Attachment_1_-_Draft_PWS_1.pdf
PDF 1 MB Posted
- Attached to
- Indian Health Services (IHS) Web Support Contract Federal contract opportunity
- Solicitation number
- 140D0423R0008
About this file
This document outlines requirements for a web support services contract. The Indian Health Service seeks a contractor to provide website development and maintenance, server support, database management, and related IT services. Key details include a one-year base period and four option years for the indefinite-delivery, indefinite-quantity contract. The requirement is set aside exclusively for Indian-owned small businesses. The contractor must comply with Section 508 accessibility standards and information security requirements. The agency will evaluate proposals based on staffing plans, quality assurance procedures, technical approach, past performance, and price to select the best value. The performance work statement in Appendix A specifies objectives like content management, application development, documentation, and project management. Appendices B through F provide additional technical details.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_5_-_IEE_Representation_Form_1.pdf | ||
| Synopsis_-_Draft_Solicitation_Notice_Letter_1.pdf | ||
| Attachment_3_-_Draft_Pricing_Sheet_1.xlsx | XLSX spreadsheet | |
| Attachment_4_-_Past_Performance_Questionaire_(PPQ)_1.docx | DOCX document | |
| Attachment_2_-_Draft_SCA_Wage_Determinations_1.pdf | ||
| 140D0423R0008_-_Draft_Solicitation_1.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Indian Health Service - Web Support Contract
1 | P a g e
Performance Work Statement
Web Support Contract
DRAFT
2 | P a g e
Contents Web Support Contract
1. Background
2. General Information
2.1 Description of Services
2.2 Place of Performance
2.3 Period of Performance
2.4 Phase-Out
2.5 Government Furnished Equipment (GFE)
2.6 Section 508 Compliance
2.7 HHS-Controlled Facilities and Information Systems Security
2.8 Other Administrative Information
3. Scope of Requirements
3.1 Primary Objectives
3.2 Develop and Maintain Website Content
3.3 Develop and Maintain Web Applications
3.4 Develop Content & Documentation
3.5 Develop and Maintain SharePoint Environments
3.6 Manage and Maintain Server Environments
3.7 Manage and Maintain Databases
3.8 Alerts management, monitoring, and reporting
3.9 Project Management
3.10 Data Quality Assurance
3.11 Security Requirements
4. Deliverables
4.1 Weekly Contract Status and Progress Review
4.2 Weekly Project Dashboard
4.3 Monthly Report
4.4 Deliverables Schedule
5. Services Summary
6. Appendices
Appendix A - Business Associate Agreement (BAA) IAW HHSAR 324.70
Appendix B – Current Database Instances*
3 | P a g e
Appendix C – Current Server Environments*
Appendix D – Current Server Types *
Appendix E – Current Software*
Appendix F – Current Documentation*
4 | P a g e
1. Background The Indian Health Service (IHS) is the principal Federal health care provider and health advocate for American Indian/Alaska Native people and provides a comprehensive health services delivery system for American Indians and Alaska Natives. The range of services includes traditional inpatient care, ambulatory care, preventive care, and population health delivered through a network of hospitals and clinics and distributed through 37 states. The IHS has an ever-expanding web presence that spans the official IHS.gov domain. IHS.gov domain includes several primary internal and external sites with several hundred topic-level pages and collaborative environments as well as dozens of web applications and their respective databases. The public IHS website, www.ihs.gov, is the primary communication tool for the Indian Health Service to the public of the United States. Information disseminated through this website includes agency information, health information for clinical providers and public consumption, research, best practices, training, blogs, cross-agency links, and news. Information accuracy, accessibility, and usability are important to successfully fulfilling the mission of the Indian Health Service. The IHS Office of Information Technology (OIT) supports and maintains the availability, integrity, and confidentiality of the IT systems that support the IHS mission.
This document defines the Scope of Work covering development, maintenance, documentation, technical support, deployment, and projects managed by the IHS Office of Information Technology (OIT) Division of Information Technology (DITO) Web Services team.
2. General Information
2.1 Description of Services
The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items to perform services that include, but are not limited to: website and web application development, web content management, server support and maintenance, database management, quality assurance, and support for the overall functionality of the Indian Health Service IHS.gov domain which currently consists of approximately 175 unique topic static websites, 80 web applications and a SharePoint environment with approximately 300 sites.
2.2 Place of Performance
The work shall be performed at the space provided by the contractor or via telework. No work will be accomplished at the IHS facilities, and all meetings will be held virtually. The only travel that may be required will be to obtain the required Personal Identity Verification (PIV) Card.
2.3 Period of Performance
The Period of Performance will be one base year and four 12-month option years.
The Contractor shall provide services between the core hours of 9:00 AM – 3:00 PM Eastern Time, except on recognized Federal Holidays.
There is a requirement for off-hour support for scheduled maintenance (ex. applying patches/updates to servers), which is anticipated to be no more than 8 hours per month.
2.3.1 Recognized Holidays
http://www.ihs.gov/
5 | P a g e
The following are recognized United States (US) holidays. The contractor shall not perform services on these days or the days they are observed unless emergency services are required:
• New Year’s Day
• Martin Luther King, Jr.’s Birthday
• President’s Day
• Memorial Day
• Juneteenth National
• Independence Day
• Labor Day
• Columbus Day
• Veteran’s Day
• Thanksgiving Day
• Christmas Day
2.3.2 Emergency Services
Contractors will be included in Call Tree for After-Hour Emergency Support. If the COR is not available or the need exceeds the manpower available, contractors may be contacted to assist. Contractors should be available to respond in most cases within a maximum of forty-five (45) minutes. The COR is responsible for determining whether or not the situation is a true emergency. If the COR is not available, then the responding contractors are responsible for making this determination. If the situation is determined to be a true emergency, the responding party should respond as soon as possible. If the situation is not an emergency, the responding party shall notify the reporting party that the request will be responded to at the start of the next business day.
2.4 Phase-Out
a. Before the completion of this contract, an observation period shall occur, at which time team management personnel of the incoming Contractor may observe operations. This will allow for orderly turnover of facilities, equipment, and records and will help to ensure continuity of services. The outgoing Contractor is ultimately responsible for performing full services IAW the contract, during the phase-out period, and shall not defer any requirements to avoid responsibility or of transferring, such responsibility to the succeeding Contractor. The outgoing Contractor shall fully cooperate with the succeeding Contractor and the Government, so as not to interfere with their work or duties.
b. To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the outgoing Contractor shall have all personnel on board during the phase-out period.
c. The incoming Contractor shall develop a phase-out plan to affect a smooth and orderly transfer of contract responsibility to a successor. The plan shall fully describe the Contractor’s approach to the following issues, at a minimum: Inventories and turn-over of government property;
reconciliation of all property accounts; turn-in of excess property; data and information transfer;
and any other actions required to ensure continuity of operations. The Contractor shall provide the plan to the COR 30 days after the award of the contract.
6 | P a g e
2.5 Government Furnished Equipment (GFE)
The Government shall furnish at a minimum for each contractor employee a laptop computer or computer workstation, with appropriate additional hardware (e.g., mouse, keyboard, card readers, monitor, and headsets) and software programs sufficient to complete assigned tasks. All hardware will be shipped by the Government to each contractor Employee. The Contractor is responsible for returning all of the hardware upon separation. The Government shall provide domain access and email accounts to Contractor staff as determined by the COR to be appropriate.
2.6 Section 508 Compliance
All Electronic and Information Technology (EIT) procured through this task, including supporting documentation, shall meet the applicable accessibility standards of 36 CFR 1194, unless an agency exception to this requirement exists. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at www.section508.gov. The Contractor shall ensure that task deliverables comply with this standard.
2.7 HHS-Controlled Facilities and Information Systems Security
a. To perform the work specified herein, (1) logical access to an HHS-controlled information system; (2) access to sensitive HHS data or information, whether in an HHS- controlled information system or in hard copy; or (3) any combination of circumstances (1) through (3).
b. To gain routine physical access to an HHS facility, logical access to an HHS-controlled information system, and/or access to sensitive data or information, the Contractor and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; Office of Management and Budget memorandum (M-05-24); and Federal Information Processing Standards Publication (FIPS PUB) Number 201.
c. This contract/order will entail the following position sensitivity level(s): Tier 2 – Moderate Risk Public Trust
d. The personnel investigation procedures for Contractor personnel require that the Contractor prepare and submit background check/investigation forms based on the type of investigation required. The minimum Government investigation for a non-sensitive position is a National Agency Check and Inquiries (NACI) with fingerprinting. More restricted positions – i.e., those above non-sensitive, require more extensive documentation and investigation.
e. As part of its proposal, and if the anticipated position sensitivity levels are specified in paragraph
(c) above, the Offeror shall notify the Contracting Officer of (1) it's proposed personnel who will be subject to a background check/investigation and (2) whether any of its proposed personnel who will work under the contract have previously been the subject of national agency checks or background investigations.
f. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable per the FAR clause, Excusable Delays.
g. Accordingly, if position sensitivity levels are specified in paragraph (c), the Offeror shall ensure
DRAFT
https://www.section508.gov/ https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.dhs.gov/homeland-security-presidential-directive-12 https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2005/m05-24.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2005/m05-24.pdf https://csrc.nist.gov/publications/detail/fips/201/2/archive/2013-09-05 https://csrc.nist.gov/publications/detail/fips/201/2/archive/2013-09-05
7 | P a g e that the employees that it proposes for work under this contract have a reasonable chance for approval.
h. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may justify reduction(s) in the contract price at the Contracting Officer’s discretion. This reduction will be no more than the cost of the additional investigation(s).
i. The Contractor shall include language similar to this “HHS-Controlled Facilities and Information Systems Security” language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS- controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or hard copy; or (4) any combination of circumstances (1) through (3).
j. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.
k. Within 7 calendar days after the Government’s final acceptance of the work under this contract, or upon the termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.
2.8 Other Administrative Information
Vendors operating in the state of New Mexico are subject to payment of the New Mexico Gross Receipts Tax (NM GRT).
The Contractor shall have a complete understanding of the IHS security policy and procedures and comply with such security requirements, including user access and verification requirements such as levels of access, password protection, and firewalls.
The Contractor agrees to comply with the applicable security requirements. The Contractor agrees to establish and follow security precautions considered by IHS to be necessary (which are subject to change during the contract) to ensure proper and confidential handling of data and information. This information is more specifically addressed in the IHS Information Security Program Policy. Current policy also requires all contractor staff performing work on IHS projects and/or connecting to IHS systems to have a Background Investigation (including fingerprints and credit release). The investigation process is initiated during the hiring and a pre-clearance is required before the commencement of duties. The Contractor shall ensure that no prospective hires appear on the Office of Inspector General (OIG) exclusion list of convicted felons (http://exclusions.oig.hhs.gov/). All costs associated with Background Investigation are to be borne by the Contractor; the Government will conduct the BI and will advise the Contractor of the costs.
Some information included in this task may be protected by the provisions of the Privacy Act of 1974 and/or the HIPAA Privacy Rule. All personnel assigned to this task will take the proper precautions to protect such information from disclosure.
The Government will retain rights to any intellectual property produced in the course of this task. The Contractor shall not divulge or disclose information received and discussed regarding data considered proprietary to other Contractors collaborating on or with this project.
http://exclusions.oig.hhs.gov/
8 | P a g e
3. Scope of Requirements
3.1 Primary Objectives
a. Maintain existing web applications and websites or develop new technology to be these needs.
b. Develop, design, and test the implementation of updates to new or existing websites, web applications, web components, and content in all environments. This includes the administration of all database instances. Refer to Appendix B and C for more details.
c. Develop and maintain web services documentation for projects and systems. This includes, but is not limited to, the documents in Appendix F.
d. Maintain and manage all environments listed in Appendix C.
e. Enable and maintain SharePoint Online in the IHS O365 tenant and prepare IHS for migration from SharePoint 2013 to SharePoint Online.
f. Ensure security compliance and accessibility per all IHS and federal regulations. This includes, but is not limited to, the following:
a. Federal Information Security Modernization Act (FISMA) of 2014
i. Agencies must develop an enterprise-wide security program
ii. NIST must develop security standards and guidelines
b. HHS Information Security and Privacy Policy (IS2P)
i. Op. Divs. must use NIST standards and guidelines to document, assess, and authorize systems
c. Indian Health Manual (IHM), Part 8, Chapter 12
i. All systems must be authorized to operate before going “live”
d. Federal Information Processing Standards (FIPS)
i. FIPS 199 – Categorization
ii. FIPS 200 – Minimum Security Controls
iii. FIPS 140-3 – Encryption
e. NIST Special Publications (SP) 800 Series
i. 800-37, Revision 2 – Risk Management Framework (RMF)
ii. 800-53, Revision 4 – Security Control Catalog
iii. 800-18, Revision 1 – System Security Plans (SSP)
iv. 800-34, Revision 1 – Contingency Planning
v. 800-47 – Interconnection Agreements
vi. 800-137 – Continuous Monitoring
vii. 800-145 – Definition of Cloud Computing
f. IHS RMF Implementation Plan
g. IHS Security Assessment & Authorization (SA&A) SOP
h. Other Related Standard Operating Procedures (SOPs)
g. IHM Part 10, Cybersecurity Maintain and improve the program management of all IT Projects according to the established IHS standards and Health and Human Services (HHS) Enterprise Performance Life Cycle (EPLC) standards where applicable.
9 | P a g e
3.2 Develop and Maintain Website Content
a. Manipulate graphics/images and optimize for website use. This is currently done using Adobe Creative Cloud (CC).
b. Design websites using languages like ColdFusion Markup Language (CFML), Hypertext Markup Language (HTML), HTML5, JavaScript, jQuery, Bootstrap, and Cascading Style Sheets (CSS) with IDEs like Mura Content Management System (CMS), Dreamweaver, and Eclipse. The government shall provide all required software/subscriptions. This includes, but is not limited to, the software in Appendix E.
c. Develop templates for mobile, desktop, and responsive design.
d. Develop graphic mockups based on user requirements.
e. Develop and maintain a standard icon library using services like Getty Images.
f. Provide user support for all web content managers, who are responsible for providing and approving all information displayed on our websites.
g. Adhere to all web federal laws and regulations outlined at, http://www.digitalgov.gov/resources/checklist-of-requirements-for-federal-digital-services/
h. Review and modify content to make it compliant with Section 508 and usability requirements established by the IHS, HHS, and the federal government. This includes, but is not limited to, formatting documents, converting video files, and subtitling video and audio files. Currently using Site Improve and Adobe CC to accomplish this.
i. Executable code will be pushed to the live production server twice a week. Refer to 4.4, Deliverables Schedule
3.3 Develop and Maintain Web Applications
a. Develop documentation, including Systems Requirements Specifications (SRS) documents and Business Requirements Documents (BRD) for web applications.
b. Develop web-based Graphical User Interfaces (GUIs) that comply with IHS usability and programming standards.
c. Develop reports based on project sponsor requirements. See section 4.4 Deliverables Schedule.
d. Develop templates for mobile, desktop, and responsive design.
e. Establish and maintain a web standards library and Standard Operating Procedures (SOP) for IHS.gov.
f. Manage and maintain all Web Service databases as they relate to the web applications.
g. Develop web applications according to Section 508 and Usability requirements established by the IHS, HHS, and the federal government.
h. Provide User Support for all web application users internal and external to IHS.
i. Provide application-level support for all IHS.gov web servers – this includes patching, troubleshooting, and bug fixes.
http://www.digitalgov.gov/resources/checklist-of-requirements-for-federal-digital-services/
10 | P a g e
j. Develop wireframes and prototypes of web applications, before coding, and make them available to the project team via SharePoint.
k. Compile and provide information describing all database tables, indexes, and formats used for each application.
l. Develop design specification documents, which include system view diagrams, software prerequisites, any typical hardware or system requirements, and any additional caveats or warnings.
m. Design project test plans documenting the testing process to determine how proposed changes/enhancements will be validated and meet the required business needs.
n. Develop and deliver ad hoc presentations and informal training for members of the Web Services team as needed.
o. Executable code will be pushed to the live production server twice a week. Refer to 4.4, Deliverables Schedule
p. Adhere to all web federal laws and regulations outlined at the following:
http://www.digitalgov.gov/resources/checklist-of-requirements-for-federal-digital-services/
3.4 Develop Content & Documentation
a. Develop and review IHS.gov content for plain writing, consistent voice, readability, and IHS.gov Style Guide compliance.
b. Prepare and maintain system documentation for Web Applications per federal requirements.
c. Provide informal training and support to IHS.gov web content managers for documentation compliance needs.
d. Maintain an up-to-date list of web content managers for every subdirectory/site. There are currently 270 web content manager accounts.
e. Maintain a record of IHS.gov documentation outlining overall Section 508 compliance where deficiencies exist.
f. Review reports generated by the website crawling tool to determine quality issues and create plans to address them.
g. Develop and maintain up-to-date documentation for all information used to support the production IHS.gov environment.
h. Develop required documentation to attain and maintain Web Services Authority to Operate (ATO). Anticipated approval of our ATO is January 2023. An ATO is typically valid for three years, unless otherwise noted in the ATO Memo. Assessments can occur out of cycle if the system undergoes a significant change. Significant change assessments are scoped to include only those controls that are affected by the change. This includes, but is not limited to, the documentation in Appendix F.
i. All documents shall be available to the Contracting Officer’s Representative (COR), other IHS staff, and contract staff.
DRAFT
11 | P a g e
3.5 Develop and Maintain SharePoint Environments
a. Respond to SharePoint requests within 1 business day.
b. Create SharePoint sites for employees within 3-5 business days of receiving requests.
c. Provide technical support for the entire SharePoint environment.
d. Prepare SharePoint 2013 environment for migration to SharePoint Online (SPO).
e. Establish a standard look and feel of SharePoint sites and assist in enforcement.
f. Develop and document SharePoint enterprise policies in collaboration with COR.
g. Provide training for employees on the use of SharePoint and its available features.
h. Monitor server usage and report findings monthly.
i. Provide architecture and governance guidance. Documentation produced from these decisions will be kept in an electronic continuity binder (ex. Office drive or SharePoint).
j. Work with other IHS vendor(s) for any new environment upgrades and migrations.
k. Guide setup/configuration of using cloud storage versus server storage.
l. Research, develop, and implement features and functionalities that are unavailable at this time, such as eDiscovery, workflows, records management, and other capabilities of SharePoint 2013 and SPO.
m. Act as the primary support role for end users.
n. Provide guidance and migrate from SharePoint 2013 to SPO.
3.6 Manage and Maintain Server Environments
a. Maintain operation of all IHS.gov system servers including, but not limited to, the LISTSERV servers, SharePoint servers, Web servers, and Database servers. Refer to Appendix D for more details.
b. Monitor and manage system resources, including Central Processing Unit (CPU) usage, disk usage, and response times to maintain operating efficiency.
c. Perform systems security administration functions, including creating user profiles and accounts and system security patches.
d. Maintain system documentation in an electronic continuity folder.
e. Install system-wide software and allocate storage space, coordinate installation, and provide backup recovery. Refer to Appendix C & Appendix D for more details about server types and server environments.
f. Develop and monitor policies and standards for allocation related to the use of computing resources.
g. Analyze the current server environments to determine if there are new technologies and innovative features to enhance and optimize the web environment. Findings should be reported to the CORs during weekly meetings to determine feasibility, develop plans/schedules, and implement these changes as applicable.
12 | P a g e
3.7 Manage and Maintain Databases
a. Maintain Database Server environment.
b. Implement and optimize the database systems that support all Web Service environments.
c. Conduct performance tuning of indexes and databases.
d. Review database design and integration of systems, provide backup recovery, and make recommendations regarding enhancements and/or improvements. Findings should be reported to the CORs during weekly meetings to determine feasibility, develop plans/schedule and implement as applicable.
e. Maintain security and integrity controls.
f. Formulate policies, procedures, and standards relating to database management, and monitor transaction activity and utilization.
g. Oversee the scheduling of database projects, database and transaction log backups, notifications, and database replication.
h. Review technical designs, reports, documentation, and other materials produced by staff.
i. Maintain and improve all Disaster Recovery Plans (DRP) to include design, configuration, testing, and documentation yearly.
3.8 Alerts management, monitoring, and reporting
a. The Contractor will be required to support all routine monitoring of the web server infrastructure, critical services, and website issues.
b. The CORs are required to be notified of all critical service impacts and outages. Monthly reports on service availability required for all web systems and services identified.
3.9 Project Management
a. Conform to IHS Office of Information Technology Program/Project Management Processes consistent with the HHS Enterprise Performance Life Cycle (EPLC) Policy.
b. Establish Change Management Plans and Risk Management Plans, documenting proposed changes and risk mitigation. Refer to Appendix F.
c. Provide project management of contracted activities including the tracking and reporting on web services projects that reflect status and variance including schedule.
d. Maintain a Work Breakdown Structure (WBS) describing the operational and developmental activities including key deliverables in Microsoft Project format.
e. Provide customer-level access to weekly updated WBS and schedule status and variances at both summary and detail levels via SharePoint.
f. Utilize an IHS-provided time tracking system to monitor and manage contractor hours expended to support IHS projects by project and number of hours.
g. Provide Program support and other data or information related to Contractor activities that are required for effective management of the Investment by the Program Manager, including that https://www.hhs.gov/web/governance/digital-strategy/it-policy-archive/policy-for-information-technology-enterprise-performance.html
13 | P a g e required by the HHS Capital Planning and Investment Control (CPIC) and OMB Exhibit 53 and 300.
h. Provide proactive outreach support to IHS and program stakeholders to translate customer requirements into the technical solution as well as an advisement to the IHS program manager regarding stakeholder perspectives and requirements.
i. Utilize IHS available tools for project management: Microsoft Project and Planview.
3.10 Data Quality Assurance
a. Maintain and improve a quality assurance process that ensures technical requirements are established; products and services conform to established technical requirements, and satisfactory performance is achieved for contracted services.
b. The contractor shall submit a finalized Quality Assurance Plan within 30 days of award providing a plan on how it intends to assure that all contract requirements and objects will be accomplished throughout the base period and all option periods.
3.11 Security Requirements
a. Ensure that all system access controls maintain compliance with the logical access control as specified in Homeland Security Presidential Directive 12 (HSPD-12)
b. Ensure that the system security objectives and needs are met and the appropriate level of effort for the system risk management activities is determined per FIPS Publication 199, NIST SP 800- 30.
c. Ensure that the security controls needed to adequately protect the system meet the security requirements of the system and are selected per NIST SP 800-53, Federal regulations, HHS policy, and IHS IT Security Policies listed in the Indian Health Manual.
d. Verify that all selected encryption products are validated under the Cryptographic Module Validation Program to confirm compliance with FIPS and provide a written copy of the validation documentation to the COR.
e. Maintain security processes that prevent the release, publication, or disclosure of information to unauthorized personnel, and protect such information per provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of sensitive information:
18 U.S.C. 641 (Criminal Code: Public Money, Property or Records); 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and Public Law 96-511 (Paperwork Reduction Act).
f. Ensure all identified IHS.gov web application users are assigned the appropriate level of security and report access as defined by the application owner before production status.
g. Collaborate with the IHS OIT Division of Information Security to facilitate initial and periodic system security assessment and authorization as well as continuous monitoring activities.
h. Resolve new risks identified by IHS, HHS, and any third-party vendors. When necessary, develop Plan of Action and Milestones (POAMs) in collaboration with the IHS Office of Information Technology Division of Information Security.
DRAFT
https://www.hhs.gov/digitalstrategy/hhs-ocio-cpic-policy-2016.html https://ocio.commerce.gov/page/commerce-and-omb-exhibit-30053-guidance https://ocio.commerce.gov/page/commerce-and-omb-exhibit-30053-guidance https://www.dhs.gov/homeland-security-presidential-directive-12 https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://www.hhs.gov/hipaa/for-professionals/security/index.html https://www.hhs.gov/hipaa/for-professionals/security/index.html https://www.ihs.gov/IHM/pc/
14 | P a g e
i. Additionally, remediate any security flaws discovered by the HHS/Federal security-scanning tool(s) and comply with remediation deadlines.
4. Deliverables The Contractor shall perform tasks and provide the deliverables as specified in the following sections. If in the Contractor’s experience some tasks or work products would provide more value to the government with different deliverable schedules or task-sequencing (result delivered as part of the different task), this may be proposed with a justification. The government reserves the right to require the items to be delivered within the task or timeframe described below.
4.1 Weekly Contract Status and Progress Review
The Contractor shall participate in weekly review meetings and be prepared to present and discuss the following with the COR and other Federal staff.
• Activities planned for the week.
• Work and deliverables completed during the period.
• Status of ongoing activities.
• Activities planned for the following period.
• Problems or issues projected or identified.
• Alternatives and/or recommended solution(s) for identified or projected problems or issues Known or projected resource (staff and funding) and schedule impacts.
4.2 Weekly Project Dashboard
The Contractor shall provide a weekly project dashboard that tracks the activity of Web Services Contractor staff. The weekly project dashboard may be delivered in combination with the weekly contract status and progress review. This deliverable shall be submitted in electronic format utilizing Microsoft Office format unless prior approval for another format has been obtained from the COR. The content shall include the following:
• Active projects
• Non-Project Development
• Closed projects
• Project queue
• Pending queue over time
• Resource allocation
• Resource allocation graph
4.3 Monthly Report
The Contractor shall provide a monthly status report of contract effort. This report must be suitable for forwarding to executive management. This deliverable shall be submitted in electronic format utilizing Microsoft Word or PDF to the COR. The content shall include the following major sections:
• Major Accomplishments
• Updates on major Projects/Initiatives
• Issues/Concerns
15 | P a g e
4.4 Deliverables Schedule
Deliverable Schedule Required Submission Format
Weekly Contract Status and Progress Review Tuesday of every week Meeting/Spreadsheet
Weekly Project Dashboard Friday of every week Meeting/Spreadsheet
Monthly Status Report No later than the 15th of the following month
Meeting/Spreadsheet
Quality Assurance Plan Draft due with proposal. Final due 30 day after Award
Written Plan/Word or PDF
Phase Out Plan 30 Days after Award Written Plan/Word or PDF
Service Availability Monthly Report No later than the 15th of the following month
Meeting/Spreadsheet
Server Usage Monthly Report No later than the 15th of the following month
Meeting/Spreadsheet
Code Push Every Tuesday and Thursday Executable code/Email notification
Disaster Recovery Plan Annually – Initial review by 15 Jan (ATO required document)
Written Plan/Word or PDF
Risk Management Plan Initial review of current plan due within 30 days of contract award. Annually After.
Written Plan/Word or PDF
Configuration Management Plan Initial review of current plan due within 30 days of contract award. Annually After.
Written Plan/Word or PDF
16 | P a g e
5. Services Summary
Performance Objective Performance Standard Acceptable Quality Level (AQL) Surveillance Method / by whom
3.2 Develop and maintain
websites
Deliver the website into production on the date scheduled.
Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection/ Customer Feedback
3.2 Develop and maintain
websites
Section 508 Compliance Deficiencies will be remedied within 1 week of discovery.
Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection/ Customer Feedback
3.3 Develop and maintain
web applications
Deliver web application into production on the date scheduled.
Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection/ Customer Feedback
3.3 Develop and maintain
web applications
Section 508 Compliance Deficiencies will be remedied within 1 week of discovery.
Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection/ Customer Feedback
3.4 Develop Content and
Documentation
Technical Guides, User Manuals, and system plans.
95% of maintained system documentation is reviewed, modified, and delivered within 7 workdays of its scheduled due date; no scheduled documentation updates are delivered more than 14 work days after its scheduled due date.
COR Routine Monitoring / Customer Feedback
3.4 Develop Content and
Documentation
Develop required documentation to attain and maintain Web Services Authority to Operation (ATO).
100% of documentation to support the ATO delivered by the agreed-upon date.
COR Routine Monitoring
3.5 Develop and Maintain
SharePoint Environment
Maintain patching and remediate vulnerabilities. Deliver updates into production on the date scheduled.
95% of Security requirements are met within 5 workdays of the agreed-upon date with the IHS Division of Information Security and are acceptable. Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection / Customer Feedback
17 | P a g e
3.5 Develop and Maintain
SharePoint Environments
Respond to SharePoint requests within 1 business day
Meets 1 business day requirement 95% of the time.
Routine Monitoring / COR Routine Inspection / Customer Feedback
3.5 Develop and Maintain
SharePoint Environments
Create SharePoint sites within 3-5 business days of receiving requests
Meets 3-5 business day requirement 95% of the time.
Routine Monitoring / COR Routine Inspection / Customer Feedback
3.6 Manage and Maintain
Server Environment IHS.gov uptime. IHS.gov maintains 99.95% uptime (not inclusive of planned maintenance).
Routine Monitoring, Direct Observation / COR Routine Inspection
3.7 Manage and Maintain
SQL Database
Maintain patching and remediate vulnerabilities. Ensure backups are performed routinely and are usable. Database uptime.
95% of Security requirements are met within 5 workdays of the agreed-upon date with the IHS Division of Information Security and are acceptable. Errors with backup jobs should be detected and reported within 1 business day. SQL Database maintains 99.95% uptime (not inclusive of planned maintenance).
Routine Monitoring / COR Routine Inspection
3.8 Alerts management, monitoring, and reporting
Respond to critical services alerts and report to COR
Critical server alerts detected and reported within 1 business day.
All critical service alerts will be reported monthly
Routine Monitoring / COR Routine Inspection
3.9 Project Management Deliver Reports by
schedule in Section 4.4
Deliver within a 10% schedule variance of the agreed-upon date.
Routine Monitoring / COR Routine Inspection
3.10 Data Quality
Assurance
Create Quality Assurance Plan
Draft due with Proposal and Final due within 30 days of contract award
Routine Monitoring / COR Routine Inspection /
3.11 Security
Requirements
Maintain patching and remediate vulnerabilities
95% of Security requirements are met within 5 workdays of the agreed-upon date with the IHS Division of Information Security and are acceptable.
Routine Monitoring / COR Routine Inspection
4. Deliverables Deliverable is provided on schedule.
Deliverable is provided no later than three days after the agreed-upon date.
COR Routine Monitoring
18 | P a g e
6. Appendices
Appendix A - Business Associate Agreement (BAA) IAW HHSAR 324.70
Pursuant to the Health Insurance Portability and Accountability Act (HIPAA) of 1996; it’s implementing regulations, the Standards of Privacy of Individual Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E (“Privacy Rule”), and 45 C.F.R. Parts 160 and 164, Subparts A and C (“Security Rule”); and the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), Title XIII, Subtitle D of the American Reinvestment and Recovery Act of 2009, Pub. L. No. 111-5, 123 Stat.
115 (2009) (“ARRA”), the Indian Health Service is required to enter into an agreement with the Business Associate, pursuant to which the Business Associate shall comply with and appropriately safeguard Protected Health Information ("PHI”) that it will use and disclose when performing functions, activities or services ("Services") for the Indian Health Service pursuant to this Contract. The Business Associate by signing the Contract shall comply with the following terms in addition to other applicable Contract terms and conditions relating to the safekeeping, use, and disclosure of PHI.
Section 1 - Definitions Terms used in this Agreement, if not otherwise defined, shall have the same meaning as those terms contained within the Privacy Rule and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
a. Breach: “Breach” shall mean the unauthorized acquisition, access, use, or disclosure of Protected Health Information (defined hereinafter) which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information;
b. Covered Entity: "Covered Entity" shall mean the Indian Health Service (IHS);
c. De-identified protected health information: “De-identified protected health information” shall have the same meaning as the term “de-identified protected health information” in 45 C.F.R. § 164.
514;
d. Designated Record Set: "Designated Record Set" shall mean (1) a group of records maintained by or for a covered entity that is: (i) The medical records and billing records about individuals maintained by or for a covered health care provider, (ii) The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan, or (iii) Used, in whole or in part, by or for the covered entity to make decisions about individuals. (2) For purposes of this paragraph, the term record means any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity; (45 C.F.R. § 164.501)
e. Electronic Health Record: “Electronic Health Record” shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff;
19 | P a g e
f. Individual: "Individual" shall have the same meaning as the term "individual" in 45 C.F.R. §
164.501 and shall include a person who qualifies as a personal representative in accordance with 45 C.F.R. § 164.502(g);
g. Limited Data Set: “Limited Data Set” shall have the same meaning as the term “limited data set” in 45 C.F.R. § 164. 514(e) (2);
h. Privacy Rule: "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E;
i. Protected Health Information: "Protected Health Information" or “PHI” shall have the same meaning as the term "protected health information" in 45 C.F.R. § 160.103;
j. Required By Law: "Required By Law" shall have the same meaning as the term "required by law" in 45 C.F.R. § 164.501;
k. Secretary: "Secretary" shall mean the Secretary of the United States Department of Health and Human Services or her designee;
l. Unsecured Protected Health Information: “Unsecured Protected Health Information” or “Unsecured PHI” shall mean protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary in guidance on the HHS website issued under section 13402(h)(2) of the HITECH Act.
Section 2 - Compliance The Business Associate agrees to comply with the business associate contract requirements under the Privacy Rule, the HITECH Act, and the provisions of this Agreement throughout the term of this Agreement. The Business Associate agrees that it will require all of its agents, employees, subsidiaries, affiliates, and subcontractors, to whom the Business Associate provides Personal Health Information (PHI), or who create or receive PHI on behalf of the Business Associate for the IHS, to comply with the Privacy Rule and the HITECH Act, and to enter into written agreements with the Business Associate that provide the same restrictions, terms and conditions as set forth in this Agreement.
In the event the Business Associate awards a subcontract under the Contract pursuant to which the Business Associate will disclose PHI to the subcontractor, notwithstanding any clause to the contrary contained in the Contract, the Business Associate agrees to obtain the IHS Contracting Officer’s written consent prior to awarding such subcontract.
Section 3 - Permitted Uses and Disclosures The Business Associate shall not use or disclose PHI except to perform functions, activities or services for or on behalf of the IHS as provided for in this Agreement, the Privacy Rule, the HITECH Act or other applicable law. The Business Associate agrees that it may use or disclose PHI on behalf of the IHS only
(1) upon obtaining the authorization of the patient to whom the PHI pertains (45 C.F.R. §§ 164.502(a)
(1) (iv) and 164.508(b)); (2) for the purpose of treatment, payment or health care operations (45 C.F.R.
§§ 164.502(a) (1) (ii), and 164.506)), unless disclosure has been restricted pursuant to the HITECH Act at § 13405(a), or (3) without authorization or consent, if in accordance with 45 C.F.R. §§ 164.506,
164.5 10, 164.512, 164.514(e), 164.514(f) or 164.514(g). The Business Associate shall use and disclose
20 | P a g e
PHI in compliance with each applicable requirement of 45 C.F.R. § 164.504(e), which section is fully incorporated herein. Except as otherwise limited in this Agreement, the Business Associate may use PHI for the management and administration of the Business Associate or to carry out responsibilities that are required of it by law (45 C.F.R. § 164.502(e)(4)(i)).
Section 4 - Safeguards The Business Associate shall develop and use appropriate procedural, physical, and electronic safeguards to protect against the use or disclosure of PHI in a manner not permitted by the Privacy Rule or this Agreement. The Business Associate will limit any use, disclosure, or request for the use or disclosure of PHI to the minimum amount necessary to accomplish the intended purpose of the use, disclosure, or request in accordance with the applicable requirements of the Privacy Rule. As mandated by the HITECH Act, Privacy Rule sections 164.308 (administrative safeguards requirements),
164.310 (physical safeguards requirements), 164.312 (technical safeguards requirements), and
164.316 (policies and procedures and documentation requirements) shall apply to the Business Associate in the same manner that such sections apply to covered entities under the Privacy Rule.
Section 5 – Minimum Necessary Prior to the Secretary issuing guidance on what constitutes “minimum necessary” for purposes of the Privacy Rule, the Business Associate will limit, to the extent practicable, any use, disclosure, or request for use or disclosure of PHI (other than those uses, disclosures or requests for use or disclosure of PHI set forth at 45 CFR section 164.502(b)(2)), to the Limited Data Set, or, if needed, to the minimum amount necessary to accomplish the intended purpose of such use, disclosure or request, respectively. Upon the effective date of the Secretary’s ”minimum necessary” guidance, the Business Associate will limit any use, disclosure, or request for use or disclosure of PHI, to the minimum amount necessary as set forth in such guidance.
Section 6 - Safeguards for Electronic PHI The Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any electronic PHI that it creates, receives, maintains, or transmits on behalf of the IHS as required by 45 C.F.R. Part 164, subpart C, Security Standards for the Protection of Electronic Health Information. Section 4 above shall apply in full to this Section 6.
Section 7 - Reporting of Unauthorized Uses or Disclosures The Business Associate shall promptly report to the IHS any knowledge of uses or disclosures of PHI that are not in accordance with this Agreement or applicable law. In addition, the Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by the Business Associate in violation of the requirements of the Privacy Rule or the HITECH Act. For those uses or disclosures that involve a breach of the security of any unsecured PHI received from, or created or received on behalf of, the IHS, the Business Associate shall comply with the requirements set forth in Section 8 below.
Section 8 - Reporting of Breach of Unsecured PHI The Business Associate shall notify the IHS of a breach of the security of any unsecured PHI that the Business Associate received from, or created or received on behalf of, the IHS within thirty (30) calendar days after the discovery of the breach by the Business Associate, its employees, officers and/or other agents unless a law enforcement official has determined that such notification would
21 | P a g e impede a criminal investigation or cause damage to national security, in which case the notification shall be delayed in accordance with the requirements of 45 C.F.R. § 164.412. Such notice shall include, to the extent possible, the identification of each individual whose unsecured PHI has been or is reasonably believed by the Business Associate to have been, accessed, acquired, or disclosed during such breach; a brief description of the circumstances of the breach of security, including the date of the breach and the date of the Business Associate’s discovery of the breach; and the type of unsecured PHI involved in the breach. In the event notification is delayed, evidence demonstrating the necessity of the delay shall accompany the notification. A breach shall be treated as discovered as of the first day on which such breach is known to Business Associate (including any person, other than the individual committing the breach that is an employee, officer, or other agents of Business Associate) or should have reasonably been known to Business Associate (or person) to have occurred.
Section 9 – Maintenance of Records and Accounting of Disclosures The Business Associate shall maintain records of PHI received from or created or received on behalf of the IHS and shall document subsequent uses and disclosures of such information by the Business Associate. W ithin 5 calendar days after receiving a request from the IHS the Business Associate shall provide to the IHS such information as the IHS may require fulfilling its obligations to provide access to, provide a copy of, and account for disclosures with respect to PHI pursuant to the Privacy Rule (e.g., 45 C.F.R. § 164.528) (individual request for an accounting of PHI disclosures), the HITECH Act and other applicable law. In accordance with the requirements of HITECH Act section 13405(c), beginning on [need to determine if BA already has an EHR system and then put in applicable date based on the requirement of HITECH section 13405(c)(4)], the Business Associate shall account for all disclosures of PHI for treatment, payment, and health care operations purposes.
Section 10 - Maintenance of Records and Accounting: Individual Access The Business Associate shall maintain a Designated Record Set for each patient for which it has PHI.
In accordance with a patient's right to access his/her PHI under the Privacy Rule, the Business Associate shall make available all PHI in the patient's Designated Record Set to the patient to whom that information pertains, or, upon the request of the patient, to that patient's authorized representative, in compliance with 45…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .