A1 - Statement of Work - Drive-Thru Testing Services.pdf
PDF 324 KB Posted
- Attached to
- Q301--RFQ Amendment - COVID-19/FLU Drive-Thru Testing Services (STX) Federal contract opportunity
- Solicitation number
- 36C25721Q0710
About this file
This request for quote solicits offers for COVID-19 and influenza PCR drive-through testing services for the South Texas Veterans Health Care System in San Antonio, Texas. The contractor must provide an estimated 32,374 tests with 24-48 hour turnaround time from sample collection at a local collection site and laboratory located in Bexar County. The base period of performance is 1 June 2021 through 31 May 2022. Technical evaluation factors are technical capability, price, and past performance. Price and past performance are approximately equal, with technical capability and past performance combined approximately equal to price. Offers are due by 13 May 2021 and should include responses to the technical requirements and a description of the Bexar County collection site location. The anticipated award is a firm-fixed price contract.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A1 - Statement of Work - COVID-19 - FLU - Drive-Thru Testing Services - Revised 5-10-2021.pdf | ||
| 36C25721Q0710 0001_1.docx | DOCX document | |
| Questions and Responses.pdf | ||
| S06 - 36C25721Q0710 0001 - SF30.pdf | ||
| A2 - DoL Wage Determination 15-5253 - Revision 12 - 12-21-2020.pdf | ||
| Technical Requirements - Drive-Thru Testing Services.pdf | ||
| S02 - 36C25721Q0710 - SF1449.pdf | ||
| 36C25721Q0710_1.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 Statement of Work 36C25721Q0710 Page 1 of 16
STATEMENT OF WORK
SARS-CoV-2 and PCR FLU Testing Services
South Texas Veterans Health Care System
Scope of Work:
The STVHCS system has a need for drive through collection and testing of Symptomatic and Non-Symptomatic Preop & Pre-Procedure patients and employees within the STVHCS Service area (Bexar County) for RT-PCR SARS-CoV-2 and RT-PCR FLU A&B testing assays with no more than 24-48-hour turn-around time (TAT). The contractor must provide all personnel, equipment, supplies, facilities, tools, materials, supervision, and other items and services necessary to services as defined in the requirements except for those items specified as government furnished property and services.
This is a non-personal services agreement. There is not employer-employee relationship between the VA and the contractor staff. The services to be performed by the contractor shall be performed in accordance with VA policies and procedures and the regulations of medical staff by the laws of the VA facility. Contractor is required to maintain medical liability insurance for the duration of the agreement. Contractor shall indemnify the Government for any liability producing act or omission by the contractor(s) occurring during this agreement.
The contractor’s laboratory must provide the following estimated number of testing and requirements:
• Estimated quantity 32,374 Inhouse COVID-19 & FLU A&B RT-PCR Testing
• 24-48 hours TAT from time of collection.
• Must be a local laboratory in Bexar County for patient access.
• Must provide drive through collection site for social distancing safety and specimen transportation.
• Must be able to perform Inhouse RT-PCR for SARS-CoV-2 and FLU A&B testing and be an approved testing site by the CDC.
• Must have EUA (Emergency Use Authorization) from FDA for RT-PCR SARS CoV-2 testing.
LOCATION:
Contractor’s facility in Bexar County, Texas
The contractor must provide the following services:
(a) Analyze and/ collect samples.
(b) Provide a monthly bill for tests completed each month following the month in which the service was delivered.
(c) Consultation service with VA Laboratory on test results by telephone as needed.
(d) Means of communication to permit immediate inquiry regarding the status of a pending test.
(e) A Laboratory User’s Manual or similar documentation. The manual shall include a list of all tests that the Contractor can provide along with the testing methodology used for each test, turn-around time for each test, days the test is run, and specimen requirements and any special handling required.
36C25721Q0710 Page 2 of 16
(f) The VA Laboratory reserves the right to request the results of any proficiency testing that the contractor subscribes. The Contractor Laboratory shall:
a. Perform testing services entirely upon their premises listed on their response.
b. Provide a list of tests currently available with a price list.
c. Perform analytical testing for STVHCS patients for the tests requested. The
Contractor shall bill only for the tests specified in the request sent by STVHCS laboratory service.
d. Provide a reference test manual and report of analytical test results, upon award, describing the full scope of its laboratory operations.
e. Provide STVHCS with laboratory supplies (collection tubes, transport packaging, etc.) not customarily utilized by STVHCS. These supplies are to be used by STVHCS only with specimens being sent for testing to the contractor.
f. Carry out its functions hereunder in full compliance with all local, state, and federal laws or regulations.
g. Provide test result by fax or electronically to STVHCS in an encrypted fashion compliant with VHA requirements. Contact information to be provided upon contract award.
h. Assign a specific local account representative. Provide telephone number(s) and contact person(s) to be used by STVHCS to make specimen problem inquiries and problem solving on weekdays.
i. If requested, provide publications that support their testing and interpretation decisions. *NOTE: Also, include names and telephone number(s) of Technical Directors and Pathologists available for consultation.
j. Maintain the minimum acceptable service, reporting systems, and quality control as specified herein. Immediate (within 24-48 hours) notification must be given to VA upon adverse action by a regulatory agency.
k. Advise STVHCS of any planned changes in methodology, codes, or new procedures at least 14 days prior to changes. If a two-week notification is not possible due to an emergency, contractor shall notify STVHCS as soon as possible.
l. Do not release patient s records that include test results to anyone other than the ordering healthcare provider, to include STVHCS where the biospecimen collection originated and STVHCS staff. All records shall be treated as confidential, to comply with all state and federal laws regarding the confidentiality of patient s records. This provision shall survive termination of the resulting contract award.
m. Certify and ensure that all employees, officers, or agents comply with standards set forth in the Health Insurance Portability and Accountability Act (HIPAA).
Test Sample Preparation:
All specimens will be properly identified and labeled for testing. The contractor shall provide an adequate supply of requisition forms, special instructions, and a current list of tests with specimen requirements. These requirements shall be defined in the laboratory user’s manual.
Reporting of Test Results:
A report is defined as a printed final copy of pathology interpretive consult. Consult reports shall be sent by contractor electronically or by fax to the ordering Laboratory. If results are telephoned prior to sending, the written report must include the name of the individual notified of the results, date, and time of telephone report. Each report shall at a minimum indicate the following information:
36C25721Q0710 Page 3 of 16
1. Patient s full name and identification code
2. Patient s date of birth
3. Patient s full social security number or unique hospital identification number
4. Provider s name
5. Test(s) ordered
6. Date/time of specimen collection (when available)
7. Date/time specimen received in Reference L
8. Date test completed
9. Type of specimen/source
10. Test result(s)
11. Flag abnormal results
12. Name of testing laboratory (contractor and/or subcontractor), address, CLIA number
13. Testing laboratory specimen number
14. Type of specimen
15. Comments related to the test provided by the submitting lab
16. Information that may indicate a questionable validity of test results
17. Unsatisfactory specimen shall be reported with reason as to its unsuitability for testing
Data Management System
a) Test ordering is easily accomplished through a menu that is intuitive, has minimal options and uses a mouse or touch screen. Upon selection of the test, the computer shall alert (flag) the user to the type of specimen required and the storage conditions. It shall also alert the user to the location of the laboratory that will be performing the test.
b) Test definitions, test information and test requirements are complete, available, and easily accessible.
c) The status and the results of testing are available within published timeframes and easily retrievable using varying options. Examples of these options are through a patient search, a sort by timeframe, a sort by test, a sort of incomplete tests, etc. Incomplete tests shall have an indication of the pending time until completion. Alert messages are generated when testing is delayed beyond published timeframes, when specimens require additional testing (reflex), or when specimens are cancelled due to unacceptability.
d) Reports of test results shall be immediately available upon verification of the test result.
The computer must be able to print test results upon request and reprint retrospective test results according to a defined timeframe.
e) Shipping manifest is generated that identifies the specimens sent to the commercial reference laboratory, transportation conditions, and testing ordered.
f) The ordering of specimen collection and transportation supplies is accomplished through direct on-line ordering.
g) Current STVHCS contracted price information is available through the computer or through other electronic modes.
36C25721Q0710 Page 4 of 16
Performance Improvement (PI) and Quality Assurance Activities
a) The Contractor shall have a detailed plan describing the performance improvement (PI) activities that are specific to the VISN 17 facilities. This plan shall minimally address the quality aspects representative to the testing process, i.e. pre-analytical, analytical, and post-analytical variables and include a description of monitoring and evaluation activities.
i) The Contractors PI plan shall include a description of their procedure for responding to issues, problems and/or concerns identified by the VISN 17 laboratories and specific information as to whom and in what time frame the matters will be reconciled. The issues that may need to be addressed may be general in nature or specific to an incident or event.
b) The Contractor shall provide the STVHCS facilities with a quarterly report of the
Contractor’s PI monitors and data.
c) The Contractor shall have a detailed Quality Assurance plan describing their monitors, to include completeness, accuracy, and reliability of tests results. The quality control processes should be inclusive for all phases of testing. The monitors may include positive identification of patient and specimen, acceptability of specimens received for testing, accuracy of data entry of test orders, accuracy of data entry of test results, revised reports, and/or lost specimens.
d) The Contractor may offer presentations/webinars/ teleconferences of new technology updates or services.
Licensing and Accreditation:
The contractor shall perform to the standards in this contract and maintain compliance with policies and procedures with the Health Insurance Portability and Accountability Act (HIPAA) and Clinical Laboratory Improvement Act (CLIA) and the College of American Pathologists (CAP) standards. Have all licenses, permits, accreditation certificates required by Federal law and State law and comply with all items listed in VHA Handbook 1106.1.
Copies of all professional certifications, licensures and renewal certifications shall be provided and updated as needed to the Contracting Officer to include the contractor laboratory s Laboratory Director(s) and/or Medical Director(s).
Medical Director(s) shall have suitable Molecular Genetics qualifications and experience to direct a laboratory providing consultation services under this contract according to CLIA and CAP standards.
Have personnel assigned to perform the services covered by the contract who are eligible to provide these services and licensed in a State, Territory, or Commonwealth of the United States or the District of Columbia. All licenses held by Contractor personnel working on the contract shall be full and unrestricted licenses. Contractor Personnel assigned by the Contractor to work under this contract shall be licensed by the governing or cognizant licensing board.
36C25721Q0710 Page 5 of 16
Comply with the regulatory requirements of Health and Human Services Health Care Financing Administration, Centers for Medicare and Medicaid (CMS).
Maintain safety and health standards consistent with the requirements set forth by the Occupational, Health, and Safety Administration (OSHA), and the Center for Disease Control (CDC) and Prevention.
Notify the Contracting Officer immediately, in writing, upon its loss (or any of its subcontractors) of any required certification, accreditation, or licensure
Contract Performance Monitoring:
Quality Control: The contractor shall operate a successful quality assurance program as required by CAP/CLIA. Services are to be performed in accordance with the requirements stated. The quality control program shall include procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor s quality control program is how the contractor laboratory assures that work complies with the requirement of the contract.
STVHCS will maintain an Internal Quality Control Program to monitor the quality of results received from the contractor. The method used for monitoring is at the discretion of STVHCS and may include, but is not limited to, unidentified split specimens sent periodically to the contractor for analysis, split specimens sent to another reference laboratory for comparison, or monitoring of turn-around-time. The contractor s facilities, methodologies (defined as the principal of the method and the references), and quality control procedures may be examined by representatives of STVHCS during the life of the contract.
Contractor Furnished Items and Responsibilities: The Contractor shall furnish all supplies, equipment, facilities, and services required to perform work as outlined in this contract.
Periodic reporting. Provide 4 quarterly (Oct- December, January- March, April-June, July- September) utilization/cost reports and an annual report (for contract performance period) to STVHCS laboratory staff and the administrative officer. The reports shall be in Microsoft excel format and include at minimum the following column headers: patient name, date of service, CPT code, test name, procedure, volume, cost per test, total cost, and test turnaround from accessioning to reporting date. These reports shall be available within 30 days after the end of the quarter.
Provide the following for transport of the specimens to include:
• Lab test request forms (it is possible that vendor may need to customize forms to include information required by the VA).
• At minimum:
o Provider data o Patient data o Full name o Date of birth o Social security number or a second identifier o Gender o Test(s) to be performed o Sample collection date/time o Sample type
36C25721Q0710 Page 6 of 16 o Special instructions for handling of specimen o Description of sample types that can be accepted for each test o Specimen collection supplies for specialized testing.
o Mailing account number to cover the costs of shipping within the US.
INVOICING: Payment to be made monthly in arrears by certified invoices and must contain the contract number and obligation number in addition to the requirements detailed in FAR Clause 52.212-4 (g) to be considered valid. Invoices shall also contain a line item for each test and quantities billed for and dates of service. The STVHCS will not pay for tests that are not clearly identified by accession number on the Contractors invoice.
WORK HOURS: Contractor shall be responsible for providing services in between the hours of 8:00am and 4:30pm Monday through Friday and Weekends, excluding Federal Holidays.
Federal Holidays are as follows:
New Years Day, Martin Luther King’s Birthday, President’s Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, Christmas Day and any other day specifically designated as a national holiday by the President of the United States.
TELECOMMUNICATION AND COMPUTER SERVICES:
Contractor must be able to have a VA nationally approved Business Partner Gateway (BPG)/Interconnection Security Agreement (ISA), which allows the contractor’s computer system to interface with the VA computer system, so that test results are imported directly into the computerized patient record system (CPRS).
The Contractor shall meet all Enterprise Cyber Security Infrastructure Project (ECSIP) requirements in order to establish an interconnection with the VA for transfer of laboratory test results directly into a VA computer system via the appropriate Laboratory Electronic Data Interchange protocol. There are three basic types of authorized connections. The ECSIP team will have the ultimate decision on which connection type is appropriate. The connection types are described below. More information can be obtained from the VA Information Security Officer at any facility or directly from the ECSIP team.
External users shall be classified in one of three distinct categories: 1) client-to-site VPN, 2) site to-site VPN, or 3) Business Partner Gateways. Table 1 can be utilized in assisting users to determine which category a connection may best be identified.
1) Client-to-Site VPNs satisfy remote connectivity for small groups of external users (IE <50) that require access to VA internal resources. Non- VA users are restricted to specific internal IP addresses identified by the Contracting Officer Representative (COR). External business partners should have access to the minimum resources required to meet contractual obligations.
2) Site-to-Site VPNs are connections to external business partners, which terminate in an ECSIP gateway. These connections will then be routed across the VA WAN to the requisite VA facility resources as defined by firewall policy.
36C25721Q0710 Page 7 of 16
3) Business Partner Gateways (BPGs) are connections to external business partners, which terminate at the requisite VA facility and do not traverse the VA WAN. These connections will be limited in number based on CIO requirement definitions.
Table 1:
Connectivity Requirement Client-to-Site
VPN
Site-to- Site
VPN
Business Partner Gateway
Small Number of Users- If the number of users accounts the ISO must administer is manageable. A client-to-site connection will usually suffice.
X
Numerous Users - Having a significant number of client-to-site user accounts to manage may justify a site-to-site VPN. X
Persistent Connection Required - The need to maintain continuous connectivity can usually be supported with a site-to-site VPN.
X X
High Bandwidth- A large volume of traffic may be a valid need to establish or maintain a Business Partner Gateway (BPG) connection (0 prevent certain traffic from traversing the VA WAN. As an example, a medical teaching University supported by a VA Hospital that sends large radiological images on a regular basis. This could have a detrimental impact on the VA WAN if that traffic traverses the WAN through a VPN connection.
X
Service Level Agreements- SLAs that guarantee specific levels of support to contracted agencies that could not be provided using a One-VA VPN may also justify a BPG connection.
X
High Availability- Availability of critical business processes, such as financial and medical applications, may justify maintaining a BPG to minimize the risk of financial and personal health data loss.
X
Sensitive Information- Every effort should be made to protect sensitive information. Although protection mechanisms are in place, there are still risks associated with transmitting sensitive data across any network, to include the VA WAN. Although the One-VA VPN satisfies this requirement, the sensitivity of the data may be such that additional precautions are warranted.
X X
Server-to-Server Connections - In most cases, a site-to-site VPN can be used to support external server connections. X X
LAN Extensions- LAN extensions to the VA WAN may be supported with a site-to-site VPN. In order to qualify for a LAN extension, VA must control both physical AND logical security at the site.
X
Requirements- A requirement for protocols not currently supported in the VA firewall policy and would be a X X
36C25721Q0710 Page 8 of 16 significant security risk 10the VA WAN is a candidate for a site-to-site VPN connection.
In addition, all Contractors shall meet the following background investigation requirements: All users with access to the data received from Department of Veterans Affairs (VA) are U.S.
Citizens with a valid Contractor's license and current background Investigation or a mutually agreed upon VA level background clearance verified at the National Agency Check with Inquiries, level for laboratory technical staff and business operations staff. Anyone with administrative or programmer access to a Federal computer system will have a background investigation commensurate with the level of access granted to the VA computer system as determined by the Information Security Officer in concert with Human Resources Management Staff and/or the Department of Veterans Affairs Security & Investigations Center. These staff must be operating within the borders of the U.S.A. and its territories.
Any equipment provided by the Contractor to VA which contains a storage device such that when the device is powered down, VA sensitive data remains on it shall be sanitized prior to removal from the VA premises, shall become the property of the Federal Government and remain on Federal property or shall be destroyed in accordance with Department of Veterans Affairs regulations at the time of removal (device decommissioning). Data required by the Health Insurance Portability and Accountability Account of 1996 (HIPAA) to remain on equipment located on Contractor's property shall be safeguarded in accordance with HIPAA and this information shall be destroyed in accordance with VA requirements when no longer required by HIPAA to be held by the contractor.
The reference laboratory shall meet VA information security and HIPPA requirements and shall be able to interface with the current or any new interface partner of the Laboratory Information System. The Contractor shall have all users with VA access complete the VHA Privacy and HIPAA Training and the VA Privacy and Information Security Awareness and Rules prior to starting services.
The Contractor shall notify the facility Privacy Officer immediately with the list of patient names if any breach of computer security or privacy incident is accessed.
The Contractor shall provide the following interfacing requirements:
1. LIS physical connection and translation (drivers)
2. Any required (additional) interface connection license(s)
3. Web-based electronic ordering and resulting
4. Provide documentation of successful interfacing with a minimum of 2 VA references (not within VISN 17) and 2 private sector, other federal agency, state, or local government agencies/ institutions. References to include the facility address, telephone number, email address, and contact person’s name which can validate experience within the last three (3) years.
5. Interface shall transmit test results to the host computer via automatic upload
6. Automatic printing of laboratory results to a dedicated reference lab printer.
Vi. IMPLEMENTATION TIME FRAME The implementation of the services/requirements described in this solicitation shall be completed by the first month of the award of the contract. Failure to provide timely implementation may
36C25721Q0710 Page 9 of 16 result in termination of the contract. The Contractor shall furnish a schedule to show a customizable implementation plan of the required services (telecommunications, interface connectivity and validation, client service support, courier/logistics, ordering, supplies, specimen processing services, reporting, quality assurance, billing, etc.)
CONTRACTING OFFICER REPRESENTATIVE: Prior to contract award, the Contracting Officer shall designate a VA Medical Center employee as the Contracting Officer's Representative (COR). All work coordination shall be made through the COR. The Contractor shall be provided a copy of the letter of delegation authorizing the COR at the commencement of the term of this agreement. No other person shall be authorized to act in such capacity unless appointed in writing by the Contracting Officer.
The Contracting Officer is the only person authorized to approve changes or modify any of the requirements under this contract. The contractor shall communicate with the Contracting Officer on all matters pertaining to contract administration. Only the Contracting Officer is authorized to make commitments or issue changes, which will affect price, quantity, or quality of performance of this contract. In the event the Contractor effects any such changes at the direction of any person other than the Contracting Officer, the change shall be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in costs incurred as a result thereof.
Deliverables/Supplies
Drive Through specimen collection and testing for COVID-19 and FLU A&B RT-PCR testing.
Government Inherent Functions:
Contractor shall not perform inherently governmental functions. This includes, but is not limited to, determination of agency policy, determination of Federal program priorities for budget requests, direction and control of government employees, selection or non-selection of individuals for Federal Government employment including the interviewing of individuals for employment, approval of position descriptions and performance standards for Federal employees, approving any contractual documents, approval of Federal licensing actions and inspections, and/or determination of budget policy, guidance, and strategy.
General Duties, Requirements, and Expectations:
1. Be professionally competent to handle required duties.
2. Work with staff to ensure safety measures are in place and documented.
3. Services provided under the terms of this contract are required to be in compliance with the American Association of Blood Banks (AABB) and College of American Pathologists (CAP) accreditation policies and all applicable Federal, State and Government laws required by the Veteran’s Healthcare System and VHA Handbook 1106.1.
Information Systems Officer, Information Protection:
36C25721Q0710 Page 10 of 16
The contractor will not have access to VA Desktop computers, nor will they have access to online resources belonging to the government while conducting services. If removal of equipment from the VA is required, any memory storage devices, such as hard drives, solid state drives and non-volatile memory units will remain in VA control and will not be removed from VA custody.
Privacy Officer:
The contractor will have access to Patient Health Information (PHI) but will not have the capability of accessing patient information during the services provided to the VA. Reference laboratory is required to Certify and ensure that all employees, officers, or agents comply with standards set forth in the Health Insurance Portability and Accountability Act (HIPAA) and meet VHA guidelines Contractor is required to be incompliance with the American Association of Blood Banks (AABB) and College of American Pathologists (CAP) accreditation policies and all applicable Federal, State and Government laws.
RECORDS MANAGEMENT:
1. Citations to pertinent laws, codes and regulations such as 44 U.S.C Chapter 21, 29, 31 and 33; Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228.
2. Contractor shall treat all deliverables under the contract as the property of the U.S.
Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.
3. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government ‘IT’ equipment and/or Government records.
4. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.
5. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.
6. The Government Agency owns the rights to all data/records produced as part of this contract.
7. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.
8. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format [paper, electronic, etc.] or mode of transmission [e-mail, fax, etc.] or state of completion [draft, final, etc.].
9. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules.
36C25721Q0710 Page 11 of 16
10. Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any sub-contractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
MONITORING RECORD/KEEPING: Procedures performed at the Reference Laboratory will be monitored and validated against billings using the VISTA Laboratory Package, VISTA Imaging, PCE (Patient Care Encounter), and PTF (Patient Treatment File). These systems will be used to verify statistics reflecting Current Procedural Terminology (CPT) codes that will be used to validate services provided under the terms of the contract.
The COR will track and record difficulties such as poor turnaround time. Any noted difficulties or deficiencies will be reported to the contracting officer for appropriate action and remedy.
VA ACQUISITION REGULATION SOLICITATION PROVISION AND CONTRACT
CLAUSE
1. SUBPART 839.2 – INFORMATION AND INFORMATION TECHNOLOGY
SECURITY
REQUIREMENTS
839.201 Contract clause for Information and Information Technology Security:
a. Due to the threat of data breach, compromise or loss of information that resides on either VA-owned or contractor-owned systems, and to comply with Federal laws and regulations, VA has developed an Information and Information Technology Security clause to be used when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor, subcontractor or a third party in any format (e.g., paper, microfiche, electronic or magnetic portable media).
b. In solicitations and contracts where VA Sensitive Information or Information Technology will be accessed or utilized, the CO shall insert the clause found at 852.273-75, Security Requirements for Unclassified Information Technology Resources.
2. 852.273-75 - SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION
TECHNOLOGY RESOURCES (INTERIM- OCTOBER 2008)
As prescribed in 839.201, insert the following clause:
The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract.
STX-HCR671-04 General Information Security Requirements /Records
1.1. All information and records provided to Contractor by VA, in whatever medium, as well as all information and documents, including drafts, emails, back-up copies, hand-written notes and copies that contain such information and records gathered or created by Contractor (collectively referred to as “VA information”) in the performance of this contract, regardless of storage media, are the exclusive property of VA. Contractor
36C25721Q0710 Page 12 of 16 does not retain any property interest in these materials and will not use them for any purpose other than performance of this contract.
1.2. Upon completion or termination of the contract, Contractor will either provide all copies of all VA information to VA or certify that it has destroyed all copies of all VA information as required by VA in a method specified by VA, at VA’s option. Medical records of any kind including notes shall be returned to the VA. The Contractor will not retain any copies of VA information. Where immediate return or destruction of the information is not practicable, Contractor will return or destroy the information within 30 days of completion or termination of the contract. All provisions of this contract concerning the security and protection of VA information that is the subject of this contract will continue to apply to VA information for as long as the Contractor retains it, regardless of whether the contract has been completed or terminated.
1.3. Prior to termination or completion of this contract, Contractor will not destroy VA information received from VA or gathered or created by Contractor in the course of performing this contract without prior written approval by VA.
1.4. Contractor will receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in accordance with the terms of this contract and applicable federal and VA information confidentiality and security laws, regulations and policies.
1.5. The Contractor shall not make copies of VA information except as necessary to perform this agreement or to preserve electronic information stored on Contractor electronic storage media for restoration in case any electronic equipment or data used by the Contractor needs to be restored to an operating state.
1.6. Contractor shall provide access to VA information only to employees, subcontractors, and affiliates only: (1) to the extent necessary to perform the services specified in this Contract, (2) to perform necessary maintenance functions for electronic storage or transmission media necessary for performance of this contract, and (3) only to individuals who first satisfy the same conditions, requirements and restrictions that comparable VA employees must meet in order to have access to the same VA information. These restrictions include the same level of background investigations, where applicable.
1.7. Contractor will store, transport or transmit VA information only in an encrypted form, using an encryption application that meets the requirements of FIPS 140-2, and is approved for use by VA.
1.8. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two other situations: (i) in response to an order of a court of competent jurisdiction, or (ii) with VA’s prior written authorization. The contractor will refer all requests for, demands for production of, or inquiries about, VA information to VA for response.
1.9. If VA information subject to the contract includes information protected by 38 USC 7332, or 5705, include the following after the last sentence of the paragraph immediately above: Contractor shall not release information protected by either 38 USC 5705 or 7332 in response to a court order, and shall immediately refer such court orders to VA for response.
36C25721Q0710 Page 13 of 16
1.10. Prior to any disclosure pursuant to a court order, the Contractor shall promptly notify VA of the court order upon its receipt by the Contractor, provide VA with a copy by fax or email, whichever is faster, and notify by telephone the VA individual designated in advance to receive such notices. If the Contractor cannot notify VA before being compelled to produce the information under court order, the Contractor will notify VA of the disclosure as soon as practical and provide a copy of the court order, including a copy of the court order, a description of the records provided pursuant to the court order, and to whom the Contractor provided the records under the court order. The notice will include the following information to the extent that the Contractor knows it, if it does not show on the face of the court order: the records disclosed pursuant to the order, to whom, where, when, and for what purpose, and any other information that the Contractor reasonably believes is relevant to the disclosure. If VA determines that it is appropriate to seek retrieval of information released pursuant to a court order before Contractor notified VA of the court order, Contractor will assist VA in attempting to retrieve the VA information involved.
1.11. The Contractor will inform VA by the most expeditious method available to Contractor of any incident of suspected or actual access to, or disclosure, disposition, alteration or destruction of, VA information not authorized under this Contract (“incident”) within one hour of learning of the incident. An incident includes the transmission, storage or access of VA information by Contractor or subcontractor employees in violation of applicable VA confidentiality and security requirements. To the extent known by the Contractor, the Contractor’s notice to VA will identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information was placed at risk or compromised), and any other information that the contractor considers relevant.
1.12. Contractor will simultaneously report the incident to the appropriate law enforcement entity of jurisdiction. The Contractor, its employees, and its subcontractors and their employees will cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The Contractor also will cooperate with VA in any civil litigation to recover VA information, to obtain monetary or other compensation from a third party for damages arising from any incident, or to obtain injunctive relief against any third party arising from, or related to, the incident.
1.13. VA will provide the Contractor with the name, title, telephone number, fax number and email address of the VA official to whom the Contractor will provide all notices required by this Contract.
1.14. VA has the right during normal business hours to inspect the Contractor’s facility, information technology systems and storage and transmission equipment, and software utilized to perform the contract to ensure that the Contractor is providing for the security of VA data and computer systems in accordance with the terms of this Contract.
1.15. Contractor will receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with all applicable Federal Information Processing Standards (FIPS) and Special Publications (SPs) issued by the National Institute of Standards and Technology (NIST) concerning VA information that is the subject of this contract. If NIST issues or updates an applicable FIPS or SP after execution of this
36C25721Q0710 Page 14 of 16 contract, the parties agree to negotiate in good faith to implement the FIPS or SP in this contract.
1.16. A determination by VA that the Contractor has violated any of the information confidentiality and security provisions of this contract, including a violation of any applicable FIPS or SP, shall be a basis for VA to terminate the contract for cause.
1.17. If anyone performing this contract, including employees of subcontractors, accesses VA computer systems or data in the performance of the contract, VA may monitor and record all such access activity. If VA monitoring reveals any information of suspected or potential criminal law violations, VA will refer the matter to the appropriate law enforcement authorities for investigation.
1.18. Contractor shall inform its employees and other individuals performing any part of this contract that VA may monitor their actions in accessing or attempting to access VA computer systems and the possible consequences to them for improper access, whether successful or not. The Contractor shall ensure that any subcontractors or others acting on behalf of, or for, the Contractor in performing any part of this contract inform their employees, associates or others acting on their behalf that VA may monitor their access activities. Execution of this contract and any subcontract or agreement constitutes consent to VA monitoring.
1.19. The Contractor will ensure that all individuals who will access VA data or systems in performing the contract are appropriately trained in the applicable VA confidentiality and security requirements. Contractor may do this by requiring and documenting that these individuals have completed the VA training for its employees.
1.20. To the extent practicable, Contractor shall mitigate any harmful effect on individuals whose VA information was accessed or disclosed in an incident.
1.21. Contractor shall require subcontractors, agents, affiliates or others to whom Contractor provides access to VA information for the performance of this contract to agree to the same VA information confidentiality and security restrictions and conditions that apply to the Contractor before providing access.
1.22. The contractor shall abide by FAR clauses 52.224-1 and 52.224.2.
1.23. The contractor shall abide by FAR clauses 52.239-1 and 52.224.1-2 for Privacy or
Security Safeguards
1.24. In the performance of any part of the work on this contract, the contractor shall utilize only employees, subcontractors or agents who are physically located within a jurisdiction subject to the laws of the United States. Contractor will ensure that it does not use or disclose Patient Health Information (PHI) received from Covered Entity in any way that will remove the PHI from such jurisdiction. Contractor will ensure that its employees, subcontractors and agents do not use or disclose PHI received from Covered Entity in any way that will remove the PHI from such jurisdiction.
VA Handbook 6500.6 Appendix C Paragraph 2 - ACCESS TO VA INFORMATION AND
VA INFORMATION SYSTEMS
1.25. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and
36C25721Q0710 Page 15 of 16 affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
1.26. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program.
The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
1.27. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
1.28. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
1.29. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
VA Handbook 6500.6 Appendix C Paragraph 6 - SECURITY INCIDENT
INVESTIGATION
1.30. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.
1.31. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
36C25721Q0710 Page 16 of 16
1.32. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.
1.33. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
VA Handbook 6500.6 Appendix C Paragraph 9 - TRAINING
1.34. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
1.34.1. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;
1.34.2. Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;
1.34.3. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and
1.34.4. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]
1.35. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
1.36. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until the training and documents are complete.
| Data Management System |
| TELECOMMUNICATION AND COMPUTER SERVICES: |
| Vi. IMPLEMENTATION TIME FRAME |
| STX-HCR671-04 General Information Security Requirements /Records |
| 1.1. All information and records provided to Contractor by VA, in whatever medium, as well as all information and documents, including drafts, emails, back-up copies, hand-written notes and copies that contain such information and records gathered or ... |
| 1.2. Upon completion or termination of the contract, Contractor will either provide all copies of all VA information to VA or certify that it has destroyed all copies of all VA information as required by VA in a method specified by VA, at VA’s option.... |
| 1.3. Prior to termination or completion of this contract, Contractor will not destroy VA information received from VA or gathered or created by Contractor in the course of performing this contract without prior written approval by VA. |
| 1.4. Contractor will receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in accordance with the terms of this contract and applicable federal and VA information confidentiality and security laws, regulations and... |
| 1.5. The Contractor shall not make copies of VA information except as necessary to perform this agreement or to preserve electronic information stored on Contractor electronic storage media for restoration in case any electronic equipment or data used... |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .