Attachment 1_PACS Radiology PWS dated 29 April 2021.pdf
PDF 549 KB Posted
- Attached to
- JBER PACS Radiology FY21 Federal contract opportunity
- Solicitation number
- FA5000-21-Q-0035
About this file
This is a performance work statement (PWS) for Picture Archiving and Communication System (PACS) Radiology support services at Joint Base Elmendorf-Richardson in Alaska. The contractor shall provide personnel to inspect, service, and maintain the 673rd Medical Group's PACS and component systems to ensure safe and reliable operation. The PACS includes servers, workstations, imaging plates, CD production equipment, voice dictation systems, and interfaces to the electronic health record and archive. The contractor will be responsible for daily system monitoring, user management, network management, study monitoring, and providing service support and maintenance. The period of performance is a one year base period from June 1, 2021 to May 31, 2022 with four one-year option periods to extend through May 31, 2026. The contractor shall provide on-site and on-call support in accordance with specified hours of operation and response times.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Q and A PACS Radiology FA500021Q0035.pdf | ||
| Attachment 2_Price Schedule.docx | DOCX document | |
| PACS Radiology_Combo.pdf | ||
| Attachment 3_SCA-WD No. 2015-5681.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
29 April 2021
PERFORMANCE WORK STATEMENT (PWS)
Hospital Radiology Picture Archiving & Communication System (PACS) Support
LOCATION TITLE PAGE
Section 1 Description Of Services 2
Section 2 Contractor Objectives & Responsibilities 4
Section 3 Performance Evaluation 8
Section 4 Experience, Training And Certifications 9
Section 5 General Information 10
Section 6 Government Furnished Property 16
Section 7 Business Associate Agreement 17
Appendix 1 Definitions And Acronyms 27
Appendix 2 Reference Publications And Forms 30
SECTION 1
DESCRIPTION OF SERVICES
1.1. Scope: Contractor shall provide personnel (def. A1.1.8) capable of performing Systems
Engineering and Program Management to inspect, report, service, provide preventive maintenance and repairs necessary to keep the 673d Medical Group’s Picture Archive Computer System
(PACS) and component systems functioning in a safe and reliable condition.
1.2. Background: The 673 MDG is comprised of six squadrons: Operational Medical Readiness, Dental, Inpatient Operations, Health Care Operations, Medical Support, and the Surgical
Operations Squadron – along with Medical Group staff. It is a specialty hospital with 49 primary, specialty, and surgical care clinics, 55 inpatient beds, and eight operating rooms. The hospital supports 30,820 enrolled beneficiaries to include 6,064 Active Duty Air Force personnel. We also provide specialty and surgical care support for 4,960 Active Duty Army personnel (empaneled to the Troop Medical Clinic on the Richardson side of base) and all facets of medical care to their families.
1.2.1. The 673d Diagnostic Imaging (DI) PACS is a virtual radiology center. The PACS is driven by Fuji Synapse software. Synapse is used throughout the Pacific Air Force Command to facilitate diagnostic interpretation of radiology images, provide access to patient images, order and view result information anywhere within the Command, as well as archive all patient images in a central location. The long-term image storage is an AGFA IMPAX IDC system. Synapse interfaces to the electronic health record (EHR) at each site to gather patient demographic, order, and result information. The PACS has its own database but can access any other Air Force site using the
Synapse CommonView feature in addition to accessing various Army and Navy sites. The PACS includes 14 virtualized servers, which include; a database server, storage server, dictation server and a test server. A compact disk (CD) burner device, PACSCube, provides the ability to copy images on a CD for the patient and their offsite providers. The database and images acquired at the site are copied to the applicable archive. Local backups of the images and database are done on a daily basis.
1.3. Contractor Responsibility Overview:
1.3.1. Contractor will be directly responsible for the daily operation of the following systems and devices:
a. Image Processing Workstation
b. Digital Imaging Plate
c. CD Production Equipment (PACSCube)
d. Regional Archive equipment (AGFA archive system)
e. Voice Dictation System (PowerScribe 360)
g. Picture Archive and Communication System (PACS)
h. Electronic Health Record (EHR) match Synapse orders
1.3.2. Refer to Section 2 for a complete list of objectives and responsibilities.
1.4. Location, Times and Period of Performance:
1.4.1. Location: 673d Medical Group, Diagnostic Imaging Flight
5955 Zeamer Avenue, JBER, AK 99506
1.4.2. Normal Office Hours: Contractor shall report to the Diagnostic Imaging Flight and be on site 0800 to 1630, Monday through Friday. Contractor personnel are not required on Federal
Holidays (Refer to 5.2.2.), designated Family days, nor on 673d Air Base Wing down Days.
1.4.3. Telephone Service Hours: The Diagnostic Imaging clinic requires 24/7/365 emergency support, after hours on-call services are infrequent, historically occurring semi-monthly, and many situations can be handled remotely. The contractor shall:
a. Participate in a rotational on-call schedule consisting of approximately two weeks per month.
b. Respond via telephone to the end-user as soon as is reasonable, but not later than 2-hours after receipt of telephone notification.
c. Be on-site as soon as is reasonable, but not later than 4-hours after system malfunction.
1.4.4. Period of Performance: The period of performance will be from 01 June to 31 May and will follow the timeline below, subject to the clauses and provisions of contract/solicitation.
Base Year: 01 June 2021 to 31 May 2022
Option Year 1: 01 June 2022 to 31 May 2023
Option Year 2: 01 June 2023 to 31 May 2024
Option Year 3: 01 June 2024 to 31 May 2025
Option Year 4: 01 June 2025 to 31 May 2026
SECTION 2
CONTRACTOR OBJECTIVES & RESPONSIBILITIES
2.1 Objectives. The contractor shall operate, administrate and network manage all PACS related servers and workstations which includes the following functions and activities to meet performance objectives:
2.1.1 Daily system monitoring of:
a. Scheduled jobs using monitoring tools.
b. Scheduled backup/archival software.
c. Storage level capacities and assuring that storage levels of all Redundant Array of
Independent Disks (RAID) partitions and Library are controlled appropriately.
d. Server Event Log and resolution of unknown errors as appropriate.
e. Server Hardware, including monitoring RAID.
f. Open work orders. Notify the Medical Equipment Repair Center (MERC) of any problems and collaborate with equipment/maintenance vendor(s) to solve problems.
2.1.2. User Management: Add/Change/Delete users on PACS and related systems, including adding new users, putting new users into appropriate user groups, granting appropriate privileges, changing user profiles, deleting/inactivating users, and maintaining all other PACS and Voice
Dictation System user management functions.
2.1.3. Network Management:
a. Name Resolution, including IP address management and compliance with the Active
Directory (ADX) naming convention.
b. Network trouble-shooting and problem solving, including factors related to network connection, data transfer performance, etc.
2.1.4. Study Monitoring and Patient Information Management:
a. Monitor unmatched studies.
b. Correct studies using drag-drop operation, when images are in the wrong study, when study is in the wrong patient or when patient merge, study re-allocation, or image re-allocation is required.
c. Correct information using Database Management Tool, when patient information is wrong; and for creating new patients, changing patient information.
2.2. Responsibilities. The contractor shall perform the following tasks:
2.2.1. Transfer of external patient exams to PACS:
a. Receive patient CDs from other facilities and transfer exams from the CD to PACS.
b. Confirm that the patient data is correct and available for review.
2.2.2. Training:
a. Provide User Training, including planning and coordinating training (personnel, site, equipment, materials) with vendor personnel, upon System purchase and during software upgrades.
b. Train additional new users and providing refresher training for all users as needed.
c. Participate in System Administrator and QC training provided by vendor; remain current in new versions and techniques.
d. Review and become familiar with supplemental training material provided by the 673d
Medical Group.
2.2.3. Trouble-shooting and Problem Solving:
a. Notify the manufacture or distributor when problems associated with their hardware requires manufacture or distributor support.
b. Analyze and solve problems related to hardware and software supplied by the Air Force.
Work with specific manufactures, distributor and Air Force Information Services personnel to resolve problems, e.g., images cannot be sent or viewed, backup or storage management does not work correctly, reports do not go into the correct folders, etc.
c. Restore data from backup.
d. Work with commercial manufactures or distribution appropriate personnel to analyze and resolve software communication problems, including modality communication problems, RIS communication problems, and other issues of similar type.
2.2.4. System Configuration Changes and Modifications:
a. Notify and coordinate installations with equipment manufactures or distributions when adding new devices (purchased workstations, servers, archives, e.g. supplied by Dell, Fuji, etc.), move or remove supplied hardware, add workstation licenses, database license, DICOM (Digital Imaging and Communication in Medicine) licenses, RIS
(radiology Information System) interface licenses, etc.
b. Install and set up workstation hardware supplied by the organization, including physicians' computers to be able to use PACS viewing software Diagnostic/Review
Desktop workstation license.
c. Notify, plan, and coordinate installation with equipment manufactures or distributors to add modality connections, including interfaces to new modalities.
d. Plan and coordinate software upgrades with appropriate manufacture or distribution personnel. Coordinate the installation and maintenance of other information software
(e.g., MS office, e- mail, etc…) to workstations.
e. Coordinate the installation and maintenance of other software programs (e.g., MS office, e-mail, etc.) to workstations.
f. Track and notify manufactures recommended technical support personnel when modality software upgrades, RIS/HIS system software upgrades, or other related information system upgrades are required.
2.2.5. Manage Voice Dictation System:
a. Monitor reports for errors and completion, consulting with radiologists and clinical staff when required to resolve issues.
b. Maintain RIS connections to ensure communication of orders and reports between systems.
c. Manage database in compliance with vendor specifications. This includes, trained words, short cuts, speech profiles, audio files, and reports.
d. Train new users in basic use of the Voice Dictation System and manage user/admin accounts and profiles.
2.3. Service Support. Contractor shall provide service support maintenance including, but not limited to, the following:
2.3.1. Perform daily operational checks of all systems and correct any deficiencies noted.
"Systems" means the combination of Equipment and related Software, licensed or acquired by the
Government, which comprise the PACS.
2.3.2. Verify that the system's internal and external calibrations are within manufacturer's specifications. Verification shall include reviewing operating system software diagnostics.
2.3.3. Visually inspect exterior of all systems for damage and cleanliness, and report any discrepancies to the PACS Maintenance Contract Monitor.
2.3.4. Make mechanical adjustments to insure proper operation.
2.3.5. Consult with the PACS Maintenance Contract Monitor regarding equipment performance.
2.3.6. Unscheduled Maintenance: The contractor shall provide on-site repair support to correct all malfunctions that may occur.
2.3.7. The contractor shall not remove any equipment owned by or in possession of the government from the 673d Medical Group without the written consent of the PACS Maintenance Contract monitor, or issuing authority.
2.3.8. Operational and Technical Documents: The contractor shall obtain, keep on file, and make available all operational and technical documentation necessary to keep the equipment at operational status.
2.3.9. Equipment Location: 673d Medical Group
5955 Zeamer Avenue
JBER, AK 99506
Diagnostic Imaging Flight
SECTION 3
PERFORMANCE EVALUATION
3.1. Service Summary
3.1.1. Overview. This Service Summary implements AFI 63-138, Acquisition of Services and identifies critical success factors for the contract and subsequent revisions. It identifies both the performance objectives for those factors and the performance threshold required for each performance objective. The Government reserves the right to surveil all services called for in the contract to determine whether or not the performance objectives were met. This Service Summary lists the performance objectives and performance thresholds for the required service that the
Government will survey.
3.2. Performance Evaluation. Performance of a service will be evaluated to determine whether or not it meets the performance threshold. If performance criteria are not met re-performance is the preferred method of correction. A determination of how recurrence of the cause will be prevented in the future must also be provided.
Performance
Objective
Section, Paragraph
Performance
Threshold
Method of
Surveillance
Daily system
Monitoring
Section 2, Paragraph 2.1.1.
100% compliance during duty hours
Periodic (Monthly)
Inspection
Assessment
User management functions
Section 2, Paragraph 2.1.2.
100% compliance within 10 days of notification
Periodic (Monthly)
Inspection
Assessment
Perform network management
Section 2, Paragraph 2.1.3.
90% compliance within 24 hours
100% compliance within 72 hours
Periodic (Monthly)
Inspection Assessment
Study monitoring and patient information management
Section 2, Paragraph 2.1.4.
90% compliance within 48 hours
100% compliance within 7 days
Periodic (Monthly)
Inspection Assessment
SECTION 4
EXPERIENCE, TRAINING AND CERTIFICATIONS
4.1. Travel Expenses. All travel and related expenses for requirements listed in this Section of this PWS are the responsibility of the contractor.
4.2. Experience Requirements
4.2.1. Contractor personnel shall have a general Information Technology (IT) background, including familiarity with Transmission Control Protocol / Internet Protocol (TCP/IP).
4.2.2. Experience in network administration, network infrastructure, command prompt, IP reality, and project management is highly desired.
4.2.3. Experience working as a PACS administrator is preferred.
4.3. Training Requirements
4.3.1. Contractor must send new PACS administrators to the Level I – Basic – Synapse System
Administration Course, or corresponding vendor specific PACS Administrator Course, within the first 6 months of employment (if available), but not before they have had the chance to become familiar with the requirements of the position.
4.3.2. The Synapse System Administration Course is a 5 day accredited class, held in the continental United States, which teaches students the basics of PACS administration on a FUJI
Synapse PACS. Other vendor classes may have different lengths, locations, and criteria.
4.3.3. The cost of the class registration fees, along with any related travel expenses, will be the sole responsibility of the contractor. If free class registration is provided as part of a new system purchase, or upgrade, contracted personnel may attend without paying a registration fee.
4.3.4. If contracted personnel have not attended a vendor sponsored admin class before the contract start, the course must be completed within an 18-month period. The contractor will arrange attendance of an Advanced PACS Admin Course, or Voice Dictation Admin Course..
4.3.5. Full course descriptions and syllabi are available from the COR.
4.4. Certification Requirements
4.4.1. Compliance with DoD 8140 is mandatory:
4.4.1.1. Contractor personnel must accomplish their CompTIA Security+ Certification within 60 days of gaining network access.
4.4.1.2. Personnel meet this requirement if they already possess one of the higher level certifications listed in DoD 8140
4.4.1.3. All certifications must be maintained throughout the term of employment.
SECTION 5
GENERAL INFORMATION
5.1. Contractor Personnel
5.1.1. Contract Employees. The contractor shall not employ persons for work on this contract if such employees are identified to the contractor by the Contracting Officer (CO), Contracting
Office Representative (COR), or the Government Supervisor/Function Representative Evaluator
Designee (FRED) as a potential threat to the health, safety, security, general wellbeing, or operational mission of the installation and its population.
5.1.2. Contractor personnel shall present a neat and professional appearance and display their hospital ID badge while on duty in the facility IAW Medical Group Instruction 36-7 paragraph 4, 5 and 6.
5.2. Hours of Operation:
5.2.1. Normal Hours of Operation. The contractor shall perform the services required under this contract during the following hours:
Contractor shall report to the Diagnostic Imaging Flight and be available from 0800 to 1630, Monday through Friday, excluding Federal Holidays, designated Family Days and down days.
5.2.2. Holidays. The contractor is not required to provide onsite service, but will provide on call support on the following Federal Holidays:
New Year’s Day, Martin Luther King, Jr.
Birthday President’s Day
Memorial Day
Independence Day
Labor Day
Columbus Day
Veteran’s Day
Thanksgiving Day
Christmas Day
5.3. Quality Assurance. The government will evaluate the contractor’s performance by appointing a representative of the contracting officer to ensure that services are received. The representative will evaluate the contractor’s performance through on-site inspections.
5.4. Freedom of Information Act Program (FOIA). All official government records affected by this contract are subject to the provisions of FOIA (5U.S.C. 552/DoD 5400.7-R/AF Supplement).
Any requests received by the contractor for access/release of information from these records to the public (including government/contractor employees acting as private citizens), whether oral or in writing, shall be immediately brought to the attention of the Contracting Officer for forwarding to the Base FOIA Manager, 3 CS/SCBR, to ensure proper processing and compliance with the Act.
5.5. Common Access Card (CAC). The contractor shall be provided a CAC for all employees who require access to DoD computer networks and systems or perform work on Elmendorf-
Richardson (JBER) regularly.
5.6. Past Performance Information (PPI). The government will formally assess and report on the contractor’s performance annually. The contractor will be provided a copy of their annual assessment at the end of each performance period. The contractor shall have 60 days to review and submit comments for the evaluation activity’s consideration before the assessment is made final.
The government will maintain each annual assessment report for a period of three (3) years. PPI assessment reports will be protected by all parties and treated by government personnel as
“FOR OFFICIAL USE ONLY” OR “SOURCE SELECTION INFORMATION”.
5.7. Records, Files, Documents and Work Papers. All official records (regardless of media) as defined in 44 U.S.C. Part 3301/AFI 33-322, paragraph 2 or required by provisions of a mandatory directive listed in Appendix 4, Applicable Publications and Forms (that are the responsibility of the contractor) are the property of the U.S. Government and shall remain so upon termination or completion of this contract. The contractor shall comply with AFI 33-322, Air Force Records
Management Program, by using the automated Air Force Records Information Management
System (AFRIMS), provided by the Air Force per AFMAN 37-123, to develop a file plan to systematically catalogue, identify and otherwise manage all official records it has responsibility for, including those inherited/transferred from the owning Air Force/Government organization.
All official records shall be maintained for the retention periods specified by the applicable records disposition authority/table and rule from AFMAN 37- 138m Air Force Records Disposition
Schedule. A Records Manager (RM) shall be appointed in writing to, and shall receive required training by 3 CS/SCBR, within three months of the effective date of the contract. The contractor shall provide the CO, on request, copies of any records created and/or maintained as a result of this contract. These copies shall be provided within five (5) working days of receiving the request.
5.8. Accreditation of Systems. Accreditation of systems shall be accomplished using Joint Base
Elmendorf-Richardson (JBER) Computer Security Plans (CSP) and AFSSI 5024 Volumes I-IV.
Accreditation data shall be maintained. To ensure system survivability commensurate with criticality, the contractor shall develop contingency plans, and shall include these plans with the basic CSP.
Contractor shall submit accreditation documents pursuant to directives outlined above. When a request for approval to operate is submitted, the system specific information shall be attached to the request.
5.9. Information Awareness. Contractor shall comply with the established C4 Systems, Information Awareness Program to integrate security education, training, and awareness covering the COMSEC, COMPUSEC, EMSEC, and OPSEC disciplines.
Contractor personnel requiring network access shall complete Government provided Cyber
Awareness training annually. The training is computer based and is typically completed within one hour.
5.10. Continuation of Essential DoD Contractor Services During Crisis. In the absence of a military PACS Administrator all services in the PWS are designated as essential services for performance during crisis. The CO, Functional Commander (FC), Program Manager or a designated representative will contact the contract manager by telephone or in person that essential services are required. This will be followed-up in writing (email or printed memorandum). The contractor shall develop an Emergency/Contingency Response Plan, for CO approval, of all services in this PWS no later than thirty (30) days after notice of award and before contract start to provide reasonable assurance of continuation of services during crisis conditions.
5.11. Fire and Safety Requirements. The contractor and contractor representative shall comply with all federal, state, and base fire and safety regulations. These include, but are not limited to:
5.11.1. Wearing of seatbelts/shoulder harnesses, observing maximum speed limits at all times.
Drivers are only authorized to use hands free cell phone devices while driving on base.
5.11.2. Contractor personnel shall remove watches, rings, and jewelry prior to servicing electrical circuits.
5.11.3. If machinery or electrical system is left in a non-operational state, it shall be tagged DO
NOT OPERATE. The tag shall also include the name of the representative placing the tag on the equipment. Training for this function is available through the 673d Medical Group, Medical
Equipment Repair Center (MERC) phone number 907-580-6397.
5.11.4. Comply with the 673d Medical Group tobacco free policy, MDGI 40-102 paragraph 2.
5.11.5. Report to the PACS Government Supervisor or FRED any problems with building utilities such as blown circuit breakers and defective/broken electrical receptacles.
5.12. FAR Subpart 22.17 Combating Trafficking in Persons. The United States Government has adopted a zero tolerance policy regarding trafficking in persons. Additional information about trafficking in persons may be found at the website for the Department of State's Office to Monitor and Combat Trafficking in Persons at http://www.state.gov/g/tip .Government contracts shall--(a)
Prohibit contractors, contractor employees, subcontractors, and subcontractor employees from-(1)
Engaging in severe forms of trafficking in persons during the period of performance of the contract; (2) Procuring commercial sex acts during the period of performance of the contract; or
(3) Using forced labor in the performance of the contract; (b) Require contractors and subcontractors to notify employees of the prohibited activities described in paragraph (a) of this section and the actions that may be taken against them for violations; and (c) Impose suitable remedies, including termination, on contractors that fail to comply with the requirements of paragraphs (a) and (b) of this section
5.13. Security Investigative Requirements: The Contractor shall ensure contract employees comply with security requirements outlined in this PWS.
5.13.1. Contract employees shall be subject to security investigative processes to facilitate criminal background investigations according to agency regulations and instructions.
5.13.2. Contract employees shall not begin performance under this contract until the complete documentation for a Personnel Background Investigation (PBI) has been submitted in accordance with local policies and procedures.
5.13.3. The Contractor shall advise their contracted employees that a favorable investigation is needed as a condition of employment under this contract. If a security or background investigation results in an unfavorable finding, the CO will notify the Contractor and the contractor will not be granted access to the MTF nor be qualified to perform services.
5.13.4. Contract employees shall be subject to the following security investigative processes, to include appointments with Security Managers:
All Contractor personnel shall provide the Security Manager a signed, digital copy of an OF306
(Declaration of Federal Employment) prior to their start date, this includes personnel hired subsequent to the contract start date. The Government will in turn submit a Tier 1 investigation request on AF IMT 2583, Request for Personnel Security Action, at no additional cost to the
Contractor. As a minimum, Contractor personnel shall have a favorable Tier 1 investigation and obtain a Common Access Card before operating Government-furnished workstations that have access to Air Force automated information systems. Contractor personnel receiving an unfavorable
Tier 1 investigation shall not be employed.
5.13.5. Contract employees shall be subject to the following security processes for fingerprints:
Once a favorable AF IMT 2583 is returned to the MDG Security Manager, the MDG Security
Manager will schedule the Contractor personnel for fingerprints with the 673d Civilian Personnel
Office.
5.13.6. The contract employee shall complete SF-85 Questionnaire for National Security Positions
(or equivalent Office of Personnel Management investigative product).
5.13.7. Contract employees shall not begin performance until the complete documentation for a
Personnel Background Investigation has been submitted. An Identification (ID) badge and
Common Access Card (CAC) shall not be issued until complete documentation has been submitted to the appropriate Installation, MTF, or other Security Manager(s), as required at the facility. The
CAC card is required for access to Government computer databases and also is presented to the security guards when entering the military installation. If a background investigation results in an unfavorable finding, the contracting officer shall notify the contractor and the contractor employee shall not be granted access to the facility, shall not be able to perform services at the facility, and must return all identification badges, CAC cards, and other items issued previously issued by the
Government.
5.14. Disease Prevention: In accordance with DoD Directive 6205.02E, all contract employees shall follow the methods for controlling and preventing disease as described by the Center of
Disease Control (CDC) Advisory Committee on Immunization Practices (ACIP) publication, Morbidity and Mortality Weekly Report (MMWR) and its supplements. The Contractor shall maintain workforce health qualifications as published in the most recent guidelines from these publications throughout the life of the contract. For purposes of this contract, CDC recommendations are considered requirements.
5.14.1. Health Requirements: The Contractor shall comply with all health requirements in this contract. Prior to physical performance of services by the employ, but no earlier than 60 days prior to physical performance of services by the employee, the Contractor shall provide documentation certifying health requirements such as immunizations, annual vaccinations, medical testing (i.e., tuberculosis, N95 particulate respirator duckbill mask fitting) and physical examination when required at the time of initial placement and annually thereafter, as required. The expense for all health requirements, to include monitoring and tracking annual requirements, shall be borne by the
Contractor at no additional cost to the Government.
5.14.2. Annual Immunizations: The Contractor shall ensure employees are immunized annually with the seasonal influenza vaccine and any other vaccine recommended by the Advisory
Committee on Immunization Practices (ACIP) of the Centers for Disease Control (CDC) for service/MTF specific guidance as outlined in DoDD 6205.02e, Policy and Program for
Immunizations to Protect the Health of Service Members and Military Beneficiaries. The annual influenza vaccine may be provided by the Government, if available, as determined by the MTF. If the contract employee chooses to be immunized by the Government, they shall sign a waiver releasing the Government from the legal liability IAW local procedures and policies. Alternately, the contract employee may obtain the vaccine at another facility, at no cost to the Government, and provide proof of vaccination to the Government. If the contract employee declines vaccination, a signed declination form will be provided to the COR IAW CDC recommendations and MTF policy.
5.14.3. Immunization Tracking: The Contractor shall maintain their own process and system of tracking the currency of health immunizations and shall not rely on the Government for ensuring the contract employees are in compliance.
5.14.4. Tuberculosis Screening: Prior to reporting for service at an MTF, each contract employee shall be screened at contractor expense for risk of exposure to tuberculosis (TB) as part of the health examination and immunization/screening requirement. If the contract employee is determined to have a low risk of exposure, no further screening or testing is required under this contract. The initial screening may be waived, at the discretion of the MTF, if the Contractor provides evidence of a prior low risk assessment by a licensed physician. If the initial screening results in a determination that the contract employee has an increased risk of exposure to TB, the contractor is responsible for ensuring that the contract employee receives targeted screening and testing IAW CDC Guidelines for Health- Care Settings at Contractor expense and submitting timely records of subsequent screening or testing to the COR.
5.15. Placement. The Contractor shall coordinate with the COR to obtain information and the necessary forms to access the installation and in-process at the MTF. The Contractor shall comply with processing procedures, orientation requirements, initial training requirements and other onboarding instructions such as security requirements at the MTF. The COR may waive the orientation requirements for personnel who have previously provided service at the 673d Medical
Group.
5.16. Maintain Employee Qualifications. The contract employee shall maintain compliance with all requirements for: continuing education; annual and specific training; and, other mandates for licensing, certification, and/or registration at the appropriate intervals to remain qualified during the performance of this contract.
SECTION 6
GOVERNMENT FURNISHED PROPERTY
6. Government Furnished Items and Services:
6.1. General: The Government will provide the use of all available MTF facilities and support services, materials, publications and forms, and equipment required for contract performance. The contractors shall ensure physical security of government property and equipment. Contractors who are issued government property (keys, codes, badges, cell phones, pagers, etc.) shall safeguard
Government property from loss, theft, damage or destruction. The Contractor may be required to reimburse the Government for lost or damaged equipment. IAW FAR 52.204-9, Personal Identity
Verification of Contractor Personnel, the Contractor shall account for all forms of government-provided identification used by the Contractor employees in connection with performance under this contract.
6.2. Business Equipment: Telephones, facsimile machines, copiers and computer equipment are authorized for transaction of official government business only and shall not be used for personal business. Personal long distance calls are not authorized. Telephones, facsimile machines and computer equipment are subject to communications security monitoring at all times.
6.3. Space: Space used by Contractors in performance of services may be used for other purposes during their absence. Items of clothing, personal effects, or equipment cannot be secured during their absence. The Government will not incur any liability for theft, damage to, or loss of personal items.
6.4. Keys: Contractors may be issued keys. The Contractor shall safeguard the keys from loss, theft or destruction, and shall present, for accountability purposes, all keys signed for at scheduled or unscheduled key control inspections. Government keys shall not be duplicated. Lost keys and/or locks shall be reported to the issuing party immediately upon recognition of the loss. The
Contractor may be required to reimburse the Government for lost keys, or lockset (if locksets are required to be replaced) as a result of lost keys.
6.5. Nametag: The Contractor shall wear a MTF issue name badge at all times while they are in the facility. This badge will be removed once they are off duty and leave the MTF.
6.6. Contractors shall turn-in all issued government furnished property to the COR, or a designated government representative, upon termination of their services or upon demand by COR or designated government official.
SECTION 7
BUSINESS ASSOCIATE AGREEMENT
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD
6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the
Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a
HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA
Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
Definition: Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated
Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of
Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the
DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF
BUSINESS ASSOCIATE].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD
HIPAA Issuances, and in reference to this BAA, shall mean 673d Medical Group.
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office
Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital
Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD
Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18
(2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are
DoDD 5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR
164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part
160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate:
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this
Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA
Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the
Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered
Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered
Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding
DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the
Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the
Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate:
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity.
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the
HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD
HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the
Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide
Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and
Restrictions:
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR
164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity:
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response:
(a) In general:
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business
Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered
Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act
Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach.
If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions:
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business
Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered
Entity determines that the breach does not constitute an HHS Breach, then the Business
Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable
Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA
Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable.
Because DoD defines “breach” to include possible (suspected) as well as actual
(confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and
HIPAA breach response requirements for all breaches, including but not limited to HHS breaches:
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business
Associate shall save a copy of the on-line report. After submission, the Business
Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business
Associate shall provide a copy of the initial or updated US-CERT report to the
Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting
Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA
Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and
Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy
Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances.
The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation:
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The
Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act
Issuances.
(i…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .