ATTACHMENT A - PWS.docx
DOCX document 56 KB Posted
- Attached to
- R408--Third Party Survey Federal contract opportunity
- Solicitation number
- 36C77620Q0121
About this file
This is a combined synopsis and solicitation for third-party salary survey data services. The Department of Veterans Affairs seeks a contractor to provide market-based compensation data through collecting, analyzing, and reporting on national and regional salary surveys. Services include purchasing survey data, matching jobs to VA positions, developing a compensation database with geographic differentials, and producing recurring reports and briefings over a one-year base period and four option years. Quotes are due by July 17, 2020 and will be evaluated based on price, technical approach, and past performance. The solicitation targets small businesses and includes subcontracting goals for veteran-owned, service-disabled veteran-owned, small disadvantaged, woman-owned, and HUBZone small businesses. The selected contractor must comply with VA security requirements and provide services on an as-needed basis at VA locations or remotely.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ATTACHMENT A - PWS 20200730.docx | DOCX document | |
| Third Party Survey - Updated Price Schedule 20200730.docx | DOCX document | |
| 36C77620Q0121 0001.docx | DOCX document | |
| RFQ Q_A 36C77620Q0121.docx | DOCX document | |
| 36C77620Q0121.docx | DOCX document | |
| ATTACHMENT E - TRAVEL AUTHORIZATION REQUEST.doc | DOC document | |
| ATTACHMENT D - CONTRACTOR PERSONNEL CHANGE FORM.doc | DOC document | |
| ATTACHMENT H - PAST PERFORMANCE_UPDATED.docx | DOCX document | |
| ATTACHMENT F - Security Request Packet.pdf | ||
| ATTACHMENT C - CONTRACTOR STAFF ROSTER.doc | DOC document | |
| ATTACHMENT G - SubcontractingPlan Template.docx | DOCX document | |
| ATTACHMENT B - QASP.doc | DOC document |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Veterans Health Administration Office of Workforce Management and Consulting Third-Party Survey Data
Performance Work Statement (PWS)
1. Background: The Department of Veterans Affairs (VA), Veterans Health Administration (VHA) is one of the largest employers for health care professionals in the United States. VHA nurses, physicians, dentists, as well as other health care occupations and ancillary support positions which are the cornerstone of our nation's largest healthcare system. As such, it is critical that individual VA medical centers are provided access to accurate, reliable, and recurring market-based third-party salary survey data. This market-based data is used to assess VA’s competitive position in each local labor market area and allows VA facilities to make informed, consistent, accurate, and timely compensation decisions for a wide variety of critical occupations. The majority of these health care professionals are appointed and paid under 38 U.S.C. Chapter 74. More specifically, VHA is required by 38 U.S.C 7451 to utilize third-party survey data, when available, to determine if title 38 Locality Pay System (LPS) adjustments are necessary in order to compensate nurses, nurse anesthetists, and physician assistants, as well as any other occupation covered by the title 38 LPS. In addition, the agency relies heavily on third-party survey data when making salary determinations for special salary rates approved under the authority of 38 U.S.C. 7455 for healthcare occupations and VHA police officers, as well as 5 U.S.C. 5305 for administrative and engineering positions. The special rates established under these authorities may be competitive with, but not exceed, pay for comparable positions at non-Federal facilities in the local labor market. VHA also utilizes third-party survey data to assist in making market pay determinations for physicians, dentists, and podiatrists covered by the Physician, Dentist, and Podiatrist Pay System under 38 U.S.C. 7431. Title 38 LPS and special rate schedules are routinely established and adjusted based on third-party survey data for specific local labor market areas. VHA routinely competes with major employers in the health care market to fill their health care positions and relies heavily on having the flexibility to utilize third-party survey data to adjust salaries to enhance the VA’s ability to recruit and retain high quality employees.
The government is looking to enter into a single award contract with award of one base plus four option years.
2. Scope of Work: The VA is seeking a contractor who can provide the following services:
a. VA will identify a list of national and regional surveys VA wishes to participate in and receive survey data from. The contractor shall establish an agreement with each third-party survey provider and maintain a calendar in order to submit timely VA employee salary and other compensation data on VA’s behalf, and in order to apprise VA as to when each third-party survey deliverable will be received.
b. VA Survey Data Collection and Distribution. Contractor shall provide VA employee survey and benefits data on behalf of 152+ VA medical centers, in different local labor market areas to third party survey providers on behalf of the VA. Using large VHA employee data files and duty station locations, the contractor shall extract, analyze, perform matching benchmark jobs based on VA job descriptions, and provide employee specific salary and benefit data to different third-party survey sources on VHA’s behalf. Each third-party survey may require data analysis of employee salaries for up to 100+ clinical, professional, administrative, technical, clerical, trade, engineering, security, or other healthcare occupations and will cover any duty station location within the VA Health Care System. This includes locations throughout the continental United States (CONUS), Alaska, Hawaii, and U.S. territories to include Puerto Rico, Guam, American Samoa, and the U.S. Virgin Islands. In order to perform appropriate job matching and benchmarking, the contractor must have extensive knowledge of more than 100 VHA healthcare occupations; knowledge of VHA’s unique grade and salary structure; and a thorough understanding of the various qualification standards for each VHA healthcare occupation.
c. Data Analysis and Report Generation - The contractor shall collect the third-party salary survey results and aggregate the market data and analysis and create market comparisons for national, as well as regional salary data, and provide VA with high quality valid survey sources. This includes appropriate job matching based on VA and survey job descriptions for each employee within each occupation. The contractor shall develop appropriate market analysis and create market comparisons for each employee within the occupation. The contractor shall provide the total compensation of all positions surveyed to include, minimum, median, maximum, and mean salary amounts for each position. The total compensation shall also include premium pay and differential amounts, recruitment and/or relocation benefits paid, educational assistance/debt reductions incentives (including student loan repayment programs), and other monetary benefits typically paid by employers. The contractor shall also obtain information on any other work/life benefits paid or offered to non-federal employees.
d. Application of Geographic Differentials - In order for VA to utilize national third-party survey data, the contractor must extrapolate and report survey data for each individual VA local labor market area, using recognized industry standards and survey methodology comparable to the methodology used by the Bureau of Labor Statistics (BLS). For geographic areas not covered by survey data, the Contractor shall use a data program that contrasts geographic salaries against regional and national average survey data. Data is gathered from public records, salary surveys, online job postings, and licensed datasets. A differential or percentage is calculated and applied to national or other regional survey data. The contractor shall develop and provide reports which allows VA to apply geographic differentials to aggregate national survey data for more than 100 healthcare occupations, and for all established duty station locations. To date, VA has over 4,000 unique duty station locations in various labor market areas.
e. All data files and/or reports provided by the contractor shall afford VA the ability to import the data to an external, cloud-based database or compensation system.
f. The survey methodology performed by the Contractor shall comply with requirements in Federal statute found in 38 U.S.C. §7404, 7431, 7451, and 7455, as well as VA policy promulgated in VA Handbook 5007, specifically parts VI, IX, and X.
3. Period of Performance: The period of performance (PoP) shall be one (1) year from date of award, with four (4) twelve (12) month option periods.
The principal place of performance shall be at the Contractors’ facilities.
No work at any Government site will take place on Federal holidays or weekends, unless directed by the Contracting Officer (CO).
Authorized holidays for Contractor personnel performing work at a Government installation shall correspond with Government holidays. There are ten (10) Federal holidays set by law (5 U.S.C. §6103);
Under current definitions, four (4) are set by date:
| New Year's Day | January 1st |
| Independence Day | July 4th |
| Veterans Day | November 11th |
| Christmas Day | December 25th |
If any of the above falls on a Saturday, then the preceding Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday. The other six (6) are set by a day of the week and month:
| Martin Luther King's Birthday | Third (3rd) Monday in January | |||
| Washington's Birthday | Third (3rd) Monday in February | |||
| Memorial Day | Last Monday in May | |||
| Labor Day | First (1st) Monday in September | |||
| Columbus Day | Second (2nd) Monday in October | |||
| Thanksgiving | Fourth (4th) Thursday in November |
4. Type of Order: All orders placed against this contract shall be Firm Fixed Price (FFP).
5. Travel: The contractor must obtain written approval from the Contracting Officer’s Representative (COR) before any travel begins, utilizing Section D, S02 Attachment 8 Travel Authorization Request Form. Travel and per diem expenses will be reimbursed on an actual expenditures basis in accordance with Federal Travel Regulations and FAR 31.205-46. Travel that occurs without written pre-approval will NOT be reimbursed. The contractor(s) MUST use S02 Attachment 1 Travel Authorization Request Form for travel pre-approval. Other documents or e-mails will NOT be accepted as pre-approval.
In order to be reimbursed for travel, the contractor(s) shall submit supporting documentation as required by Federal Travel Regulations with invoices for expenses incurred. Expenses for subsistence and lodging will be reimbursed to the contractor only to the extent where an overnight stay is necessary and authorized by Federal Travel Regulations in effect at the time of the stay for the specific location.
Travel and per diem expenses will be reimbursed on an actual expenditures basis in accordance with Federal Travel Regulations and FAR 31.205-46. In order to be reimbursed for travel, the contractor shall submit supporting documentation as required by Federal Travel Regulations with invoices. Federal Travel Regulations require receipts for travel expenditures of $75.00 or more. Expenses for subsistence and lodging will be reimbursed to the contractor only to the extent where an overnight stay is necessary and authorized by Federal Travel Regulations in effect at the time of the stay for the specific location. Profit and G&A will not be an allowable reimbursement expense for travel. Additional information can be found at:
http://www.gsa.gov/Portal/gsa/ep/channelView.do?pageTypeId=17113&channelPage=%2Fep%2Fchannel%2FgsaOverview.jsp&channelId=-24564
6. Deliverables:
| Task |
| Task Name |
| Task Description |
| Task 1 |
| VA Survey Collection |
| The contractor shall be responsible for ensuring receipt of VA employee salary data files, duty station files, LPS schedules, special rate schedule files, General Schedule (GS) locality pay schedules, Title 38 pay schedule files, Federal Wage System pay schedules, Senior Executive Service pay schedule files from VHA WMC HRCoE on a quarterly basis. The contractor will use these data files to provide detailed information to third-party survey sources on behalf of VA. |
| Subtask 1.1 |
| VA Data Reformatting |
| The Contractor shall reformat employee compensation data based on data that is duty station specific (City/State) to benchmark positions in each Third-Party Surveyor. |
| Subtask 1.2 |
| VA Data Distribution |
| The contractor shall be responsible for the entire survey submission and purchasing process on behalf of VA. This includes providing detailed information using employee data files and location files (see Task 1) in order to provide VA information requested from a variety of third-party survey data companies/organizations that have been identified by VA. |
| Task |
| Task Name |
| Task Description |
| Task 2 |
| Survey collection and analysis of Third-Party Surveys |
| The contractor shall compile data from VA and participate in Third-Party Surveys on VA behalf based on which surveyors are required per the Task Order. |
| Subtask 2.1 |
| Data Analysis |
| The contractor shall analyze the data collected from the Third-Party Surveyors. This analysis shall include aggregation of the market data which includes benchmarking and establishing comparisons between VA and third-party survey data. |
| Subtask 2.2 |
| Geographical Differential Analysis |
| The contractor shall apply geographical differentials (drilled down to city/state) to national survey data. |
| Task 3 |
| Compensation |
Survey File/ Database The contractor shall provide a Compensation Survey File/Database to be used by VA employees working in human resource departments. This report/file shall be capable of the following:
a. Using established geographic differentials, the file/database will apply a differential or percentage which is used to calculate national or other regional survey data in order to populate salary information for a specific VA duty station location. This aggregated survey data is then reported for all established VA duty station locations for a wide variety of clinical, professional, administrative, technical, clerical, trade, engineering, security/law enforcement, or other healthcare occupations.
b. Using a sort feature, HR Specialists will select the city and state. The compensation file/database will aggregate the national survey data based on the geographic differential.
c. The file/database will provide a listing of all VA duty station locations and the geographic differential percentage applied for the specific duty station location.
d. The file/database will also provide job titles, job descriptions along with the corresponding VA job match, and a list of participating establishments.
e. Survey data may include the following components: minimum and maximum rates actually paid in a given job category, published minimum and maximum rates paid, mean salary, median salary, and percentile survey data, along with additional data for premium or differential pay rates, bonuses, any performance or merit based pay components, etc.
f. One version of all data files and/or reports provided by the contractor shall afford VA the ability to import the data to an external, cloud-based database or compensation system.
The development of the Compensation Survey File/Database will only be required during the Base Year.
| Subtask 3.1 |
| Instruction Guide for Compensation |
Survey File/ Database Contractor must develop a survey deliverable instruction guide/training tool containing information on data definitions, instructions on how to utilize the file/database, as well as a description of how the geographic differentials were determined and applied.
| Subtask 3.2 |
| Instruction Guide Updates |
| The Contractor shall refer to Tasks 1 and 2 to update the Compensation Survey File/Database. The file/database, along with the corresponding instruction guides, shall be updated each option year to include the newly collected VA and Third-Party Salary Survey information. The updated Compensation Survey Files/Database and Instruction Guides will then be provided (or updated) to the VHA WMC HRCoE Program Manager based on an agreed upon delivery schedule. |
7. Formal Acceptance or Rejection of Deliverables: The Government will have ten (10) business days to review each deliverable and provide feedback/comments. The contractor shall have three (3) business days to incorporate feedback/comments and make appropriate revisions. The contractor shall provide the revised version of each deliverable to the COR and VA PM. The COR will review and determine final acceptance by the Government. The COR will notify the contractor of final acceptance within five (5) business days.
Method and Distribution of Deliverables: The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include the latest version of the following software, but no earlier than 2016: Microsoft (MS) 365, MS Word, MS Excel, MS PowerPoint, MS Project, MS Visio, AutoCAD, and Adobe Postscript Data Format (PDF). These files must have the capability to be imported into an external site. One version of all data files and/or reports provided by the contractor shall afford VA the ability to import the data to an external, cloud-based database or compensation system.
The contractor shall adhere to all pertinent Veterans Affairs (VA) policy standards including but not limited to ensuring that all documentation and deliverables are stored on appropriate VA servers within one week of their completion. The contractor shall use the VA Nationwide Teleconferencing System (VANTS), Microsoft Skype, or Microsoft Teams for all pertinent conference calls, and the VA Exchange server for all pertinent email. Upon assignment of VA email accounts, use of external email accounts for the purpose of VA communications and business will be prohibited. The contractor shall be responsible for adhering to all pertinent VA information technology policies and procedures, which are discussed in Section 11 of this PWS.
8. Section 508 Acceptance Criteria: Supplies or services delivered as a result of this solicitation will be accepted based in part on satisfaction of identified Section 508 requirements for accessibility. If the deliverable includes features and functions in addition to those identified as requirements, these features and functions also need to conform to relevant Section 508 technical provisions, functional performance criteria, and information, documentation and support.
NOTE FOR DELIVERABLE ACCEPTANCE / QUALITY ASSURRANCE: Generally accepted inspection and test methods corresponding to the identified Section 508 standards is reflected in the attached EIT Acceptance Guide. This guide may be used to assist in the inspection and testing of supplies and services provided as contract deliverables corresponding to this solicitation.
9. Changes to the Statement of Work: Only the Contracting Officer is authorized to make any changes to this PWS; and the Contract Specialist will authorize such changes only through written correspondence. The Contract Specialist will keep a copy of each change in a project folder along with all other products of the project. The contractor shall bear any and all costs incurred by the contractor through the actions of parties other than the Contracting Officer.
10. The COR and PM representative or any other individual (including VA or other Government agency employees or employees of other contractors) other than the VA Contracting Officer are not authorized to make any changes of a contractually binding nature to the period of performance, funding and/or any other terms and conditions of any award or order resulting from this solicitation.
11. General Requirements
11.1 POSITION/TASK RISK DESIGNATION LEVEL(S) AND CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
POSITION/TASK RISK DESIGNATION LEVEL(S)
| Position Sensitivity |
| Background Investigation (in accordance with Department of Veterans Affairs 0710 Handbook, “Personnel Security Suitability Program,” Appendix A) |
| Low |
| National Agency Check with Written Inquiries (NACI) A NACI is conducted by OPM and covers a 5-year period. It consists of a review of records contained in the OPM Security Investigations Index (SII) and the DOD Defense Central Investigations Index (DCII), FBI name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is used for Non-sensitive or Low Risk positions. |
| Moderate |
| Moderate Background Investigation (MBI) A MBI is conducted by OPM and covers a 5-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check], a credit report covering a period of 5 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, law enforcement check; and a verification of the educational degree. |
| High |
| Background Investigation (BI) A BI is conducted by OPM and covers a 10-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check report], a credit report covering a period of 10 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, spouse, neighbors, supervisor, co-workers; court records, law enforcement check, and a verification of the educational degree. |
The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the Performance Work Statement are:
Position Sensitivity and Background Investigation Requirements
| Task Number |
| Low/NACI |
| Moderate/MBI |
| High/BI |
| ALL TASKS |
| |_| |
| |X| |
| |_| |
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
11.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
a. All Contractor employees who require access to the Department of Veterans Affairs’ (VA’s) information or computer systems shall be the subject of a background investigation in accordance with VA Directive 0710. This requirement is applicable to all subcontractor personnel requiring the same access. All Contractor (and subcontractor) employees who require access to the Department of Veterans Affairs’ building(s), ground(s), and space(s) (public and secure) will be issued a Contractor Personnel Identification Verification (PIV) Credential as described by Homeland Security Presidential Directive -12 (HSPD-12) and VA Directive 0735. The VA Directive 0710 provides additional guidance and clarification specific to Contractors’ investigations. In all cases, access (physical and computer) cannot be granted until the COR is officially notified by Security Investigations Center (SIC), Little Rock, Arkansas that contractor staff have meet the requirements of this section. Access can be granted however, prior to VA receiving final adjudication results.
(1) Position Sensitivity – The position sensitivity for each Contractor position is determined by the U.S. Office of Personnel Managements, Position Designation of National Security and Public Trust Positions (OPM – PDAT). Each position will be designated at the high, moderate, or low risk level, depending on the position’s potential for adverse impact to the integrity and efficiency of the services (CFR 731.106). Multiple positions within a skilled trade or professional classification (examples: electricians’, general construction labors’, Health Care Professionals (RN, DO, MD,) maybe documented on a single PDAT Form. Risk levels determine what level of investigation is required.
(2) Background Investigation – The level of background investigation commensurate with the required level of access may be either a Special Agreement Check (SAC)/National Criminal History Check (NHCH), National Agency Check with Inquiries (NACI) (low risk), Moderate Background Investigation (MBI) (moderate risk), or Background Investigation (high risk). Non-citizen contract personnel appointed to low risk positions will be subject to a National Agency Check with Law Enforcement and Credit Check.
(3) Contractor Personnel Identification Verification (PIV) Credential – This form of universal government identification is the only acceptable form or Federal Identification permitted on government property. This credential is government property and will be surrendered upon the completion of contract or at the destruction of the government. The bearer is responsible for the loss, theft or improper destruction, and as such may be subject to replacement costs at time of reissue. PIV Credentials have an expiration date and will be become void upon the date indicated. The type of PIV Credential required is commensurate with the required level of access, length of contract award, and physical/computer access. There are three types of Contractor PIV Credentials:
a. Flash Badge PIV Credential – requires the bearer to be subject to agency ID Proofing and issued for periods of one (1) day up to 180 days (continual usage).
b. Non-PIV Credentials - requires the bearer to be subject to agency ID Proofing, a SAC/NCHC (fingerprinting), to undergo a background investigation (low risk), and issued for periods of 180 days up to one (1) year.
c. PIV Credential - requires the bearer to be subject to agency ID Proofing, a SAC/NCHC (fingerprinting), to undergo a background investigation (low risk), and issued for periods of one (1) year up to three (3) years.
NOTE: There are no costs for the issuance of the Contractor PIV Credential.
(4) Contractor Responsibilities:
(a) The Contractor (subcontractor) shall prescreen all personnel requiring access to VA information or any VA computer systems to ensure that they are able to read, write, speak, and understand the English language.
(b) E-mail notifications will be received by the Contractor from the VA Security Investigations Center (SIC) explaining specific instructions once an investigation has been ordered. The Contractor (subcontractor) employees will be required to complete their background investigation using the Electronic Questioner Investigation Process (eQIP) hyperlink within the allotted period (5 calendar days) from notification by the SIC. The Contractor will be required to complete and provide all required background investigation document(s) to the SIC via traceable method (FedEx, DHL, etc.) within three (3) calendar days of electronic release of the eQIP background investigation.
(c) Contractors who have a favorably adjudicated background investigation and it has been determined by the SIC to be acceptable may be eligible for Reciprocity. The Contractor will be required to complete the Declaration of Federal Employment Form (OF-306) and complete a new SAC/NCHC submission. The SIC is the Agency Authority regarding Reciprocity. Access to the VA facilities, information, or systems cannot be granted until the SIC has received all requirements from the Contractor. (subcontractor).
(d) The Contractor (subcontractor) employee shall complete the SAC/NCHC (fingerprinting) requirement electronically at the VA Medical Center. The Contractor shall contact by telephone the local VA Medical Center (VA Police or VA Human Resource Office) or visit http://www.va-piv.com to establish appointments for fingerprinting. VA uses electronic fingerprint machines which require the Contract (subcontractor) employee to fill out the Electronic Fingerprint Verification Letter on the Veteran Health Administration (VHA) Service Center Website.
Please feel free to contact the SIC at VSC.Security@va.govwith any questions during this process.
(e) The Contractor, when notified of an unfavorable determination by the Government, will immediately withdraw the employee from consideration from working under the contract and return all Government Property.
(f) Upon contract award and request by the contracting office, the Contractor (subcontractor) shall furnish the Information Security Office and the Contracting Officer a list of personnel performing work on the contract. The list will include a brief description of the work to be performed and degree of access to information management systems required. The description of required degree of access will address if remote access is required. The Contractor shall update and submit the list of personnel performing work on the contract to the Information Security Office every (calendar) year, throughout the contract period. Furthermore, the Contractor shall notify the Information Security Office when personnel performing work under this contract no longer require access to the information management systems within 24 hours of employee change.
(g) Per VA Directive 6500 the Contractor (subcontractor) employee shall complete all required VA Information Security Training classes entitled “VA Information Security Awareness” and VHA Privacy Policy” on a yearly basis. Certificate(s) of successful completion will be generated for each course. These certificates of successful completion shall be maintained by the Contractor, the Information Security Office and the Contracting Officer and be made available for inspection and audit as determined by the Government.
(h) Failure to comply with the Contractor personnel security requirements shall result on termination of the contract for default.
(5) Government Responsibilities:
(a) Upon receipt, the VA Office of Security and Law Enforcement will review the completed electronic submission(s), and all completed forms for accuracy, then release (electronically) and forward via official mail the forms to OPM to conduct the background investigation.
(b) The VA facility/activity will pay for the investigations conducted by the Office of Personnel Management (OPM) in advance. In these instances, the Contractor WILL reimburse the VA within 30 days of receiving the Bill of Collections for these costs.
(c) The VA Office of Security and Law Enforcement will notify the Contracting Officer and Contractor after adjudicating the results of the background investigation(s) received by OPM using the Certificate of Investigations Form.
(d) The Contracting Officer will ensure that the Contactor (subcontractor) provides evidence that investigations have been completed or are in process of being requested.
b. Contractor (subcontractor) personnel performing work under this contract shall satisfy all requirements for appropriate security eligibility in dealing with access to sensitive information and information systems belonging to or being used on behalf of the Department of Veterans Affairs’. The Contractor (subcontractor) will be responsible for the actions of those individuals they provide to perform work for the VA under this contract. In the event that damages arise from work performed by Contractor (subcontractor) provided personnel, under the auspices of this contract, the Contractor will be responsible for all resources necessary to remedy the incident. Printed output containing sensitive VHA data will be stored in a secured area and disposed of properly by shredding using NIST-compliant shredder or other VA approved method. Under the provisions of the Privacy Act of 1974 as amended, personnel performing work under this contract have an obligation to protect VA information indefinitely. Furthermore, it is the Contractor’s responsibility to notify the Information Management Staff when access to Information Management systems is no longer needed by personnel performing work under this contract.
c. No contractor (non-VA) equipment is permitted to be connected to the VA network without prior approval. If a laptop or desktop computer must be connected, a security check must be completed by the Information Technology Staff at the local Information Security Office. If unapproved equipment is detected, it will be immediately disconnected from the VA network.
d. If remote access is required in order to perform the work in this contract, a VPN request form must be completed and approved by the local COR designee, and submitted to the Information Security Office (ISO). The account will be given access only to the IP addresses required by this contract. The Contractor (subcontractor) will make every attempt to use the VA’s RESCUE software in order to remotely connect to the VA network. Use of CITRIX may also be used to remotely connect to the VA network with proper authorization. If RESCUE/CITRIX cannot be used to perform the required risks, then a waiver request must be submitted in order to use temporary "PIV EXEMPT PASSWORD".
e. Contractor (subcontractor) personnel are not permitted to have administrative rights on a VA server without an approved waiver. Contractor personnel must work with the local VA IT staff to perform administrative functions. A waiver will only be considered in cases where the use of VA IT staff is not possible or not feasible. The waiver must be submitted to and approved by the Information Security Office.
13.0 FACILITY/RESOURCE PROVISIONS - The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.
The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.
VA will provide access to VA specific systems/network as required for execution of the task via remote access technology (e.g. Citrix Access Gateway (CAG), site-to-site VPN, or VA Remote Access Security Compliance Update Environment (RESCUE)). The Contractor shall utilize Government-provided software development and test accounts, document and requirements repositories, etc. as required for the development, storage, maintenance and delivery of products within the scope of this effort. The Contractor shall not transmit, store or otherwise maintain sensitive data or products in Contractor systems (or media) within the VA firewall IAW VA Handbook 6500.6 All VA sensitive information shall be protected at all times in accordance with VA policy.
11.3 GOVERNMENT FURNISHED PROPERTY
The Government will not provide property to the contractor.
11.4 VA INFORMATION CUSTODIAL LANGUAGE
The following security requirement must be addressed regarding Contractor supplied equipment: Contractor supplied equipment, PCs of all types, equipment with hard drives, etc. for contract services must meet all security requirements that apply to Government Furnished Equipment (GFE) and Government Owned Equipment (GOE). Security Requirements include: a) VA Approved Encryption Software must be installed on all laptops or mobile devices before placed into operation, b) Bluetooth equipped devices are prohibited within the VA; Bluetooth must be permanently disabled or removed from the device, c) VA approved anti-virus and firewall software, d) Equipment must meet all VA sanitization requirements and procedures before disposal. The COR, CO, the Project Manager, and the Information Security Officer (ISO) must be notified and verify all security requirements have been adhered to.
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
b. VA information should not be co-mingled, if possible, with any other data on the Contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Directive 6500, Cybersecurity Program. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose, and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
i. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.
12. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.
b. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
c. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with VA Handbook 6500.3, Assessment, Authorization, and Continuous Monitoring Of VA Information Systems and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.
d. The contractor/subcontractor’s system shall adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process. The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing, and updating, all the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.
e. The contractor/subcontractor shall conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment shall be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor shall take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.
f. VA prohibits the installation and use of personally owned or contractor/subcontractor owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.
g. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information shall be handled in adherence with VA Handbook 6500. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500 requirements. This shall be completed within 30 days of termination of the contract.
13. SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access, in accordance with VA Handbook 6500.2 Management of Security and Privacy Incidents
b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
c. In instances of theft or break-in or other criminal activity, the contractor/subcontractor shall concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
14. LIQUIDATED DAMAGES FOR DATA BREACH
a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.
b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.
c. Each risk analysis shall address all relevant information concerning the data breach, including the following:
(1) Nature of the event (loss, theft, unauthorized access);
(2) Description of the event, including:
(a) date of occurrence;
(b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;
(3) Number of individuals affected or potentially affected;
(4) Names of individuals or groups affected or potentially affected;
(5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;
(6) Amount of time the data has been out of VA control;
(7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);
(8) Known misuses of data containing sensitive personal information, if any;
(9) Assessment of the potential harm to the affected individuals;
(10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and
(11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.
15. SECURITY CONTROLS COMPLIANCE TESTING
On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .