ATTACHMENT A - Terms and Conditions - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf

PDF 970 KB Posted

Attached to
Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
Solicitation number
RFP-758-2500000171-6
Issued by
Kentucky

View the file

Other files for this state and local contract opportunity

Other files attached to Kentucky Analytics Platform Solution (KAPS), newest first.
File Type Posted
ATTACHMENT H - Solution Matrix- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT L - Penalties - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT B - Cost Proposal Form - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT C - Annual Affidavit and Other Affidavits -RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT E-Personal Information Security & Breach Investigation Act-HB5- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT F - Mandatory Requirements Checklist RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT G - Security Requirements for Vendor Cloud Hosted Systems V1.3.6 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT N - CHFS TsCs_Version 110623 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT O CHFS-219V Form Version 2.7 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT P - Business Associate Agreement, Version 070623 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT Q - QHI White Paper, Version 3.0.4 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT T - Sources of Data - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT V - IAS Dashboards and Reports - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT D - Vendors' Question Form -RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT K- Proposed 1st Quarter Performance Report Card - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT M - Acronyms - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT S - MITA SSA 2022 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT J Minimum Contract Deliverables - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT U IAS Dashboard Examples Redacted - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT A

Commonwealth of Kentucky Request for Proposal (RFP)

For

KENTUCKY ANALYTICS PLATFORM SOLUTION (KAPS)

RFP 758 2500000171

Release Date: December 26, 2024 CLOSING DATE AND TIME March 27, 2025, at 3:30pm ET

Issued by

The Finance and Administration Cabinet On Behalf of the Cabinet for Health and Family Services (CHFS)

Commonwealth Buyer:

Melissa Hubbard, KCPM Statewide Procurement Analyst II

COMMONWEALTH OF KENTUCKY

FINANCE AND ADMINISTRATION CABINET

Office of Procurement Services 200 Mero Street, 5th Floor.

Frankfort, KY 40622

(502) 782-5336

Melissa.Hubbard@ky.gov

TABLE OF CONTENTS

Proposal Submission Checklist Section 1 – Summary Section 2 – Introduction Section 3 – Scope of Work Section 4 – Commonwealth Office of Technology Requirements Section 5 – Procurement Requirements and Instructions Section 6 – Proposal Submission Section 7 – Proposal Evaluation Section 8 – Negotiations Section 9 – Contract Requirements Section 10 – Standard Terms and Conditions Section 11 – Attachments mailto:Melissa.Hubbard@ky.gov

Proposal Submission Checklist

The Vendor MUST include the following with the proposal submission.

If the items highlighted below are not submitted with the proposal submission, the Commonwealth MUST deem the proposal non-responsive and SHALL NOT consider for award.

All other items MUST be submitted prior to award.

*PROPOSED TECHNICAL SOLUTION

*PROPOSED COST SOLUTION

TRANSMITTAL LETTER [see Section 6.7(A)]

REVENUE FORM 10A100 KENTUCKY TAX REGISTRATION APPLICATION (see Section 6.7 (C)]

CERTIFICATE OF AUTHORITY- REGISTRATION WITH SECRETARY OF STATE BY A FOREIGN

ENTITY [see Section 6.7 (D)]

REQUIRED ANNUAL AFFIDAVIT AND OTHER AFFIDAVIT(S)

https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and% 20Contractors.pdf

EEO FORMS IF APPLICABLE [see Section 10.19]

MANDATORY REQUIRENTS CHECKLIST [ see Attachment F ]

*Please see Attachment E - The Protection of Personal Information Security and Breach Investigation Procedures and Practice Act (KRS 61.931), et seq.

effective January 1, 2015.

https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf https://finance.ky.gov/office-of-the-secretary/FinanceForms/Annual%20Required%20Affidavit%20for%20Bidders%20Offerors%20and%20Contractors.pdf

SECTION 1 – RFP SUMMARY

1.1 Estimated Schedule of RFP Activities

The following table presents the anticipated schedule for major activities associated with the RFP distribution, proposal submission, proposal evaluation process, and contract award. The Commonwealth reserves the right at its sole discretion to change the Schedule of Activities, including the associated dates and times.

Anticipated Schedule of Activities

Release of RFP

December 26, 2024

Vendors’ Written Questions due by 12:00 PM ET.

(SUBMIT QUESTIONS ON ATTACHMENT D-VENDORS’ QUESTION

FORM)

January 24, 2025

Commonwealth’s Response to Vendors’ Written Questions

February 21, 2025

Proposals due by 3:30 PM ET

March 27, 2025

1.2 Issuing Office

The Commonwealth of Kentucky, Finance and Administration Cabinet, Office of Procurement Services(OPS), is issuing this Request for Proposal (RFP) on behalf of the Cabinet for Health and Family Services (CHFS). The Finance and Administration Cabinet is the only office authorized to change, modify, amend, alter, or clarify the specifications, terms, and conditions of this RFP.

A contract, based on this RFP, may or may not be awarded. Any contract award from this RFP is invalid until properly approved and executed by the Finance and Administration Cabinet.

1.3 Agencies to Be Served

This contract shall be for use by the CHFS. No shipments shall be made except upon receipt by vendor or an official delivery order from the using agency.

Extending the Contract Use to Other Agencies The Office of Procurement Services reserves the right, with the consent of the vendor, to offer the Master Agreement resulting from this solicitation to other state agencies requiring the product(s) or service(s).

SECTION 2 – INTRODUCTION

2.1 Purpose

The purpose of this RFP is to solicit proposals for competitive negotiations pursuant to 200 KAR 5:307 (Kentucky Administrative Regulations [KAR]).

https://apps.legislature.ky.gov/law/kar/titles/200/005/307/ https://apps.legislature.ky.gov/law/kar/titles/200/005/307/

The Commonwealth of Kentucky (Commonwealth), CHFS, is seeking a qualified Vendor to provide a comprehensive and extensible analytics and research platform solution in a cloud environment. The solution will integrate data and provide dashboards, reporting, and analytic tools to support a broad spectrum of analysis, program evaluation, and research for emerging policy priorities. CHFS’ mission is to be a diverse and inclusive organization providing programs, services, and support to protect and promote the health and well-being of all Kentuckians and their communities.

The Vendor should provide a readily available, cloud-hosted, user-friendly, configurable, mobile-friendly, Healthcare Insurance Portability and Accountability Act of 1996 (HIPAA) compliant, Software as a Service (SaaS) solution for the Kentucky Analytics Platform Solution (KAPS). The Commonwealth utilizes the National Institute of Standards and Technology (NIST) Special Publication 800-145 as a definition for SaaS and NIST Special Publication 500-291, Version 2, NIST Cloud Computing Standards Roadmap. The Solution should be configured and customized as necessary to meet the requirements as defined in this RFP. Additionally, the Vendor should perform maintenance and operations throughout the life of the resulting contract.

The research and analytics solution is anticipated to become the foundational tool for all aspects of analytics, including monitoring of existing programs and scientific evaluations of demonstrations, and other experimental pilot projects. In addition, the solution will help to improve the data-driven decision-making for beneficiaries participating in programs and services provided by a wide range of public and private sector agencies.

2.2 Background

The Kentucky CHFS, the Department for Medicaid Services (DMS), and other CHFS agencies are committed to a data-driven and evidence-based approach to public program administration.

Due to the nature of CHFS' mission to provide a safety net, all significant CHFS policy issues involve multiple programs and associated datasets. As a result, CHFS must be able to monitor services across programs over time utilizing descriptive statistics, spatial visualizations, predictive analytics, trend monitoring, data modeling, and intuitive analytics.

CHFS manages all health and human services-related technology applications utilized in the administration of the Supplemental Nutrition Assistance Program (SNAP), Temporary Assistance for Needy Families (TANF), and the Kentucky Children's Health Insurance Program (KCHIP). In addition, CHFS manages and maintains the Kentucky Health Information Exchange (KHIE), Kentucky All Schedule Prescription Electronic Reporting (eKASPER) application, and the Statewide Automated Child Welfare Information System (SACWIS), among others. All these programs support numerous Cabinet initiatives, such as disease surveillance, prescription medication monitoring, substance abuse and mental health services, child welfare, and family and income support.

2.3 Present System Summary

The original data warehouse used for analytics originated in 2016 and initially supported the operations for claims and encounters for DMS. Several additional data sources were incorporated into the current Interim Analytics Solution (IAS) to enrich and expand the analytic capabilities and services. To better serve the needs of CHFS, the data analytics staff was transferred to the newly created Office of Data Analytics (ODA) within CHFS in June 2018. ODA manages the establishment of CHFS-wide data governance procedures and formal inter-agency data-sharing agreements. Since June 2018, ODA has focused on 1) centralizing integrated data, and 2) assisting many CHFS agencies by providing analytic services.

https://csrc.nist.gov/pubs/sp/800/145/final https://csrc.nist.gov/pubs/sp/800/145/final https://www.nist.gov/system/files/documents/itl/cloud/NIST_SP-500-291_Version-2_2013_June18_FINAL.pdf https://www.nist.gov/system/files/documents/itl/cloud/NIST_SP-500-291_Version-2_2013_June18_FINAL.pdf

This expanded scope increased the number of data-related queries the analytics team could process. The ability to describe trends expanded to include increasingly sophisticated techniques for estimating how Kentuckians react to programs or policy changes. To facilitate this, IAS was designed to integrate multiple disparate data sources and provide functional "key"-based data marts (See Attachment T – Sources of Data for more detail). Each data mart contains unique key values, which are typically IDs. This enables analysts to locate records based on a topic (e.g., individuals diagnosed with Substance Use Disorder [SUD]) and then retrieve additional details as needed. This design facilitates quick, efficient, and effective data retrieval for requesting officials.

Typical data initiatives consist of statistical summaries, dashboard visualizations, study designs, program evaluations, and formal reports. Structured Query Language (SQL) Server, Tableau, SAS®, Statistical Package for the Social Sciences (SPSS®), STATA®, Esri ArcGIS®, Quest/Toad, and R Studio are the primary tools currently in use.

The functionalities of the IAS comprise a mix of business processes, as depicted in the current state figure below, Data Sources, a Data Lake, a Production Server, and a Reporting and Analytics Platform. Data is transferred between partner agencies and the Data Lake.

Figure 1: Current State Context

In addition to the IAS, agencies may be utilizing analytics and research through other methods, using multiple types of tools.

The Commonwealth is expecting the new solution to provide information quickly and robustly, with industry-leading tools. CHFS is seeking more independence and flexibility in its research and analytics.

SECTION 3 – SCOPE OF WORK

PROPOSALS THAT DO NOT MEET MANDATORY REQUIREMENTS WILL BE DEEMED NON-

RESPONSIVE AND WILL NOT BE CONSIDERED. REFER TO ATTACHMENT F – MANDATORY

REQUIREMENTS CHECKLIST.

Mandatory Requirement means “a condition set out in the specifications or statement of work that must be met without exception.”

3.1 Scope of Work

CHFS intends to select a Vendor that offers a demonstrated history of a proven government cloud-based solution, managed by the Vendor, including but not limited to projects with large dataset analyses, capable of health analytics, general analytics, cognitive analytics, and generative/predictive analytics. Vendors should use their expert judgment to propose a model of how to complete this scope of work. Data should be sourced from operational sources of truth, or the Commonwealth’s data hub, with agreed-upon data refresh schedules and quality standards.

The solution should meet these CHFS high-level objectives:

Development of a single longitudinal health record for each individual, ensuring access to comprehensive and accurate health information to support optimal care delivery and coordination by building and utilizing a Master Client Index (MCI).

Enhance healthcare policies, programs, and operations by collecting and providing the infrastructure and tools to analyze data to promote quality improvement and reporting.

Maintains the functionality to monitor and address Social Determinants of Health (SDOH) and Population Health Management (PHM) to aid in improving health equity and outcomes, lowering costs, and supporting Commonwealth value-based care policies.

The Vendor is responsible for the activities listed in this RFP, as well as the RFP attachments, including supporting those current activities expected to remain in existence as outlined in Section 2.3. The Vendor’s failure to fulfill these responsibilities may result in financial penalties and/or the assessment of financial damages. (See Attachment K – Proposed 1st Quarter Performance Report Card and Attachment L – Penalties.)

The Vendor’s solution should integrate all of CHFS' data, such as structured, semi-structured, unstructured, claims, and clinical coming from data hubs, agency-owned applications and systems, Commonwealth government, and cross-sector partners, federal agencies, and other public-use files. Examples of public data includes population surveys and census-type data on community and neighborhood characteristics.

The solution should include, but is not limited to:

• Support of crossover queries between different databases;

• Support Upserts;

• Process monthly refreshes and recreation of Datamarts with minimal downtime;

• Support role-based access control for users and groups to restrict access to specific data and functionalities;

• Provide logical separation of data sources based on project;

• Support migrating existing SQL queries, stored procs, scripts, and data from other platforms or database systems;

• Provide direct access to query database via statistical tools and query tools;

• Ability to optimize based on common queries; and

• Ability to load data by data analyst role.

The implementation includes data sources identified in Attachment T – Sources of Data. The solution should be able to interact with all the data sources identified by CHFS and offer agency-approved users quick and easy access to data. Vendors providing cloud solutions should factor in the Commonwealth Office of Technology (COT) oversight, which includes, but is not limited to, an isolated tenant, cloud network access (peering connection), and monitoring solutions.

Additional information can be found in Section 4 – COT Requirements and in Attachment G – Security Requirements for Vendor/Cloud-Hosted Systems. The solution should be able to produce accurate data and analytics for oversight, administration, evaluation, integrity, and transparency.

Milestones are outlined below:

Milestone I – Pre-production Milestone II –Integration and Configuration Milestone III – Testing Milestone IV – Training Milestone V – Implementation Milestone VI – Operations and Warranty

Vendors are encouraged to propose a solution that demonstrates the reuse of developed technologies available and configurable to meet CHFS’ requirements. If a Vendor proposes a reused component or product from another state, the Vendor should identify how they would approach integration.

The Vendor's proposed solution should support, but not be limited to, data mining and data analytics, such as statistical analysis, generative/predictive analytics, trending, measures, and storing data in various structural forms (structured, unstructured, and semi-structured data) within a data lake. The solution should contain, but not be limited to, various tools, technology for data Integration, data quality, business intelligence reporting, dashboards, visualization tools, statistical analysis tools, Geographic Information System (GIS), natural language processing (NLP), reference data management, and metadata management.

A detailed list of requirements is included in Attachment H-Solution Matrix and Attachment I- Technical Matrix which outline the functional, technical, and additional requirements that define what the Vendor’s proposed solution and services should accomplish. These matrices should be completed by the Vendor and used to determine how the Vendor’s proposed solution should fulfill the Commonwealth’s expectations and desires. The Vendor should adhere to the applicable requirements identified within those attachments and refined during requirement validation sessions after project kickoff.

The proposed solution should support the increase of the Centers for Medicare and Medicaid Services (CMS) Medicaid Information Technology Architecture (MITA) maturity levels (see Attachment S –MITA SSA 2022).

A. Data Sources

The solution proposed by the Vendor should be capable of integrating structured, semi-structured, and unstructured datasets; and storing them in a manner that maximizes their efficacy for exploration, analysis, visualization, and reporting. The data sources should be imported and integrated to support the intended purpose of bringing all necessary data sources into a fully scalable data analytics solution that can be utilized at various skill levels.

The sources should be initially imported and then refreshed according to a Commonwealth and Vendor-determined frequency. The solution will support the requirements for refresh and the time frames to be supported (real-time, near real-time, daily, weekly, etc.). The tools and configuration should allow Commonwealth personnel to maintain and expand the available data. The solution will also support the creation of additional permanent or transient data stores. This will enable a single enterprise analytics solution that offers real, or near real-time, reporting, visualizations, trending, and predictive analytics for Commonwealth-specific objectives.

All data that may no longer be necessary should be archived so that it can be restored if necessary unless otherwise notified by CHFS in writing that it can be deleted. The solution should support the inclusion of data in its current state and the modification of data during the refresh procedure. The solution should be able to support seven plus (7+) years of data, although some data sources may go as far back as 2009. The solution should also have the capability to adjust past data loads (e.g., claims adjustments from MMIS data).

The Vendor should propose data models and data refresh schedules from multiple sources, including a refresh of data marts, dashboards, and reports. In their response, the Vendor should explain how CHFS power users will be able to interact with and manipulate the proposed data model. For reporting and analytics, the solution should be able to convert and transform specific data sources containing healthcare records in HL7, HL7 Clinical Document Architecture (CDA), X12, and Fast Healthcare Interoperability Resources (FHIR) formats.

Attachment T - Data Sources, contains a comprehensive inventory of Data Sources and associated data sets for all anticipated Data Sources. The list of data sources is specific to the current state environment. It should be noted that data sources and technologies across CHFS may be changing over time. The Vendor should provide all intermediate steps, methods, timelines, and processes reasonably necessary to implement the Solution in a cost-effective manner, utilizing a Phased approach to achieve the desired outcome based on all Data Sources identified in Attachment T – Data Sources.

B. Data and Information Management Services The solution should offer data management tools and services. This includes but is not limited to the definition of data services, data cataloging, data profiling, business intelligence, data governance, and data security components. The Vendor should propose a solution for managing security certificates and data use agreements as well. The Vendor should establish a MCI record for all citizen records and other data management system features.

The solution should provide a normalized, extensible, and business-aligned data model for analytical and reporting needs.. The solution should maintain data consistency, quality, and integrity throughout the contract.

The solution should incorporate the use of a Master Data Management (MDM) software solution for managing master reference data, as well as incorporate the management of processes, governance, and policies. The Vendor should provide the strategy, to integrate with CHFS’s MCI (CHFS' IBM MDM) solution as needed, which manages master client records with a consolidated view of individual and Medicaid provider records. Only a few of the CHFS systems are part of CHFS’s MDM solution.

C. Data Marts The solution should provide the functionality to CHFS users to have the ability to create and utilize their data-specific data marts using the Vendor’s tools. The Vendor should provide the ability to build out any data-specific data marts that are identified during requirement validation sessions.

D. Access and Presentation Services

All user interface components and solution access channels should be addressed by the Access and Presentation Services layer. The solution can be divided into two (2) tiers of user interaction: access channels and presentation.

The access layer provides a versatile framework for managing and delivering internal and external communications via various routes. Users should have the ability to access the solution’s services through a variety of channels including, but not limited to, online apps, mobile phones, tablets, and email.

The presentation layer should offer users access through a dependable, thin-client, browser-based solution delivered over the internet. The presentation layer should be accessible to people with disabilities by adhering to the Americans with Disabilities Act (ADA) mandates listed in the Rehabilitation Act of 1973, Section 508, as well as the Web Content Accessibility Guidelines (WCAG) 2.1 Level A and AA. The system should allow mobile access to Business Intelligence (BI) dashboards.

The Vendor should supply the software licenses for CHFS users to be able to support and utilize the solution by a defined number of employees. For any required software licenses, when it is in the best interest of the Commonwealth, the Commonwealth reserves the right to procure any software via the Commonwealth software reseller contracts. The actual number of users for the solution will be determined during Pre-production and Implementation.

E. Application and Shared Services

The Application and Shared Services layer provides the system with reusable commodity features and operations. The Shared Services layer is a subset of Application Services that can be exposed externally for reuse by other systems, applications, or external entities.

The proposed solution should include architecture components with full functionality for creating, managing, maintaining, and versioning business rules outside of the application code. The solution should provide configurable query governance limits for ad-hoc reports to prevent runaway reports from consuming valuable system resources and interfering with the operation of other system components. The solution should provide standard, open, and re-usable Application Programming Interfaces (API) for public data consumption, as approved by the Commonwealth.

https://www.section508.gov/manage/laws-and-policies/ https://www.w3.org/TR/WCAG21/ https://www.w3.org/TR/WCAG21/

The solution should provide Application Services capable of delivering fundamental commodity features and domain business services, as defined in requirement validation sessions.

F. Infrastructure Services

The Infrastructure Services layer design should facilitate the delivery of high-quality, scalable application services to end users. This procurement promotes the use of Commercial off-the-shelf software (COTS) for Extract, Load and Transform (ELT), Extract, Transform and Load (ETL), health analytics, structured data analytics, unstructured data analytics, presentation tools, data lakes, and data marts.

During the term of this contract, the Vendor should provide and maintain separate environments for, at a minimum, pre-production, and production. Vendor should ensure that CHFS has access to these environments. One physical platform may suffice if environments are separated. The solution may include additional or differing environments with their respective purposes, and data content.

The solution should exhibit high availability and guard against tools or applications going offline because of component failures or data refreshes. To handle surges in user demand, the applications and services should be setup on a flexible architecture with real-time resource provisioning.

To enable security, governance, management, and data/metadata replication across all storage and access points, the solution infrastructure should be in the cloud. The physical maintenance of the virtual data architecture should be carried out on one or more data platforms, such as object stores, file systems, traditional relational Database Management Systems (DBMS), and more modern DBMSs (for columnar, NoSQL, and graphs). Elasticity, low Total Cost of Ownership (TCO), minimal system integration, business agility, stability, reliability, and high availability should all be features of the cloud solution.

To ensure that all functionality is accessible to stakeholders with the least amount of downtime, the Vendor should provide the full life cycle of infrastructure support in a solution that includes the hosting, management, and maintenance of all infrastructure components.

This entails monitoring performance and uptime standards and checking all infrastructure parts for upgrades or optimizations. The Vendor is not restricted to any single managed infrastructure solution and is encouraged to propose the solution(s) that meets the requirements of this RFP.

The Vendor should conform to all Commonwealth architectural standards. If for any reason during the life of the contract, the Vendor believes an exception to the Commonwealth’s architectural standards is necessary, the Vendor shall submit an exception request to CHFS and the Commonwealth Office of Technology (COT) fully detailing the request. Exception requests must be reviewed and approved by COT.

G. Integration and Interface The Vendor should be responsible for supporting all phases of the solution development, including table creation, ETL/ELT script development, ETL/ELT job scheduling, historical data loading, metadata management, data quality monitoring, data profiling, initial user role setup, and maintenance activities. The Vendor will closely collaborate with CHFS staff to plan secure data exchanges between application modules utilizing conventional or alternative data formats, standards, and protocols within the specified Service Level Agreement (SLA).

The Vendor should follow CHFS' guidelines for data quality.

The Vendor should provide a temporary processing area or staging area for the integration of data from all sources. The Vendor should be responsible for the ETL/ELT of data into the solution. The Vendor should be accountable for reporting data load figures to CHFS. The Vendor should give CHFS personnel access to performance monitoring tools. The Vendor should obtain MCI records from CHFS' MDM platform for data sources from CHFS-managed application systems. Using a master data management program or a robust algorithm for matching and linking, the Vendor’s proposed solution should also link citizen records from all data sources listed in Attachment T.

The solution should be able to ingest, integrate, and store structured, semi-structured, and unstructured data in all formats, including audio, claims, notes, and files, among others. The semi-structured and unstructured data should be stored in a format that enables integrated analytics.

Some of the most important aspects of the solution’s functional needs are dependent on the availability of data from multiple sources, both internal and external to CHFS and the Commonwealth. The State Data Hub (SDH) or its successor, the State Integration Hub (SIH) are the central communication/integration platform that facilitates information flow between all modules, other Commonwealth systems, and business partners. The SDH/SIH platform supports architectures including, but not limited to, queuing, service orchestration, and web services. Secured File Transfer Protocol (SFTP) and Electronic Data Interchange (EDI) connectivity are supported by the SDH/SIH. The Vendor is responsible for ensuring that the solution uses the SDH/SIH to construct essential components such as APIs for all information interactions with all modules, other Commonwealth systems, and business partners. To build/deploy the interfaces on the SDH/SIH, the Vendor should collaborate with the Office of Application Technology Services (OATS).

The Vendor should be responsible for designing, developing, and testing all physical interfaces, web services, messaging, file-sharing requirements, and batch processes required for data interchange with SDH/SIH. MITA 3.0 requirements should be followed for all data transmissions. The Vendor should ensure that all data exchanges are secure from beginning to end. Additional files defined during the solution implementation Pre-production Milestone should be considered in the project's scope.

H. Data Governance

The Vendor should be responsible for the necessary tools and processes required to seamlessly integrate platform governance with the existing governance practices. The Vendor should comply with the CHFS Data Governance standards. The Vendor should include a tool to manage data sharing agreements and Memorandum of Understanding (MOU). The Vendor should also include a tool for data scientists for analysis, trends, predictions etc.

Other forms of governance include, but are not limited to, information management, data dictionary documentation, access controls, and data retention policies. These are examples of additional services required to ensure the responsible use of data.

I. Business Intelligence Tools The Commonwealth's goal is to implement a Business Intelligence (BI) solution that incorporates modern, industry-standard tools within the solution platform. As part of the solution, the Vendor should propose and provide all necessary tools. The solution should provide a comprehensive suite of tools to support operational management, and strategic decision-making across CHFS. The suite of tools should support online analysis within the host environment (i.e., moving away from siloed analysis practices). Additionally, the scope of analysis functionality should include statistical studies, member predictive analysis, sampling, extrapolation, trending, geospatial reporting, and analysis through the proposed reporting tools and capabilities.

To facilitate data analytics and reporting, the solution may incorporate predefined reports and dashboards, as well as user-defined ad hoc reporting and data queries. The functions or tools provided by the solution should support or include, but are not limited to, the following:

1. Ad-hoc queries;

2. Pre-defined reports;

3. Dashboards;

4. Geographical mapping;

5. Statistical analysis;

6. Data mining;

7. Clinical analysis;

8. Trending and Predictive analytics;

9. Scaling analysis;

10. Healthcare Effectiveness Data and Information Set (HEDIS) reporting and

11. Performance reports

The Commonwealth should be able to present graphical representations of the current status in a dashboard manner, which users may customize by selecting key performance areas or status information of interest.

Because certain populations or conditions may have a geographical or geospatial element that should be considered, the capacity to do geospatial analysis and heat mapping should be included as part of the solution. This type of study involves geospatial-capable software and applies analytical methodologies to terrestrial or geographic datasets, including the application of geographic information systems. This capability should include drill-down and drill-up functionality.

J. Reporting and Analytics The solution should support simple queries and preformatted reports that are easy to access, follow a user-friendly protocol, and produce responses in a timely and efficient manner.

Dashboard and reporting examples that should be available within the solution can be found in Attachment U – IAS Dashboard Examples Redacted and Attachment V – IAS Dashboards and Reports.

Statistical reporting should have the capability to assist programs with reporting on monitoring performance and health outcomes supporting care programs, and operations management tasks. New healthcare delivery mechanisms, changing healthcare payment arrangements, and a new patient-centric focus in the healthcare industry are altering the demand for data that enables health and human services organizations to:

1. Improve service administration,

2. Conduct advanced data analysis to determine patterns, relationships, and trends,

3. Evaluate program efficacy,

4. Determine, track, and monitor citizen demographics and Social Determinants of

Health to support health equity,

5. Detect and prevent fraud, waste, and abuse,

6. Interpret disease management and epidemiological patterns, and

7. Develop the ability to predict risk, healthcare expenditures, and the impact of policy changes.

The ability to use predictive analytics, create severity-adjustment methodologies, incorporate robust data sources, and harness internal clinical expertise will enable CHFS to examine population health outcomes and develop meaningful quality, utilization, and performance measurements.

Advanced reporting techniques and access to non-traditional MMIS data will enable CHFS to identify and predict health risks and outcomes, identify practice and utilization patterns, identify and rank outlier providers and clients, provide reports of provider group and individual billing, and analyze recipient group and individual medical episodes.

K. Segregated Environment

The solution should provide an environment where provisioned users from the Commonwealth can import data files for temporary business needs such as statistical analysis, generating ad hoc reports, or recurring data extract files.

The segregated environment should allow provisioned users to save reports and queries created within the environment to the report library so outputs/results may also be shared with external users.

3.1.1 Related Services

3.1.1.1 Requirement Analysis

The CHFS team compiled a list of functional and technical requirements, which discuss critical operational, functional, and technical design matters that are essential to the operations of the Solution (see Attachment H Solution Matrix and Attachment I Technical Matrix). It is important to understand that while these preliminary requirements, to some extent, define the scope and vision for the system, the requirements are not the final detailed requirements for the system.

The Vendor should conduct a Requirements Analysis to review, refine, and seek approval for all preliminary requirements, and add requirements where gaps are identified through a detailed analysis exercise. Any additional in-scope requirements not initially identified should be included at no additional cost. All other added requirements should go through the change control process (refer to Section 3.3.1.A Change Control Management). The result should be a set of detailed requirements to be used to configure the solution. These requirements should be the basis for the Vendor to create usage scenarios and detailed process workflows.

At the conclusion of the Requirements Analysis, the Vendor should work with the CHFS team to prioritize requirements and, if necessary, identify possible iterations for the configuration of the overall requirements. The Vendor’s Project Work Plan (schedule) should show updates to identify all possible iterations of implementation. Once approved, the schedule for Requirements Analysis should be included in the Project Work Plan.

3.1.1.2 Security

The Vendor coordinates with the CHFS Security Team to ensure any current or proposed solutions align with the CHFS information assurance strategy. Vendor abides by the Security requirements as negotiated and approved. CHFS currently uses Archer to manage security related incidents and Plan of Action and Milestones (POA&M).

In addition to Section 4, Commonwealth Office of Technology (COT) Requirements, Vendor responsibilities include, at a minimum, the following:

A. Data Breach

Adhere to the requirements of Kentucky’s data breach notification law codified at KRS §

365.732 and KRS § 61.931 to KRS § 61.934 (Kentucky Revised Statutes [KRS]), which require the Vendor to report to their CHFS point of contact and CHFS Information Security Representative any suspected data breach involving CHFS, including any reasonable belief that an unauthorized individual has accessed CHFS data. The report shall identify the nature of the event, a list of the affected individuals and the types of data, and the mitigation and investigation efforts of the Vendor. The Vendor must make the report available to CHFS immediately upon discovery of the data breach, but in no event more than twenty-four (24) clock hours after discovery of the data breach (including all Personally Identifiable Information [PII] and Protected Health Information [PHI]). This notification time is reduced to twelve (12) clock hours for a data breach involving Federal Tax Information (FTI) and reduced to thirty (30) minutes for a data breach involving Social Security numbers. The Vendor shall provide investigation updates to CHFS.

In addition to any other remedies available to the Commonwealth of Kentucky under law or equity, the Vendor shall promptly reimburse the Commonwealth in full for all costs incurred by the Commonwealth in any investigation, remediation, or litigation resulting from any data breach resulting from a deficiency in security controls for which the Vendor is responsible.

The Vendor’s responsibility to reimburse the Commonwealth includes, but is not limited to, reimbursing to the Commonwealth its cost incurred in doing the following:

1. Notification to third parties whose information may have been or were compromised and to regulatory bodies, law enforcement agencies, or other entities as may be required by law or contract;

2. Establishing and monitoring call center(s) and credit monitoring and/or identity restoration services to assist each person impacted by a data breach of a nature that, in Commonwealth’s sole discretion, could lead to identity theft; and

3. Payment of legal fees and expenses, audit costs, fines and penalties, and other fees imposed upon the Commonwealth by a regulatory agency, court of law, or contracting partner as a result of the data breach.

Upon a Data Breach, the Vendor is not permitted to notify affected individuals without the express written consent of the Commonwealth. Unless Vendor is required by law to provide notification to third parties or the affected individuals in a particular manner, the Commonwealth controls the time, place, and manner of such notification.

The Vendor shall notify CHFS within the specified time period below upon both the suspected or confirmed discovery of a breach.

https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43326 https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43326 https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43575

The Vendor shall ensure that all applicable security standards and regulatory requirements are utilized based on the type of data, processing environment, and function of the IT solution based on the table below throughout the lifecycle of the awarded contract.

Table 1: Sensitive Data Notification Time Requirements

Sensitive Data Type Processed Vendor Notification Time Requirement

Social Security Administration (SSA) Information Thirty (30) Minutes

Personally Identifiable Information (PII) Twenty-four (24) Clock Hours

Protected Health Information (PHI) Twenty-four (24) Clock Hours

Federal Tax Information (FTI) Twelve (12) Clock Hours

All Other Information Twenty-four (24) Clock Hours

The Vendor shall notify the CHFS point of contact and CHFS Information Security of all security incidents as noted above.

B. Cyber Insurance and Performance Bond The Vendor shall hold Cyber Insurance policies and a performance bond, to cover liability that includes, at a minimum, costs of cyber security breaches, unauthorized data disclosure, data tampering, data loss, credit monitoring, system restoration/repair, follow-on lawsuits, and other damages during the entire life of this Contract, including any renewals. This is not a substitute for a robust security program.

Pursuant to KRS 45A.190 and 200 KAR 5:305, the Vendor shall furnish a performance bond equal to the entire first year cost of the contract. The bond furnished by the Vendor shall incorporate by reference the terms of the contract as fully as though they were set forth verbatim in such bonds. In the event the awarded contract is amended, the penal sum of the performance bond must be deemed and increased by a like amount. (See Section 10.32)

The initial bond will be submitted to the FAC Buyer within thirty (30) calendar days of execution of a contract. Any required amendment to the bond must be submitted to the FAC Buyer within thirty (30) calendar days of said amendment.

C. Production Data Ensure no production data exists in any other environment other than production. All non-production environments shall be designed to use data-masking routines to transform personal and confidential data, while retaining its contextual meaning and referential integrity.

The authorized CHFS management staff and CHFS Security approve any exceptions.

D. CHFS Security Review of Implementation Plan and Detailed System Architecture Ninety (90) calendar days before the go-live date, provide to CHFS Information Security a copy of the Implementation Plan and Detailed System Architecture (with Service Maps, Hardware Architecture, Application Network Map, and Data Flow diagrams), which includes each Infrastructure component, such as Servers, Databases, Storage, Appliances, Firewalls, Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), with associated software details as part of the initial deliverables. Timeframes are agreed to as part of the project plan.

Additional security requirements can be found in Attachment G –Security Requirements for Vendor/Cloud Hosted Systems.

https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=54631 https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=54631 https://apps.legislature.ky.gov/law/kar/titles/200/005/305/

E. System Security Plan

Provide a Security Plan that addresses all levels of security in the solution for approval by CHFS prior to the completion of the System Design/Configuration noted in the schedule. The plan should include complete Control Implementation Descriptions. A template without implementation descriptions is not acceptable. The Vendor should leverage the most recent version of NIST. The Security Plan should include at a minimum:

1. Access Control;

2. Awareness and Training;

3. Audit and Accountability;

4. Communications Protections;

5. Configuration Management;

6. Contingency Planning;

7. Identification and Authorization;

8. Incident Response;

9. Maintenance;

10. Media Protection;

11. Physical and Environmental Controls; and

12. Personnel Security System.

Additional security requirements can be found in Attachment G Security Requirements for Vendor/Cloud Hosted Systems and Attachment I Technical Matrix.

F. Plan of Action and Milestones (POA&M) Strategy The CMS has implemented an Information Security and Privacy Program to protect CMS information resources. One component of this program is the implementation of an effective Plan of Action and Milestones (POA&M) strategy. A POA&M is a corrective action plan for tracking and planning the resolution of information security and privacy weaknesses. It details the resources (e.g., personnel, technology, funding) required to accomplish the elements of the plan, milestones for correcting the weaknesses, and scheduled completion dates for the milestones as described in Office of Management and Budget (OMB) Memorandum 02-01, Guidance for Preparing and Submitting Security Plans of Action and Milestones. The Vendor must complete the exercise prescribed by CMS for every newly identified POA&M item during the term of the contract within the Vendor’s responsibility.

1. Controls: The Minimum Acceptable Risk Safeguards for Exchanges (MARS-E) (most current version) at the time of initial contract execution, security controls are in scope for assessments under this Service Level.

2. Identification Date: The date when either party identifies a weakness, but it is not yet determined to be Vendor’s responsibility.

3. Commencement: The first date in which parties begin to meet post Identification.

Commencement ends upon the Vendor's acceptance of responsibility, weakness is validated, the risk is determined to calculate the expected completion date, and preliminary milestones, dates, and resources are provided, at which point Remediation Status begins.

4. Remediation Status: The period from the end of Commencement to the Remediation Date, which is the period used to measure the Service Level Metric.

5. Remediation Date: The date upon which a POA&M item is sent by Vendor to the Commonwealth in a pending closed status. The POA&M item is still subject to Commonwealth and CMS review/approval, but the Service Level Metric would pause https://www.whitehouse.gov/wp-content/uploads/2017/11/2002-M-02-01-Guidance-for-Preparing-and-Submitting-Security-Plans-of-Action-and-Milestones-1.pdf once a pending closed status is sent by the Vendor. Should the Commonwealth/CMS reject the remediation plan, the Vendor would have an additional 30 calendar days from the date of notice of rejection to perform additional remediation activities before the Service Level Metric starts again.

Additional information related to penalties associated with POA&M can be found in Attachment L – Penalties.

3.1.1.3 Security Review

The Vendor shall perform a mutually agreed upon independent infrastructure vulnerability assessment annually with an independent security assessment company at no additional cost to CHFS. The infrastructure vulnerability assessment must follow NIST 800-115 guidelines.

The Vendor shall produce a SOC 2, Type 2, or alternate CHFS-approved assessment report to CHFS Information Security on an annual basis. CHFS-approved assessment reports include, but are not limited to, International Organization for Standardization (ISO) 27001 and Health Information Trust Alliance (HITRUST). The reports are required to be Vendor-targeted, and not replaceable with higher-level business partner reports.

The Vendor shall conduct an annual independent Application and Infrastructure security test, including independent security testing upon the release of each major revision application version. Ensure the components, including modules and sub-components, delivered by the Vendor and/or subcontractors, are tested. The Vendor shall provide to CHFS an unaltered and unfiltered copy of the internal Dynamic Application Security Test (DAST) report, external Penetration Testing report, and internal Infrastructure Vulnerability Scan report within fourteen

(14) business days of their execution. The Vendor must provide a mediation plan that meets risk assessment and is agreed to by CHFS.

The Vendor shall cooperate with any third-party Vendor(s) that CHFS engages to complete a federal partner certification and accreditation of the system controls prior to each phase’s go-live in accordance with CHFS standards and policies for certification and accreditation. Reviews should be included in the Project Work Plan.

3.1.1.4 Training

The Vendor should provide training for CHFS staff throughout the life of the Contract. The Vendor should propose training via any of the following methods: Web-Based Training (WBT), Computer-Based Training (CBT), online tutorial, or virtually (e.g., Microsoft Teams [preferred], Zoom), as agreed upon by CHFS.

The Vendor should coordinate with CHFS to identify the training needs required to develop comprehensive training related to the proposed solution. The Vendor should train Vendor staff, CHFS, and any other staff regarding the proposed solution to ensure they understand the tools being implemented with the proposed solution and are comfortable navigating and using the solution. The proposed solution should have the ability for CHFS to download training materials, guides, and links to videos.

Training should be provided prior to initial startup when new employees are hired, when Vendor provides major software updates, and upon request. The timing of the training should be mutually agreed upon.

https://csrc.nist.gov/publications/detail/sp/800-115/final

Training manuals and other training documentation should be made available in a recorded or printable format. All training materials shall be compliant with the ADA mandates listed in the Rehabilitation Act of 1973, Section 508.

A. CHFS Staff Training

CHFS views the successful rollout of an end-user training program as one of the critical elements in the overall success. The Vendor should coordinate with CHFS staff to identify training needs required to ensure the successful implementation. This includes development and maintenance of a Master Training Plan, training location (onsite, off-site, and/or web-based [preferred]), training materials, and appropriate delivery of material.

B. CHFS Staff Training Prerequisites The Vendor should identify potential prerequisites to any training session. This includes developing a plan for how trainees can fulfill the prerequisites. In this section, the Vendor should describe their approach for measuring the skill sets of future solution users.

C. CHFS Staff Training Development The Vendor should ensure the training materials focus on the technology and tools and how they are related to the solution. It is critical that the training materials are up to date. The materials should incorporate currently known concepts of Adult Learning. The Vendor should ensure that all training materials have been reviewed and approved by CHFS at least thirty

(30) calendar days prior to the beginning of the training window using the 10-5-5 Review Cycle.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .