ATTACH N - Awardable Task Order Domain 3 IT Discovery.pdf
PDF 374 KB Posted
- Attached to
- OPTN Operations Transition IDIQ Federal contract opportunity
- Solicitation number
- 75R60224R00008_FINAL
About this file
This document is a Performance Work Statement (PWS) for an awardable task order under the OPTN Operations Transition IDIQ contract for Domain 3 IT Discovery. The PWS outlines the requirements for a comprehensive review and mapping of the Organ Procurement and Transplantation Network (OPTN) Information Technology (IT) System, its components, and relevant policies. The goal is to enhance system efficiency, data integrity, interoperability, and compliance with healthcare standards. Key tasks include conducting a detailed analysis of data sources, system functionalities, outputs, and deliverables, culminating in a robust OPTN Technology Ecosystem Report. The period of performance is 9 months, with the work performed primarily off-site at the contractor's location. Deliverables include draft and final discovery plans, monthly progress reports, various technical reports, and a final OPTN Technology Ecosystem Report.
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OPTN Operations Transition IDIQ RFP No. 75R60224R00008 Attachment N – Awardable Task Order for Domain 3 IT Discovery
Task Order Title: OPTN Information Technology (IT) Discovery Task Order
Date: April 29, 2024
I. BACKGROUND
The Health Resources and Services Administration (HRSA), an agency of the U.S. Department of Health and Human Services (HHS) is the primary federal entity responsible for oversight of the Organ Procurement and Transplantation Network (OPTN) (OPTN website), authorized by the National Organ Transplant Act of 1984, as amended (NOTA), 42 U.S.C. § 273 et seq., and implemented by the Organ Procurement and Transplantation Network regulations, 42 CFR part 121 (Final Rule). The Final Rule establishes a regulatory framework for the structure and operations of the OPTN. Research, evaluation, and supplementation of OPTN data is used to improve the OPTN’s functions and gain insight into how factors, including socioeconomic, demographics, and geographic location, impact patients’ access to organ transplantation.
Among its statutory responsibilities, the OPTN must operate and monitor an equitable system for allocating organs, maintain a waiting list of potential recipients, match potential recipients with donor organs, work to increase the supply of donated organs, and coordinates, as appropriate, the transportation of organs from organ procurement organizations and transplant centers. The OPTN establishes and maintains membership criteria for institutions, individuals, and interested parties, while establishing and maintaining training and experience criteria for designated transplant personnel at transplant programs.
Through committees and the OPTN Board of Directors (BOD), the OPTN also establishes, maintains, and monitors compliance with OPTN policies, including those for the equitable allocation of donor organs among transplant patients.
II. PURPOSE AND PROBLEM STATEMENT
This Performance Work Statement outlines the requirements for a comprehensive review and mapping of the Organ Procurement and Transplantation Network (OPTN) Information Technology (IT) System, its components, and relevant policies. The goal is to enhance system efficiency, data integrity, interoperability, and compliance with healthcare standards. The contractor shall conduct a detailed analysis of data sources, system functionalities, outputs, and deliverables, culminating in a robust OPTN Technology Ecosystem Report.
III. PERIOD OF PERFORMANCE/PLACE OF PERFORMANCE
The period of performance will be nine (9) months. The period of performance under this Task Order will commence with the effective date of the contract (EDOC). The work will be performed off-site, primarily at the location of the Contractor’s site.
IV. TASKS
1. OPTN IT Systems Discovery The scope of this task is to conduct a review and mapping of OPTN IT systems as it currently exist, along with all relevant structures, policies, workflows, operations, and assets. The review and mapping will capture how the OPTN IT system works and provides all functions as required by NOTA, the Final Rule, contractual obligations, and all relevant statutes and regulations. The review and mapping will capture how OPTN IT system are kept in compliance with NOTA, the Final Rule, contractual obligations, and any specific direction that may be provided by the HHS Secretary,.
https://optn.transplant.hrsa.gov/ https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title42-section274&num=0&edition=prelim https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title42-section274&num=0&edition=prelim https://www.ecfr.gov/current/title-42/chapter-I/subchapter-K/part-121 https://www.ecfr.gov/current/title-42/chapter-I/subchapter-K/part-121
Desired outcomes of this task include a comprehensive understanding of all workflows, policies, and architecture for OPTN IT systems.
The contractor shall collaborate with HRSA and identified OPTN contractor(s) to develop a discovery framework to document and map existing and new systems and processes.
1.1 Discovery Planning
The Contractor shall:
1. Submit a draft OPTN IT Systems Discovery Plan to the COR for review within fifteen (15) days after the EDOC.
2. Submit a final OPTN IT Systems Discovery Plan to the COR for approval, addressing HRSA feedback, within 5 business days after COR feedback on the revised OPTN IT Systems Discovery Plan.
3. Update the OPTN IT Systems Discovery Plan and submit to the COR for approval as required.
4. The OPTN IT Systems Discovery Plan shall include, at minimum:
a. how the contractor will complete discovery of all inputs, functions, and outputs in accordance with this PWS;
b. strategies for mitigation of conflicts of interests with parties involved in the review and mapping;
c. anticipated activities, broken down by task;
d. processes for obtaining feedback from diverse and various groups and populations served by the OPTN;
e. processes for involving the COR and identified HRSA, HHS, or federal personnel during all phases of the review and mapping;
f. proposed level of effort and required expertise; and
g. timeline and milestones to complete the efforts.
1.1.1 Discovery Plan Implementation
The Contractor shall
1. Implement the OPTN IT systems Discovery Plan.
2. Submit written monthly progress reports to the COR detailing activities and achievements from the prior month, planned activities for the upcoming month, and overall status of the project in the context of the OPTN IT Systems Discovery Plan
1.2 Inputs
1.2.1 Data Sources Mapping and Analysis:
The Contractor shall:
1. Submit Data Sources Mapping Report to the COR for approval within 30 days of implementation of the OPTN IT Systems Discovery Plan that includes a comprehensive mapping of all data sources integrating with the OPTN, including but not limited to transplant, hospitals, labs, and organ procurement organizations.
2. Document the data formats, nature, and frequency of data exchanges in the Data Sources Mapping Report ensuring a detailed understanding of data source integration points.
1.2.2 Members and Partners Engagement Analysis:
OPTN Operations Transition IDIQ
Attachment N – Awardable Task Order for Domain 3 IT Discovery
The Contractor shall:
1. Analyze and document the interactions between OPTN members, partners, and the system, with a focus on data exchange, API interoperability and standards compliance.
2. Provide for COR approval an in-depth Engagement Analysis of the information flow, identifying any gaps or inefficiencies in current processes within 30 days of Data Sources Mapping Report submission.
1.2.3 Intake Forms and Data Points Review
The Contractor shall:
1. Compile a list of all OMB-approved intake forms and data points, documenting their relevance to the OPTN's operations.
2. Submit to the COR for approval the Standard Inputs Report which details all findings within this task area within 90 days of the EDOC,.
1.3 Functions
1.3.1 System Functionalities and Interactions Mapping
The Contractor shall:
1. Map the OPTN computer systems' core functionalities, focusing on API interactions and data processing workflows, and identify areas for improvement.
2. In accordance with the approved OPTN IT Systems Discovery Plan, but no later than 120 days of the EDOC, submit a draft System Functionalities Report to the COR for review and input.
3. Submit a final System Functionalities Report to the COR for approval, addressing HRSA feedback, within 5 business days after COR feedback.
1.3.2 Data Processing and Compliance Analysis
The Contractor shall:
1. Conduct a thorough analysis of data processing workflows, compliance with healthcare standards, and data privacy and security mechanisms.
2. Identify and provide recommendations for enhancing data processing efficiency and compliance.
3. Map the flow of data throughout the OPTN IT system(s), including all systems/components therein. This mapping should also extend to cover the broader OPTN ecosystem, particularly focused on how partners interact with the system via APIs.
4. Document the data flow, highlighting the pathways, nodes, and processes involved in the data’s lifecycle across the system and its interactions with external entities.
5. Evaluate the mechanisms in place for maintaining data integrity within the OPTN IT systems and across the broader OPTN network.
6. Identify potential vulnerabilities or areas for improvement in the system's current data integrity safeguards.
7. Propose recommendations for enhancing data integrity measures, ensuring reliability and trustworthiness of the data across all touchpoints.
8. Submit the Processing and Compliance Report to the COR for approval in accordance with the approved OPTN IT Systems Discovery Plan, but no later than 180 days of the EDOC
9. Submit a revised Processing and Compliance Report to the COR for approval, addressing HRSA feedback, within 5 business days after COR feedback.
1.4 Outputs
OPTN Operations Transition IDIQ
1.4.1 Data Output and API Documentation
The Contractor shall:
1. Catalog and document all system outputs and API specifications, including data formats, authentication methods, and usage guidelines. This should include, but not limited to:
• A thorough review of all API interactions between the OPTN IT systems and external systems/components. This includes mapping out all existing APIs, their interactions, and how these support the systems’ functionalities.
• Create comprehensive documentation for each identified API and API interaction, including any data flow, detailed designs that outline how these APIs facilitate interoperability within the OPTN ecosystem.
2. Assess the standards currently in use for these interactions and identify any gaps in alignment with industry-standard rules and specifications for interoperability, such as HL7® FHIR® (Fast Healthcare Interoperability Resources).
3. Conduct an evaluation of the systems’ adaptability to future standards and technologies to include, but not limited to, analyzing the system architecture for flexibility and scalability, ensuring long-term sustainability.
4. Submit the Data and API Outputs Report to the COR for approval in accordance with the approved OPTN IT Systems Discovery Plan, but no later than 210 days of the EDOC.
5. Submit a revised Data and API Outputs Report to the COR for approval, addressing HRSA feedback, within 5 business days after COR feedback.
1.4.2 Reporting and Analytics Capabilities Review
The Contractor shall:
1. Analyze the reporting and analytics functionalities, ensuring they meet the needs of OPTN stakeholders.
2. Submit the Reporting and Analytics Report to the COR for approval in accordance with the approved OPTN IT Systems Discovery Plan, but no later than 180 days of the EDOC.
3. Submit a revised Reporting and Analytics Report to the COR for approval, addressing HRSA feedback, within 5 business days after COR feedback.
1.5 Final OPTN Technology Ecosystem Report
The Contractor shall:
1. Submit the OPTN Technology Ecosystem Report to the COR for review no later than 225 days of the EDOC. The report must include, at a minimum:
• An executive summary, mappings, background information and data about the review and mapping, charts, graphics, analyses, and appendices.
• Synthesis of findings from tasks 1.1-1.4.
• Actionable recommendations for system enhancements based on the comprehensive analysis conducted.
• Strategies for keeping the OPTN technology ecosystem adaptable to future changes in technology, regulations, and healthcare practices.
2. Submit a revised OPTN Technology Ecosystem Report to the COR for review, addressing
HRSA feedback, within ten (10) days after COR feedback.
3. Submit a final OPTN Technology Ecosystem Report to the COR for approval, addressing any additional feedback, within ten (10) days after COR feedback on the revised OPTN IT Systems Discovery Plan.
OPTN Operations Transition IDIQ
2. Contract Management
2.1 Branding
The Contractor shall:
1. All contractors shall brand all OPTN products produced under contracts associated with this
IDIQ as OPTN products. OPTN contractor products shall be approved by a process established by the Board and/or HRSA. OPTN products can only contain OPTN branding. Contractors shall not brand any OPTN product as a product of the entity supporting the OPTN or as joint OPTN products. Additionally, no contractor shall brand any product not produced or approved to support the OPTN as an OPTN product.
2.2 Kickoff Meeting
The kickoff meeting shall occur virtually. The Contractor shall furnish a platform approved by the COR to host the meeting. The COR shall give the Contractor advance notice that the meeting shall take place in person prior to the Contractor scheduling the meeting.
The Contractor shall:
1. Set up a kickoff meeting between all key contractor staff, the COR, and other designated government officials. The Contractor must contact the COR to setup the kickoff meeting no later than two (2) business days after the EDOC. The kickoff meeting must occur no later than ten (10) business days after the EDOC.
2. Submit a Kickoff Meeting Agenda electronically to the COR for approval at least two (2) business days before the kickoff meeting. The Kickoff Meeting Agenda must address each of the kickoff meeting objectives.
3. The objectives of each kickoff meeting must include the following, at minimum:
a) introducing key project participants and identifying their roles to initiate the communication process between the COR, other designated government officials, other HRSA contractor(s), and the Contractor;
b) establish contract expectations;
c) Discuss proposed approach to meet the requirements under this contract;
d) review the submitted Project Management Plan (PMP); and
e) review invoicing requirements.
4. Submit detailed meeting minutes electronically to the COR within two (2) business days following the kickoff meeting. The meeting minutes must include, at a minimum, a list of action items, the personnel assigned to action items, and due dates.
5. Ensure that all Contractor key personnel are present and active participants in each kickoff meeting. Active participant means, at minimum, that personnel are present and prepared to respond to questions or concerns directed at them from the COR, or other designated government officials.
2.3 Project Management Plan
The Contractor shall:
1. Submit a Project Management Plan electronically to the COR for approval within five (5) business days after the kickoff meeting. The Project Management Plan must address the
OPTN Operations Transition IDIQ recommendations provided by the COR and other COR designated government officials during the project kickoff meeting.
2. Submit a corrected Project Management Plan addressing all COR feedback electronically to the COR for approval within two (2) business days after receipt of COR feedback.
3. Implement the COR approved Project Management Plan.
2.4 Bi-Weekly Conference Calls
The Contractor shall:
1. Conduct bi-weekly (every other week) conference calls with the COR and other COR designated government officials to discuss the status of the activities under the contract.
2. Submit an agenda electronically to the COR before no later than one (1) business day before each call. The agenda must follow a format approved by the COR. At a minimum, the conference call agenda must include documentation that demonstrates project status, level of effort (LOE), timelines, risks, and mitigations to identified risks.
1. Submit a comprehensive summary of each conference call electronically to the COR within two (2) business days following the call. The conference call summary must include at a minimum a summary of issues discussed, action items, the personnel assigned to action items, and due dates.
2.5 Ad-Hoc Meetings and Alerts
The Contractor shall:
1. Alert the COR regarding any issues related to the performance of this contract and coordinate a conference call to discuss the issues.
2. Meet with the COR, and other COR designated government officials, upon request by the
COR to discuss any issues related to this contract.
3. Submit an agenda that outlines the issue(s) to be discussed electronically to the COR before each call. The Contractor must submit the agenda as soon as is practicable, depending on the ad hoc or alert situation.
4. Submit a comprehensive summary of the call electronically to the COR within an agreed upon timeline determined during the meeting. The meeting summary must include, at a minimum, a summary of issues discussed, action items, the personnel assigned to action items, and due dates.
2.6 Progress Reports and Contract Meetings
2.6.1 Progress Reports
The Contractor shall:
1. Propose the format of the Progress Reports to the COR for approval within thirty (30) calendar days after the EDOC. If COR requires changes, submit a corrected format of the Progress Reports electronically to the COR within five (5) business days after receipt of COR feedback.
2. Submit a Progress Report electronically to the COR for approval covering the prior three months after months 3 and 6 within five (5) business days after the end of months 3 and 6.
If COR requires changes, submit a corrected Progress Report electronically to the COR within five (5) business days after receipt of COR feedback.
3. Progress Reports shall include, at minimum, a status of progress toward completion of activities to date as outlined in the Project Management Plan, accomplishments, challenges, identified risks and vulnerabilities, actions taken to mitigate the risks and
OPTN Operations Transition IDIQ vulnerabilities during the previous performance period, and activities to be performed during the subsequent reporting period.
2.6.2 Progress Meetings
Meetings shall occur virtually, at the direction of the COR. For virtual meetings, the Contractor must furnish a platform approved by the COR for hosting the meetings. The meetings will occur virtually unless the COR indicates otherwise. The COR will give the Contractor advance notice that a meeting will take place in person at least ten (10) calendar days prior to the meeting.
The Contractor shall:
1. Conduct a Progress Meeting within 15 days of the start of months 4 and 7, for a total of three (2) Progress Meetings. The Progress Meetings will include the COR and COR designated government officials and will discuss the status of progress toward completion of activities under the contract.
2. Submit a Progress Meeting Agenda electronically to the COR for approval at least two (2) business days in advance of each meeting. The agenda must follow a format approved by the COR. The meeting agenda must include discussion and documentation that covers project status, level of effort (LOE), timelines, risks, and mitigations to identified risks.
Agendas must also include all departmental and functional area task updates. If COR requires changes, submit a corrected Progress Meeting Agenda electronically to the COR within five (5) business days after receipt of COR feedback.
3. Submit a detailed summary of each Progress Meeting electronically to the COR within two
(2) business days following each meeting. The meeting summary must include, at a minimum, a summary of the discussion, action items, the personnel assigned to action items, and due dates.
3. Capital Planning and Investment Control (CPIC)
Capital Planning and Investment Control (CPIC) is an integral part of the Agency's strategic planning initiative. In accordance with the CPIC process, Clinger-Cohen Act, and Federal Information Technology Acquisition Reform Act (FITARA), the Contractor shall follow the HHS/HRSA CPIC framework and provide complete, reliable, consistent, and timely life-cycle information, to include development and cost information for qualifying projects; and systematic measurement of performance. Within 90 days of task award, the Contractor must conduct an Integrated Baseline Review (IBR) in accordance with the DHHS and HRSA requirements, if applicable. Additionally, the Contractor shall prepare and submit a monthly project management report in the government-desired format, as specified by the HRSA CPIC guidance.
4. HHS Policy for Information Technology Procurements - Security and Privacy Language
I. Procurements Requiring Information Security and/or Physical Access Security
1. Baseline Security Requirements
a. Applicability. The requirements herein apply whether the entire contract or modification (hereafter "contract"), or portion thereof, includes either or both of the following:
i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
OPTN Operations Transition IDIQ
ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
b. Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with OMB, NIST, HHS, HRSA policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) must:
i. Protect the:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information.
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity;
and
• Availability, which means ensuring timely and reliable access to and use of information.
ii. Categorize all information owned and/or collected/managed on behalf of HHS/HRSA and information systems that store, process, and/or transmit HHS information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Based on information provided by the Information System Security Officer (ISSO), Chief Information Security Officer (CISO), HRSA Senior Official for Privacy (SOP), or other representative, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:
Confidentiality: [ ] Low [X] Moderate [ ] High
Integrity: [ ] Low [ ] Moderate [X] High Availability: [ ] Low [X] Moderate [ ] High
Overall Impact Level: [ ] Low [ ] Moderate [X] High
• It has been determined that this contract is subject to the Privacy Act of 1974, because this contract provides for the design, development, or operation of a system of records about individuals from which records are retrieved by name or other identifying particular.
• The System of Records Notice that is applicable to this contract is: 09-15-0055, Organ Procurement and Transplantation Network (OPTN)/Scientific Registry
OPTN Operations Transition IDIQ RFP No. 75R60224R00008 Attachment N – Awardable Task Order for Domain 3 IT Discovery http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf of Transplant Recipients (SRTR) Data System, HHS/HRSA/HSB/DoT.
(https://www.federalregister.gov/documents/2009/11/04/E9-26527/privacy-act-of-1974-report-of-an-altered-system-of-records).
• The system of records design, development, or operation work the Contractor is to perform is: Collection, use, and dissemination of OPTN data.
• The disposition to be made of the Privacy Act records upon completion of contract performance is: The records are currently unscheduled and must be retained indefinitely, pending completion of a disposition schedule approved by
NARA.
iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of HHS/HRSA regardless of location or purpose.
iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government COR, CO and to the HRSA Computer Security Incident Response Team (hrsacsirt@hrsa.gov) or 301- 443-3333.
v. Adopt and implement all applicable policies, procedures, controls, and standards required by the HHS and HRSA Information Security Program and HHS and HRSA Privacy Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain all applicable security and privacy policies by contacting the CO/COR or HHS/HRSA security and/or privacy officials.
c. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS must be used only for the purpose of carrying out the provisions of this contract and must not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and must ensure that all work performed by its employees and subcontractors must be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed must be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information must be protected in accordance with HHS and HRSA policies. Unauthorized disclosure of information will be subject to the HHS/HRSA sanction, policies and/or governed by the following laws and regulations:
i. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
ii. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
iii. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
OPTN Operations Transition IDIQ RFP No. 75R60224R00008 Attachment N – Awardable Task Order for Domain 3 IT Discovery https://www.federalregister.gov/documents/2009/11/04/E9-26527/privacy-act-of-1974-report-of-an-altered-system-of-records https://www.federalregister.gov/documents/2009/11/04/E9-26527/privacy-act-of-1974-report-of-an-altered-system-of-records mailto:hrsacsirt@hrsa.gov
d. Information and Communications Technology (ICT). ICT products and services from prohibited entities/sources must not be used/acquired in compliance with Public Law 115- 232, Section 889 Parts A and B, FAR 4.21, FAR 52.204.23, FAR 52.204.24, and FAR
52.204.25. The contractor (and/or any subcontractor) must notify the government if they identify prohibited ICT products and/or services are used during the contract performance.
e. Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS must enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, HTTPS is not required, but it is highly recommended. Consult the HHS Policy for Internet and Email Security for additional information.
l. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract must complete the HRSA non-disclosure agreement. Contractors (and/or subcontractors) must submit a copy of each signed and witnessed NDA to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
2. Training Requirements
a. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract and have access to HRSA’s network must complete the applicable HHS/HRSA Cybersecurity Awareness, Privacy, and Records Management Training (provided upon contract award) before performing any work under this contract. Thereafter, the employees must complete HHS/HRSA Cybersecurity Awareness, Privacy, and Records Management Training at least annually, during the life of this contract. All provided training must be compliant with HHS training policies.
All Contractor (and/or any subcontractor) employees assigned to work on this contract without HRSA accounts must complete information security awareness, privacy, and records management training consistent with appropriate NIST standards before performing any work under this contract. Thereafter, the employees must complete the aforementioned training at least annually, during the life of this contract.
b. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete Role-Based Training for IT Admin annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
c. Training Records. The Contractor (and/or any subcontractor) must maintain training records for all its employees working under this contract in accordance with HHS policy.
A copy of the training records must be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
i. The types of information required in an incident report must include at a minimum:
company and point of contact information, contact information, impact
OPTN Operations Transition IDIQ classifications/threat vector, and the type of information compromised. In addition, the Contractor must:
Cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
Not include any sensitive information in the subject or body of any reporting e-mail; and
Encrypt sensitive information in attachments to email, media, etc.
ii. Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, and HHS and HRSA privacy breach response policies when handling PII breaches.
iii. Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation.
3. Position Sensitivity Designations All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract: non-sensitive, moderate risk public trust Tier 2 investigation or for those who will need network level admin rights it is a non-sensitive, high risk public trust Tier 4 investigation.
4. Homeland Security Presidential Directive (HSPD)-12 The Contractor (and/or any subcontractor) and its employees who require physical access to HRSA facilities or logical access to HRSA IT networks or systems must comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; OMB M-05-24; OMB M-19-17; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD- 12 policy; and Executive Order 13467, Part 1 §1.2.
5. Roster The Contractor (and/or any subcontractor) must submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster must be submitted to the COR and/or CO within 14 days of the effective date of this contract. Any revisions to the roster as a result of staffing changes must be submitted within 14 days of the change. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor must provide a position description and the Government will determine the appropriate suitability level.
6. Contract Initiation and Expiration
OPTN Operations Transition IDIQ
a. Sanitization of Government Files and Information. As part of contract closeout and at expiration of the contract, the Contractor (and/or any subcontractor) must provide all required documentation, including HRSA Disposition Plan to the CO and/or COR to certify that, at the government's direction, all electronic and paper records are appropriately disposed of and all devices and media are sanitized in accordance with NIST SP 800- 88, Guidelines for Media Sanitization.
b. Notification. The Contractor (and/or any subcontractor) must notify the CO and/or COR and system ISSO within 14 days before an employee stops working under this contract.
c. Contractor Responsibilities upon Physical Completion of the Contract. The contractor (and/or any subcontractors) must return all government information and IT resources (i.e., government information in non-government-owned systems, media, and backup systems) acquired during the term of this contract to the CO and/or COR. Additionally, the Contractor must provide a certification that all government information has been properly sanitized and purged from Contractor-owned systems, including backup systems and media used during contract performance, in accordance with HHS and/or HRSA policies.
d. The Contractor (and/or any subcontractor) must perform and document the actions identified in the HRSA Clearance Form for Separating Employees and Contractors (Form-
419) when an employee terminates work under this contract within 14 days of the employee's exit from the contract. All documentation must be available to the CO and/or COR upon request.
7. Records Management and Retention
a. The Contractor (and/or any subcontractor) must maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules and HHS Policy for Records Management and HRSA policies and must not dispose of any records unless authorized by HHS/HRSA.
b. In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, he/she must document and report the incident in accordance with HHS/HRSA policies.
8. High Value Asset (HVA) This system has been identified as HVA, and the contractor must comply with the HHS Policy for the High Value Asset (HVA) Program and the DHS HVA Control Overlay in addition to the above requirements.
III. Procurements Involving Government Information Processed on GOCO or COCO Systems
1. Security Requirements for GOCO and COCO Resources
a. Assessment and Authorization (A&A). A valid authority to operate (ATO) certifies that the Contractor's information system meets the contract's requirements to protect the agency data. The Contractor must conduct the A&A requirements in accordance with HHS IS2P/HRSA Information Security Policy, NIST SP 800-37, Guide for Applying the Risk Management Framework to Information Systems: A Security Life Cycle Approach (latest revision), NIST SP 800-53B, Control Baselines for Information Systems and Organizations, and the NIST SP 800-53A (latest revision).
OPTN Operations Transition IDIQ RFP No. 75R60224R00008 https://www.cisa.gov/publication/high-value-asset-control-overlay
HRSA’s acceptance of the ATO does not alleviate the Contractor's responsibility to ensure the system security and privacy controls are implemented and operating effectively.
i. An A&A package must contain the following documentation. Following the initial ATO, the Contractor must review and maintain the ATO in accordance with HHS/HRSA policies. The Contractor (and/or any subcontractor) must provide an A&A package at least 30 days prior to the ORR to the CO and/or COR. Additional information on each of the listed document requirements can be found in [System Security Requirements and Guidance.pdf].
ii. Information Security Continuous Monitoring. Upon the government issuance of an Authority to Operate (ATO), the Contractor (and/or subcontractor)-owned/operated systems that input, store, process, output, and/or transmit government information, must meet or exceed the information security continuous monitoring (ISCM) requirements in accordance with FISMA and NIST SP 800- 137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, HHS ISCM Strategy, and HHS IS2P.
iii. Annual Security Control Assessment - Assess the system security and privacy controls (or ensure an assessment of the controls is conducted) at least annually to determine the implemented security and privacy controls are operating as intended and producing the desired results. In addition, review all relevant A&A documentation (SSP, POA&M, Contingency Plan, etc.) and provide updates by specified due date.
iv. Penetration Test – Applicable to HVA and Systems categorized as High. Involves penetration testing conducted by the agency or independent third-party.
v. Asset Management - Using any available Security Content Automation Protocol (SCAP)-compliant automated tools for active/passive scans, provide an inventory of all information technology (IT) assets for hardware and software, (computers, servers, routers, databases, operating systems, etc.) that are processing HHS-owned information/data. The Contractor must produce this inventory information with the ATO package and update it on a monthly basis thereafter. IT asset inventory information must include IP address, machine name, operating system level, security patch level, and SCAP-compliant format information. The contractor must maintain a capability to provide an inventory of 100% of its IT assets using SCAP-compliant automated tools in accordance with the HHS Policy for Information Technology Asset Management (ITAM) and any other applicable HHS policy.
vi. Configuration Management - Use available SCAP-compliant automated tools as per NIST IR 7511 and HHS Minimum Security Configurations Standards Guidance to scan all IT assets, including but not limited to: computers, servers, routers, databases, operating systems, application, etc., that store and process government information. Provide scan reports to HHS/HRSA at least monthly and upon request. The contractor must maintain a capability to provide security configuration compliance information for 100% of its IT assets using SCAP-compliant automated tools.
vii. Vulnerability Management - Contractors must actively manage system vulnerabilities using automated tools and technologies where practicable and in
OPTN Operations Transition IDIQ accordance with HHS Policy for Vulnerability Management. Automated tools must be compliant with NIST-specified SCAP standards for vulnerability identification and management. The contractor must maintain a capability to provide security vulnerability scanning information for 100% of IT assets using SCAP-compliant automated tools and report to the agency at least weekly and upon request.
viii. Patching and Vulnerability Remediation - All vulnerabilities and findings must be remediated, in accordance with timelines based on their residual risk as specified in the HHS POA&M Standard and HHS Policy for Vulnerability Management:
15 days from discovery date for Critical risk vulnerabilities o Critical vulnerabilities require remediation prior to release into Production.
30 days from discovery date for High-risk vulnerabilities o High vulnerabilities require remediation prior to release into Production.
90 days from discovery date for Moderate risk vulnerabilities
365 days from discovery date for Low-risk vulnerabilities
The HRSA VM team and the ISSO will determine the risk rating of vulnerabilities. The HRSA CISO may direct out of band patching due to potential active exploit, zero-day vulnerability, etc.
ix. Secure Coding - Follow the HHS Policy for Software Development Secure Coding Practices and secure coding best practice requirements, as directed by United States Computer Emergency Readiness Team (US-CERT) specified standards and the Open Web Application Security Project (OWASP), that will limit system software vulnerability exploits. Code and Application Scans provided prior to all new releases.
x. Boundary Protection - The contractor must ensure that government information, other than unrestricted information, being transmitted from federal government entities to external entities is routed through a Trusted Internet Connection (TIC).
b. Government Access for Security Assessment. In addition to the Inspection Clause in the contract, the Contractor (and/or any subcontractor) must afford the Government access to the Contractor's facilities, installations, operations, documentation, information systems, and personnel used in performance of this contract to the extent required to carry out a program of security assessment (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of HHS, including but are not limited to:
i. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government's direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the contract.
OPTN Operations Transition IDIQ
The Government includes but is not limited to the U.S. Department of Justice, U.S.
Government Accountability Office, and the HHS Office of the Inspector General (OIG). The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross site scripting vulnerabilities, SQL injection vulnerabilities, and any other known vulnerabilities.
ii. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity. It includes timely and complete production of requested data, metadata, information, and records relevant to any inspection, audit, investigation, or review, and making employees of the contractor available for interview by inspectors, auditors, and investigators upon request. Full cooperation also includes allowing the Government to make reproductions or copies of information and equipment, including, if necessary, collecting a machine or system image capture.
Segregate Government protected information and metadata on the handling of Government protected information from other information. Commingling of information is prohibited. Inspectors, auditors, and investigators will not be precluded from having access to the sought information if sought information is commingled with other information.
Cooperate with inspections, audits, investigations, and reviews.
c. End of Life Compliance. The Contractor (and/or any subcontractor) must use Commercial off the Shelf (COTS) software or other software that is supported by the manufacturer. In addition, the COTS/other software need to be within one major version of the current version; deviation from this requirement will only be allowed via the HHS waiver process (approved by HHS CISO if it impacts enterprise-wide systems and services, or by the HRSA CISO if it impacts only HRSA). The contractor must retire and/or upgrade all software/systems that have reached end-of-life in accordance with HHS End of Life Operating Systems, Software and Application Policy.
d. Desktops, Laptops, and Other Computing Devices Required for Use by the Contractor. The Contractor (and/or any subcontractor) must ensure that all IT equipment (e.g., laptops, desktops, servers, routers, mobile devices, peripheral devices, etc.) used to process information on behalf of HHS are deployed and operated in accordance with approved NIST, HRSA, HHS and OMB security configurations and meet the following minimum requirements:
e. Rights to Data. All contracts that require data to be produced, furnished, acquired, or used in meeting contract performance requirements, must contain terms that delineate the respective rights and obligations of the Government and the contractor regarding the use, reproduction, and disclosure of that data. Data rights clauses do not specify the type, quantity or quality of data that is to be delivered, but only the respective rights of the
OPTN Operations Transition IDIQ
Government and the contractor regarding the use, disclosure, or reproduction of the data.
Accordingly, the contract must specify the data to be delivered.
i. Require external providers handling federal information or operating systems on behalf of the federal government to meet the same security and privacy requirements as federal agencies.
ii. Require external providers to express security and privacy requirements (including the controls for systems processing, storing, or transmitting federal information) in contracts or other formal agreements.
iii. Establish Service Level Agreements (SLAs), patching vehicles and disclosure requirements in the case of a security incident or new vulnerability being discovered; and
iv. Ensure that the supplier applies same contractual requirements to any sub-contractors/suppliers that they involve in the provision of the product or service to the customer; and
v. Prohibit the use of covered telecommunications and video surveillance equipment or services.
IV. Contracts Involving Cloud Services
1. HHS FedRAMP Privacy and Security Requirements
The Contractor (and/or any subcontractor) must be responsible for the following privacy and security requirements:
a. FedRAMP Compliant ATO. Comply with FedRAMP Assessment and Authorization (A&A) requirements and ensure the information system/service under this contract has a valid FedRAMP compliant (approved) authority to operate (ATO) in accordance with Federal Information Processing Standard (FIPS) Publication 199 defined security categorization. If a FedRAMP compliant ATO has not been granted, the Contractor must submit a plan.
b. Data Jurisdiction. The contractor must store all information within the security authorization boundary, data at rest or data backup, within CONUS and Non-foreign area - The states of Alaska and Hawaii, the Commonwealths of Puerto Rico and the Northern Mariana Islands, Guam, the U.S. Virgin Islands, and the territories and possessions of the United States (excludes the former Trust Territories of the Pacific Islands, which are considered foreign areas for the purposes of the FTR).
c. Interconnection Agreements/Memorandum of Agreements. The Contractor must establish and maintain Interconnection Agreements and or Memorandum of Agreements/Understanding in accordance with HHS/HRSA policies.
2. Protection of Information in a Cloud Environment
a. If contractor (and/or any subcontractor) personnel must remove any information from the primary work area, they must protect it to the same extent they would the proprietary data and/or company trade secrets and in accordance with
OPTN Operations Transition IDIQ
HHS/HRSA policies https://www.hhs.gov/web/governance/digital-strategy/it-policy-archive/index.html.
b. HHS will retain unrestricted rights to federal data handled under this contract.
Specifically, HHS retains ownership of any user created/loaded data and applications collected, maintained, used, or operated on behalf of HHS and hosted on contractor's infrastructure, as…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .