ASPEN Draft SOW 08 02 2021.pdf

PDF 595 KB Posted

Attached to
Request for Information Federal contract opportunity
Solicitation number
08022021
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Centers for Medicare & Medicaid Services Center for Clinical Standards and Quality Information Systems Group

Division of Quality Systems for

Assessments and Surveys 7500 Security Boulevard Baltimore, MD 21244-1850

Automated Survey Processing Environment (ASPEN) Operations and Maintenance (O&M)

Statement of Work (SOW)

TABLE OF CONTENTS

Contents

C.1 INTRODUCTION

C.1.1 BACKGROUND

C.1.3 TASK ORDER SCOPE

C.1.3.1 TASKING 9

C.1.4.1.1 Applications C.1.4.1.1.a ASPEN Central Office/Regional Office (ACO/ARO) C.1.4.1.1.b ASPEN Complaints/Incidents Tracking System (ACTS) C.1.4.1.1.c ASPEN Enforcement Manager (AEM) C.1.4.1.1.d ASPEN Scheduling and Tracking (AST) C.1.4.1.1.e ASPEN-Web Electronic Plan of Correction Manager (e-POC) C.1.4.1.1.f ASPEN-Web Clinical Laboratory Improvements Amendment (CLIA) C.1.4.1.1.g ASPEN-Web Accrediting Organization System for Storing User Recorded C.1.4.1.1.h ASPEN Survey Explorer–Quality (ASE-Q) C.1.4.1.1.i Long Term Care Survey Process (LTCSP) C.1.4.1.2 System Development C.1.4.1.3 Programming Support:

C.1.4.1.4 Data C.1.4.1.5 Documentation C.1.4.1.6 Help Desk C.1.4.1.7 Administrative Support C.1.4.1.8 Hardware/Software Communications C.1.4.1.10 System Validation C.1.4.1.10.1 Test Plans C.1.4.1.10.2 Test Cases C.1.4.1.10.3 Integration Testing C.1.4.1.10.4 Test Tools C.1.4.1.10.5 Test Summary Reports C.1.4.1.10.6 Test Environments C.1.4.1.11 Support Services C.1.4.1.11.1 Administrative Support C.1.4.1.11.2 Systems Security/Data Confidentiality C.1.4.1.11.3 Cooperative Projects C.1.4.1.11.4 Meetings/Workgroups

C.1.5 INTERFACES

C.1.6 DELIVERABLES

C.2 STANDARDS, POLICIES, AND PROCEDURES

C.2.1 FEDERAL STANDARDS, POLICIES AND PROCEDURES

C.2.2 CMS INFORMATION TECHNOLOGY STANDARDS

CMS Expedited Life Cycle (XLC)

HCQIS XLC

C.2.3 CMS INFORMATION SECURITY

C.2.4 SECTION 508 – ACCESSIBILITY OF ELECTRONIC AND INFORMATION

TECHNOLOGY

Software The following standards are applicable:

The following standards are applicable:

C.2.5 COMMON SECURITY CONFIGURATION

C.2.6 CONFIGURATION MANAGEMENT

C.7 DELIVERY SCHEDULE

C.1 INTRODUCTION

The purpose of this contract is to obtain operations and maintenance services to support the Automated Survey Processing Environment (ASPEN) system. All efforts shall be performed in accordance with the Centers for Medicare & Medicaid (CMS) requirements and shall meet the objectives of increasing efficiency and effectiveness of operations and timely implementation of statutory and regulatory requirements.

C.1.1 BACKGROUND

The Social Security Act (the Act) mandates the establishment of minimum health and safety and CLIA standards that must be met by providers and suppliers participating in the Medicare and Medicaid programs. The Secretary of the Department of Health and Human Services (DHHS) has designated the Centers for Medicare and Medicaid Service (CMS) to administer the standards compliance aspects of these programs.

CMS ensures compliance with healthcare standards through extensive and complex processes comprising its Survey and Certification (S&C) program operations. S&C operations involve many functionally diverse and geographically distributed stakeholders including: CMS Central Office (CMS-CO), CMS Regional Offices (CMS-RO), State Survey Agencies (SA), regulated healthcare providers/suppliers, other federal and state agencies such as the Veterans Administration – non-government agencies including accrediting organizations, financial institutions, and many others.

CMS has substantial technology investments in systems to streamline and organize these complex and distributed S&C operations. Collectively, these investments comprise the Quality Improvement and Evaluation System (QIES). QIES encompasses a multitude of programs and services to monitor, track, report and implement the quality initiatives that CMS’ Medicare and Medicaid regulations require. A key component of QIES is the Automated Survey Processing Environment (ASPEN) system which supports the daily S&C operations performed by over 6,000 state and federal staff relating to 39 different federal healthcare provider/supplier categories and sub-types. ASPEN collects, organizes, tracks, analyzes and maintains data on demographics, certification, surveys, deficiencies, complaints, enforcement, and accreditation. ASPEN is the primary tool used by these agencies to ensure healthcare providers/suppliers meet CMS health and life-safety standards.

ASPEN comprises numerous, highly integrated modules which are each aligned with a major Survey and Certification (S&C) process area. ASPEN utilizes modern technologies specifically selected to best meet the functional needs of the business area they support, to provide maximum interoperability and includes both client-server and web-based technologies.

ASPEN components and related S&C business areas are:

• ASPEN Central Office/Regional Office (ACO/ARO) – Health provider/supplier enrollment, certification, survey operations, reporting and federal oversight monitoring.

• ASPEN Complaints/Incidents Tracking System (ACTS) – Investigation and process management of public complaints against healthcare providers/suppliers

• ASPEN Enforcement Manager (AEM) – Process management and tracking of enforcement and legal actions taken against non-compliant provider/suppliers including the imposition and collection of financial penalties.

• ASPEN Survey Explorer – Quality (ASE-Q) – Manages and directs the survey inspection process performed on-site at the provider/supplier location by state and federal health professionals.

• ASPEN Scheduling and Tracking (AST) – Supports agency planning, scheduling and execution of certification and complaint processes.

• ASPEN-Web Electronic Plan of Correction Manager (e-POC) – Provides an online interface between SAs, CMS-ROs, and provider/suppliers for the purpose of preparing and transmitting the plan of correction (POC) on CMS health and life-safety standards.

• ASPEN-Web Clinical Laboratory Improvements Amendment (CLIA) – An extensive and complex set of sub-systems for Clinical Laboratory enrollment, certification, inspection, billing and payment processing, proficiency testing, and related S&C processes.

• ASPEN-Web Accrediting Organization System for Storing User Recorded Experiences

(ASSURE) – Provides online interface to CMS for accrediting organization submission of healthcare provider deeming information.

• ASPEN Long Term Care Survey Process (LTCSP) – provides a single nationwide automated survey process for a resident-centered, outcome-oriented inspection that relies on a case-mix stratified sample of residents to gather information about the facility’s compliance with participation requirements.

S&C business processes are highly integrated – actions in one process may trigger or affect actions in another process area. To avoid redundant data capture and ensure process continuity, ASPEN’s architecture must continue to provide complete process integration, and the adaptability to modify or implement new processes to support S&C’s rapidly changing business needs.

Similarly, ASPEN is highly integrated into the overall QIES architecture. ASPEN’s technical platform includes adaptable, message-based transaction processing that delivers S&C healthcare compliance data to the QIES reporting systems for research and analysis purposes, and supports CMS public websites for provider performance and ranking statistics. Furthermore, ASPEN connects to clinical information within QIES to calculate complex quality indicators and deliver beneficiary health information to assist inspectors in identifying non-compliance during onsite investigations.

Because of the organizational and operational distribution of S&C staff, ASPEN modules are deployed in a distributed, multi-tier system, including: central operations within the CMS data center;

agency operations within each state; and, mobile operations performed onsite at the healthcare provider/supplier. ASPEN’s platform must continue to provide the sophisticated inter-operability functions necessary for operational transparency across these tiers and to ensure data synchronization, security and encryption.

ASPEN must comply with CMS infrastructure, security, encryption, and technology structures.

ASPEN must comply with CMS systems and documentation Section 508 accessibility standards. If new technologies are needed to support S&C business operations, the ASPEN contractor must have the capability and business-area expertise to represent the business need and technology options to the CMS technical review boards.

To support rapidly changing S&C business needs, multiple ASPEN projects involving shared technical components and source code may be in-flight simultaneously. Successful release cadence requires advanced version-control, build, quality assurance and release management practices. Furthermore, ASPEN releases must be coordinated with QIES system teams and projects developed in collaboration with other contractors who are developing other QIES systems which are dependent on ASPEN transaction processing. Applicable CMS project life-cycle standards and methods direct ASPEN and other QIES technology projects.

To ensure engagement, communication and review of project artifacts with policy, user and technical stakeholders throughout the ASPEN project life-cycle, ASPEN contractor services should include an automated project management system accessible by all stakeholders.

A key stakeholder in CMS S&C operations are the 53 states and similar agencies. Not only do these organizations serve as CMS agents in performing S&C operations, they also perform agency-specific licensing operations for healthcare providers under their jurisdiction, using the CMS-provided ASPEN system. Knowledge of these stakeholder interests and the configuration capabilities in ASPEN to support these functions is vital to successful on-going operations.

ASPEN directly supports and implements provisions of the Omnibus Budget and Reconciliation Act (OBRA) 1987 & 1989, Health Insurance Portability and Accountability Act (HIPAA), Balanced Budget Act (BBA) 1997, and the Medicare Modernization Act (MMA), and numerous implementing regulations. ASPEN also fulfills CMS action items pursuant to GAO and OIG reports and Congressional committee corrective action plans on the Nursing Home enforcement and complaints processes. ASPEN is critical to CMS’s payment and quality of care improvement processes, and to implementation and support of statutory mandates and major CMS and Department of Health and Human Services (DHHS) initiatives.

ASPEN supports the administration of the Quality Innovation Network (QIN) Program. The Social Security Act, as set forth in Part B of Title XI - Section 1862(g), established the Utilization and Quality Control Peer Review Organization Program, now known as the Quality Innovation Network.

The statutory mission of the QIN is to improve the effectiveness, efficiency, economy, and quality of services delivered to Medicare beneficiaries. The work under this contract aligns with the work and mission under Section 10303 of Pub. L. 111–148, Mar. 23, 2010, 124 Stat. 119, known as the Patient Protection and Affordable Care Act, TITLE III – Improving the Quality and Efficiency of Health Care, Subtitle C – Provisions related to Title III.

ASPEN supports these mission-critical S&C operations within a complex technical environment, and with diverse stakeholder interests. Within this context, to ensure continuity of S&C’s mission- critical operations, and to efficiently adapt ASPEN to meet new S&C business needs, as well as for new CMS technical architectures, requires contractor services with diverse technical capabilities, a flexible and efficient project management approach, and an extensive S&C operational understanding and expertise, including:

• Deep understanding of S&C’s complex business processes, and how ASPEN’s architecture relates to and performs these processes. Such business area expertise should span contractor staff resources -- from technical project managers, developers, software quality assurance engineers, and technical writers.

• Advanced expertise in the technology platform upon which ASPEN systems are built, and knowledge of how this platform was designed to adapt to changing business needs.

• Extensive experience with the overall technology framework and information structures of QIES, and full understanding of technology used by ASPEN to interface within QIES.

• Knowledge and experience of state and CMS agency operations, interests, IT infrastructures and technical support capabilities.

• Proven capability implementing systems within CMS technical, architectural, and security infrastructure, and accessibility standards.

• Proven capability implementing systems within CMS technical project life-cycle methodology, as well as expertise in advanced version control methods and other practices for efficiently managing multiple, simultaneous projects involving shared source and object code.

• Experience managing stakeholder participation throughout the project life-cycle requiring communication based on a strong policy and process understanding, as well as automated Capability and experience collaborating with CMS technical staff and other contractors to manage and deploy systems within QIES.

C.1.3 TASK ORDER SCOPE

Independently and not as an agent of the Government, the Contractor shall furnish all the necessary services, qualified personnel, material, equipment and facilities, not otherwise provided by the Government, as needed to perform the requirements of this Statement of Work.

Technical proposals shall name any subcontractors included in the proposal.

The Contractor must interact and work in conjunction with existing CCSQ contractors to accomplish tasks. The Contractor shall possess extensive knowledge and technical understanding of QIES and ASPEN. The Contractor shall provide expertise in the operation and functionality of the hardware/software currently resident within the CMS and State-based IT environment to support users.

The Contractor shall be required to inactivate functionality within the ASPEN suite of tools as iQIES functionality comes online as outlined in the iQIES timeline (see attached graphic).

The Contractor shall:

1. Furnish the necessary personnel, materials, services, and facilities (except as otherwise specified herein) and take all actions necessary for or incident to providing the requested services.

2. Support and maintain an integrated system capable of supporting legacy ASPEN survey and certification business operations as specified by CMS policy and technical staff and be capable of interacting with other components of the QIES architecture.

3. Have expertise in the design, development, testing, and implementation of the ASPEN system and be capable of servicing all CMS approved IT, administrative and clinical requirements of the ASPEN user community.

4. Have familiarity with the uses of CMS data including: ASPEN, QIES, CLIA and related survey and certification data, and functions such as the health provider ‘Compare’ websites; clinical data, assessments and analytical files and functions such as quality indicator calculations and other information specific to or supportive of Survey & Certification.

5. Continue to produce an efficient and flexible system that meets the ongoing needs of CMS, ASPEN providers, State Agencies, CMS customers, and other affiliated partners in our mission to improve the care provided to Medicare beneficiaries.

6. Provide appropriate and timely documentation to the ASPEN user community in order to ensure optimum use of the system's capabilities.

7. Provide expertise in the operation and functionality of the hardware/software currently resident within the CMS and State-based IT environment to support ASPEN users.

8. The Contractor shall have expertise in the design and operation of a system with QIES-like configurations.

9. The Contractor shall also have subject matter experts with expertise in S&C and knowledge of the major technical components of the ASPEN system (including hardware/software, business requirements, communications, etc.) and will support or enhance the system's functionality and performance. Software expertise, at a minimum, shall include Oracle RDMS and related technology, Sybase iAnywhere and related components including advanced security, SQL/PL SQL, iSQL, Visual C++, Visual C#, .NET framework, MS Access, XML, Java, J2EE, JavaScript, WebLogic, GonG, CMSNet network and related components, and all other software and system components, currently resident in or related to processing of the ASPEN data models. The ASPEN data models are defined as all data stored within the State-based, mobile and CMS repositories (e.g., Oracle and other databases, clinical data, ad hoc data, etc.).

10. Enhance surveyor software to add reports and further integrate with assessment based systems.

11. Support minimal new legislative and regulatory mandates.

12. Provide needed customer support for ASPEN users, to include technical assistance and Tier-2 Help Desk support.

13. Provide Tier-2 Help Desk support for the ASPEN Help Desk. This would include all ASPEN related problems. The contractor shall, at a minimum, answer questions submitted by telephone, fax, or e-mail. The contractor shall log the questions, answers, and the source of the questions into a database.

14. Provide support services and resources in coordination with, and as directed by CMS, in the following areas:

a. Systems Development and Enhancement

b. Data Requirements and Analysis

c. Documentation

d. Tier 2 Help Desk support

e. Support Services

f. Government subcontracting Requirements

g. Hardware and environmental sizing and support, including configuration management and validation

h. Data exchange with iQIES system components

C.1.3.1 TASKING

1. State, CMS and QIES systems operation, support and development, including specific experience with:

a. Design, development, analysis, installation and implementation of system enhancements and provisions for CMS IT services;

b. Major hardware and software operating components of the ASPEN system, including user improvements, and technical support, including performance testing, quality assurance tasks and potential possibilities and plans for future ASPEN IT architecture;

c. Evaluating, managing and/or acquiring equipment and Government owned software, subject to licensing restrictions.

d. Possess knowledge of and translation of the S&C business processes into the ASPEN suite of products.

2. Hardware/software, tools, resources, technology, communications, data sets, performance tuning, etc. that enable efficient and optimum use of QIES and ASPEN in support of CMS activities for long-term and short-term program goals, including the ability to:

a. Collect data on a timely basis.

b. Populate each database and to subset and distribute other data/information/reports as needed to facilitate fulfillment of the ASPEN contractual obligations, including project support, QIN support and case review support.

c. Maintain and support software and databases for the QIES data collection vehicles and the national repository, including application programs, replication techniques, and transmission options.

d. Utilize knowledge of existing system design features intended to provide adaptability to efficiently implement new legislatively mandated S&C business processes.

e. Utilize and extend existing system services for transaction processing, messaging, security, etc., to support new data collection or processing initiatives.

f. Exchange data with the new iQIES system.

3. A demonstrated ability to adhere to guidelines and standards approved by CMS Office of Information Technology (OIT), such as the CMS Expedited Life Cycle (XLC) process and the CMS Information Security Acceptable Risk Safeguards (ARS). Provide an integrated project management system for tracking the system lifecycle, artifacts and for engaging project stakeholders throughout the life cycle. Or, utilize an equivalent system provided by CMS.

4. Maintenance and support of network security for access and confidentiality, including limited access, passwords and user profiles, etc.

5. Organizing and/or taking an active role in meetings, workgroups, user groups and any other activity that would allow for improvement in the support, operation and enhancement of CMS's administrative and programmatic goals. At a minimum this includes:

a. Maintenance of technical and user documentation for all systems analysis, clinical enhancements and maintenance activities.

b. Maintenance of a technical library at a CMS designated site. At a minimum, the

Contractor shall insure that this library contains the latest versions (electronic and/or hardcopy, as directed by CMS) of all technical and user documentation that may be related to the overall mission of this contract. The Contractor shall maintain this documentation in a manner that allows easy and prompt access by government and/or contractor personnel.

c. Maintaining, updating, and refining existing IT/systems documentation; expanding upon documentation as enhancements are approved, and providing status reports to CMS with suggestions designed to improve efficiency.

d. Provide topology drawings for Oracle tables as changes are made to the database.

e. Evaluating, managing and/or acquiring equipment and Government owned software, subject to licensing restrictions.

f. Attending and participating on the QIES integration team meetings.

g. Providing Help Desk support for problem resolutions and documentation; sharing this information within the QIES community to avoid replication and standardizing solutions/ideas/methodologies, etc.

h. Implementation and maintenance of: change control procedures, operational documentation, and problem management processes, including, but not limited to:

i) The addition, removal or modification of software, procedures and documentation.

ii) The utilization of an approved process analysis, rapid application development, joint application development, rapid prototyping and/or other Expedited Life Cycle (XLC) tools and mechanisms.

iii) The utilization of a CMS Health Care Quality Information Systems (HCQIS) approved configuration management tools.

6. Providing risk management support through the identification of potential and existing risk factors, presenting strategies and suggesting recommendations for the mitigation of such risks, and controlling and tracking activities approved by the CMS COR. Each approved activity should have its own risk management plan (RMP), with an integrated RMP for the entire ASPEN system. Such RMP’s shall be reviewed, updated and reprioritized during each development life cycle phase.

C.1.4.1.1 Applications

The Contractor must possess extensive knowledge and technical understanding of the various ASPEN applications. The Contractor’s Business Analysts shall provide the COR with all business requirements documentation. These documents will be delivered in accordance with the deliverable schedule and include the designated contact individuals.

The Contractor shall maintain and support data transmission, validation, and data storage in support of the continued operations of all ASPEN applications. The Contractor shall support provider efforts to compile and transmit information. The Contractor shall deliver business requirements in accordance with the deliverable schedule and continue to support the following applications:

Applications C.1.4.1.1.a ASPEN Central Office/Regional Office (ACO/ARO)

Applications C.1.4.1.1.b ASPEN Complaints/Incidents Tracking System (ACTS)

C.1.4.1.1.c ASPEN Enforcement Manager (AEM)

C.1.4.1.1.d ASPEN Scheduling and Tracking (AST)

C.1.4.1.1.e ASPEN-Web Electronic Plan of Correction Manager (e-POC)

C.1.4.1.1.f ASPEN-Web Clinical Laboratory Improvements Amendment (CLIA)

C.1.4.1.1.g ASPEN-Web Accrediting Organization System for Storing User Recorded Experiences (ASSURE)

C.1.4.1.1.h ASPEN Survey Explorer –Quality (ASE-Q)

C.1.4.1.1.i Long Term Care Survey Process (LTCSP)

C.1.4.1.1.a ASPEN Central Office/Regional Office (ACO/ARO) The ASPEN Central Office/Regional Office (ACO/ARO) is a system which provides health provider/supplier enrollment, certification, survey operations, reporting and federal oversight monitoring.

C.1.4.1.1.b ASPEN Complaints/Incidents Tracking System (ACTS) The ASPEN Complaints/Incidents Tracking System (ACTS) is a system which provides investigation and process management of public complaints against healthcare providers/suppliers.

C.1.4.1.1.c ASPEN Enforcement Manager (AEM) The ASPEN Enforcement Manager (AEM) is a system which provides process management and tracking of enforcement and legal actions taken against non-compliant provider/suppliers including the imposition and collection of financial penalties.

C.1.4.1.1.d ASPEN Scheduling and Tracking (AST) The ASPEN Scheduling and Tracking (AST) is a system which supports agency planning, scheduling and execution of certification and complaint processes.

C.1.4.1.1.e ASPEN-Web Electronic Plan of Correction Manager (e-POC) The ASPEN-Web Electronic Plan of Correction Manager (e-POC) is a system which provides an online interface between SAs, CMS-ROs, and provider/suppliers for the purpose of preparing and transmitting the plan of correction (POC) on CMS health and life-safety standards.

C.1.4.1.1.f ASPEN-Web Clinical Laboratory Improvements Amendment (CLIA)

The ASPEN-Web Clinical Laboratory Improvements Amendment (CLIA) is an extensive and complex set of sub-systems for Clinical Laboratory enrollment, certification, inspection, billing and payment processing, proficiency testing, and related S&C processes.

C.1.4.1.1.g ASPEN-Web Accrediting Organization System for Storing User Recorded Experiences (ASSURE) The ASPEN-Web Accrediting Organization System for Storing User Recorded Experiences (ASSURE) is a system which provides an online interface to CMS for accrediting organization submission of healthcare provider deeming information.

C.1.4.1.1.h ASPEN Survey Explorer–Quality (ASE-Q) The ASPEN Survey Explorer-Quality (ASE-Q) is a standalone application which manages and directs the survey inspection process performed on-site at the provider/supplier location by state and federal health professionals.

C.1.4.1.1.i Long Term Care Survey Process (LTCSP) The Long Term Care Survey Process (LTCSP) is a software application which manages the specialized nursing home inspection process based on a case-mix stratified sample of residents to gather information about the facility’s compliance with participation requirements.

C.1.4.1.2 System Development

The Contractor shall provide programming and systems maintenance and support for the ASPEN environments. Support may include, but is not limited to, the following areas:

a. problem analysis and correction;

b.optimization and/or enhancement;

c. modification and/or conversion;

d.efforts developed and/or coordinated with other CCSQ Contractors, and/or subcontractors;

The Contractor shall provide state-of-the-art technology with respect to hardware/software, communications, LAN/WAN, etc. The Contractor, however, shall meet CMS standards where necessary. The Contractor shall provide system analysis, programming and subcontracting expertise.

C.1.4.1.3 Programming Support:

The Contractor shall provide the capability for programming support to CMS as may be necessary to support existing programs, modifications to existing programs/modules, data transformations, ad hoc requests and other support as may be necessary to fulfill CMS requirements.

At a minimum, the Contractor shall be responsible for:

a. modifying and testing the programming code per CMS’s requirements;

b. working with the other ISG contractors;

c. performing quality assurance activities (e.g., version and change control, configuration management);

d. providing software support for ASPEN throughout the life of the contract. This software support is to ensure that the technical environment is functioning in accordance with requirements. This support includes, but is not limited to ensuring that the quality, reliability, and functionality of the systems are in accordance with identified requirements.

e. providing technical support for the ASPEN throughout the life of the contract. This support is to ensure that the technical environment is functioning in accordance with requirements. This support includes, but is not limited to ensuring that the quality, reliability, and functionality of the systems are maintained in accordance with identified requirements; and

f. ensuring that CMS has received a copy of ALL source code prepared, altered and/or used by the prime or any subcontractor or partner participating in the QIES/ASPEN environment.

The Contractor shall use all HCQIS approved configuration management tools to reduce time and errors related to build and deployment of applications and services.

C.1.4.1.4 Data

The Contractor shall have a demonstrated expertise in the design and operation of a system with QIES-like configurations. The Contractor shall also have subject matter experts on the major operating components of the ASPEN systems including hardware/software, clinical requirements, communications, etc. and will maintain, support and enhance the system's functionality and performance. Software and coding expertise, at a minimum, shall include Oracle, SAS, Info-Maker, Visual Basic, DB2, SQL, COBOL, JCL, C, C++, ACCESS, NDM, JAVA, and all other software currently resident with the ASPEN data models.

The ASPEN data models are defined as all data stored within the State-based and CMS repositories (e.g., Oracle and other databases, clinical data, ad hoc data, etc.).

The Contractor shall be responsible for the ongoing population, software enhancement, and performance of the ASPEN models, which would include but may not be limited to the following:

a. Updating or enhancing the existing ASPEN models and data population functions based on program requirements, user needs, performance factors, etc.;

b. maintaining, updating or enhancing the existing ASPEN model including the Central and State-based repositories, the ASPEN collection, processing and reporting systems, and making all electronic and hardcopy documentation easily accessible and user friendly to CMS’s partners. Documentation shall include a library of standard routines and other metadata such as data limitations and data quality issues;

c. timely communication of all proposed modifications to the Data Models and/or documentation surrounding the Data Models prior to final release to the user community.

All proposed modifications/enhancements shall be submitted to CMS for approval;

d. providing access, retrieval, extractions and distribution of data from a variety of QIES, ASPEN, or iQIES sources; including the population of the Data Model(s) and/or the creation of new analytical files; and

e. reviewing, analyzing and incorporating other possible data sources for population of the Data Models or new analytic files in addition to specified work assignments.

ASPEN data is replicated to the QIES national repository. The Contractor must support this transmission/replication process. The Contractor must also support the transmission of data to and from the new iQIES system as needed for each system to successfully perform the needed work processes.

The Contractor shall support and maintain an integrated system capable of supporting all field surveyor operations and capable of interacting with other components of the ASPEN architecture. ASPEN must interface with other CMS QIES systems, such as CASPER, QBIC and other reporting systems, as well as new iQIES components. The Contractor shall collaborate with and work in conjunction with existing ISG contractors, including the OIT Contractors, HCQIS Infrastructure Contractors, and iQIES and QTSO contractors. This interface is essential to complete the successful transition of ASPEN data to the QIES national repository as well as the operation of the newer systems.

The Contractor shall collaborate and work in conjunction with the iQIES contractor to facilitate data exchange between the legacy and new systems. The Contractor shall perform Quality Assurance (QA) testing to provide production ready software to hand over for Independent Verification and Validation (IVV) testing. The Contractor shall assist CMS and other contractors during the Independent Verification and Validation (IV&V) and testing phase to verify adherence to the business requirements.

This may be required for legacy QIES and ASPEN software and will be required for the data interface with the new iQIES software.

The Contractor shall provide “train the trainer” courses (and other alternative solutions) that enable individuals other than the Contractor to provide acceptable training to the user communities.

C.1.4.1.5 Documentation

a. The Contractor shall be responsible for the development and maintenance of all ASPEN artifacts. An artifact is one of many kinds of tangible byproducts produced during the development of software. The purpose of the CMS Expedited Life Cycle (XLC) artifacts is to concisely capture, share and store critical project information within their associated timelines in attempt to make the best use of planning, resources and technology throughout the XLC. The Contractor shall prepare and maintain system artifacts for ASPEN that are required by CMS, including but not limited to:

• Project Management Plan

• Project Charter

• Annual Operational Analysis

• Risk Management Plan

• Risk Register

• Contingency Plan

• Systems Security Plan

• Risk Assessment

The Contractor shall be responsible for the development and maintenance (and distribution, where required) of all documentation relating to the design, development, analysis, acquisition, testing, installation, implementation, operation, maintenance and support for CMS and/or the user community, including documentation transferred from previous Contractors and/or subcontractors.

The Contractor shall produce systems documentation throughout the development life cycle of each effort. At a minimum, the Contractor shall anticipate preparing the following systems documentation:

(1) overall systems design narratives and flow charts

(2) design narratives and flow charts for each module

(3) data dictionary definition and element description

(4) table definition and element descriptions

(5) specifications for all programs

(6) listing of all SQL scripts

(7) system security procedures

(8) system operating procedures

(9) testing and system validation activities

(10) topology

(11) source code

b. The Contractor shall make this documentation easily accessible to CMS and the user communities, in a CMS approved format that displays efficiency and purpose for the user audience. Provision of documentation shall be timely, in conjunction with the targeted contract effort, and meet the goals/purpose of its use. The Contractor shall publish and distribute user documentation as specified in individual work assignments and prior to implementation to facilitate and coordinate the flow of information to the user community.

c. Documentation is defined as end user support materials required by CMS, that include, but may not be limited to the following general categories:

(1) Data Models

(2) Communications

(3) Data Dictionaries

(4) Program code

(5) Technical Support

(6) Database Administration (including backup and recovery)

(7) Data Management Applications

d. Documentation, including activities and outputs required by CMS, includes but may not be limited to the following:

(1) Project Initiation

(2) System Requirements Definition

(3) System Design Alternatives

(4) System External Specification

(5) System Internal Specification

(6) Program Development

(7) Testing

(8) Conversion

(9) Implementation Phase

(10) User Documentation

e. The Contractor shall incorporate the following steps into the documentation process for the distribution of any user (technical or end user) documentation where required and/or as directed by CMS:

(1) Development of outline

(2) Preparation of draft version

(3) Walk-through with CMS (and/or user community pilot)

(4) Preparation of final version (all documentation must be in electronic form)

(5) Obtain CMS approval and release

(6) Enter and maintain in Confluence or any CMS HCQIS approved configuration management tool

f. Other documentation requirements are as follows:

(1) For software or hardware upgrades, the Contractor shall prepare an implementation plan, including details on how changes and enhancements will be released (e.g., scripts, schedule, roll out plan, etc.)

(2) All documentation shall be in both hardcopy and/or electronic format unless directed in writing by the CMS COR. Unless authorized in writing by the CMS COR, all documentation shall conform to current CMS standards.

(3) All new COTS packages and their enhancements shall include user manuals and reference manuals, as directed by CMS.

Prior to release to the user community the Contractor shall be prepared to ensure all user documentation relating to the systems, or software residing within the system, is 508 compliant and has been internally tested for clarity, friendliness and accuracy.

C.1.4.1.6 Help Desk

The Contractor shall provide ASPEN related problem resolutions and documentation. The Contractor shall make responses and resulting dissemination, including resolution, in a reasonable and timely manner. The Contractor shall work in coordination with existing ISG contractors to accomplish tasks. The Contractor shall provide expertise in the operation and functionality of the hardware/software currently residing within the CMS and State-based IT environment to support users.

C.1.4.1.7 Administrative Support

The Contractor shall provide administrative support to CMS, State Agencies, and other CCSQ contractors, as required. This support which shall be identified and confirmed in writing by CMS shall include, but not necessarily be limited to, the following:

(1) organizing and taking an active role in meetings, workgroups, user groups and any other activity that would allow for improvement in the support, operation and enhancement of CMS's administrative and programmatic goals;

(2) demonstrating the ability to interact with ROs and State Agencies;

(3) assisting CMS employees and other CCSQ contractors; and

(4) interact and perform duties in conjunction with other contractors involved with the ASPEN and QIES project.

C.1.4.1.8 Hardware/Software Communications

The Contractor shall have access to, and the use of, Government owned computer equipment, and Government owned software, subject to the required licensing restrictions. The Government has implemented new program named Corporate Furnished Equipment (CFE) that alleviates the CMS burden of acquiring government furnished equipment and CMSNet connectivity. The Contractor shall participate in CFE after contract award.

The Contractor shall support and enhance existing hardware/software for the ASPEN user community. Software enhancement shall include hardware, software (COTS and custom-developed), communications, WAN/LAN, databases, file management, configurations, scripts, Intranet/Internet, Help Desk, etc.

The Contractor shall address user requirements in all areas to optimize system performance to meet user requirements in an efficient, effective and user friendly manner.

The Contractor shall negotiate group rates where possible for all purchases.

C.1.4.1.10 System Validation

System validation defines the techniques, procedures and methodologies that will be used to assure timely delivery of the ASPEN systems meeting specified requirements within project resources.

Using system validation will help assure the following: (1) the system enhancements, evaluation and acceptance standards are developed, documented and followed; (2) the results of system validation test activity will be given to appropriate COR in a formal manner (Test Summary Reports); the report provides feedback as to how well the development effort is conforming to various CMS development standards; and (3) the test results adhere to acceptance standards.

The Contractor shall perform the duties described in this section with consultation from the COR and if needed with other stakeholders.

C.1.4.1.10.1 Test Plans

A system test plan is a document that describes the objectives, scope, approach and focus of a system testing effort. It will be provided to the COR prior to testing. The process of preparing a test plan is a means to map out the efforts needed to validate the acceptability of a system. The completed test plan document will assist stakeholders outside the test group understand the “why” and “how” of product validation, the environment for testing, and the scope of what will or will not be tested. The test plan should be thorough enough to be useful, but not so thorough that no one outside the test group will read it.

C.1.4.1.10.2 Test Cases

A test case is a document that describes an input, action, or event and an expected response, to determine if a feature of a system is working correctly. A test case should contain the following particulars such as test case identifier, test case name, objective, test conditions/setup, input data requirements, steps and expected results.

The process of developing test cases can assist in finding problems in the requirements or design of a system, since it requires completely thinking through the operation of the system. For this reason, it is useful to prepare test cases early in the development cycle if possible.

C.1.4.1.10.3 Integration Testing

Integration testing includes the test planning and execution to ensure multiple systems interoperate correctly. This includes not only functional testing, but error handling as well.

The Contractor shall coordinate with all development contractors to ensure systems integrate correctly and meet the expectations of the COR.

C.1.4.1.10.4 Test Tools

The Contractor shall utilize automated testing tools to maximize the test coverage and efficiency for all projects. A formal methodology shall be developed and adhered to ensure standardization of test automation strategies across all project areas.

The Contractor shall utilize defect management tools for the recording of issues and subsequent activity associated with the resolution of these issues.

C.1.4.1.10.5 Test Summary Reports

Test Summary Reports offer a detail of information which comes out of the testing procedure, including but not limited to the following: a record of what testing was done, an assessment of how well the testing was performed, an assessment of the quality of the system and any incidents that occurred. This documentation is used to determine if the system being tested is viable enough to proceed to the next stage of development.

The Contractor shall perform the duties described in this section and provide regular feedback to the COR for decision-making on action to take on bugs/enhancements.

C.1.4.1.10.6 Test Environments

The Contractor shall maintain a systems validation environment for test activity. This environment must closely resemble the production environment in terms of hardware, network and software. This environment shall be secure and restrict access from anyone whose access could compromise the quality of the test activity.

C.1.4.1.11 Support Services

The Contractor shall provide for additional technical, administrative and support services not identified above. This would include, but not be limited to, support of the CMS Systems for Providers link, the individual State-based locations, CMS Central and Regional components and our supporting partners and subcontractors.

C.1.4.1.11.1 Administrative Support

The Contractor shall provide administrative support to CMS, State Agencies, and other QIES contractors, as required. This support which shall be identified and confirmed in writing by CMS shall include, but not necessarily be limited to, the following:

(1) organizing and taking an active role in meetings, workgroups, user groups and any other activity that would allow for improvement in the support, operation and enhancement of CMS's administrative and programmatic goals;

(2) demonstrating the ability to interact with ROs and State Agencies;

(3) assisting CMS employees and other QIES contractors; and

(4) interact and perform duties work in conjunction with other contractors involved with the QIES project.

C.1.4.1.11.2 Systems Security/Data Confidentiality

The Contractor shall ensure that developed systems provide for all levels of security access and confidentiality, including but not limited to CMS developed passwords, user profiles limiting access, network passwords and user profiles, etc. The Contractor shall prepare comprehensive system security documents, including but not limited to system security plan, risk assessment and privacy impact analysis, etc.

C.1.4.1.11.3 Cooperative Projects

When requested, the Contractor shall provide technical support to the user community in the development, and enhancement of data communication and transfer efforts to access, retrieve, subset, and transfer large volumes of data across the CMSNET to various QIES user sites in an efficient and secure manner. This may involve the design of several standard formats for the creation of specifically targeted analytical files. The Contractor must perform duties in cooperation with existing QIES contractors.

C.1.4.1.11.4 Meetings/Workgroups

The Contractor shall cooperatively participate and/or lead meetings, conferences and/or workgroups, including the initiation of and participation in user groups, regarding the ASPEN systems as needed by CMS. For example, the Contractor shall attend all S&C Design and QIES integration meeting(s), where the Contractor shall meet with existing ISG contractors and CMS staff, discuss project requirements, discuss current status, and reach agreement on goals and how they will work together. The Contractor shall participate in and/or lead biweekly status and/or project meetings, which will include the contractor task leader and the QIES integration management team. These status meetings may be via audio- conference or face-to-face meetings as requested by the CMS COR. At a minimum, the Contractor shall use the requirements gathered to enhance the ASPEN projects. The Contractor shall capture, coordinate and distribute agendas and minutes of all weekly, monthly, and workgroup meetings pertaining to ASPEN.

The Contractor shall meet with existing ISG contractors and CMS on a weekly basis. The

Contractor shall serve as the QIES/ASPEN Integration Contractor for tasks involving multiple ISG contractors. The Contractor shall be responsible for developing, updating and maintaining ASPEN project plans and timelines. The Contractor shall meet with CMS and existing ISG contractors on an annual basis to identify and prioritize the annual workload and develop project prioritization lists, action items, and any other needed documents.

C.1.5 INTERFACES

QIES operates on the Health Care Quality Information System (HCQIS). HCQIS is a network environment that uses shared database servers and WAN/LAN resources to monitor and improve utilization and quality of care for Medicare and Medicaid beneficiaries.

The Contractor must support the State infrastructure. The QIES State infrastructure consists of 53 State servers. There is a server located in each of the 50 States, Puerto Rico, the Virgin Islands and the District of Columbia. Data from these servers is replicated to the QIES National Systems.

The Contractor must have network connectivity with the QIES National Systems.

There is continual transmission/replication of files between the QIES National Systems, and the ASPEN system. The Contractor must support this transmission/replication process.

The Contractor shall perform duties in cooperation with existing ISG contractors. The Contractor shall be responsible for developing and maintaining ASPEN project plans and timelines for all ASPEN projects. The Contractor shall also interface with the CMS Office of Information Technology (OIT) contractor. The OIT contractor manages the CMSNet and maintains the Help Desk for broadband issues.

Users of QIES and ASPEN include: CMS Central and Regional Offices, State Agencies, Medicare/Medicaid certified LTC facilities, HHAs, Inpatient Rehabilitation Facilities, Swing-Bed Facilities, LTCHs, Medicare Administrative Contractors, Recovery Audit Contractors, and Outside Group Access (OGA) users.

C.1.6 DELIVERABLES

In accordance with Section J, the Contractor shall produce all deliverables as outlined. In addition, the Contractor shall produce the following deliverables for ASPEN:

• Review the ASPEN systems design and user requirements and expand, modify, update and implement releases of all required enhancements to the ASPEN products. Documentation will include, but shall not be limited to user guides, requirement definitions, and data dictionary.

• Capture, coordinate and distribute the agendas and minutes of all Contractor and State weekly and monthly meetings, teleconferences, audio-conferences, and telephone calls for ASPEN.

Minutes are to be completed within 14 days in a standard format.

• Provide the database technical and administrative support necessary to enhance the functionality of the ASPEN system. At a minimum, this includes all required back-ups, reorganizations, procedures and sub-systems.

• Provide needed systems support for transmission/replication of data between ASPEN and the

QIES National Systems or iQIES.

• Supply the COR with source code and documentation for all modules, test scripts or software produced. All written documentation shall be prepared using CMS standard applications.

• Use the version management feature to check in/out code from the prescribed CMS

Configuration Management (CM) tool for system enhancements and deliver releases as a versioned baseline from the tool. The versioned baseline shall be delivered to the subsequent events at development completion (e.g. Test, QA, production).

• Use earned value methodology to measure results, assess performance and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .