9-Appendix H Information Technology Requirements.pdf
PDF 300 KB Posted
- Attached to
- All Payers Claims Database State and local contract opportunity
- Solicitation number
- 26-665-3030-78227
- Issued by
- New Mexico
About this file
This document is Appendix H: Information Technology Requirements for a contract involving the New Mexico Department of Health (NMDOH) and the Regulated Licensing Division (RLD). The appendix outlines comprehensive technical system requirements for a proposed solution, with 53 mandatory and desirable specifications that potential contractors must meet. The requirements cover a wide range of IT infrastructure and security needs, including user interface accessibility, system availability (99.9% uptime), browser compatibility, network configurations, environment management, authentication methods, and integration capabilities.
Key technical specifications include supporting Active Directory Federated Services, configurable role-based access control, HIPAA compliance, data encryption, security logging, periodic database refreshes, and the ability to interface with the Department of Health's Enterprise Master Patient Index (EMPI). The solution must operate across multiple network configurations, support various user access scenarios, and maintain separate production, training, test/UAT, and development environments. Desirable specifications include developing automated test suites and potentially setting up daily data replication processes. Contractors must demonstrate compliance with each requirement through a "Vendor Response" and "Vendor Narrative" column, with most requirements scored on a pass/fail basis.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| 1-26-665-3030-78227 All Payers Claims Database.pdf | ||
| 10-Appendix I System Hosting Evaluation Questionnaire.pdf | ||
| 3-Appendix B Campaign Contribution Disclosure Form.pdf | ||
| 4-Appendix C Draft Agreement.pdf | ||
| 6-Appendix E Organizational Reference Questionnaire.pdf | ||
| 8-Appendix G Cost Response Form.pdf | ||
| 2-Appendix A Acknowledgement of Receipt Form.pdf | ||
| 5-Appendix D Letter of Tansmittal Form.pdf | ||
| 7-Appendix F Detailed Scope of Work.pdf | ||
| 11-Appendix J Client List Form.pdf | ||
| 12-Pre-Proposal Conference Link.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
APPENDIX H
INFORMATION TECHNOLOGY REQUIREMENTS
Offerors shall:
1. Review the information technology requirements in Table H-1of Appendix H below and provide a statement of concurrence in that their proposed solution will meet all mandatory requirements using “Vendor Response” column outlined in Table H-1 of Appendix H by Indicating a “Yes” as concurrence in Table H-1 of Appendix H if the proposed solution meets all the functionality described in the row in the Vendor Response column. Otherwise, enter “NO”.
2. Provide information in their narrative response in the Vendor Narrative Column as to how their solution meets the requirements in the table, for all mandatory requirements and the highly desirable requirements the offeror’s solution meets.
Table H-1: Information Technology Requirements The following table contains technical system requirements for the solution and its delivery.
# Requirement Scoring Vendor Response
Vendor Narrative
Mandatory Requirements
IT
-1
All user interfaces shall be accessible via an Internet browser and not require any software to be installed on a client workstation or device except for browser software and drivers required to and similar input/ output (I/O) devices.
Pass/Fail
IT
-2
The solution shall allow direct access to the database(s) by State employees who possess the proper access rights. These employees shall be able to choose from a variety of analytical / query tools (e.g. SAS, SQL Server Management Studio, etc.)
Pass/Fail
IT
-3
The solution shall be available twenty-four (24) hours a day, seven (7) days a week, 365 days a year, except during scheduled maintenance. The Contractor shall guarantee 99.9% uptime 7 days a week, 24 hours a day, 365 days a year, exclusive of the regularly scheduled maintenance window.
Pass/Fail
IT
-4
The solution shall run on the two most recently released versions of Internet Explorer (IE), Edge (both pre and post version 78), Firefox, Chrome and Safari, including the versions that are available for Apple’s IOS and Android devices.
Pass/Fail
IT
-5
The solution shall be able to operate under all of the following network configurations:
Wireless connectivity Mobile hotspots Wired connectivity
Pass/Fail
IT
-6
The Contractor shall provide and maintain separate production, training, test/UAT and development environments.
Pass/Fail
IT
-7
The solution shall support Active Directory Federated Services (ADFS) Single Sign-On user access control.
Pass/Fail
IT
-8
The solution shall support configurable role-based access to control user access to the data entry system, reports and data.
The Contractor shall work with the State to define mutually agreed-upon user roles and associated access rights.
Pass/Fail
IT
-9
The solution shall enforce unique usernames and ID’s. Pass/Fail
IT
The solution shall provide State employee access to be controlled from NMDOH’s and/or RLD’s Active Directory via Active Directory Federation Services. All username and password rules will be administered in Active Directory.
Pass/Fail
IT
The solution shall comply with user account and password requirements (including length, types of required characters, expiration, etc.) for all users who do not have a NMDOH or RLD Active Directory account, according to NMDOH and RLD policies, procedures and rules as set forth by the NMDOH and RLD CSOs. The solution shall provide the capability to encrypt passwords in transmission and at rest within the system.
Pass/Fail
IT
The solution shall include a self-service password reset tool that allows a user to reset a personal password (forgotten or inactive) to unlock that user’s account. The solution shall provide the capability to email password reset links to a user.
Pass/Fail
IT
The solution shall include the ability to enforce session timeouts during periods of inactivity. The solution shall provide the capability for the State to configure the maximum session inactivity time to meet NMDOH and RLD security policies.
Pass/Fail
IT
The solution shall not store authentication credentials or sensitive data in its code or unencrypted in databases or files.
Pass/Fail
IT
The solution shall meet all HIPAA audit logging standards. Pass/Fail
IT
The solution shall provide the capability to encrypt all application data and to protect it from unauthorized use when in transit and at rest.
Pass/Fail
IT
The Contractor shall ensure that any application enhancements or upgrades do not remove or degrade security.
Pass/Fail
IT
The Contractor shall develop a security plan encompassing addressing workforce, incident reporting, and technical security of information assets throughout lifecycle (creation to destruction).
Pass/Fail
IT
The Contractor shall ensure that all software and hardware are free of malicious code.
Pass/Fail
IT
The Contractor shall ensure the application is secure against all flaws outlined in the Open Web Application Security Project (OWASP) Top Ten (http://www.owasp.org/index.php/OWASP_Top_Ten_Proje ct). The Contractor shall provide an independent, third-party validation that the application has been hardened and secured as defined by NMDOH and RLD CSOs.
Pass/Fail http://www.owasp.org/index.php/OWASP_Top_Ten_Project http://www.owasp.org/index.php/OWASP_Top_Ten_Project
The Contractor shall host the solution in a secure hosting environment on one of the following:
Microsoft’s Azure Government, Google Cloud Platform for Government, Amazon’s AWS GovCloud (US), or
A facility that adheres to Uptime Institute’s Tier III Concurrent Maintenance criteria as provided in Tier Standard Topology*. The facility must be HIPAA compliant and sign a HIPAA Business Associates Agreement (BAA).
The facility shall maintain the following certifications: o Uptime Institute’s Tier III (or Tier IV) Gold Certification of Operational
Sustainability Uptime Institute’s Tier III (or Tier IV) Certification of
Constructed Facility.
FedRAMP Moderate Provisional Authority to Operate (P-
ATO)
o DISA Level 2 Provisional Authorization (PA)
*available at: http://uptimeinstitute.com/tierpublication
Pass/Fail
IT
The solution shall have the capability to meet peak performance use requirements of not less than the following number of simultaneous users: Staff – Processing applications, compliance, etc.: 150 Entities – managing inventory, product movements: 5,000 Point of Sale Terminals: 6,000 Individuals – submit and query applications online: 3,000 Laboratories – submit test results: 100
Pass/Fail
IT
The Contractor shall operate hosting services on a network or cloud environment offering adequate performance to meet the current and any future business requirements for the State application.
Pass/Fail
IT
If redundant Internet connections are not available to the Contractor, then the Internet Provider who provides the internet service to the Contractor shall have their service supplied by a vendor that has multiple feeds to ensure that a failure in one of the larger carriers will not cause a failure of the State’s service.
Pass/Fail
IT
The Contractor’s network architecture shall include redundancy of routers and switches in the Data Center.
Pass/Fail
IT
The Contractor shall maintain the solution hardware and software in accordance with the specifications, terms, and requirements of the contract and sufficient to run the application.
Pass/Fail
IT
The Contractor shall repair or replace solution hardware or software, or any portion thereof, so that the system operates in accordance with the specifications, terms, and requirements of the contract.
http://uptimeinstitute.com/tierpublication
The Contractor must monitor the application, database, connectivity, interfaces, and all servers with established performance checks agreed to by the State and shall automatically notify both Contractor and State application support personnel twenty-four (24) hours a day, seven (7) days a week, 365 days a year, when abnormalities are detected.
Pass/Fail
IT
The Contractor shall install and update all server patches, updates, and other utilities within sixty (60) days of their release from the manufacturer unless security risks would create a potential breach, in which case the updates shall be installed at the earliest opportunity.
Pass/Fail
IT
The Contractor shall monitor system, security, and application logs based upon mutually agreed protocols delineated in the final contract.
Pass/Fail
IT
The Contractor shall manage sharing of data resources based upon mutually agreed protocols delineated in the final contract.
Pass/Fail
IT
The Contractor shall manage daily backups, data storage, and restore operations. The Contractor shall ensure that backups are encrypted in a manner meeting minimum Federal Information Processing Standards (FIPS) 140-2 standards and that they are stored in a facility geographically separate from the Contractor’s primary data center.
Pass/Fail
IT
The Contractor shall transfer a backup copy of the solution database(s) to NMDOH monthly via Secure File Transfer Protocol (SFTP).
Pass/Fail
IT
The Contractor shall notify the NMDOH and RLD CSOs of all breach of security issues via telephone and in writing within 30 minutes of becoming aware of the issue.
Pass/Fail
IT
In instances where the State requires access to the application, database or server resources, the Contractor shall provide remote desktop connection to the server through secure protocols such as a Virtual Private Network (VPN) and/or appropriate database management, query and/or browser tools.
Pass/Fail
IT
The State shall have unlimited access to submit support requests to Contractor technical support staff – via phone or e-mail or help desk system – twenty-four (24) hours a day, seven (7) days a week, 365 days a year. The Contractor’s response for support must conform to problem resolution escalation procedures that prioritize problems based upon mutually agreed protocols that will be delineated in the final contract.
Pass/Fail
IT
All database tables will have a unique identity field. Pass/Fail
The solution’s technical architecture shall be documented and the documentation kept updated throughout the contract term.
Documentation shall include all aspects of the solution stack from hardware/network platform through database, application and User Interface layers including security aspects, as applicable.
Pass/Fail
IT
The Contractor and the Procuring Agency shall identify a regularly scheduled maintenance window (such as weekly, monthly, or quarterly) during which all relevant server patches and application upgrades shall be applied (other than emergencies).
Pass/Fail
IT
The Contractor shall adhere to the NMDOH and RLD change management process of application enhancements and upgrades. The Contractor shall submit relevant Change Management Requests (CMR) no less than two (2) weeks prior to production implementation, using standard forms provided by Procuring Agency.
Pass/Fail
IT
The Contractor shall notify the State representative a minimum of two (2) business days prior to implementation of any changes and/or updates to the solution. The Contractor shall provide the State with training on any new features or changes to existing features.
Pass/Fail
IT
The Contractor shall fully support all solution hardware and software components, including the hosting infrastructure, including licensing and maintenance contracts with respective suppliers and manufacturers at all times. The Contractor shall supply all licenses necessary for functioning of applications, including all software and hardware licenses for all environments.
Pass/Fail
IT
The Contractor shall maintain a record of its activities related to repair or maintenance performed for the State, and shall report quarterly on:
Server up-time All change requests implemented, including Operating
System patches All critical outages reported including actual issue and resolution Number of deficiencies reported by class with initial response time and time to resolve
Pass/Fail
IT
For any outage (when a business function cannot be met by a nonperforming application and there is no work around to the problem) greater than 15 minutes, the Contractor shall provide an incident report for the interruption of service to the State. An incident report shall document, at a minimum:
outage cause, solution implemented, amount of downtime, related communications, suggested support improvements, and suggested solution improvements when the solution has been brought back online. The Contractor shall provide the incident report within two (2) weeks of incident resolution.
The Contractor shall allow and support the State to schedule and perform a periodic security assessment and to perform solution testing activities by internal State and external 3rd party auditor.
Pass/Fail
IT
The Contractor shall submit a Business Continuity and Disaster Recovery Plan. This plan must be tested during the UAT phase and approved by the Procuring Agencies. The plan shall be kept up to date to reflect changes to the system servers, application, supporting software, and network infrastructure. This plan will be tested at least once a year to ensure viability and meet expectations for Return Time Objectives (RTO) and Return Point Objectives (RPO).
Pass/Fail
IT
The solution shall have the ability to interface with the DOH Enterprise Master Patient Index (EMPI) based on the latest New Mexico Department of Health Enterprise Master Person Index (EMPI) Bidirectional HL7 Interface Guide. And the equivalent systems for RLD. At a minimum, the solution must send Patient information to the EMPI. The preference is that the solution fully integrate with the EMPI in a bi-directional manner. See page 5 of the guide for a use case flow example.
Pass/Fail
IT
The Contractor shall develop and submit a plan for State approval to address upgrades or replacement of hardware, software or network infrastructure at least two years prior to one or more of these components reaching End of Life
(EOL).
Pass/Fail
IT
The Contractor shall refresh non-production databases at least every 6 months from the production database to include both application code and program data.
Pass/Fail
IT
Security and Privacy: The application shall adhere to HIPAA security and privacy specifications. The application should be protected from loss or corruption of data and corruption of software or introduction of malware, such as viruses. Access to the application and data should be role based and controlled by an industry recognized authentication method.
The application should meet the following requirements:
a. provide security consistent with the functions provided;
b. prevent unauthorized users from accessing the system;
c. make data available to the authorized users in an expedient and secure environment;
d. have the capability to record an unauthorized attempt in a log;
e. will not compromise the current efforts of the DOH systems to provide physical and remote access control to DOH systems;
f. implement controls to ensure the privacy of information, individuals, and corporations are not compromised;
g. use audit controls, electronic signatures, data encryption and other methods to assure the authenticity of transaction and other relevant data; and implement controls to ensure the authenticity of data is preserved.
IT
The Contractor shall complete and provide Appendix I, System Hosting Evaluation Questionnaire (SHEQ) upon finalizing the awarded contract
Pass/Fail
Desirable Specifications
IT
It is highly desirable that the Contractor develop, use and maintain automated test suites for smoke testing and regression testing.
IT
The Contractor may work with the State to set up a daily data replication process.
File details come from the government source that posted it. Updated .