS/HRSA sanction policies and/or governed by the following laws and regulations:
1. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
2. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
3. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
f. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the HRSA non-disclosure agreement, see SOW Attachment C. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
g. Training.
1. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/HRSA Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete HHS/HRSA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
3. Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. The training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
h. Rules of Behavior.
1. The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior, the HRSA Information Technology Rules of Behavior (included in the HRSA Information Security and Privacy Awareness Training), and any applicable system-level rules of behavior.
2. All Contractor employees performing on the contract must read and adhere to the
Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual HRSA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable.
i. Incident Response.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor), the Contractor (and/or any subcontractor) shall:
1. Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
2. Not notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send notifications to affected individuals as expeditiously as practicable, without unreasonable delay, and in accordance with applicable law.
3. Report all suspected and confirmed information security and privacy incidents and breaches to the HRSA Security Operations Center (SOC), COR, CO, HRSA SOP (or his or her designee), and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour, and consistent with the applicable HRSA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:
a) Cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b) Not include any sensitive information in the subject or body of any reporting e-mail; and
c) Encrypt sensitive information in attachments to email, media, etc.
4. Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally
Identifiable Information, HHS, and HRSA incident response policies when handling PII breaches.
5. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls.
j. Position Sensitivity Designations.
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:
T2S moderate risk position(s).
k. Homeland Security Presidential Directive (HSPD)-12.
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
For additional information, see HSPD-12 policy at: https://www.dhs.gov/homeland-security-presedential-directive-12.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster shall be submitted to the COR, with a copy to the Contracting Officer, within 14 days of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 14 days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
l. Contract Initiation and Expiration
1. General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the HRSA EPLC framework and methodology (https://sharepoint.hrsa.gov/oo/oit/dcppm/pmo/Shared Documents/z_Old PMO Archives/Documents.aspx) and in accordance with the HHS Contract Closeout Guide (2012).
HHS EA requirements may be located here:
https://www.hhs.gov/ocio/ea/documents/proplans.html https://sharepoint.hrsa.gov/oo/oit/dcppm/pmo/Shared%20Documents/z_Old%20PMO%20Archives/Documents.aspx https://sharepoint.hrsa.gov/oo/oit/dcppm/pmo/Shared%20Documents/z_Old%20PMO%20Archives/Documents.aspx https://www.hhs.gov/ocio/ea/documents/proplans.html
2. System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for system development and provide system documentation at designated intervals (specifically, at the expiration of the contract) within the EPLC that require artifact review and approval.
3. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) shall provide all required documentation to the CO and/or COR to certify that, at the government’s direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
4. Notification. The Contractor (and/or any subcontractor) shall notify the CO and/or
COR and system ISSO within 10 days before an employee stops working under this contract.
5. Contractor Responsibilities Upon Physical Completion of the Contract. The contractor (and/or any subcontractors) shall return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR.
Additionally, the Contractor shall provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or HRSA policies.
6. The Contractor (and/or any subcontractor) shall perform and document the actions identified in the HRSA Contractor Employee Separation Checklist when an employee terminates work under this contract within 10 days of the employee’s exit from the contract. All documentation shall be made available to the CO and/or COR upon request.
V. Schedule of Deliverables
The contractor shall ensure all products and services delivered under this contract are compliant with Section 508 in accordance with the Health and Human Services Acquisition Regulation (HHSAR). These Section 508 Standards were issued by the https://www.access-board.gov/ and published in the Federal Register, on January 18, 2017, as the https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule. The final rule updates the Section 508 Standards along with accessibility guidelines for telecommunication products and equipment covered by section 255 of the Communications Act.
The Section 508 Standards applicable to this contract are:
https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines
• Web Content Accessibility Guidelines (WCAG) 2.0 o Success Criteria, Level A and AA
• Chapter 3: Functional Performance Criteria (FPC)
• Chapter 4: Hardware (If Applicable)
• Chapter 5: Software
• Chapter 6: Support Documentation and Services
Regardless of format, all digital content or communications materials produced as a deliverable under this contract must conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. The contractor is responsible for remediating all deliverables that do not comply with the applicable requirements as set forth below.
HHS guidance regarding accessibility of documents can be found at https://www.hhs.gov/web/section-508/making-files-accessible/index.html.
Item Description Quantity Due Date Format Submit to:
Federal Records Management Schedule and Disposition Plan.
(Section IV, Task 1). One (1) per 12 month period
Federal Records Management Schedule and Disposition Plan due after BPA Call Order Award and prior to commencing work.
.pdf Delivered to COR via email
Federal Records Management Training.
(Section IV, Task 2). One (1) per 12 month period
Federal Records Management Training due after BPA Call Order Award and prior to commencing work.
.pdf Delivered to COR via email
Kickoff Meeting Agenda.
(Section IV, Task 3). 1 per
Kickoff Meeting
Three (3) days prior to the Kickoff Meeting.
Word document
Delivered to COR via email
Kickoff Meeting Minutes.
(Section IV, Task 3). 1 per
Kickoff Meeting
Within three (3) days after the Kickoff Meeting.
Word document
Delivered to COR via email.
Project Timeline / Work Plan.
(Section IV, Task 4).
Within three (3) days after the Kickoff Meeting.
Word document
Delivered to COR via email
Updated on a monthly basis thereafter.
Transaction Monitoring.
Summary Report of the status of LGP Health Center transactions.
(Section IV, Task 5).
Semi-annual Report
Semi-Annually. Word document
Delivered to COR via email
Existing Guarantee On-site Review and Report (program monitoring).
Summary of Applicant's compliance to Loan Guarantee and Programmatic and Financial Monitoring.
(Section IV, Task 6).
1 per event
Within fifteen
(15) days after a on-site review.
Word document
Delivered to COR via email
Pre-application Consultation Report.
Summary of the TA and/or guidance provided to the Applicants.
(Section IV, Task 7).
1 per event
Within three (3) days after completion of consultation session.
Word document
Delivered to COR via email
Application Review, On-site Review Agenda.
Discussion topics for the On-site Review.
(Section IV, Task 8).
1 per event
Three (3) days prior to on-site review.
Word document
Delivered to COR via email
Application Review, Report and Recommendations.
Summary of the desk and On-site Reviews, risks associated with the proposed financing, specific conditions and reporting requirements.
(Section IV, Task 8).
1 per event
Within seven (7) days after completion of on-site review.
Word document
Delivered to COR via email
Develop Protocol.
(Section IV, Task 9).
Protocol development to occur within ten
(10) months of contract award.
Word document
Delivered to COR via email
Develop Lender’s Handbook (Section IV, Task 9)
Protocol development to occur within ten
(10) months of contract award.
Word document and matching 508 compliant PDF document
Delivered to COR via email
Loan Closing Report.
Summary of Loan Closing.
(Section IV, Task 10).
1 per event Within five (5) days after loan completion.
Word document
Loan Assistance Summary.
(Section IV, Task 11).
1 per event
Within five (5) days after completion of loan assistance.
Word document
Delivered to COR via email
Contract Status Reports.
Monthly contract progress reports of all activities being performed under the contract.
(Section IV, Task 12).
1 per event
Within seven (7) days of first of each month.
Word document
Travel for On-Site Loan Assistance.
(Section IV, Task 13).
1 per event
Within seven (7) day after travel.
Word document
Delivered to COR via email
Legal Consultative Services.
(Section IV, Task 14). 1 per event within five (5) days of satisfactorily completion.
Word document
Delivered to COR via email
18 Non-Disclosure Agreement.
(Section IV, Task 15).
One (1) per contractor employee performing work.
After Award and prior to commencing work.
PDF Email to the
COR.
HHS/HRSA Contractor Information Security Awareness, Privacy Training Certificate.
(Section IV, Task 15).
One (1) per contractor employee performing work.
Within 30 days after Award.
Annually thereafter.
PDF Email to the
COR.
20 Role Base Training Certificate.
(Section IV, Task 15).
One (1) per contractor employee performing work.
Within 30 days after Award.
Annually thereafter.
PDF Email to the
COR.
Rules of Behavior Training Certificate.
(Section IV, Task 15).
One (1) per contractor employee performing work.
Within 30 days after Award.
Annually thereafter.
PDF Email to the
COR.
22 Incident Response.
(Section IV, Task 15).
One (1) per issue reported
Within 1 hour.
23 Roster.
(Section IV, Task 15).
One (1) after
Award and updated as needed.
Within 14 days of Award and updated as needed.
Word or PDF Email to the
COR.
Contractor Employee Stops Working for Contractor Notification.
(Section IV, Task 15).
One (1) per departure.
Within 10 days of departure. Word or PDF Email to the
COR.
VI. Payment Schedule
This is a Firm Fixed Price BPA. Payment schedules will be provided with BPA Call Orders. See the Price Catalog (SOW Attachment A) for details on BPA Pricing.
BPA Call Orders will be placed using BPA Call Orders and the BPA Call Order Form (SOW Attachment B).
File details come from the government source that posted it. Updated .