Attachment 1 - SOW Drinking Water Analysis 2020.pdf

PDF 137 KB Posted

Attached to
Bacteriological Testing Federal contract opportunity
Solicitation number
FA480920Q0056
Issued by
Department of the Air Force Air Combat Command

View the file

Other files for this federal contract opportunity

Other files attached to Bacteriological Testing, newest first.
File Type Posted
Attachment 1 - SOW Revised 18 Jun 2020.pdf PDF
Combo - Bacteriological Testing.pdf PDF
Attachment 2 - WD 2015 4379 Rev 13.pdf PDF
Attachment 4 - FAR and DFARS Provisions and Clauses.pdf PDF
Attachment 3 - WD 2015-4397 Rev 12.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

FOR

Drinking Water Analysis

AT

Seymour Johnson Air Force Base

AND

Fort Fisher Recreation Area

24 Mar 2020

Seymour Johnson Air Force Base

STATEMENT OF WORK

DRINKING WATER SAMPLING AND ANALYSIS

SEYMOUR JOHNSON AIR FORCE BASE & FORT FISHER RECREATION CENTER,

NORTH CAROLINA

INTRODUCTION: Seymour Johnson Air Force Base (SJAFB) (Public Water System ID NC0496055) is a Purchase Community Water System (CWS) located in Goldsboro, North Carolina (NC). Fort Fisher Recreational Area (FFRA) (Public Water System ID NC0465197) is a Recreation Center maintained by SJAFB. It is a Purchase Non-Transient, Non-Community Water System located in Kure Beach, NC. The Bioenvironmental Engineering Flight (BEF) is responsible for managing the Environmental Protection Agency’s (EPA) Safe Drinking Water Act (SDWA). North Carolina has primacy and the North Carolina Department of Environment and Natural Resources (NC DENR) is responsible for enforcing the SDWA in North Carolina. The NC DENR Washington Regional Office and Wilmington Regional Office are responsible for enforcing compliance standards of the SDWA for SJAFB and Fort Fisher respectively.

1.1 GENERAL REQUIREMENTS

The Contractor shall be responsible for collecting samples, transporting samples, providing sample analysis and reporting services according to NC DENR guidelines. Samples shall be taken at various locations throughout SJAFB and Fort Fisher at points and times designated by the Sampling Plans/Schedules (see Table 1.1 and Table 1.2).

1.2 LABORATORY CERTIFICATION

The Contractor shall be certified by the North Carolina Department of Health Human Services (NC DHHS) and shall be in compliance with all other NC DENR and U.S. Environment and Natural Resources (NC DENR) and shall be in compliance with all other NC DENR and U.S. Environmental Protection Agency (EPA) mandated Quality Assurance /Quality Control (QA/QC) programs requirements to keep and maintain its certification.

1.2.1 The Contractor shall furnish a copy of its certificate to the Government prior to contract award and upon any recertification. (Note: If any testing is subcontracted to another lab, it is the primary contractors responsibility to provide the certificates of the subcontracted lab to the government).

1.3 SCOPE OF WORK

The Contractor shall provide laboratory services including the furnishing of all materials, equipment, supplies, transportation, facilities, utilities, supervision, and quality control required for the laboratory analysis, and reporting of test results regarding samples collected and/or obtained at SJAFB to both the NC DENR and the Government.

1.3.1 The contractor shall provide 4 OMRS/SGXB seventy-two (72) hours advanced notice prior to arrival at SJAFB or FFRA to collect water samples.

1.3.2 All equipment and procedures used for the performance of the laboratory analyses shall be in conformance with the regulatory program guidelines cited by the EPA and NC DENR. The contractor shall follow and meet the quality control and assurance requirements for the performance of the tests (where available) as stated in the referenced test method and regulatory program documents.

1.3.3 The Government will conduct all lead, copper and Asbestos sampling and provide those samples to the Contractor for analysis. The contractor shall pick up these samples when they are on site conducting their sampling.

1.3.4 The Government may inspect for analysis and reporting compliance at their discretion.

1.3.5 Submit completed reports to 4 OMRS/SGXB (4amds.sggb@us.af.mil), 2803 Medical Campus Drive, Seymour Johnson AFB, NC 27531 and shall be completed in accordance with 1.7 and 1.8 of this statement of work.

1.3.5.1 The Contractor will submit data to the State on behalf of the 4 OMRS/SGXB for testing performed under this statement of work once the government has reviewed drafted reports and approved them. The NC DENR reporting system depends upon laboratories reporting compliance results via mail and electronically at their website.

1.3.5.2 The Contractor shall be liable for ensuring that all data is reported in a timely manner and prior to the statutory due date.

1.3.5.2.1 If the Contractor misses the due date for report submission, the Contractor shall be liable for any Notices of Violation as well as associated fines, penalties, etcetera assigned to the Government.

1.3.5.2.2 If the Contractor or the Government determines that a report was submitted to the state that contains errors or erroneous information, such as typos, wrong location code, etcetera the Contractor will immediately rectify the error and re-submit the report to both NC DENR and the Government.

1.3.6 Unless otherwise noted, all rework caused by failure of the Contractor to collect or analyze a sample according to the appropriate sampling and analysis methods, improper quality control and/or quality analysis, improperly generating sample reports, such as with typos, etcetera, shall be re-accomplished at the expense of the Contractor.

1.3.6.1 Chlorine concentration levels and action are as follows:

a. If the chlorine concentration is greater than 1mg/L, the Contractor shall collect the sample.

b. If the chlorine concentration is less than 1mg/L, the Contractor shall contact the designated Government personnel to flush the lines and collect the sample.

1.3.7 Emergency samples will be collected by the Contractor based on the Government’s needs, or after positive coliform results, release from hurricane watch conditions, etcetera. The Contractor will perform analyses per the Contractor’s standard operating procedures. The Government will inform the Contractor if the emergency sample results are needed expediently. The Contractor will be reimbursed for emergency samples collected based on the offer schedule (See attachment).

1.3.7.1 Any positive bacteriological sample tests require a telephone notification to be made within 24 hours in accordance with paragraph 1.3.4 and 1.8 of this statement of work.

1.3.7.2 The collection of emergency samples shall be directed by 4 OMRS/SGXB and accomplished no later than 24 hours after the notification to collect emergency samples.

1.3.8. Contractor will provide supplies and analysis for disinfectant by-products at FFRA.

1.3.9 Contractor will collect TTHM/HAA5 samples quarterly for FFRA at two locations: Bldg. 138 and 118.

1.3.10 Contractor will collect the TTHM/HAA5 samples quarterly for SJAFB (Slocomb and Ash for the Stage 2 DBP) side by side with the City of Goldsboro, and the housing area for bacteriological analysis, and the quarterly Additional Parameters (nitrate, nitrite, free ammonia).

1.3.11 Contractor will provide the Government the sampling supplies and analysis for bacteriological samples in the industrial area at SJAFB, and the extra TTHM samples for FFRA. Government BE Technicians will collect the bacteriological samples in the industrial area at SJAFB and the extra TTHM/HAA5 samples for FFRA.

1.3.12 Contractor will test for total chlorine and pH for all SJAFB samples collected and test for free available chlorine and pH for all FFRA samples collected and supply these results to the Government on sample collection form.

1.3.13 Contractor will provide the Government the sampling supplies and analysis for Lead and Copper samples in the industrial area and base housing at SJAFB; they will also provide sampling supplies and analysis for lead and copper samples at FFRA. Government BE Technicians will collect the Lead and Copper samples in the industrial area and base housing area at SJAFB as well as the Lead and Copper samples for FFRA.

1.3.14 Contractor will provide the Government the sampling supplies and analysis for PFOS/PFOA samples at SJAFB. Government BE Technicians will collect the PFOS/PFOA samples at SJAFB.

1.3.15 Contractor will provide the Government the sampling supplies and analysis for Asbestos samples in the industrial area at SJAFB. BE Technicians will collect the Asbestos samples in the industrial area of SJAFB.

1.3.16 Contractor will take bacteriological samples in the housing area during chlorine conversion, which will be specified by the City of Goldsboro at specified time directed by the Government.

1.4 SAMPLE COLLECTION

Collection of samples shall be consolidated into the minimal amount of trips as possible per month.

For example, collection of quarterly and annual test shall be consolidated with a trip to collect monthly samples as much as possible to minimize impact on government personnel.

1.5 SPECIFICATIONS AND STANDARDS

All sample collection, sample handling and laboratory analyses of all samples shall be performed in accordance with the EPA and/or BC DENR for each type of analyte, as stated in 40 CFR Part 136, 40 CFR part 141, 40 CFR part 143, 40 CFR part 261, 15A NCAC 18C and any subsequent amendments or regulations.

1.6 HOURS OF OPERATIONS

The Government’s normal hours of operation are 7:30 AM to 4:30 PM, Monday through Friday. The Contractor is not required to provide normal service except for emergencies on the following days: Any

Weekend, New Year’s Day, Martin Luther King’s Birthday, President’s Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas Day.

1.6.1 The Contractor shall provide one (1) week advanced notice to the SJAFB BE Flight Commander, excluding legal holidays, any restrictions in work hours and designated workdays that may prevent the Contractor from being able to perform in accordance with this statement of work. The Contractor may contact 4 OMRS/SGXB, BE representative, outside of normal hours of operation via on call phone (919- 750-2124).

1.7 AVAILABILITY OF UTILITIES

The Government has identified sampling sites per the sampling schedule in Table 1.1 and Table 1.2.

1.8 TELEPHONE REPORTS

The Contractor shall report to the Government by telephone in the following cases:

1.8.1 Telephone reports shall be made as soon as analysis is completed and result indicates a positive for Total/Fecal Coliform. The telephone report shall include the location, sample number, location code, test result, HPC count, other data required for reporting per the test method, and any abnormalities or deviations needed.

1.8.2 Telephone reports shall be made as soon as analysis is completed if a fast analysis response is requested. The telephone report shall include the test result, units, other data required for reporting per the test method, and any abnormalities or deviations noted.

1.8.3 Telephone reports shall be made as soon as abnormal conditions are noted by the Contractor.

Examples include:

a. The sample shows a lack of expected homogeneity (i.e. sample has excessive sediment, excessive amount of floating material, or physical appearance is markedly different from that observed for any four (4) previous samples collected from that sampling point.)

b. The sample has an abnormal odor.

c. The sample has an abnormal color.

d. The sample shows other abnormal conditions.

Note: Do not analyze sample(s) if any of the above conditions exist. Contact OIC/NCOIC of

Environmental Surveillance immediately and notify of situation.

1.8.4 Telephone reports shall be made as soon as abnormal results revealed during analysis. The Contractor shall make same-day telephone reports whenever any analysis result is:

a. A positive result for coliform bacteria in drinking water samples

b. A violation of the primary drinking water maximum contaminant levels for drinking water samples

c. Matrix quality control is outside expected limits

d. An error occurs in the analysis precluding the use of the results.

e. Any hold times have been exceeded

1.9 WRITTEN AND ELECTRONIC REPORTS

The test results submittal shall be in typed form and shall include, but is not limited to, the following information:

• Date of Report

• Name and address of laboratory performing the analysis

• Discharge Serial Number when applicable

• Name and employer of person collecting the sample

• Sample identification (sample numbers and sample location address, building number or other location descriptions)

• Dates and times sampled

• Dates and times analyses performed

• Name of analyst(s) who performed each analysis (initials acceptable)

• Sample type: daily composite, flow, or time-based, or grab

• Parameters analyzed (analytes)

• Analytical and microbiological techniques or methods used

• Results of all required analyses reported with units of measure and other reporting data required by the test method

• Report on deviations or abnormalities, if applicable

• Laboratory supervisor signature certifying the adequacy and accuracy of procedures and test results

2.0 HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) OF

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA.

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean 4th Medical Group.

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate

(NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity.

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report.

After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business

Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text.

Examples of updated information the Business Associate shall report include, but are not limited to:

confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.

(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.

(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and

(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address

(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.)

that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The Covered Entity will determine the appropriate level of support services.

(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.

(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.

(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber security incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forth here. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.

VI. Termination

(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors) with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the underlying Contract.

(b) Effect of Termination.

(1) If this Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If this Agreement does not have records management requirements, the records should be handled in accordance with paragraphs VI.(2) and (3) below. If this Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if the Covered Entity gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or the Covered Entity’s direction.

(2) If this Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of this Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.

(3) If this Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such

PHI.

VII. Notices. Any notices to be given hereunder will be made in the most expedient manner, via e-mail, facsimile, U.S. Mail, or express courier to such party’s address.

VIII. Miscellaneous

(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of this Agreement.

(b) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA Issuances.

3.0 OPERATIONS SECURITY (OPSEC) PLAN.

3.1 PURPOSE. The OPSEC Program will provide the structure to ensure that OPSEC requirements are met for the MTF’s activities involving the contract as well as all subcontracts involved. This plan is based upon the results of the 4 MDG OPSEC process and is intended to protect critical information related to the healthcare, as well as information about the 4th Fighter Wing, its contracts, and subcontracts. While critical information, indicators, threat information, risk assessment, OPSEC Standard Operating Procedures (SOP), and all updates will be provided under separate cover, this plan covers general vulnerabilities and the required countermeasures that will mitigate and lower risk to the MTF.

3.2 ORGANIZATION. There is an OPSEC Coordinator on each contract assigned to this duty throughout the course of this contract.

3.3 REQUIREMENTS.

3.3.1 OPSEC Process.

3.3.1.1 Critical Information. A critical information list and updates will be provided under separate cover after contract award to the subcontracted employee(s) who are supporting the contract and handling critical information.

3.3.1.2 General Threat Assessment. The worldwide intelligence collection threat is comprised of multi-disciplined, highly sophisticated, and extremely dedicated adversaries. There is a consensus within the U.S. Intelligence Community that their collection efforts target almost all DoD contractors developing new technologies. Any business enterprise operating in the global competitive market should recognize that it is continually targeted by intelligence collection efforts. Adversaries can produce reliable information on business capabilities, vulnerabilities, and intentions. Moreover, the intelligence threat to the U.S. economic and scientific base has increased dramatically in recent years.

3.3.1.3 Vulnerability Analysis. Vulnerabilities (and indicators) of the program may reveal critical information. A detailed list will be provided after contract award.

3.3.1.4 Countermeasures. In conjunction with OPSEC awareness, subcontracted personnel who handle critical information should be aware the MTF’s countermeasures to protect critical information.

A detailed list will be provided after contract award.

3.3.1.5 Disciplinary Actions. Failure to follow directed OPSEC measures and/or unauthorized disclosure of critical information will be consideration for disciplinary action and may result in the healthcare worker’s removal from the position.

Table 1.1

1 September 2020 - 31 August 2021 SEYMOUR JOHNSON AFB

SAMPLING PLAN/SCHEDULE

Address / Location Description

Analyte / Contaminant Group

Last Sample Date Next Sample Date Sampling Frequency Location Code

Bldg 3650 (DFAC*) Bacteriological 1st Week of each Month 0177-PD-506 Bldg 3500 (LRS*) Bacteriological 1st Week of each Month 0177-PD-512

Bldg 2219 Bacteriological 1st Week of each Month 0177-PD-099 Bldg 3100 (V. Maint) Bacteriological 1st Week of each Month 0177-PD-518

108 Allen Bacteriological 2nd Week of each Month 0177-PD-418 154 Westover Bacteriological 2nd Week of each Month 0177-PD-406

416 Geiger Bacteriological 2nd Week of each Month 0177-PD-403 301 Chanute Bacteriological 2nd Week of each Month 0177-PD-409

Bldg 3300 (CE*) Bacteriological As Needed 0177-PD-509 Bldg 3601 (Legal) Bacteriological As Needed 0177-PD-515

Bldg 4421 (335 FS*) Bacteriological As Needed 0177-PD-106 Bldg 2121 Asbestos Aug 2013 Aug 2022 Every 9 Years A01 Bldg 4901 Asbestos Aug 2013 Aug 2022 Every 9 Years A02 127 Lowry Asbestos Aug 2013 Aug 2022 Every 9 Years A03 Bldg 4743 Asbestos Every 9 Years A04 Bldg 1700 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-100 Bldg 2109 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-101 Bldg 2020 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-102 Bldg 4522 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-103 Bldg 4537 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-104 Bldg 4713 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-105 Bldg 2154 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-548 Bldg 4530 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-547 Bldg 3802 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-535 Bldg 5006 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-549 Bldg 2151 Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-541

100 Allen St. Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-542 508 Gilbert Court Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-527 316 Beck Street Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-530 226 Nellis Drive Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-531 425 Geiger Street Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-532 103 Keesler Lane Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-533

4 Biggs Court Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-534 142 Westover Road Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-543

217 Squier Ave Lead & Copper Aug 2019 Aug 2022 Every 3 Years 0177-PD-544

216 Kirkland Drive Lead & Copper

(Extra Site) Aug 2019 Aug 2022 Every 3 Years 0177-PD-545

Bldg 1600 Lead & Copper

(Extra Site) Aug 2019

Aug 2022 Every 3 Years 0177-PD-500

Bldg 4312 Lead & Copper

(Extra Site) Aug 2019

Aug 2022 Every 3 Years 0177-PD-539

122 Westover Road Lead & Copper

(Extra Site) Aug 2019

Aug 2022 Every 3 Years 0177-PD-528 Elm Meter Pit (MRT*) TTHM / HAA5 (S1) Feb, May, Aug, Nov Qrtly 0177-PD-303 Ash Meter Pit (MRT) TTHM / HAA5 (S1) Feb, May, Aug, Nov Qrtly 0177-PD-306

Slocumb Meter Pit (MRT) TTHM / HAA5 (S1) Feb, May, Aug, Nov Qrtly 0177-PD-309

Bldg 2803 PFOS/PFOA 2019 June 2020 Once a year for 2 years 0177-PD-200

Table 1.2

1 September 2020 - 31 August 2021: Fort Fisher Recreation Area Sampling Plan

(PWSID: 04-65-197)

Address / Location

Description

Analyte / Contaminant

Group

Last Sample

Date Next Sample

Date Sampling Frequency Location

Code Bldg 138, Maintenance Shop Bacteriological Qtrly Nov, Feb, May, Aug Feb/Aug- in 1st Wk of Mth F01

Bldg 118, Recreation Office Bacteriological Qtrly Nov, Feb, May, Aug May/Nov- in 1st Wk of Mth F02

Bldg 121, Restaurant Bacteriological Qtrly Nov, Feb, May, Aug As needed F03

Bldg 138, Maint Shop TTHM / HAA5 Qtrly Nov, Feb, May, Aug Qtrly F01

Bldg 118, Recreation Office TTHM / HAA5 Qtrly Nov, Feb, May, Aug As needed F02

Bldg 142, Dining Facility

TTHM /HAA5

(extra sites) Qtrly Nov, Feb, May, Aug

As needed 103

Bldg 122, National Guard Bldg

TTHM/ HAA5

(extra sites) Qtrly Nov, Feb, May, Aug

As needed 102

Meter Pit

TTHM/ HAA5

(extra sites)

Qtrly Nov, Feb, May, Aug

As needed E01

Bldg 142 Lead & Copper Aug

Aug 2022 Every 3 Years 103

Bldg 122 Lead & Copper Aug

Aug 2022 Every 3 Years 102

Bldg 118 Lead & Copper Aug

Aug 2022 Every 3 Years F02

Cottage 302 Lead & Copper Aug 2019 Aug 2022 Every 3 Years F04

Cottage 312-2 Lead & Copper Aug 2019 Aug 2022 Every 3 Years F05

Bldg 118, Recreation Office Asbestos Aug 2013 Aug 2022 Every 9 yrs F02

Pool pH, FAC May-Sept Monthly

File details come from the government source that posted it. Updated .