Attachment A - SOW COVID_Strep 05-25-23.pdf
PDF 273 KB Posted
- Attached to
- Real Time Polymer Chain Reaction Testing Federal contract opportunity
- Solicitation number
- W81K0023R0012
- Issued by
- Department of the Army Medical Command
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 01 - W81K0023R0012.pdf | ||
| Conformed - W81K0023R0012_2 June 2023.pdf | ||
| Attachment D - Question and Answer W81K0023R0012.pdf | ||
| Attachment A - SOW COVID_Strep 06-02-23.pdf | ||
| Attachment B - Pricing Worksheet 05-09-23.xlsx | XLSX spreadsheet | |
| Solicitation_W81K00-23-R-0012.pdf | ||
| Attachment C1 - DHA Cybersecurity RMF Requirements.pdf | ||
| Attachment C2 - RMF TimeFrames.pdf | ||
| Attachment C3 - RMF Cybersecurity Assessment Questionnaire 15May.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
SARS-CoV-2 & influenza AB Testing, and Streptococcus pyogenes (Strep Group A)
Department of Pathology and Area Laboratory Services (DPALS)
Brooke Army Medical Center (BAMC)
1. Scope: This is a supply requirement.
1.1. The Contractor shall provide new molecular testing equipment, reagents, consumables, maintenance support and instrument warranties used in support of detection of SARS-CoV-2, Influenza A/B, Streptococcus pyogenes (Strep Group A) for the Department of Pathology and Area Laboratory Services
(DPALS) Microbiology Labs at the Brooke Army Medical Center (BAMC) and its surrounding clinics/healthcare network, located at or near Joint Base San Antonio, TX 78234.
1.1.1. All supplies and warranties outlined in this Statement of Work (SOW) shall be supplied and serviced through a single Contractor (to whom the contract is awarded, to include any parts, equipment, or supplies not manufactured, provided or serviced by the Contractor).
1.1.2. All supplies and work performed in connected with warranties shall preserve the US Food and Drug
Administration (FDA) approved status of the assays and instrumentation used.
2. Purpose
During the ongoing global pandemic of SARS-CoV-2 (also known as COVID-19), BAMC’s Microbiology Section have been using Nucleic Acid Amplification Tests (NAAT) as diagnostic tests to identify infected individuals with
SARS-CoV-2 and Influenza A/B viruses to help prevent further person-to-person transmission and appropriately guide clinical management decisions. The overlap of SARS-CoV-2 and Influenza A/B viral infections during 2022-
2023 Flu season poses a unique and challenging testing demand to the laboratory. Therefore, it is vital that the laboratory maintains the existing SARS-CoV-2 and Influenza A/B rapid testing capabilities to facilitate the clinical management of patients that are at high-risk for respiratory complications, pending admission or have been hospitalized.
The rapid strep A PCR tests have shown equivalent sensitivity and specificity to bacterial cultures, and improved sensitivity compared to rapid antigen detection test (RADT) from throat swabs and is routinely used to confirm
Group A Streptococcal (GAS) pharyngitis. Importantly, they can provide results in 10–20 minutes. A rapid test result, in conjunction with a throat culture and clinical information, is to aid in the diagnosis and help clinicians timely prescribe appropriate antibiotics. Clinicians cannot differentiate viral and GAS pharyngitis in the absence of viral symptoms. The strep A PCR demand has increased in the pediatric population during the SARS-CoV-2 and Flu season. Therefore, it is essential that BAMC maintains rapid strep A PCR testing capability to confirm GAS pharyngitis mainly in children older than 3 years of age to appropriately guide treatment decisions.
In order to be able to conduct these tests, reagents and automated analyzers are needed for period of performance with a five (5) year ordering period from 1 October 2023 thru 30 September 2028. The equipment shall be able to connect to the MHS Genesis and shall come with an un-interruptible power supply capable of providing power for at least 45 to 60 minutes. All equipment and supplies shall be approved by the FDA and able to support testing operations at BAMC main-hospital and 4 outlying clinics. This requirement is needed NLT 1 October 2023. All detailed information regarding delivery and installation is provided in the SOW.
3. Ordering Period
Ordering Period Yr 1: 1 October 2023 – 30 September 2024
Ordering Period Yr 2: 1 October 2024 – 30 September 2025
Ordering Period Yr 3: 1 October 2025 – 30 September 2026
Ordering Period Yr 4: 1 October 2026 – 30 September 2027
Ordering Period Yr 5: 1 October 2027 – 30 September 2028
3.1. The Government will order items on as needed basis, and shall only pay for the actual number of tests ordered, received, and accepted by the Government. The quantities listed in the workload data table represent anticipated test volumes for the period of performance listed; however, quantities could increase and/or decrease during certain periods and/or months.
3.2. The inspection and acceptance for all deliverables rendered under this contract will be by the appointed
Ordering Officer. The performance by the Contractor technician, the quality of services rendered, and any documentation or written material in support of same, shall be subject to continuous inspection, surveillance, and review for acceptance by the designated ordering officer representative. Other evaluation factors will be monitored that are not quantified by numerical measurements.
4. Hours of operation:
The microbiology laboratory is in operation 24 hours a day, 7 days a week. Normal business hours for administrative personnel are Monday through Friday between the hours of 0730 – 1630 CST. Contractor shall coordinate maintenance scheduled with Ordering Contracting Officer and appointed on duty staff in absence of
OCOR no less than 48 hours.
5. Security requirements and safety:
5.1. SECURITY. The Contractor shall ensure its personnel comply with the local installation requirements for vehicle registration and operation on the military facility. Any vehicle entering the military installation shall have the minimum liability coverage required by the state in which the performance is located. The
Contractor shall ensure its personnel comply with installation and MTF personnel identification and access requirements.
5.2. Contractor and all associated sub-Contractors personnel shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and
Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures
(provided by Government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
5.3. SAFETY. The Contractor shall ensure its personnel comply with all installation and MTF safety regulations. Such regulations include, but are not limited to, general safety, fire prevention, and waste disposal. Copies of these regulations are available in the medical activity safety office or may be obtained through the appointed personnel. The use of cellular phones and 2-way radios is expressly forbidden in all
Medical Treatment Facilities and Health Clinics. The Government and the Contractor’s service representative will exchange hazard communication information before the commencement of any repair.
When required, the Contractor’s service representative will comply with the Office of Safety and Health
Administration (OSHA) lockout/tag-out standards while performing sustainment on MD/MDS.
6. Instrument/equipment requirement (owned by Contractor):
Multiple automated RT-PCR platforms intended for the rapid in vitro qualitative detection and differentiation of SARS-CoV-2, Influenza A, Influenza B, and Streptococcus pyogenes (Strep Group A) to support testing at BAMC. The Contractor shall provide at a minimum a total of 15 RT-PCR testing platforms to support microbiology laboratory operations at BAMC main hospital and 4 outpatient clinics as listed below in section 7.11.
The analyzer shall:
6.1. Be FDA-approved, CLIA-waived, point-of-care analyzers and company willing to supply analyzers on a reagent rental basis to support the assays listed below.
6.2. Plug into standard 120V outlet and be provided with individually dedicated electrical cord.
6.3. Individual analyzers shall fit into a foot print no larger than 12 inches x 16 inches and have a maximum height of 18 inches.
6.4. Individual analyzer computer shall be integrated to minimize footprint
6.5. Analyzer shall be able to report results of test within 45 minutes of starting test run.
6.6. Analyzer shall be able to scan barcodes and be compatible with 39 and 128 barcode types.
6.7. Turnaround time (TAT) less than 45 minutes and hands-on time less than 5 minutes.
6.8. Ability to scan barcodes generated in-house.
6.9. Fully automated sample extraction, PCR amplification, and detection
6.10. Real time PCR based technology.
6.11. Be capable of interfacing with the military hospital computer system, i.e., Military Health System Genesis
(MHS Genesis). The Contractor shall have an established driver compatible for interfacing the analyzer with MHS Genesis.
6.11.1 The analyzer system shall be capable of interfacing with the military hospital computer system, i.e., the
Military Health System Genesis. The Contractor shall have a driver compatible for interfacing the analyzer with
MHS Genesis. The interface between MHS Genesis and the analyzer shall be bi-directional. The contractor shall identify the contractor specific equipment or third-party contractor’s equipment including hematology and coagulation that is able to connect via driver to IT (Middleware) interface; contractor to include two (2) third party licenses for additional connectivity.
6.11.2 The analyzer system shall include a data management system for control of the operation of the analyzer system, management of the quality control program, management of the on-instrument useful life of the reagents/reagent packs, and management of patient results; and a printer for the production of hard copy patient reports and other reports generated via the analyzer system’s data management system. The Data Management system shall have a comprehensive, fully integrated Quality Control (QC) software module that stores and evaluates quality control results. Results can be viewed in a variety of formats including Levy-Jennings charts, moving patient averages, CAP connectivity, EP Evaluator, and statistical summaries. The application shall validate QC results by checking them against user selected rules and automatically alert the operator when a rule violation has occurred. The software program shall have the capability to incorporate Bio-Rad’s online/onboard Quality Control analysis package, Unity Interlaboratory Program and Unity QC Data
Management Solutions.
6.12. Integrated quality control in every test cartridge.
6.13. Self-contained-test cartridge/assay tube.
6.14. The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of Government data.
Contractors shall ensure ability to conform to all standards set forth by Department of Defense Risk
Management Framework.
6.14.1 The Contractor shall employ physical security safeguards for IS/Networks involved in processing or storage of Government Data to prevent the unauthorized access, disclosure, modification, destruction, use, etc., and to otherwise protect the confidentiality and ensure use conforms with DoD regulations. In addition, the
Contractor shall support a Physical Security Audit performed by the Government of the Contractor's internal information management infrastructure.
6.14.2 The MHS Physical Security Audit Matrix is available at:
http://www.tricare.osd.mil/tmis_new/Policy/PSA_Matrix_%20012304%200930%20clean%20version.xls.
http://www.tricare.osd.mil/tmis_new/Policy/PSA_Matrix_%20012304%200930%20clean%20version.xls
6.14.3 The Contractor shall correct any deficiencies identified by the Government of the Contractor's physical security posture. New Army policies will be posted to the following website: http://www.apd.army.mil.
7. Reagent Requirements – Microbiology Laboratory
The Contractor shall provide the following at a minimum for microbiology laboratory operations at the main hospital located at BAMC:
7.1. Be FDA-cleared or authorized by FDA under the Emergency Use Authorization (EUA) for use.
7.2. Reagent capability to multiplex a SARS-CoV-2 and Influenza A/B assay in one run.
7.3. Streptococcus group A (Streptococcus pyogenes) with a documented accuracy and sensitivity >95%.
Streptococcus pyogenes (Strep Group A) test does not require need for confirmatory culture testing in adults and children, unless result is negative and clinical symptoms persist, or in the event of an outbreak of acute rheumatic fever.
7.4. All reagents shall be in one assay tube/cartridge self-contained.
7.5. Acceptable specimen for SARS-CoV-2, SARS-CoV-2 & Influenza A/B test shall be nasopharyngeal swab in Viral Transfer Medium (VTM).
7.6. Acceptable specimen for Streptococcus pyogenes (Strep Group A) or throat swabs shall be throat swab in
Amies liquid transport medium
7.7. The Contractor shall provide all reagents/reagents packs, calibrators/standards, quality control materials, user-replaceable maintenance items, and analyzer specific tools/supplies to support the ongoing delivery of laboratory services using the equipment outlined in this section.
7.8. Reagents/consumables shall meet the requirements of the 24/7 BAMC mission, workload, and test menu
(outlined in Table 1).
7.9. The Contractor shall repair/replace any unsatisfactory items at contractor’s expense.
7.10. All items are to have a minimum 6-month shelf-life from date of receipt.
7.11. All reagents shall be available for delivery as specified in the delivery order award.
Delivery shall be to the following address:
a. Brooke Army Medical Ctr Bldg 3600
3551 Roger Brooke Dr
Fort Sam Houston TX 78234
b. Jennifer M. Moreno Clinic
Bldg. #1179 Garden Avenue
Fort Sam Houston, TX 78234
c. Taylor Burke Health Clinic
5026, Camp Bullis Rd
San Antonio, TX 78257
d. Westover Medical Home
10010 Rogers Crossing
San Antonio, TX 78251
e. Schertz Medical Home
6051 FM3009
Schertz, TX 78154
The Point of Contact (POC) for all deliveries:
NCOIC or Supervisor, Microbiology Laboratory
Department of Pathology and Area Laboratory Services http://www.apd.army.mil/
San Antonio Military Medical Center
Tel: (210) 916-5005
8. Delivery of Equipment
8.1. Contractor shall provide transition plan for instrument(s)/equipment delivery, installation, and verification that aims at avoiding or minimizing interruption of in-house testing, expenses associated with send-out of samples to reference laboratory for testing, and impact to patient care.
8.2. Contractor shall indicate in transition plan what facility modifications will be required for instrument(s)/equipment delivery.
8.3. All equipment (owned by Contractor) shall include delivery, installation, maintenance, and removal upon termination of contract. Contractor shall furnish all necessary calibrators/standards and quality control materials necessary to perform the initial method verifications per CLIA/NCCLS guidelines.
8.4. The instrument(s)/equipment shall be delivered within 30 days or less after contract award to the following addresses:
a. Brooke Army Medical Ctr Bldg 3600
b. Jennifer M. Moreno Clinic
Bldg. #1179 Garden Avenue
Fort Sam Houston, TX 78234
c. Taylor Burke Health Clinic
5026, Camp Bullis Rd
San Antonio, TX 78257
d. Westover Medical Home
10010 Rogers Crossing
San Antonio, TX 78251
e. Schertz Medical Home
6051 FM3009
Schertz, TX 78154
8.5. Exact installation location shall be coordinated by Contractor and Government point of contact (OIC and/or NCOIC). Equipment setup, LIS connectivity, on-site training, and method verification studies, shall be completed by contractor personnel within six (6) weeks or less after contract award to ensure that equipment is fully operational.
8.6. SAFETY DATA SHEETS (SDS): The Contractor shall provide safety data sheets (SDS) for each item delivered under this contract that is considered to be HAZARDOUS MATERIAL. The SDS shall contain information on the hazards associated with each specific chemical or material. The SDS shall contain at a minimum the following information: identification of the specific hazard, the required practice for the safe use of the product, first aid procedures, and what to do in the event of a spill or other mishap or accident.
8.7. The Contractor shall be responsible for installation, which consists of in-house delivery, positioning, and mounting of all equipment listed on the delivery order and connections of all equipment and interconnecting wiring and cabling if applicable in coordination with the facility biomedical engineer.
Upon receipt of notice to proceed with installation, it shall be the Contractor's responsibility to inform the
Contracting Officer of any problems which may be anticipated in connection with installation, or which will affect optimum performance once installation is completed. In the event that progress of the installation is interrupted through no fault of the Contractor, the continuous installation referenced in the preceding paragraphs may be terminated until such time as the cause of delay has been eliminated, and then shall be resumed within 24 hours after the Contractor has been notified that work may again proceed.
8.8. Contractor shall provide equipment installation and possible reinstallation at minimal costs if the equipment is required to be moved due to construction or laboratory redesign.
8.9. All reagents shall be available for delivery within one business day of contract award date.
Delivery shall be to the following address:
Brooke Army Medical Ctr Bldg 3600
The Point of Contact (POC) for all deliveries:
NCOIC or Supervisor, Microbiology Laboratory
Department of Pathology and Area Laboratory Services
San Antonio Military Medical Center
Tel: (210) 916-5005
9. Installation and Validation
During the installation and validation of the equipment and tests to be performed by the Contractor, the Contractor will coordinate scheduled meetings with technical experts of the Laboratory to discuss milestones and to provide updates on completion date. Following the completion of the installation of the new equipment and validation of the tests to be performed, the Contractor will meet with technical experts from the laboratory at times mutually agreeable to discuss areas of interest to the laboratory or hospital staff. When the validation of the equipment and tests are to be performed, the Contractor shall provide all reagents, calibrators, controls and any other materials used at no additional cost to the Government. The Contractor will provide analyzed data to laboratory supervisor for approval. If the validations are not found to be adequate, the Contractor will be responsible for repeating studies in a timely manner for the laboratory to meet go live deadlines.
10. Preventative maintenance, failures and repairs
10.1. The Contractor shall provide all personnel, equipment, tools, materials, supervision, parts, transportation, and other items and services necessary to perform all required repairs and scheduled preventive maintenance/safety inspections and calibrations of their equipment. Contractor shall coordinate with the designated point of contact all scheduled maintenance within ten (10) business days prior to performing preventative maintenance services.
10.2. The performance of scheduled periodic preventive maintenance, safety checks, and calibrations that are not normally performed at the operator level will be performed by Contractor service personnel in accordance with requirements as specified in the Contractor’s instrument maintenance manual. The
Contractor shall be responsible for furnishing maintenance, services, repairs, and parts as required by manufacturer to maintain the system in optimal operating condition.
10.3. The Contractor shall provide a full-service plan to include the recommended unscheduled and preventive maintenance service for their instrument/equipment period. Service shall include repair and replacement of defective parts, complete maintenance program (as required by the manufacturer’s maintenance manuals), and hotline telephone service, in order to assist customer in troubleshooting problems.
10.4. Preventive maintenance services shall be performed in accordance with the manufacturer’s standard/procedures. A preventive maintenance service shall include, but is not limited to, safety, calibration, complete operational testing, lubrication, adjustments, and cleaning of equipment to which the operator does not have access. This also includes the installation of all non-operator parts required to ensure proper operation.
10.5. Upon notification of equipment failure own by Contractor, the Contractor shall respond to telephonic requests for unscheduled repair within 24 hours. Should the instrument/equipment become inoperable, the
Contractor’s Repair Service Engineer / technician shall be on-site within 24 hours of initial notification for routine/emergency failures. If the equipment is out of service for longer than 72 hours (from the time-of-service technician’s arrival on site), the Contractor shall notify the Government point of contract on duty, in writing, as to the reason(s) (i.e. non-availability of parts, etc.) for non-compliance.
10.6. If the equipment cannot be repaired, a replacement instrument shall be provided within seven (7) days. If the equipment cannot be replaced, the Government may seek remedies for non-compliance with terms and conditions of this contract.
10.7. Within one (1) business day after completion of a repair, the Contractor’s representative shall furnish the
Point of Contact (POC) one (1) copy of a service report for all services performed. The service report shall contain, at a minimum, the following information:
a. Nomenclature, date, description of services performed (i.e., preventative maintenance service, or unscheduled repair service)
b. Location of services performed, duration of services performed, list of parts replaced
c. Other actions taken to restore operability of the instrument/equipment, name of technician.
**Full report shall be submitted to designated Government point of contact**
10.8. Contractor shall notify Government of any hazard information before beginning equipment repair and shall comply with the Occupational Safety and Health Administration while performing maintenance on electrical equipment.
10.9. When appropriate, the Contractor’s representative shall attach and complete a DD Form 2163 (sticker), entitled “Medical Equipment Verification/Certification” to the equipment upon completion of calibration services. The Point of Contact will provide the DD Form 2163 to the Contractors’ representative. If the
DD Form 2163 is already attached to the equipment, the Contractors' representative shall update the existing DD Form 2163. Procedures for updating the 2163 will be provided by the Point of Contact.
11. Customer service
11.1. The Contractor shall provide direct customer service and support, during normal business hours and on-call emergency repair service support, to assist operators in correcting equipment operation problems.
11.2. For emergency services and unscheduled services, the Contractor’s qualified service technician shall be on-site to provide emergency service (service requiring immediate repair) within 24 hours. The equipment shall be repaired and operational at the minimum of 72 hours after arrival of Contractor on site.
11.3. The Contractor shall perform preventive maintenance services (PMS), safety tests, calibrations, and unscheduled repair services in accordance with procedures and practices prescribed by the manufacturer of the equipment. Scheduled routine services shall be performed between 0730-1630 (CST) Monday-Friday, excluding U.S. Holidays.
11.4. The Contractor shall provide a full unscheduled and preventive maintenance service for the instrument/ equipment owned by Contractor. All maintenance and repairs shall be inclusive of all costs for the performance of scheduled periodic maintenance (as required by the Contractor’s instrument maintenance manuals), unscheduled maintenance and repair of the analyzers and any associated equipment provided by the Contractor as part of the analyzer system, including replacement parts, replacement part shipment costs, and service technician travel costs for performance of maintenance services.
11.5. The Contractor’s qualified service technician shall be on site to provide routine services; service requiring immediate repair; and scheduled services for preventive maintenance (as specified in the Contractor’s instrument maintenance manual), safety and calibration as required by this statement of work. The equipment shall be repaired and operational within 72 hours after arrival of Contractor on site.
11.6. Upon analyzer failure, the Contractor’s qualified service technician shall be on-site to provide unlimited emergency service (service requiring immediate repair; an unscheduled maintenance/service requirement) within 24 hours. The equipment shall be repaired and operational within 72 hours after arrival of
Contractor on site.
11.7. Should the analyzer at BAMC become inoperable, the Contractor’s technical repair specialist shall be on-site within 24 hours of initial notification and make the repair within 72 hours after arrival of Contractor on site. If the analyzer cannot be repaired within 72 hours after arrival of Contractor on site, a replacement analyzer, at no additional cost to the U. S. Government, will be provided within seven (7) days of the initial notification to be utilized by the U.S. Government until the original instrument is fully repaired and accepted for service.
11.8. During the period when the analyzer is inoperable, the Contractor will arrange the pickup and delivery of critical specimens to a College of American Pathologists accredited clinical laboratory of their choice.
The selected laboratory will provide patient reports. Each patient report shall include the testing laboratory’s reference range for the test being performed. The Contractor will be responsible for all costs associated with the provision of this service, including those for delivery of hardcopy patient results, for as long as the analyzer remain inoperable.
11.9. The Contractor shall provide all necessary user-replaceable maintenance items that will be required to support the analyzer, and any analyzer specific tools/supplies necessary to perform operator-level periodic maintenance tasks, at no additional cost to the U.S. Government.
11.10. Minimal hands-on system maintenance required, including limited reagent preparation time/steps prior to use. List reagent /calibrator prep for assays.
11.11. Computer Patient Data Handling: No hardware, containing any patient information is to be removed from any location, without the approval and removal of data by the facility information technology department.
11.12. Preventative and Predictive Maintenance: Contractor shall provide regular, scheduled maintenance to assure the continued reliable operation of the equipment. These preventive maintenance visits shall be of a frequency that conforms to the manufacturer's operation and maintenance instructions for the supported equipment. Minimum of 1 per year per instrument unless documentation for volume performed denotes not required for optimum quality of operation.
11.13. Emergency Repair: Emergency repairs shall be performed after notification that the equipment is inoperative. The Contractor shall provide the Government with a designated point of contact and shall plan to enable its maintenance representative to receive such notification. The Contractor shall perform emergency repair service within 24 hours of time of notification of the malfunction.
11.14. Maintenance Support: Service repair person locally based within San Antonio geographical area,
11.15. Operator Procedure Manuals: operator and service manuals along with Clinical and Laboratory
Standards Institute (CLSI) compliant procedures shall be furnished for each instrument model supplied, unless provided electronically on board the instrument. Contractor to write Standard Operating
Procedures for each assay in the laboratory template, to ensure that procedures are totally available prior to implementation.
12. Training
12.1. The Contractor will provide initial operator training to all technicians assigned to the U.S. Government site (BAMC, Department of Pathology, microbiology laboratory staff), as well as annual refresher training, as needed, to ensure adequate user competency during times of personnel turnover.
12.2. All training manuals/guides, instructional literature, and any other related written/electronic material shall be provided. Training shall include basic operation of the equipment, troubleshooting procedures, performance of operator-level periodic preventive maintenance procedures, and use of the data management/quality control software.
12.3. In addition, the Contractor shall provide supplemental operating training to above Government personnel, without additional charge to the Government, upon installation of the upgrade in equipment hardware or operating system software connected with the operation of an instrument already furnished.
12.4. In the case of any significant software or assay procedural updates, the Contractor shall provide one (1) primary (key) operator training slot per major instrument/equipment, one (1) key operator training per new instrument install, one (1) key operator raining for the existing instrumentation, two (2) on-site in lab training slots for the instrumentation to be used over the 5-year term of the agreement as the lab needs for staff changes. This training can be on or off-site at the Contractor’s full expense.
Personally Identifiable Information, Protected Health Information, and Federal
Information Requirements (Revised 10/27/2020)
1. General Requirements Overview ‐ Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws. This Section addresses the
Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of
Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the Contractor shall comply with the specific requirements set forth in this
Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.
This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.
For purposes of this Section, the following definitions apply.
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are
DoDI 5400.11, DoD Privacy and Civil Liberties Programs, January 29, 2019, and DoDI 5400.11‐
R, Department of Defense Privacy Program, May 14, 2007.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement
Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45
Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C
(Security), Subpart D (Breach) and Part 160, Subparts C‐E (Enforcement), as amended.
Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD
Military Health System (MHS). These issuances are DoDM 6025.18, “Implementation of the
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care
Programs,” March 13, 2019, DoDI 6025.18, Health Insurance Portability and Accountability Act
(HIPAA) Privacy Rule Compliance in DoD Health Care Programs, March 13, 2019, and DoDI
8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs, August. 12, 2015.
Defense Health Agency (DHA) Privacy Office is the DHA Privacy and Civil Liberties Office. The
DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA.
2. Records Management
When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DoD AI‐15), “OSD Records and
Information Management Program” (May 3, 2013) and Records Management requirements outlined in the current TRICARE Operations Manual (TOM).
http://www.dtic.mil/whs/directives
3. Freedom of Information Act (FOIA)
The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:
The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request preferably sent via the National FOIA Portal at: www.FOIA.gov. However, requesters may also submit requests via email at DHA.FOIA@mail.mil; or via postal delivery addressed to the DHA
Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042‐5101. All FOIA requests shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Contract and/or Modification numbers shall be included in all FOIA requests seeking
DHA procurement records. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible and respond to DHA within ten working days.
In response to requests received by the Contractor for the release of information, unclassified information, documents, and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of
Information Officer, for appropriate action. Direct contact, including interim replies, between
TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the
DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.
4. Systems of Records
In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the
Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil
Liberties, and Transparency Division, and as required by the DoD Privacy Act Issuances.
Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99‐05, Attachment B, OMB Circular A‐
130, and Privacy Act of 1974 requirements applicable to contractors operating systems of records on behalf of federal agencies. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.
5. Privacy Impact Assessment (PIA) http://www.foia.gov/
If DHA data is stored on a Contractor owned system, a PIA is required from the Contractor.
6. Data Sharing Agreement (DSA)
6.1 (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de‐identified data)
The Contractor shall consult with the DHA Privacy Office to determine if the Contractor shall obtain a DSA or Data Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.
The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and DoD
HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.
Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor shall gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA
Privacy Board requests for additional documentation.
To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the
DHA Privacy Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data involved:
• DSA for De‐Identified Data
• DSA for PHI
• DSA for PII Without PHI
• DUA for Limited Data Set
DSAs executed for contract support will expire after 1 year. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.
6.2 (Applies if contract requirements may include human subject research)
This Contract incorporates by reference the Protection of Human Subject Research clause in the
Defense Federal Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235‐7004. A separate DFARS provision, 48 CFR 235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR
219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a contractor participates in a study or demonstration project or other activity that involves human subject research, then the contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If contractor activity appears to involve human subject research, then the contractor shall consult the DHA Privacy
Office, which may contact the Research Regulatory Oversight Office in the Office of the Under
Secretary of Defense for Personnel and Readiness (OUSD(P&R)).
7. Privacy Act and HIPAA Training
The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of substance use disorder patient records, 42 CFR Part 2. Refer to
FAR 52.224‐3 regarding specific requirements for Privacy Training appropriate to the
Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a
Covered Entity, or Business Associate.
The Contractor shall ensure all personnel and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.
8. HIPAA Business Associate Provisions
8.1 Business Associate – General Provisions
The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business
Associate Agreement (BAA) between the Contractor and DHA is required to comply with the
HIPAA Rules and the DoD HIPAA Issuances. The contractor shall use the DoD BAA, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD
Components”, located at, https://www.health.mil/Military‐Health‐Topics/Privacy‐and‐Civil
Liberties/Privacy_Contract‐Language/HIPAA‐Compliant‐Business‐Associate‐Agreement‐for_the‐
MHS. b.i. and (3)b.ii
9. Breach Response
This paragraph 9 is inoperative, and all references herein to “paragraph 9” shall be deemed to refer to the TOM breach responses provisions, if the contract incorporates the TOM by reference
9.1 Definitions Related to Breach response
9.1.2 Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The foregoing definition is based on the definition of breach in
DoDM 6025.18. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non‐cyber (i.e., involving either electronic PII/PHI or paper/oral
PII/PHI).
9.1.3 A possible breach is an incident where the possibility of unauthorized access is suspected
(or shall be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the contractor does not initially know whether or not the PII/PHI was encrypted, then the incident shall initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the contractor. In determining whether unauthorized access shall be suspected, the contractor shall consider at least the following factors:
• How the event was discovered;
• Did the information stay within the covered entity’s control;
• Was the information actually accessed/viewed; and http://www.health.mil/Military
• Ability to ensure containment (e.g., recovered, destroyed, or deleted).
9.1.4 A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the contractor knows that the
PII/PHI is unencrypted, then the contractor shall classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the contractor knows this even without knowing whether or not unauthorized access to the PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the contractor shall re‐classify the incident as a non‐breach incident.
9.1.5 A HHS breach is an incident that satisfies the definition of breach in Section 164.402 of the HIPAA Breach Rule. The text of the HHS definition states:
Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.
HHS breach excludes:
Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the HIPAA
Privacy Rule.
Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the
DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy
Rule.
A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made shall not reasonably have been able to retain such information.
Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of reidentification.
The unauthorized person who used the PHI or to whom the disclosure was made;
Whether the PHI was actually acquired or viewed; and
The extent to which the risk to the PHI has been mitigated.
9.1.6. A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI.
A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection shall be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non‐breach cybersecurity incident has occurred.
9.2 General
9.2.1 The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.
9.2.2 Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps
(breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation (which includes individual notification), eradication, recovery, and follow‐up.
9.2.3 The contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The contractor shall consult with the DHA Privacy Office where guidance is needed, such as when the contractor is uncertain whether a discovered breach is the contractor’s responsibility (e.g., if the contractor discovers a breach not caused by the contractor), or how the contractor is to classify an incident (breach vs.
non‐breach, confirmed vs. possible, cyber vs. non‐cyber). Under no circumstances will a contractor delay reporting a confirmed or possible breach to the DHA Privacy Office beyond the
24‐hour deadline. In conjunction with its initial investigation, the contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.
9.2.4 In the event of a cybersecurity incident not involving a PII/PHI breach, the contractor shall follow applicable DoD cybersecurity and NIST requirements, which include United States
Computer
Emergency Readiness Team (US‐CERT) reporting (see paragraph 9.3). If at any point a contractor finds that a cybersecurity incident involves a PII/PHI breach (possible or confirmed), the contractor shall immediately initiate the reporting procedures set forth below. The contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.
9.2.5 Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the contractor immediately after discovery. The time of that report to the contractor shall trigger the contractor’s DHA Privacy Office reporting deadline (24 hours) under paragraph 9.3.2. If a cybersecurity incident is involved, the contractor’s deadline for US‐CERT reporting (1 hour) runs from the time the incident is confirmed. The contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the contractor to complete the breach response requirements herein. Alternatively, the contractor and subcontractor may agree that the subcontractor shall report directly to US‐CERT and the DHA
Privacy Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the contractor of the incident and the subsequent response actions.
9.2.6 Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .