Atch 2 - Performance Work Statement FA301621U0102 Official Release.pdf
PDF 451 KB Posted
- Attached to
- OBSTETRICS PATIENT SAFETY CONFERENCE COORDINATOR Federal contract opportunity
- Solicitation number
- FA301621U0102
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Atch 1 - Schedule of Services FA301621U0102 Official Release.pdf | ||
| FA3016-21-U-0102 - OB Saftey Conference Coordinator Official Release.pdf | ||
| Atch 3 - Caluses and Provisions FA301621U0102 Official Release.pdf | ||
| Atch 4 - Professional Exemption Form FA301621U0102 Official Release.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
(NON-PERSONAL SERVICE)
FOR
OBSTETRICS PATIENT SAFETY CONFERENCE COORDINATOR
27 June 2021
1. Description of Services.
1.1. Requirement with Background. The Department of Defense Military Treatment Facilities (MTF) in San Antonio, Texas, has a requirement for non-personal services as described in this PWS. The contractor shall provide an Obstetrics Patient Safety Conference for education and training purposes. As part of their duties, the contractor will be responsible for planning, preparing, organizing, and conducting a two-day Critical Care/Safety Educational Conference for San Antonio Military Medical Center (SAMMC) obstetric providers and nurses that is open to all Military Health System providers. The contractor shall perform services and support compatible with the medical facility’s operating capacity and equipment.
1.2. Specific Tasks. Contractor shall perform organizational tasks in support of the medical facility and the Air Force Medical Service (AFMS).
1.2.1. The OB Patient Safety Conference Contractor shall perform the following tasks:
1.2.1.1. Identify a civilian, nationally recognized, maternal-fetal medicine specialist who will serve as course director. The contractor and director will coordinate with the Maternal-Child Patient Safety Program Manager, Surgeon General’s OB/GYN, Maternal-Fetal Medicine and Perinatal Nursing Consultants or their appointees to analyze current knowledge gaps related to obstetric critical care and maternal morbidity and mortality in Air Force medicine. This position will begin developing meeting agendas and establish the required conference dates within two weeks upon initiation of the contract. At a minimum there shall be monthly updates on the status of the developing agenda and to address or refine any additional topics. These updates can be provided via email, virtually, or in person. Periodic interactions with the committee outside of the monthly update will be on an as needed basis to ensure the full intent of the conference is met. The contractor shall participate in any additional meetings via telephone or other virtual means established by the committee.
1.2.1.2. Conference. The contractor shall organize the Critical Care/Safety Educational Conference for Air Force Medical Service obstetric providers and nurses with an annual target event date beginning in the 4th quarter of fiscal year 2021. If the contractor can fully execute the event remotely, their attendance at the conference is not required. All costs associated with this conference shall be the responsibility of the contractor and shall include the course director payment, speakers’ honoraria, handouts, training materials, venue, and any other appropriate associated costs.
1.2.1.3 Contractor shall provide necessary handouts and training materials 2 days prior to conference.
These items will include but are not limited to copies of lecture slides and biographies of the speakers.
1.2.2.1. The education conference must be held for two days and last approximately 8-10 hours per day.
The selected conference venue shall hold approximately 100 – 150 obstetric physicians and nurses and have audio-visual services to include streaming capabilities. If the selected venue does not have appropriate audio-visual services, a subcontractor may be used. Attendees are not responsible for a registration fee.
1.2.2.2. Educational conference training will be developed through coordination meetings with the committee. The committee will convey knowledge gaps related to obstetric critical care and maternal morbidity and mortality including care of critically ill pregnant women, management of obstetric emergencies, and procedures to prevent recurrence of catastrophic outcomes. Training material for the conference shall be submitted to the event committee for review and approval before it is produced or distributed. All training material will be provided to the attendees of the conference.
1.2.2.3. In conjunction with course director, the contractor will procure 2 - 3 nationally recognized Maternal-Fetal Medicine specialists and 1-2 nationally recognized perinatal nurses with experience providing lectures at similar conferences. Speakers may include military or civilian Maternal-Fetal Medicine specialists, OB/GYN physicians, or perinatal nurses with relevant expertise. The agenda, venue, and invited speakers will be approved by the event committee before it is finalized.
1.3. General Information.
1.3.1. Contractor Representative. The contractor shall identify the name and telephone number of the contractor’s point of contact to the Contracting Officer (CO) in writing prior to beginning performance.
The contractor shall identify in the designation letter any limitations on its representative's authority to act on behalf of the contractor. The contractor shall provide an updated designation letter whenever any changes occur. The contractor representative may be required to meet with the Government during the performance of this contract at the request of the CO.
1.3.1.1. The Contractor Representative shall respond to a request to meet with the CO within twenty-four
(24) hours of notification under routine circumstances.
1.3.2. Hours of Performance.
1.3.2.1. The duty hours for this contract are not specified. It is anticipated that the work required to meet the requirement above is approximately 60+ hours. The contractor performing under this contract shall abide by the provisions of MDWI41-101, paragraph 2.1.3. The CLIN structure will be one job for CLIN 0001 at the awarded price and CLIN 0002 for travel expenses will be one job at the set NTE.
1.3.2.2. The contractor is advised that special activities including but not limited to commander’s calls, sports days, employee quality of life meetings, late reporting, staggered reporting times, early release, physical fitness time, office picnics, and holiday parties are for Government personnel only and do not apply to the contractor employees unless expressly stated otherwise in the contract. If any special activity occurs, the contractor will continue to perform contract requirements unless expressly excused by the contracting officer. In the event that the contracting officer excuses performance, the contractor understands that its employees’ participation in such event will not be at government expense. The contractor is further advised that any special time off granted by the President or other competent authority is for Government personnel only and does not apply to the contractor employees. Contractor personnel shall take their direction concerning their duty status and hours of performance from their contractor management chain and not from Government personnel.
1.3.2.3. Absences. The contractor shall ensure that scheduled absences do not interrupt service performance. Scheduled absences shall be scheduled at least thirty (30) calendar days in advance and the government POC shall be notified of such absences.
1.3.2.4. If the contractor is prevented from performing due to acts beyond the contractor’s control including emergency base closure the standards in FAR clause 52.212-4(f) as appropriate will be applied to determine if the non-performance is excusable. In the event of an emergency base closure due to weather or other contingency situation the contracting officer will notify the contractor of any changes in performance requirements. The Contractor shall be responsible for instructing contractor personnel concerning their duty status. Under no circumstances will the contractor be paid for services not delivered. In addition, if Public Health decides that the in-person Obstetric Safety Conference must be canceled, then the conference will be modified to a virtual conference, with attendant requirements for AV support/IT services.
1.3.2.5. Federal Holidays: The MTF will observe the following federal holidays.
Holiday Projected Date
New Year's Day January 1 Martin Luther King Jr's Birthday 3rd Monday in January President’s Day 3rd Monday in February Memorial Day Last Monday in May Juneteenth National Independence Day Act June 19 Independence Day July 4 Labor Day 1st Monday in September Columbus Day 2nd Monday in October Veterans' Day November 11 Thanksgiving Day 4th Thursday in
November Christmas Day December 25
Should the official holiday fall on Saturday then the observed holiday is the previous Friday.
Should the official holiday fall on Sunday then the observed holiday is the following Monday.
1.3.2.6. Contractor employees performing under this contract shall abide by the provisions of MDWI 41- 101 Medical Expense and Performance Reporting System (MEPRS), (Paragraph 2.1.3.).
1.3.2.7. Services performed under this contract have been determined not to be essential for performance during crisis declared by the National Command Authority.
1.3.3. Compliance.
1.3.3.1. The Contractor shall comply with all applicable Air Force Instructions (AFI), Department of Defense (DoD) Regulations, and Medical Wing Instructions (MDWI) as outlined in Appendix A.
1.3.4. Conduct Requirements.
1.3.4.1. The Government will restrict the performance on this contract of any individual who is identified as a potential threat to the health, safety, security, general well-being, or operational mission of the MTF and its population.
1.3.4.2. The Contractor shall not advise, recommend, or suggest to persons eligible to receive medical care at Government expense that such person should receive care at an outside agency or provider at any place other than as designated under this contract.
1.3.4.3. The Contractor shall not use Government facilities or other Government property for personal use or other business not related to this contract.
1.3.4.4. Contractor shall not respond to any media inquiries nor provide interviews, comments, or any other responses to the media regarding any subject related to this contract. All inquiries or complaints from the media or other sources shall be immediately relayed to the COR.
1.3.4.5. The contractor shall ensure that its employees conduct themselves in a professional manner while on the installation and refrain from disruptive, offensive, or otherwise improper behavior that undermines order and discipline. The CO may direct the contractor to remove from performance of this contract on this installation any contractor employee engaging in such misconduct.
1.3.4.6. Abide by federal and local MTF regulations concerning the confidentiality of patient records, as embodied in federal statutes including the Privacy Act of 1974 and the Health Insurance Portability & Accountability Act of 1996. All medical records and reports will remain the property of the Government.
All financial, statistical, personnel, and/or technical data which is furnished, produced or otherwise available to the Contractor during the performance of this contract are considered confidential business information and shall not be used for purposes other than performance of work under this contract. The Contractor shall not release any of the above information without prior written consent of the CO.
1.3.4.7. Smoking in AF Facilities. Contractors are advised that the AF has placed restrictions on the smoking of tobacco products in AF facilities. AFI 40-102, Tobacco Use in the Air Force, outlines the procedures used by the commander to control smoking in our facilities. Contractor employees and visitors are subject to the same restrictions as government personnel. Smoking is permitted only in designated smoking areas.
1.3.4.8. Joint Base San Antonio (JBSA) Traffic Code. All applicable Traffic Codes will be enforced and apply to all personnel operating vehicles on a JBSA installation. The governing instruction for all Traffic Codes is AFI 31-218(I) and AFMAN 31-116. For a complete listing of all JBSA Traffic Codes and all other applicable traffic policies and procedures, please contact the Contracting Office.
1.3.4.9. Cell Phone Usage. Contractors are advised that DoD Instruction (DoDI) 6055.04 prohibits cellular telephone usage when approaching, entering or exiting any installation gate. Cell phone usage by drivers on installations is prohibited in moving vehicles unless used with a hands-free device. The installation Security Forces Squadron (SFS) is strictly enforcing this regulation. Those found in violation of this regulation are subject to be ticketed.
1.3.4.10. Base Fire Prevention Program. The contractor will be required to comply with the applicable Fire Prevention Program, for JBSA Lackland the applicable directive is AFI 91-203. Contact the Contracting Office for a copy of AFI 91-203.
1.3.5. Security.
1.3.5.1. General Security Requirements. The Contractor shall follow all guidelines found in the Security Requirements for Solicitation and Contract clause.
1.3.5.2. Internal Operating Instructions (OI). The Contractor shall abide by the MTF’s current OIs for internal circulation control, the protection of resources, and the regulated entry into Air Force controlled areas during normal, simulated, and actual emergency operations.
1.3.5.3. Reporting Requirements. The contractor shall comply with AFI 71-101, Volume 1, Criminal Investigations Program (Chapter 2, paragraph 2.7) and Volume-2, Protective Service Matters, (Paragraph
1.2). Contractor shall report to Security Forces any information or circumstances which may pose a threat to DoD or Contractor, resources, or DoD information.
1.3.5.4. Removal of Contractor. The Government, through the CO, reserves the right to require immediate removal from contract performance on the installation or any Government facility, any individual whose actions raise reasonable suspicion that patient care or services may be compromised in any way, or that pose a threat of harm to other contractor/Government personnel or self. Removal under other circumstances will be subsequent to, and at the direction of the CO only.
1.3.5.4.1. If a situation meriting removal occurs as outlined in the previous paragraph, the government POC will contact the CO and the contractor’s representative within twenty-four (24) hours. A meeting may be required with the CO, government POC and contractor representative to discuss further action.
1.3.5.4.2. The CO will notify the Contractor if and when permanent removal is required. In the event of a disagreement between the Government and the Contractor, the decision of the CO will be final. During the period of time between the removal and the final decision of the CO, the Contractor agrees to provide backup/replacement Contractor in accordance with the terms of this contract.
1.3.5.6. Installation Access. Criminal History Check will be conducted on all prime/subcontractor employees requiring base access. The contractor shall provide the Contracting Officer and the Information Protection Office a current list of employees needing access within 3 working days after receiving award or Notice of Award. The list shall include employee’s name, date of birth, social security number, state driver’s license/state ID number and state of issue. Notifications of contractor employee additions and deletions shall be provided with the same information listed above and within 3 working days. Within 10 business days after receipt of the list the Government will notify the Contractor that installation access passes are available for those employees clearing the criminal history check. The duration of any pass issued will not exceed one year or the duration of the contract, whichever is shorter.
This process will be repeated at the exercise of any option period.
1.3.5.7. Government Data. The Contractor shall manage all data created for Government use or legally controlled by the Government, in support of the functional activity or required by AF publication, IAW with the records management procedures in Air Force Instruction (AFI) 33 - 322, Records Management Program, Air Force Manual (AFMAN) 33-363, Management of Records.
1.3.5.8. Freedom of Information. The contractor shall not respond to any Freedom of Information Act request or release any information in response to a Freedom of Information request. Any request for information received by the contractor under the Freedom of Information Act will be referred to the Contracting Officer.
1.3.5.9. Physical Security. The contractor shall comply with Force Protection Condition (FPCON) procedures, Random Antiterrorism Measures (RAMS) and local search/identification requirements.
The contractor shall safeguard all government property, including controlled forms, provided for contractor use. At the close of each work period, government training equipment, ground aerospace vehicles, facilities, support equipment, and other valuable materials shall be secured.
1.3.5.10. Key Control. The contractor shall safeguard all keys issued by the government and ensure they are used only by authorized contractor personnel. The contractor shall not duplicate issued keys and shall report lost keys to the contracting officer immediately. The contractor will be charged for lost keys, re-keying, and lock replacement as applicable.
1.3.5.11. Additional Security Requirements. NACIs will be IAW Homeland Security Presidential Directive 12 (HSPD-12).
1.3.5.12. Unescorted Entry to Restricted/Controlled Areas. If this contract requires unescorted entry to controlled or restricted areas, the contractor shall comply with DOD 5200.2-R, Appendix 1, and AFI 31- 501, Personnel Security Program Management (Paragraph 3.24). If the performance of this contract requires unescorted entry to a restricted/controlled area, personnel must have a favorably adjudicated NACI investigation. All contractor employees affected by this requirement must have completed an acceptable submission that complies with all directions for completion, of the investigation request through the government security office within 30 calendar days of Contract Award or Notice of Award.
To begin this process, all affected contractor employees must complete within 15 calendar days after Contract Award or Notice of Award Standard Form 85P worksheet that can be downloaded from http://www.opm.gov/forms/pdf_fill/SF85P.pdf . The contractor shall notify the Contracting Officer Representative (COR) or Government Inspector when the worksheet is complete. The affected employee will then be scheduled by the government for two or more appointments to complete the security package.
If at any point after submission of the security worksheet, disqualifying information is discovered or developed, the government reserves the right to deny entry to restricted/controlled areas. In this instance the Contracting Officer will notify the contractor of the denial. That individual will not be allowed to perform duties requiring access to restricted/controlled areas. Upon receipt of a favorable investigation results and authorization by the appropriate commander, the contractor member will receive appropriate entry credentials for access to restricted/controlled areas, unless disqualifying information is subsequently discovered. In this instance access will be revoked. The NACI adjudication process normally takes 2 to 5 months after submission of the package.
1.3.5.13. Weapons, Firearms, and Ammunition. Contractor employees are prohibited from possessing weapons, firearms, or ammunition, on themselves or within their contractor-owned vehicle or privately-owned vehicle while on JBSA Lackland.
1.3.6. Health Requirements and Immunizations.
1.3.6.2. Medical Tests. The Contractor shall not obtain medical tests or procedures at the MTF, unless identified in Section three (3). The Contractor shall be responsible for the cost of any emergency medical services received.
1.3.7. Hazardous Materials. This PWS does not call for any hazardous material to be provided by the Contractor.
1.3.8. Reports. The Contractor shall submit reports to the Government POC and/or credentials office (as applicable) for use in monitoring performance. Such reports may include:
1.3.8.1. Initial – Effective date of award
Quarterly – 1st Qtr (October 1), 2nd Qtr (January 1), 3rd Qtr (April 1), and 4th Qtr (July 1) Annual – September 5
Report Timeline
Personnel Changes Quarterly Security requirements Initially
1.3.8.3. Quality Control. The Contractor shall be responsible for quality control for all work accomplished during the performance of the contract. The Contractor shall maintain a Quality Control Plan (QCP) which ensures the requirements in this PWS are met. As a minimum, the Contractor shall develop quality control procedures that address the areas identified in section 2, Service Summary.
1.3.8.4. Quality Assurance. The government will periodically evaluate the Contractor's performance through the government POC to monitor performance and ensure the services received are acceptable.
The government POC will evaluate the Contractors performance in accordance with the government's performance objectives developed for this requirement as outlined in the Service Summary chart below.
2. Service Summary.
P.0. # Performance Objective (PO)
PWS
Paragraph
Performance Threshold (Per
FTE)
1. Shall organize and attend conferences and training identified on procedures related to obstetric patient safety.
1.2 One Hundred
Percent Inspection
2. Provide timely reports and analysis data summarizing key areas of strength and weakness as identified
1.2.1.1 No more than
(1) substantiated complaints
3. Provide training materials timely for review and approval.
1.2.1.2 No more than
(1) substantiated complaints
4. List of Appendices
Appendix A: Referenced Department of Defense, Air Force, and 59th Medical Wing Publications Appendix B: HIPAA Business Associate Agreement (BAA)
APPENDIX A
REFERENCED DEPARTMENT OF DEFENSE, AIR FORCE, AND 59TH MEDICAL WING
PUBLICATIONS
In all instances, current version applies. Publications can be found electronically at http://www.e-publishing.af.mil and http://www.e-publishing.af.mil/otherpublishingsites.asp. Medical Wing Instructions and Operating Instructions will be furnished upon request.
AFI 31-218, Motor Vehicle Traffic Supervision in its entirety) AFI 31-501, Personnel Security Program Management AFI 31-401, Information Security Program Management AFI 33-322, Records Management Program AFMAN 33-363, Management of Records AFI 40-102, Tobacco Use in the Air Force (in its entirety) AFI 48-105, Surveillance, Prevention and Control of Diseases and Conditions of Public Health or Military Significance. (Paragraph 1.10.10.)
AFI 71-101, Volume I, Criminal Investigations. (IAW 802 CONS & 802 SFS MOA) AFI 71-101, Volume 2, Protective Service Matters. (IAW 802 CONS & 802 SFS MOA) DoD Directive 5200.28, Security Requirements for Automatic Data Processing (ADP) Systems (Paragraph E6.4.1.2) AFI 91-203, Air Force Consolidated Occupational Safety Instruction DoD Directive 5200.2-R, DoD Personnel Security Program (Chapter 5) MDWI 36-2601, Human Resource Development (in its entirety) MDWI 41-101, Medical Expense and Performance Reporting Systems (MEPRS) (Paragraph 2.1.3.)
APPENDIX B
HIPAA BUSINESS ASSOCIATE AGREEMENT (BAA)
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.
Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the Contractor.
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the 59th Medical Wing - Wilford Hall Ambulatory Surgical Center.
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD
5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity.
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of
PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number.
Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions
(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity.
The Business Associate’s notification to the individuals, at a minimum, shall include the following:
(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.
(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and
(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address
(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.
(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.
(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.
(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber-security incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forth here. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.
VI. Termination
(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors) with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the underlying Contract.
(b) Effect of Termination.
(1) If this Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If this Agreement does not have records management requirements, the records should be handled in accordance with paragraphs VI. (2) and (3) below. If this Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if the Covered Entity gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or the Covered Entity’s direction.
(2) If this Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of this Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.
(3) If this Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.
VII. Notices. Any notices to be given hereunder will be made in the most expedient manner, via e-mail, facsimile, U.S. Mail, or express courier to such party’s address given below.
If to the Business Associate: (Contractor information contained on the contract unless the Contractor provides different information.)
If to the Covered Entity:
Attn: Attn: Ms. Elaine R. Hatcher
Title: Title: MTF HIPAA Privacy Officer Company: Unit: 59 MDW/SGSBT Address: Address: 2200 Bergquist Drive, Suite 1 JBSA Lackland, TX 78236
Phone: Phone: 210-292-5318 Fax: Fax: no fax E-mail: E-mail: elaine.hatcher.1@us.af.mil
With a copy to:
Name: Name: Marcus Mattingly 502d Contracting
Squadron/JBKBA Company: Title: Contracting Officer Address: Address: 395 B. Street West, Suite 2 Bldg 224 JBSA Randolph, TX 78150-4525
Phone: Phone: 210-652-3058 Fax: Fax: n/a Email: Email: marcus.mattingly@us.af.mil
Each party named above may change its address and that of its representative for notice by the giving of notice thereof in the manner provided in this subsection.
VIII. Miscellaneous
(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of this Agreement.
(b) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA
File details come from the government source that posted it. Updated .