Attachment B- SCope of Work.pdf

PDF 233 KB Posted

Attached to
H258--Medical Physics STX Equipment List Federal contract opportunity
Solicitation number
36C25724Q0652
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 17

About this file

This document is a Statement of Work (SOW) for a Department of Veterans Affairs (VA) service contract to provide diagnostic medical physics services at the South Texas Veterans Health Care System (STVHCS) and its off-site clinics. The SOW details 19 specific tasks the contractor must perform, including annual reviews, equipment performance evaluations, quality assurance testing, shielding surveys, and radiation safety support. The contractor must meet stringent qualifications for a licensed, board-certified diagnostic medical physicist. The period of performance is a base year from June 27, 2024 to June 26, 2025, with four one-year option periods. The contractor's personnel are subject to VA background investigations and must complete required security and information technology training. All work records belong to the VA and must be returned or destroyed at contract completion.

The related federal contract opportunity is a Request for Quotation (RFQ) for this diagnostic medical physics services requirement, with an expected award date of June 19, 2024. The RFQ is set aside for Service-Disabled Veteran-Owned Small Businesses (SDVOSB) under NAICS code 541690. Quoters must provide a statement accepting the RFQ's terms and conditions.

View the file

Other files for this federal contract opportunity

Other files attached to H258--Medical Physics STX Equipment List, newest first.
File Type Posted
36C25724Q0652_2.docx DOCX document
Copy of Imaging Systems Inventory.xls XLS spreadsheet
Attachment D- Wage Determination.pdf PDF
Attachment A -Schedule of Prices.pdf PDF
36C25724Q0652_1.docx DOCX document
Atachment C- Clauses and Provisions.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

B.4 SCOPE OF WORK

Scope of Work. The Contractor shall provide all personnel, transportation, and equipment.

Services shall be performed by a licensed qualified diagnostic medical physicist. Contract is for Department of Veterans Affairs / South Texas Health Care System (STVHCS) AND OFF-SITE CLINICS for monthly, annual, and or emergent basis. These services will adhere to the requirements and expectations of The Joint Commission (TJC), VHA National Health Physics Program (NHPP), and the American College of Radiology (ACR), Mammography Quality Standards Act (MQSA), and Food and Drug Administration (FDA), and internal requirements of this facility where applicable. The Texas Department of State Health Services regulations contained in 25 TAC §289 are not in force at STVHCS but shall be followed as closely as practical.

All work shall be performed during business hours of 6:00 am to 4:30 PM Monday through Friday, except Federal Holidays. After hours and weekends shall be scheduled at least 30 days prior services (POC). To perform the following tasks:

• Task 1: Annual review of STVHCS overall Imaging Quality Assurance program for diagnostic imaging equipment to include protocol reviews. [NHPP]

• Task 2: Upon awarded of the vendor initiate STVHCS security/unescorted access requirements within 30 days of contract award. Credentialing process, to gain access to the desired service/department, the contractor must request STVHCS appropriate photo ID badge and authorization to proceed.

• Task 3: Coordinate and schedule via email for annual review of STVHCS equipment copying COR, RSO, Biomedical Services and POC for each service (see Attachments B).

• Task 4: Keep track and schedule Annual Equipment Performance Evaluations (EPE) as required.

• Task 5: Establish or upgrade the Quality Assurance / Quality Control Program (QA/QC) to ensure compliance with Joint Commission, ACR.

• Task 6: Annual, should not to exceed 12 months / shall not exceed 13 months, quality assurance testing survey and certification of all diagnostic x-ray and imaging equipment (to include MRI, and Nuclear Medicine). All equipment surveys should be scheduled with the COR and equipment’s service point of contact (POC) no later than 60 days prior to the survey but shall be scheduled not later than 30 days prior to survey. A scheduled shall be e-mailed to the RSO monthly. See Attachments A for list of existing equipment.

This list may be modified (equipment added or removed) at any time. [TJC, NHPP]

• Task 7: Recertification of imaging equipment prior to first patient use when required due to repairs or modification that may affect the radiation output or image quality. Within 24 hours of contact, the contractor will coordinate with the affected service (POC) and RSO to have the recertification scheduled.

• Task 8: Written reports signed by the diagnostic medical physicist documenting the testing, including a summary of methods, instruments used, measurements and deficiencies identified, for all diagnostic x-ray and imaging equipment. The Contractor shall provide a copy of the physicist report to the COR, RSO, Biomedical Services and Chief of Service and POC for each service (see Attachments B) within (5) five working days of completion of the work. The report may be in electronic format. [TJC, NHPP]

• Task 9: Deficiencies or non-conformances which represent unsafe conditions during inspection shall be verbally reported to the RSO, Biomedical Services, Chief of Services, and/or POC immediately prior to leaving facility. A log of deficiencies identified shall be reported to the COR and RSO on a monthly basis. The log at a minimum shall include the following: Service, EE#, deficiencies, date of deficiencies identified, date deficiencies corrected. Verbal reports must be provided after testing so that STVHCS will know that equipment can be immediately put into use.

• Task 10: Dose rate surveys in unrestricted areas adjacent to the radiation areas are to be included during testing and in the final report.

• Task 11: A patient exposure calculations will be performed for each unit inspected for common projections and procedures.

• Task 12: Shielding design approvals for new construction and renovations.

• Task 13: Shielding surveys for new construction, modifications, and replacement of equipment.

• Task 14: Annual quality assurance testing of mammography review workstation and or attached printer. [MQSA]

• Task 15: Support the STVHCS Radiation Safety Office by membership and attendance on the appropriate STVHCS committee meetings (i.e., Radiation Safety Committee, Image Quality Committee) on a quarterly or as needed basis. The STVHCS Radiation Safety Officer will request the diagnostic medical physicist to attend when expertise is required. [TJC]

• Task 16: Provide as-needed medical radiation producing equipment training to STVHCS medical staff. The course will be a one-hour, hands-on training session designed to enhance the understanding and implementation of operational radiation protection principals to promote the reduction of occupational exposures to ionizing radiation in the clinical environment. The course content will to include: exposure (air kerma) outputs, high-level control options, occupational dose reduction techniques (positioning, shielding, and optimal equipment settings), and procedures for recording pertinent data.

• Task 17: Provide consultation and final reports for dose estimates calculations for patient, staff, and fetal exposures; and sentinel event investigations.

• Task 18: Twenty-four (24) hour emergency response time on unanticipated and/or emergent equipment needs.

• Task 19: Participation in quarterly on-site review (4 meetings per year) of the technical Radimetrics QA program for all modalities. Assist STVHCS with establishing baseline Radimetrics QA thresholds. The review shall include a trend analysis of the Radimetrics QA data. Any trends that identify problems shall be discussed in the quality control meeting and included in the report along with recommendations corrective actions. The quality control meeting will include reviewing the CT protocol dose optimization.

Reviewing CT protocols shall be completed at least annually with a signed copy furnished to the RSO.

The annual quality assurance testing will include all radiology and dental equipment at STVHCS

– San Antonio, Kerrville, and off-site clinics. All quality assurance testing reports and mammography equipment performance evaluations reports shall be submitted to the STVHCS Radiation Safety Office for review and approval subsequent to the completion of all testing, calibration and surveys of the equipment, facilities and procedures. The reports shall identify all items of noncompliance and include general and specific recommendations for correcting any items of noncompliance. “All records (administrative and program specific) created during the period of the contract belong to VA South Texas Health Care System(STVHCS) and must be returned to STVHCS at the end of the contract or destroyed in accordance to the VHA Record Control Schedule (RCS)10-1.”

Period of Performance:

Base Year: June 27, 2024 to June 26, 2025 Option Year 1: June 27, 2024 to June 26, 2026

Option Year 2: June 27, 2024 to June 26, 2027 Option Year 3: June 27, 2024 to June 26, 2028 Option Year 4: June 27, 2024 to June 26, 2029

Acronyms:

AAPM American Association of Physicist in Medicine ACR American College of Radiology CBCT Cone Beam Computed Tomography CFR Code of Federal Regulations COR Contracting Officer Representative CT Computed Tomography FDA Food and Drug Administration FOV Field of View HVL Half Value Layer IEC International Electrotechnical Commission MQSA Mammography Quality Standards Act MRI Magnetic Resonance Imaging NCRP National Council for Radiation Protection NHPP National Health Physics Program PET Positron Emission Tomography POC Point of Contact QMP Qualified Medical Physicist QA Quality Assurance RSO Radiation Safety Officer SOW Statement of Work SPECT Single-Photon Emission Computed Tomography TJC The Joint Commission STVHCS South Texas Veterans Health Care System VHA Veterans Healthcare Administration

Quality Assurance Testing:

All Quality Assurance Tests shall meet or exceed current and possible future changes in NRC, ACR, MQSA, NHPP, NCRP, FDA and TJC requirements and recommendations.

All Quality Assurance Tests shall meet or exceed the requirements in the following VHA directives and handbooks and future directives and handbooks:

• VHA Directive 1105, Management of Radioactive Materials

• VHA Handbook 1105.02, Nuclear Medicine and Radiation Safety Administrative

Service

• VHA Handbook 1105.03, Mammography Program Procedures and Standards

• VHA Handbook 1105.04, Fluoroscopy Safety

• VHA Handbook 1105.05, Magnetic Resonance (MR) Safety

• VHA Directive 1129, Radiation Protection for Machine Sources of Ionizing

Radiation

Diagnostic X-ray Equipment (Radiography and Fluoroscopy):

The testing must include, but is not necessarily limited to, the following (as applicable):

Per VHA Handbook 1105.04, Fluoroscopy Safety:

• Measurement of radiation output parameters, including beam intensity and beam quality;

• Testing of all modes of operation used clinically, including automatic exposure rate controls of fluoroscopy systems;

• Assessment of image quality;

• Assessment of technique factors used clinically;

• Measurement of appropriate indices of patient dose output chart must be generated for each survey in accordance 25 TAC. Dose rates at typical clinical technique factors, with comparison to national standards.

Per the American College of Radiology Technical Standard for Diagnostic Medical Physics Performance Monitoring of Radiologic and Fluoroscopic Equipment:

• Integrity of unit assembly

• Collimation and radiation beam alignment

• Fluoroscopic system resolution

• Automatic exposure control system performance

• Fluoroscopic automatic brightness control performance (high-dose-rate, pulsed modes, and field-of-view [FOV] variation)

• Image artifacts

• Fluoroscopic phantom image quality

• kVp accuracy and reproducibility

• Linearity of exposure versus mA or mAs

• Exposure reproducibility

• Timer accuracy

• Beam quality assessment (half-value layer)

• Fluoroscopic entrance exposure rates

• Image receptor entrance exposure

• Equipment radiation safety functions

• Patient dose monitoring system calibration

• Video and digital monitor performance within manufactures specifications compliance with standard of practice.

• Digital image receptor performance

If the review of clinically-used technique factors or the comparison of measured dose indices with national standards indicates that an optimum balance has not been achieved between patient dose and image quality or that the dose indices exceed national standards, the technique factors, whether posted in a chart or programmed into the fluoroscope, must be modified as necessary. [VHA Handbook 1105.04]

Reports shall be generated indicating appropriate indices of patient dose, measured by a diagnostic medical physicist at clinically-used technique factors, to be posted near the controls of each fluoroscope. These indices include typical and maximal entrance skin dose or air kerma rate for each fluoroscopic mode of operation (e.g., pulse rate and magnification mode). For each image recording mode used clinically, these include the entrance skin dose or air kerma per image or the entrance skin dose or air kerma per second of imaging (e.g., cinefluorography in the cardiac catheterization laboratory) for a patient of typical thickness. [VHA Handbook 1105.04]

Computed Tomography:

Per the American College of Radiology Technical Standard for Diagnostic Medical Physics Performance Monitoring of Computed Tomography (CT) equipment:

• Alignment light accuracy

• Image localization from scanned projection radiograph (localization image)

• Table incrementation accuracy

• Radiation beam width (collimation)

• Reconstructed image thickness

• Image quality o High-contrast (spatial) resolution o Low-contrast sensitivity and resolution o Image uniformity o Noise o Artifact evaluation

• CT number accuracy

• Acquisition workstation display

• Dosimetry o Radiation output of CT scanner (CT dose index [CTDIvol] or equivalent) o Patient radiation dose estimate for representative examinations

• Protocol review o The Diagnostic Medical Physicist can become a member of protocol review committee of the most commonly used protocols. These should include head and abdomen protocols for adult and pediatric patients as applicable to the facility’s practice. In addition, facility protocols for very high dose procedures (e.g., brain perfusion) should be reviewed.

o Elements reviewed should include documentation of kVp, mA, rotation time, detector configuration, pitch, reconstructed image thickness, and use of automatic exposure control (including ensuring documentation of reference settings used), and the indicated dose indices (CTDIvol) resulting from each examination.

• Safety Evaluation o Visual inspection o Work load assessment o Scatter and stray radiation measurements (if work load and other related parameters have changed since acceptance testing) o Audible/visual signals o Posting requirements

• Other tests as required by state or local regulations

Per the TJC Revised Requirements for Diagnostic Imaging Services (Prepublication Requirements; subject to change):

• Image uniformity

• Slice thickness accuracy

• Slice position accuracy (when prescribed from a scout image)

• Alignment light accuracy

• Table travel accuracy

• Radiation beam width

• High-contrast resolution

• Low-contrast resolution

• Geometric or distance accuracy

• CT number accuracy and uniformity

• Artifact evaluation

• Dosimetry o The diagnostic medical physicist measures the radiation dose (in the form of volume computed tomography dose index [CTDIvol]) produced by each diagnostic CT imaging system for the following four CT protocols: adult brain, adult abdomen, pediatric brain and pediatric abdomen. If one or more of these protocols is not used by the hospital, other commonly used CT protocols may be substituted.

o The diagnostic medical physicist verifies that the radiation dose (in the form of CTDIvol) displayed by the CT imaging system for each tested protocol is within 20 percent of the CTDIvol displayed on the CT console. The dates, results, and verifications of these measurements are documented.

• Image acquisition display monitors o Maximum luminance o Minimum luminance o Luminance uniformity o Resolution o Spatial accuracy

Dental:

The physics inspection shall conform to the Conference of Radiation Control Program Directors (CRCPD), Quality Control Recommendations for Diagnostic Radiography Volume 1 Dental Facilities July 2001. The performance of dental x-ray inspections shall be annually or every 2 years. This evaluation should include, but not be limited to, the following tests (as applicable):

• Collimation

• Beam quality (half-value layer)

• Timer Accuracy and Reproducibility

• kVp Accuracy and Reproducibility

• mA or mAs Linearity

• Exposure Reproducibility

• Entrance skin exposure evaluation, with comparisons to published diagnostic reference levels and achievable doses (e.g. NCRP Report No. 172)

• Technique Chart Evaluation

• Image uniformity (artifact evaluation)

Dental Cone Beam Computed Tomography (CBCT) Acceptance and Performance Testing

a) Acceptance Testing. Acceptance testing and measurements of air kerma at the isocenter for each kVp station for a range of clinically used mAs settings will performed initially when the CBCT unit is installed, and following any move of the CBCT to another area inside or outside the initial clinical site. This testing is to ensure that the equipment performance is in agreement with the manufacturer’s technical specifications.

b) Performance Testing. Each CBCT unit shall undergo periodic quality control tests to ensure that the performance of the machine has not significantly deteriorated and is operating within the manufacturer’s technical specifications. This performance testing is performed by a qualified expert annually, at intervals not to exceed 14 months, and after repairs to the CBCT unit that may affect the radiation output or image quality.

c) Some manufacturers provide a phantom and procedures to perform machine specific quality assurance (QA) tests. In cases where the manufacturer provides a phantom and procedures to perform specific tests but the tests are not included in this SOW, then the manufacturer’s machine-specific QA tests shall be performed in addition to the QA tests in this SOW.

Acceptance and Annual physics testing for Dental CBCT

a) Radiation output Repeatability

Make four measurements of the air kerma at the isocenter at a clinically used setting. The measurements should be less than +/-5% of the average of the five measurements and the measurements should be less than +/- 5% of the previous year’s measurement.

b) Radiation Output Reproducibility

Measure the air kerma at the isocenter for each kVp station and a range of clinically used mAs setting. Compare the results to the baseline values established at the initial acceptance testing. The values should be +/-5% of the baseline.

c) kVp Accuracy

Measure the kVp at all clinically used settings. The measured kVp should be +/-5% of the selected kVp.

d) kVp Repeatability

Make five kVp measurements each for two clinically used kVp settings. All measured values should be +/-5% of the mean kVp.

e) kVp Reproducibility

Measure the kVp at all available kVp settings. The measured values should be +/-5% of the baseline.

f) Beam quality

Measure the half value layer (HVL) for aluminum. The minimum shall comply with Section F.4.d of the Suggested State Regulations for Control of Radiation, Conference of Radiation Control Program Directors.

g) Radiation field of view (FOV)

Measure the width of the radiation field at the isocenter. The width of the beam should be 3 mm or 30% of the total nominal collimated width.

h) Image Quality

Image the phantom provided by the manufacturer or another suitable phantom. Assess high contrast spatial resolution, uniformity of transaxial images, and image noise.

Imaging uniformity shall be assessed over the entire range of axial images.

i) Accuracy of Linear Measurements

Using images of an appropriate phantom, assess the accuracy of distance measurements.

j) Accuracy of Patient Dose Metric Indication

Assess the accuracy of the indicated dose metric (typically DAP).

k) Patient Dose Assessment

From a scan or scans using the facility’s standard techniques, record the dose metric (typically DAP) and compare to achievable levels and diagnostic reference levels (if available)

l) Review of the technical QA program

The qualified expert shall review the technical QA program. The review shall include a trend analysis of the QA data. The results of the technical QA program review shall be included in the written report. Any trends that identify problems shall be included in the report along with recommended corrective actions.

m) Display Monitors

Perform a visual analysis of the SMPTE test pattern.

i. Display the test pattern on the imaging console. Set the display window width/level to the manufacturer-specified values for the pattern. Do not set the window/level by eye;

doing so invalidates the procedure.

ii. Examine the pattern to confirm that the gray level display in the imaging console is subjectively correct.

1. Review the line pair patterns in the center and at each of the corners.

2. Review the black-white transition.

3. Look for any evidence of “scalloping” (loss of bit depth) or geometric distortion.

iii. Use a photometer to measure the maximum and minimum monitor brightness (0% and 100% steps)

iv. Measure additional steps within the pattern to establish a response curve.

v. Measure the brightness near the center of the monitor and near all 4 corners (or all 4 sides, depending on the test pattern used).

n) Viewing Conditions

Assess the viewing conditions for the area in which the monitor used to evaluation the CBCT studies is located.

Mammography:

The qualified diagnostic medical physicist shall provide the facility with up to date documentation demonstrating they qualified diagnostic medical physicist is MQSA qualified. Inspections of mammography equipment must comply with the latest requirements posted on the ACR website for the manufacturer of the digital mammography unit being inspected. Inspection items may include:

• Mammographic Unit Assembly Evaluation

• Mammographic Unit Assembly Evaluation

• Mammographic Unit Assembly Evaluation

• Collimation assessment

• Artifact evaluation

• kVp accuracy and reproducibility

• Beam quality assessment – HVL measurements

• Evaluation of system resolution

• Automatic Exposure Control (AEC) function performance

• Breast entrance exposure, AEC reproducibility and average glandular dose

• Radiation output rate

• Phantom image quality evaluation

• Signal–to–noise ratio and contrast – to noise ratio measurements

• Viewbox luminance and room illuminance

• Review workstation (RWS) tests

Mammography Display Monitors:

The physics inspection shall conform to the AAPM On-line Report No. 03, Assessment of Display Perform for Medical Imaging Systems. The performance of each display monitor shall be evaluated initially, acceptance testing, and at least annually thereafter.

This evaluation should include, but not be limited to, the following tests (as applicable).

Acceptance testing (Table 7 from AAPM On-line Report No. 03):

• Geometric distortions

• Reflection

• Luminance response

• Luminance dependencies

• Resolution

• Noise

• Veiling glare a low‐frequency degradation described by a point spread function

(PSF).

• Chromaticity

Annual testing (Table 8c. from AAPM On-line Report No. 03)

• Geometric distortions

• Reflection

• Luminance response

• Luminance dependencies

• Resolution

• Noise

• Veiling glare

• Chromaticity

• Mammography printers in accordance to MQSA requirements

• Grey artifacts

• Low contrast

• High contrast

• Evaluate ACR phantom from printer print out

For PET:

The physics inspection shall conform to the ACR PET Phantom Instructions for Evaluation of PET Image, ACR Nuclear Medicine Accreditation Program PET Module.

The performance of each PET scanner shall be evaluated semiannually. For PET/CT units the CT must be inspected at least annually. This evaluation should include, but not be limited to, the following tests (as applicable):

• Uniformity

• Spatial resolution

• SUV analysis

• Review quality control and radiation safety documents

• Phantom evaluation for PET scanner (semiannually)

• Evaluate acquisition work station (AWS) image quality

Nuclear Medicine:

The physics inspection shall conform to the ACR annual performance tests for nuclear medicine cameras. The performance of each nuclear medicine scanner shall be at least annually. The qualified diagnostic medical physics shall also perform the semiannually testing as outlined by the ACR. This evaluation should include, but not be limited to, the following tests (as applicable):

• Intrinsic Uniformity: fail criteria: > 5.0%

• System Uniformity: fail criteria: > 5.0%

• Intrinsic or System Spatial Resolution: fail criteria > 3.5 mm bars

• Relative Sensitivity: fail criteria: COV > 2.5%

• Energy Resolution: fail criteria: >12%

• Count Rate Parameters: fail criteria

• Formatter/Video Display

• Overall System Performance for SPECT

• System Interlocks

• Dose Calibrators (Geometry (if applicable), Accuracy)

• Thyroid Uptake and Counting Systems

• Review quality control and radiation safety documents

• Phantom evaluation for Nuclear Medicine scanner (semiannually)

• Evaluate acquisition work station (AWS) image quality

MRI Equipment:

Per the American College of Radiology Technical Standard for Diagnostic Medical Physics Performance Monitoring of Magnetic Resonance Imaging (MRI) Equipment:

• Magnetic field homogeneity

• Slice position accuracy

• Slice thickness accuracy

• Radiofrequency (RF) calibration for all coils o Frequency and gain/attenuator verification (prescan values) o Image signal–to-noise ratio (SNR) for all coils o Intensity uniformity for all volume coils o Phase stability and image artifact assessment for all coils

• Softcopy (monitor) fidelity

• Evaluation of quality control (QC) program

Per the TJC Revised Requirements for Diagnostic Imaging Services (Prepublication Requirements dated December 20, 2013; subject to change):

• Image uniformity for all radiofrequency (RF) coils used clinically

• Signal-to-noise ratio (SNR) for all coils used clinically

• Slice thickness accuracy

• Slice position accuracy

• Alignment light accuracy

• High-contrast resolution

• Low-contrast resolution (or contrast-to-noise ratio)

• Geometric or distance accuracy

• Magnetic field homogeneity

• Artifact evaluation

• Image acquisition display monitors o Maximum luminance o Minimum luminance o Luminance uniformity o Resolution o Spatial accuracy

Structural Shielding:

For any room in which a fluoroscopic imaging system is installed, or in which a mobile fluoroscopic imaging system is frequently used, the doses to persons in adjacent areas, including any areas above and below, must be evaluated by a diagnostic medical physicist or medical health physicist. Structural shielding must be installed as necessary to maintain doses to persons in these areas ALARA and within regulatory limits. [VHA Handbook 1105.04]

For the structural shielding of rooms containing x-ray imaging devices, the shielding design goal must be 5 milligray (mGy) in a year to any person in a controlled area. For uncontrolled areas, the shielding design goal needs to be 1 mGy in a year to any person, and 0.02 mGy in any hour. [VHA Handbook 1105.04]

The design of shielding for and acceptance testing surveys of imaging rooms must conform to National Council on Radiation Protection and Measurements (NCRP) Report No. 147, Structural Shielding Design for Medical X-ray Imaging Facilities. The shielding design calculations, as-built shielding plans, and the report on the acceptance testing of the structural shielding must be kept for the duration of use of the room for x-ray imaging. [VHA Handbook 1105.04]

Qualifications. Prior to commencing work, all contractor employees shall meet certain criteria to perform work under this contract as a Diagnostic Medical Physicist. Qualification documents must be submitted as part of the bid to the Contracting Officer and be approved by the RSO or his/her designee. All qualifications are subject to review by the STVHCS Chief of Radiation Safety Service.

Diagnostic Medical Physicist:

The Diagnostic Medical Physicist who performs the work at STVHCS shall meet the following education, certification, and qualification standards:

• Hold a Masters Degree or higher in Medical Physics, Health Physics or a related field.

• Hold current Board Certification by the American Board of Radiology or American Board of Medical Physics.

• Licensed by the State of Texas as a Professional Medical Physicist.

• Licensed with up to date documentation of MQSA qualifications.

• Meet all NRC, ACR, MQSA, FDA and TJC requirements for a qualified diagnostic medical physicist.

• The qualified diagnostic medical physicist inspecting mammography equipment must meet the qualifications outline in the Mammography Quality Standards Act (MQSA).

• A physicist assistant personally must be accompanied and supervised by a fully licensed qualified diagnostic medical physicist.

• A temporary license medical physicist must be supervised as defined by: Temporary Medical Physicist Supervisor Agreement Plan for Texas.

The Diagnostic Medical Physicist shall have current knowledge, understanding, and recent experience in the following:

• Texas Department of State Health Services, Radiation Control Regulations

• Current NRC regulations

• Current FDA regulations (including MQSA)

• Current recommendations of the ACR and TJC on diagnostic x-ray and imaging equipment

• Current recommendations of the NCRP and AAMP on medical imaging facility design and shielding

• Current techniques for the calibration and testing of diagnostic x-ray equipment

Holidays:

Work at the government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO). Also included would be any other day specifically declared by the President of the United States to be a National Holiday. Federal Holidays observed by the ELPVAHCS are:

New Years' Day Labor Day Martin Luther King Day Columbus Day Presidents' Day Veterans' Day Memorial Day Thanksgiving Day Juneteenth Day Christmas Day

Independence Day

Contractor Personnel Security Requirements - Information Systems Access

Upon contract award, all personnel with access to the facility shall be subject to the appropriate type of background investigation or screening per VA/VHA policy as delineated below, and must receive a favorable adjudication from the local VA facility or VA Security and Investigations Center (SIC) depending on the type of investigation/screening required. This requirement is also applicable to all subcontract personnel.

Contract personnel who previously received a favorable adjudication as a result of a Government background investigation or screening may be exempt from this contract requirement provided that they can provide documentation to support the previous adjudication.

Proof of previous adjudication must be submitted by the Contractor to VA Contracting Officer.

Proof of previous adjudication is subject to verification. Some positions maybe subject to periodic re-investigation/screening.

Position Risk/Sensitivity. For all positions required under this contract, the position risk/sensitivity has been designated as: Low Risk/Non-Sensitive.

Prior to completing the required forms, contract personnel should review the attachments entitled Common Errors on NACI Security Questionnaires, Example_SF85, Example_OF306, and General Questions and Answers about OPM background Investigations in order to ensure the forms are properly completed. Please note that incomplete forms will be rejected and could result in a delay of work under the contract.

Once the items requested are received, VA will pre-screen these items for completeness, and forward them to the appropriate party(s) in order to initiate the required background investigation(s) or screening(s) within fourteen (14) calendar days of appointment. Only after the VA Contracting Officer notifies the Contractor that the background investigation(s) or screening(s) was initiated shall the Contractor be authorized to provide services under the contract.

The Contractor, when notified of an unfavorable determination by the Government, shall withdraw the contract person from consideration of working under the contract.

Failure to comply with these Contractor personnel security requirements may result in termination of the contract for default.

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Position Sensitivity – The position sensitivity has been designated as Low Risk/Non-sensitive.

a. Background Investigation – Upon contract award, all personnel with access to the facility shall be subject to the appropriate type of background investigation or screening per VA/VHA policy, and must receive a favorable adjudication from the local VA facility or VA Security and Investigations Center (SIC) depending on the type of investigation/screening required.

b. Contractor Responsibilities

(1) The Contractor shall submit or ensure that their employees submit the required information to the Contracting Officer and Contracting Officer’s Representative (COR).

The Contractor shall submit the required forms to the VA Security and Investigations Center within 5 days of receipt of the e-mail with instructions to do so. The Contractor shall not allow Contractor personnel who require a background investigation to start performing until the Contractor has received written confirmation from the Contracting Officer that the SIC has initiated a background investigation.

(2) The Contractor, when notified of and unfavorable determination by the Government, shall withdraw the employee from consideration from working under the contract.

(3) Unless written authorization is issued by the Contracting Officer, contractor employees will not use any form of removable storage media when providing services under the terms of this contract. Removable storage media includes, but is not limited to, USB thumb drives, MP3 Players, and external hard drives. Should the Contractor determine that the use of removable storage devices is required they must submit a written request with full justification to the Contracting Officer.

Failure to comply of with the contractor personnel security requirements may result in termination of the contract for cause.

Information Security The diagnostic medical physicist working with the contractor may have access to sensitive patient information displayed on the control panel of X-ray equipment. However, contractor owned IT devices (such as laptop computer) shall not interface with any VA internet trusted (i.e., non-public) network. Therefore, the certification and accreditation (C&A) requirements do not apply, and a Security Accreditation Package is not required. Contractor shall not print or copy any sensitive patient information.

GENERAL

Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

c. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.

d. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor

e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

VA INFORMATION CUSTODIAL LANGUAGE

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

b. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

g. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.

h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

i. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.

k. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus.

If the contractor/subcontractor is in receipt of a court order or other requests for the above mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.

l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.

LIQUIDATED DAMAGES FOR DATA BREACH

a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis.

Failure to cooperate may be deemed a material breach and grounds for contract termination.

c. Each risk analysis shall address all relevant information concerning the data breach, including the following:

(1) Nature of the event (loss, theft, unauthorized access);

(2) Description of the event, including:

(a) date of occurrence;

(b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;

(3) Number of individuals affected or potentially affected;

(4) Names of individuals or groups affected or potentially affected;

(5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

(6) Amount of time the data has been out of VA control;

(7) The likelihood that the sensitive personal information will or has been compromised

(made accessible to and usable by unauthorized persons);

(8) Known misuses of data containing sensitive personal information, if any;

(9) Assessment of the potential harm to the affected individuals;

(10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and

Privacy Incidents, as appropriate; and

(11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

d. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $_0_ per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

(1) Notification;

(2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

(3) Data breach analysis;

(4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

(5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and

(6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

TRAINING

a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

(1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;

(2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

(3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

(4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]

b. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

41. Information System Officer, Information Protection: The contractor will not have access to VA Desktop computers they will not have access to online resources belonging to the government.

Privacy Officer: The Contractor will not have access to protected Patient Health Information (PHI) nor will they have capability of accessing patient information during the services provided to the VA and if removal of equipment from the VA is required, any memory storage device will remain in VA control and will not be removed from VA custody. All research data available for Contractor analysis is de-identified.

Records Manager:

a. Citations to pertinent laws, codes and regulations such as 44 U.S.C chapters 21, 29, 31 and 33; Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228.

b. Contractor shall treat all deliverables under the contract as the property of the U.S.

Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest.

c. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records.

d. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act.

e. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract.

f. The Government Agency owns the rights to all data/records produced as part of this contract.

g. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

h. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format [paper, electronic, etc.] or mode of transmission [e-mail, fax, etc.] or state of completion [draft, final, etc.].

i. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules.

j. Contractor is required to obtain the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .