Attachment_C_-_Agency_Terms_R.F.P._Clean_01.16.2025.pdf

PDF 343 KB Posted

Attached to
Online Data Base, non-IT State and local contract opportunity
Solicitation number
EV00000674
Issued by
Oklahoma

About this file

This document is an Attachment C - Agency Terms for a contract with the Oklahoma Health Care Authority (OHCA), detailing the comprehensive terms and conditions for a supplier providing services to the agency. The contract covers a range of requirements including system security, disaster recovery, data protection, confidentiality, and operational standards for a service or technology engagement. While the specific services are not fully detailed in this attachment, the document outlines extensive compliance expectations, including adherence to federal and state regulations such as HIPAA, information technology accessibility standards, and security protocols.

The contract includes specific financial and operational provisions, such as payment terms where OHCA will reimburse the supplier for satisfactory services, with total payments not exceeding the amount specified in a separate attachment. The supplier is required to maintain substantial insurance coverage, including $2 million in Commercial General Liability Insurance, $2 million in Directors and Officers Insurance, and $10 million in Security and Privacy Liability insurance. The contract emphasizes strict data protection requirements, mandating that all functions and health data must be performed and accessed within the continental United States, with comprehensive security and privacy safeguards, and potential withholding of up to 15% of invoice amounts to ensure proper contract execution and turnover.

View the file

Other files for this state and local contract opportunity

Other files attached to Online Data Base, non-IT, newest first.
File Type Posted
Attachment_B-NegotiableTerms_1.docx DOCX document
Exhibit_2-Cost_Sheet.pdf PDF
Agency_Bid_Instructions_-final_copy.pdf PDF
BID_PACKET_ATTACHMENTS_INSTRUCTIONS.pdf PDF
Exhibit1-ExecutiveSummaryWorksheet_(3).xlsx XLSX spreadsheet
OMESFormCP004.pdf PDF
Attachment_A-AgencyPurposeScopeNonNegotiable_-_final_copy.pdf PDF
Fillable_OMESFormCP076.pdf PDF
Amendment_1_Vendor__Q_A.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT C – AGENCY TERMS

CONTRACT TERMS AND CONDITIONS

OKLAHOMA HEALTH CARE AUTHORITY

Based upon the following recitals, the Oklahoma Health Care Authority (hereinafter referred to as OHCA), and Supplier enter into this Contract. All terms are as applicable.

Contents

C.1 CONTRACT GENERAL TERMS AND CONDITIONS

C.2 PAYMENTS AND REIMBURSEMENT

C.3 AVAILABILITY OF FUNDING

C.4 HOLD HARMLESS

C.5 FORCE MAJEURE

C.6 CONTRACT COMPLIANCE AND PENALTIES

C.7 TERMINATION

C.8 SCOPE OF WORK

C.9 LAWS APPLICABLE

C.10 FEDERAL REGULATIONS

C.11 AUDIT AND INSPECTION

C.12 CONFIDENTALITY AND SECURITY OF PROTECTED HEALTH INFORMATION

C.13 REQUIRED INSURANCE COVERAGE

C.14 DECEPTIVE TRADE PRACTICES; UNFAIR BUSINESS PRACTICES

C.15 MEDIA OWNERSHIP (DISK DRIVE AND/OR MEMORY CHIP OWNERSHIP) 20

C.16 INFORMATION TECHNOLOGY ACCESS CLAUSE

C.17 SYSTEM SECURITY

C.18 DISASTER PREPARATION AND DATA RECOVERY

C.19 DISASTER RECOVERY PLAN

C.20 OFFSHORING

C.21 OWNERSHIP OF MATERIALS

C.22 PUBLICATIONS RIGHTS/SCHOLARY WORK

C.23 PUBLICITY

C.24 TURNOVER

C.25 DISCLOSURE OF OWNERSHIP

C.1 CONTRACT GENERAL TERMS AND CONDITIONS

1. Purpose The purpose of this Contract is to acquire the services necessary to assist OHCA in successfully carrying out functions described in Attachment A: Proposal.

2. The Parties

a. Oklahoma Health Care Authority (“OHCA”)

i. OHCA is the single State agency designated by the Oklahoma Legislature through 63 O.S. § 5009(B) to administer Oklahoma’s Medicaid Program .

ii. OHCA has authority to enter into this Contract pursuant to 63 O.S. § 5006(A), 74 O.S. § 85.1 et. seq. OHCA’s Chief Executive Officer has authority to execute this Contract on OHCA’s behalf pursuant to 63 O.S. § 5008(B).

iii. OHCA’s contact information for the purposes of this Contract is as follows:

Email (preferred): Procurement@okhca.org

Mailing address: Oklahoma Health Care Authority

Attn: Contracts Development Unit 4345 N. Lincoln Boulevard Oklahoma City, OK 73105-5101

iv. OHCA’s email address for electronic submission of invoices is as follows:

Contracts@okhca.org

v. OHCA may update its contact information described above upon written notice (email is sufficient) to Supplier.

b. Supplier

i. Supplier has the authority to enter into this Contract pursuant to its organizational documents, bylaws, or properly enacted resolution of its governing authority. The person executing this Contract has authority to execute this Contract on Supplier’s behalf pursuant to Supplier’s organizational documents, bylaws, or properly enacted resolution of Supplier’s governing authority.

3. General Provisions

a. Contract Term mailto:Procurement@okhca.org mailto:Contracts@okhca.org

i. This Contract shall begin on the date of signature and will expire as described in Attachment A.

b. Contract Extension Option

i. OHCA may choose to exercise an extension for up to 180 days beyond the final renewal option period at this Contract pricing rate; the extension shall be executed by mutual agreement. If this option is exercised, OHCA shall notify the Supplier in writing prior to this Contract end date.

ii. OHCA may choose to exercise subsequent extensions, up to 180 days each, by mutual agreement and at this Contract pricing rate, to facilitate the finalization of related terms and conditions of a new contract or as needed for transition to a new Supplier.

4. Amendments/Modifications

a. This Contract contains all of the agreements of the parties and no oral representations by either Party are binding. Any amendments and/or modifications to this Contract’s term, scope of work, and/or pricing methodology shall be in writing and signed by both Parties.

b. Legislative, regulatory, and programmatic changes may require changes in the terms and conditions of the Contract. Modifications of terms and conditions of this Contract shall be authorized in such cases upon mutual approval by OHCA and Supplier. At all times, all Parties shall adhere to the overall intent of the Contract.

c. Not-to-exceed increases or decreases, solely at the time of Contract renewal, shall not require an amendment/modification.

5. Independent Contractor

a. Supplier is in all respects an independent contractor and is neither an agent nor an employee of OHCA.

b. This Contract does not create an employment relationship. Supplier and

Supplier’s employees shall not be considered employees of the State of Oklahoma nor of OHCA for any purpose, and accordingly shall not be eligible for rights or benefits (including but not limited to worker’s compensation) accruing to State employees.

c. The Supplier shall not have authority to bind OHCA.

6. Assignment/Subcontract

a. Supplier shall not assign, transfer, or subcontract any rights or obligations under this Contract without prior written consent of OHCA. This Contract shall be binding and effective on any and all permitted successors and assigns.

b. Supplier shall be responsible for all subcontractors’ performance and shall be solely responsible for meeting all the terms of the Contract. No subcontract or delegation shall relieve or discharge Supplier for any obligation or liability under this Contract. Any subcontractor shall be subject to the same conditions as Supplier, including Contract modifications subsequent to award, confidentiality, audit, certifications, and other relevant Contract terms.

c. All subcontractors shall be identified by name and FEIN in a document made available in an electronic form for review or inspection by OHCA within thirty

(30) days after the execution of the Contract.

d. All subcontracts shall be available in an electronic form for review or inspection by OHCA upon request.

7. Product and/or Services Substitutions Substitutions are not permitted without the written permission of OHCA or authorized in the Scope of Work.

8. Conflict of Interest

1. Supplier certifies and agrees that it presently has no interest and shall not acquire any interest, either direct or indirect, which would conflict in any manner or degree with the performance of this Contract. The Supplier must disclose any outside activity or interest that conflicts or may conflict with the best interest of the State of Oklahoma. In the event that Contractor acquires any interest that may be in conflict with the performance of this Contract, Supplier will notify OHCA within three (3) business days. Any conflict of interest shall, at the sole discretion of OHCA, be grounds for partial or whole termination of the Contract.

9. Equipment and Electronic Communication

a. Equipment is defined by the State of Oklahoma as a tangible nonexpendable item having a useful life of more than one year and total acquisition cost of $500.00 or more per unit. In the event Supplier is loaned equipment by OHCA under this Contract, this equipment remains the property of OHCA. Supplier may not add software to any equipment and shall follow all OHCA policies regarding computer usage and storage. The equipment shall be returned to OHCA in the same condition as when originally loaned upon completion of this Contract, subject to normal wear and tear through routine use.

b. In order to access OHCA’s systems network for purpose of performing duties pursuant to this Contract, Supplier is required to utilize equipment supplied by OHCA or equipment that meets the security requirements of OHCA.

c. Supplier is prohibited from using OHCA’s equipment, OHCA’s offices, or any other resources of OHCA or the State for any purpose other than performing services under this Contract. For this purpose, equipment includes, but is not limited to, copy machines, computers, and telephones. Any charges incurred by Supplier using OHCA’s equipment for any purpose other than performing services under this Contract shall be fully reimbursed by Supplier to OHCA within ten (10) business days upon demand by OHCA. Such use shall constitute breach of Contract and may result in termination of this Contract and other remedies available to OHCA under this Contract and applicable law.

10. Use of State Property Supplier is prohibited from using any OHCA fitness/gym equipment/facilities.

Additionally, Supplier is prohibited from participating in any OHCA sponsored activities and/or events, including, but not limited to, all-star days, employee recognition days, holiday celebrations, and activities related to physical exertion or general clinical/health/wellness guidance sessions whether on premises or off-site. Supplier hereby waives, discharges, releases, promises to indemnify, and forever hold harmless the State of Oklahoma and OHCA, its respective officers, agents, servants, representatives, and employees and any associated entity from any and all personal or derivative actions, claims, all pain and suffering, damage to property, all losses and expense of whatever character, and demands, whether it be caused by the negligence of OHCA, its agents, servants, or employees or any other associated entity that Supplier, Supplier’s heirs, executors, administrators, legal representatives, assignees, and successors in interest, now or hereafter, have related to the prohibited use of fitness/gym equipment/facilities during business hours, non-business hours, and weekends.

11. Public Disclosure Supplier shall not cause public disclosures or news releases pertaining to this Contract without prior written approval of OHCA.

12. Non Tobacco – Smoke Free By operation of the Governor’s Executive Order 2012-01, effective August 6, 2012, the use of any tobacco product shall be prohibited on any and all properties owned, leased, or contracted for use by the State of Oklahoma, including but not limited to, all buildings, land and vehicles owned, leased, or contracted for use by agencies or instrumentalities of the State of Oklahoma.

C.2 PAYMENTS AND REIMBURSEMENT

1. In consideration of satisfactory performance of the services enumerated in Attachment A of this Contract, OHCA shall make payments to Supplier at the rate specified in the proposal. Total payments shall not exceed the amount specified in Attachment A for the initial phase of the contract. Final approval of scope expansion and renewal amounts will be at the sole discretion of OHCA. Payment shall be inclusive of all costs (e.g., salaries, fringe benefits, supplies, equipment, travel, long distance, copying, etc.) required to provide the services detailed in this Contract. Billable time shall include time spent working at OHCA or time spent working on assigned OHCA business. No additional payments shall be made under this Contract.

2. It is understood and agreed to by the Parties hereto that all obligations of OHCA, including the continuation of payments, are contingent upon the availability and continued appropriation of State and Federal funds, and in no event shall OHCA be liable for any payments in excess of such available appropriated funds.

3. Supplier shall submit a proper invoice for services rendered in order to receive payment. A proper invoice is one which contains, at a minimum, the following information:

a. Supplier name;

b. FEI or vendor number;

c. Invoice number;

d. Purchase order number (where applicable);

e. Description of service(s);

f. Date(s) of service;

g. Detail of amount(s) billed; and,

h. Detailed attachments to support work and travel being billed.

4. Supplier shall maintain documentation of all billed charges and shall submit documentation to OHCA with invoice submission.

5. All invoices for services rendered under this Contract shall be received by OHCA within 90 calendar days of the services being rendered. OHCA will not be held responsible for payment of invoices submitted beyond the deadline established by this paragraph.

6. OHCA shall have 45 calendar days within which to pay a proper invoice. If OHCA fails to pay an invoice within that time, Supplier shall have the right to interest thereon pursuant to 62 O.S. §§ 34.71 and 34.72.

C.3 AVAILABILITY OF FUNDING

In the event funding of the Medicaid Program from the State, Federal, or other sources is withdrawn, reduced, or limited in any way after the effective date of this Contract, OHCA may reduce or terminate this Contract upon notice to Supplier delivered through email. OHCA shall be the final authority as to the availability of funds. The effective date of such Contract reduction or termination shall be specified in the notice. In the event of a reduction, Supplier may cancel this Contract as of the effective date of the proposed reduction upon notice to OHCA delivered through email. OHCA agrees to reimburse Supplier for all work satisfactorily performed prior to the date of any notice of termination of this Contract pursuant to this section. This clause shall operate as an exception to the notice provisions otherwise applicable to amendment or termination of the Contract.

C.4 HOLD HARMLESS

The Parties intend that each shall be responsible for its own intentional and/or negligent acts or omissions to act. OHCA shall be responsible for the acts and omissions to act of its officers and employees while acting within the scope of their employment according to the Governmental Tort Claims Act, 51 O.S. § 151, et seq. Supplier shall be responsible for any damages or personal injury caused by the negligent acts or omissions to act by its officers, employees, or agents. Supplier agrees to hold harmless OHCA for any claims, demands, liabilities, and causes of action resulting from any act or omission on the part of Supplier and/or its agents, servants, subcontractors, and employees in the performance of this Contract. It is the express intention of the Parties hereto that this Contract shall not be construed as, or given the effect of, creating a joint venture, partnership, affiliation, or association that would otherwise render the Parties liable as partners, agents, employer-employee, or otherwise create any joint and severable liability.

C.5 FORCE MAJEURE

1. Insofar as it is consistent with Section 17 of Attachment neither Supplier nor OHCA shall be liable for any damages or excess costs for failure to perform their Contract responsibilities if such failure arises from causes beyond the reasonable control of and without fault or negligence by Supplier or OHCA. Such causes may include, but are not limited to, catastrophic events or acts of God. In all such cases, the failure to perform must be beyond the reasonable control of, and without fault or negligence of, either Party.

2. Within 72 hours of the occurrence of such an event, Supplier shall initiate disaster recovery and/or back up procedures to provide alternate services. Supplier shall notify OHCA prior to initiation of alternate services as to the extent of the disaster and/or emergency and the expected duration of alternate services within this same 72 hour period.

C.6 CONTRACT COMPLIANCE AND PENALTIES

1. Performance-based contracts may require Supplier to meet specific standards and/or metrics. Supplier’s performance may be assessed by such means as written reports, oral communication, onsite visits, audit, and data analysis.

2. Supplier shall be required to complete deliverables as offered on or before the agreed upon completion date. Deviations, substitutions, or changes in the deliverables shall not be made unless expressly authorized in writing by OHCA, as applicable.

3. OHCA and Supplier shall establish performance standards for this Contract based on the scope. All products and services are subject to inspection, testing and acceptance by OHCA. Any products and services that do not meet or exceed the specifications may be rejected. If Supplier fails to meet these standards or fails to meet any other Contract requirements, OHCA will email Supplier to discuss the issues. OHCA may request Supplier to prepare and submit for approval a Corrective Action Plan (CAP) for identified issues.

4. The CAP shall clearly specify which sections of this agreement describe the affected work, the performance deficiencies, and identify specific actions to be performed by Supplier to correct the performance. Supplier shall implement the CAP to correct the product/services deficiencies within the timeframe specified by OHCA.

5. If the Supplier’s product or services fail to meet the specifications, then the products or services may be rejected and returned to the Supplier with a Notice stating the reasons for non-acceptance. Such rejection will exempt OHCA from all related costs incurred by the Supplier. The Supplier shall be given thirty (30) business days to cure the nonconforming products or services and resubmit the deliverable(s) to OHCA, with a letter explaining the corrections made, for inspection, retesting, or reevaluation, OHCA shall be given up to one hundred and twenty (120) business days or no less than the original time period established for the product or service agreed upon by OHCA in the project a written notice of acceptance or rejection of the deliverables. If the deliverables submitted fail to pass acceptance within one hundred and twenty business days, OHCA may, at is sole discretion, continue with the Supplier or terminate the agreement.

6. Supplier warrants that, upon receipt of written Notice by OHCA of a latent defect in design, material, or workmanship, or a latent nonconformity of the software or services to the specifications which would have constituted a basis for rejection if discovered prior to acceptance, it will repair or replace or otherwise correct the defect to the level of performance specified within ten (10) calendar days of the date the Supplier was notified by OHCA of latent defect. If the Supplier fails to correct the latent defect(s) within ten (10) calendar days, OHCA may, at its sole discretion, continue with the Supplier or terminate the agreement.

7. Failure to resolve the issue may result in a penalty which is the withholding or reduction of Supplier reimbursement for the specific deliverable, milestone, product or service included in the CAP or Contract action, up to and including termination.

C.7 TERMINATION

1. Either Party may terminate this contract in whole or in part for cause with a 30-day written notice to the other Party. Either Party may terminate this contract in whole or in part without cause with a 60-day written notice to the other Party. In the event of termination, payments will be made for all work satisfactorily performed up to the date of termination.

2. OHCA may terminate this Contract immediately, in whole or in part, with a written notice to Supplier when one of the following applies:

a. Funding of the Medicaid Program from the State, Federal, or other sources is withdrawn, reduced, or limited in any way after the effective date of this Contract;

b. This Contract is no longer authorized by law or is otherwise found illegal;

c. Violations are found to be an impediment to the function of OHCA;

d. Conditions preclude the 30 day notice;

e. OHCA determines that an administrative error occurred prior to Contract performance; or,

f. Both Parties agree to terminate this Contract immediately without cause.

3. Upon termination of this contract, the termination and turnover provisions of sections C.12 and C.18 apply.

C.8 SCOPE OF WORK

1. The scope of work is described in the Attachment A.

C.9 LAWS APPLICABLE

1. The Parties to this Contract acknowledge and expect that changes may occur over the term of this Contract regarding Federal and State Medicaid statutes and regulations, and other statutes and regulations governing the practice of health care professions. The Parties shall be mutually bound by such changes.

2. The parties agree to comply with all applicable relevant federal and state laws, including but not limited to the following:

a. Bipartisan Budget Act of 2018 and its implementing regulations issued by CMS;

b. the Medicare Improvements for Patients and Providers Act of 2008 and its implementing regulations issued by CMS; 42 CFR Part 422;

c. Title IX of the Education Amendments of 1972, as amended (20 USC § 1681 et seq.);

d. Section 654 of the Omnibus Budget Reconciliation Act of 1981, as amended (41

USC § 9849);

e. Age Discrimination in Employment Act, 29 U.S.C. § 621 et seq.

f. Rehabilitation Act of 1973, 29 U.S.C. § 701 et seq.;

g. Drug-Free Workplace Act, 41 U.S.C. § 8101 et seq.;

h. Title XIX and Title XXI of the Social Security Act, 42 U.S.C. § 1396 et seq. and §

2101 et seq.;

i. Civil Rights Act, 42 U.S.C. § 2000d et seq. and § 2000e et seq.;

j. Age Discrimination Act, 42 U.S.C. § 6101 et seq.;

k. Americans with Disabilities Act, 42 U.S.C. § 12101 et seq.;

l. Oklahoma Anti-Discrimination Act, 25 O.S. § 1101 et seq.;

m. Oklahoma Worker’s Compensation Act, 85A O.S. § 1 et seq.;

n. Fair Labor Standards Act, 29 U.S.C. § 201 et seq.;

o. Equal Pay Act, 29 U.S.C. § 206(d);

p. 31 U.S.C. § 1352 and 45 C.F.R. § 93.100 et seq., which

i. Prohibit the use of Federal funds paid under this Contract to lobby Congress or any Federal official to enhance or protect the monies paid under this Contract; and,

ii. Require disclosures to be made if other monies are used for such lobbying;

q. Presidential Executive Orders 11141, 11246, 11375, and 11478, and Amendments thereto, and 5 U.S.C. § 3501, and as supplemented in the Department of Labor regulations at 41 C.F.R. Subtitle B, Chapter 60, which together require certain Federal contractors and subcontractors to institute affirmative action plans to ensure absence of discrimination for employment because of age, race, color, religion, sex, sexual orientation, gender identity, disability, or national origin;

r. The Federal Privacy Regulations and the Federal Security Regulations as contained in 45 C.F.R. Parts 160 through 164 that are applicable to such Party as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the Health Information Technology for Economic and Clinical Health Act (HITECH) (42 U.S.C. § 300jj et seq. and § 17921 et seq.);

s. The American Recovery and Reinvestment Act of 2009 (Pub. L. 111-5), pursuant to Title XIII Of Division A and Title IV of Division B, called the “Health Information Technology for Economic and Clinical Health” (HITECH) Act, provides modifications to the HIPAA Security and Privacy Rule (hereinafter, all references to the “HIPAA Security and Privacy Rule” are deemed to include all amendments to such rule contained in the HITECH Act and any accompanying regulations, and any other subsequently adopted amendments or regulations);

t. Vietnam Era Veterans’ Readjustment Assistance Act, 38 U.S.C. § 4212 and 41 C.F.R. Part 60-300;

u. Protective Services for Vulnerable Adults Act, 43A O.S. § 10-101 et seq.;

v. Non-procurement, debarment, and suspension, 2 C.F.R. Part 376;

w. 74 O.S. § 85.44(B) and (C) and 45 C.F.R. §§ 75.320, 75.439, and 75.465 (as defined by 45 C.F.R. § 75.2);

x. Anti-Kickback Act of 1986, 41 U.S.C. § 8701 et seq.;

y. Oklahoma Anti-Kickback Act of 1974, 74 O.S. § 3401 et seq.;

z. Federal False Claims Act, 31 U.S.C. §§ 3729-3733 and § 3801 et seq.;

aa. Oklahoma Medicaid False Claims Act, 63 O.S. § 5053 et seq.; and

bb. Oklahoma Taxpayer and Citizen Protection Act of 2007, 25 O.S. § 1313 and participation in the Status Verification System. The Status Verification System is defined at 25 O.S. § 1312 and includes, but is not limited to, the free Employment Verification Program (e-Verify) available at www.dhs.gov/E-Verify.

3. The explicit inclusion of some statutory and regulatory duties in this Contract is not intended to, and shall not be construed to, exclude other statutory or regulatory duties under applicable federal and/or State law.

4. All questions pertaining to validity, interpretation, and administration of this Contract shall be determined in accordance with the laws of the State of Oklahoma, regardless of where any service is performed.

5. The venue for civil actions arising from this Contract shall be in the District Court of Oklahoma County, Oklahoma. For the purpose of Federal jurisdiction, in any action in which the State of Oklahoma is a party, venue shall be in the United States District Court for the Western District of Oklahoma.

6. If any portion of this Contract is found to be in violation of State or Federal statutes, that portion shall be struck from this Contract and the remainder of this Contract shall remain in full force and effect.

C.10 FEDERAL REGULATIONS

1. The Federal Government reserves a royalty-free, non-exclusive, and irrevocable license to reproduce, publish, or otherwise use and to authorize others to use for Federal government purposes, such software, modifications, and documentation according to 45 CFR 95.617(b).

2. Supplier shall comply all applicable federal regulations, including without limitation (as applicable):

Category Citation Procurement Standards SMM Section 11267

45 C.F.R. § 95.615 45 C.F.R. Part 74 State Medicaid Director (SMD) Letter of Dec. 4, 42 C.F.R. § 433.122 42 C.F.R. § 433.112

Access to Records 45 C.F.R. §95.615 SMM Section 11267 http://www.dhs.gov/E-Verify

Software & Ownership Rights, Federal Licenses, Information Safeguarding, Health Insurance Portability and Accountability Act of 1996 (HIPAA) Compliance, and Progress Reports

The State shall own any software, procedures, or publications designed, developed, installed, or improved with 90 percent FFP. The State shall retain the right to sign, extend, and cancel any licenses for software used in operation of MMIS.

OHCA has a royalty-free, non-exclusive, and irrevocable license to reproduce, publish, or otherwise use and authorize others to use software, modifications to the software, and documentation designed, developed, installed, or improved with 90 percent FFP.

45 C.F.R. § 95.617 42 C.F.R. 433.112 42 C.F.R. § 431.300 45 C.F.R. Part 164

Information Safeguarding 42 C.F.R. § 433.112(b)(9) 45 C.F.R. § 205.50

Progress Reports SMM Section 11267 Disaster Recovery Procedure All Supplier(s) will be required to develop and maintain a Business Continuity Plan that will address aspects of disaster recovery. The Business Continuity Plan will provide procedures for emergencies and disasters, and for maintaining a state of readiness to meet all operational requirements.

IV&V 45 C.F.R. § 95.626

C.11 AUDIT AND INSPECTION

1. As used in this Contract, “records” includes books, documents, accounting procedures and practices, and other data regardless of type and regardless of whether such items are in written or electronic form, in the form of computer data, or in any other form.

2. Supplier shall keep records as are necessary to fully disclose the extent of service provided under this Contract, and shall furnish records and information regarding any claim for providing such service to OHCA, the State Auditor & Inspector (SA&I), the Office of Management and Enterprise Services Central Purchasing Division (CPD), the U.S. General Accounting Office (GAO), the Oklahoma Attorney General’s Medicaid Fraud Control Unit (MFCU), and the U.S. Secretary of the Department of Health and Human Services (hereinafter, referred to as “Secretary”). Supplier is required to retain records relating to this Contract for the duration of this Contract and for a period of ten

(10) years following completion and/or termination of the Contract. If an audit, review, litigation, or other action involving such records is started before the end of this ten (10) year period, the records are required to be maintained for two (2) years from the date that all issues arising out of the action are resolved, or until the end of the ten (10) year retention period, whichever is later.

3. Authorized representatives of OHCA, SA&I, CPD, GAO, MFCU, and the Secretary shall have the right to make physical inspection of Supplier’s location or facility and to examine records relating to financial statements or claims submitted by Supplier under this Contract and to audit Supplier’s financial records.

4. Pursuant to 74 O.S. § 85.41, OHCA, CPD, and the SA&I shall have the right to examine

Supplier’s books, records, documents, accounting procedures, practices, or any other items relevant to this Contract. OHCA shall allow for the inspection of public records in accordance with the provisions of the Oklahoma Open Records Act, 51 O.S. §§ 24A et seq.

5. Supplier shall, upon request Health and Human Services, and/or their representatives access to State agency documents papers, or other records pertinent to the procurement of this contract in order to make federal audits, examinations, excerpts and transcripts.

C.12 CONFIDENTIALITY AND SECURITY OF PROTECTED HEALTH

INFORMATION

1. To the extent any provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), including, but not limited to, the Privacy Rule and the Security Rule, or the Health Information Technology for Economic and Clinical Health Act (HITECH) and its implementing regulations, affect the duties and responsibilities of this Contract, both Parties agree to these terms. Supplier acknowledges that in its role as Supplier, it may have or obtain access to protected health information (PHI), including, but not limited to, individually identifiable health information, some of which may be electronic protected health information (ePHI), both as defined by HIPAA. PHI shall hereinafter refer collectively to both PHI and ePHI.

2. Definitions for the Purposes of this Section:

a. HIPAA shall mean the Health Insurance Portability and Accountability Act of

1996, the Privacy Rule, and the Security Rule, and other administrative simplification provisions as contained in 45 C.F.R. § 160.103 and the HITECH Act of 2009.

b. The following terms used in this Contract shall have the same meaning as those terms in HIPAA: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, and Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

c. Supplier is a “Business Associate” as defined by 45 C.F.R. § 160.103.

d. Discovery shall generally mean the first day a security incident or breach is known to Supplier or, by exercising reasonable diligence, would have been known to Supplier.

e. OHCA is a “Covered Entity” as defined by 45 C.F.R. § 160.103.

f. HIPAA Security and Privacy Rule shall mean the Privacy, Security, Breach

Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.

g. Security Event shall mean the attempted or successful unauthorized access, use, disclosure, modification, loss, theft, or destruction of information or interference with the Hosted environment used to perform the services.

h. Security Incident or Incident shall mean an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. A Breach as defined by HIPAA and the HIPAA Security and Privacy Rule shall constitute a Security Incident. Security Incident shall include, but is not limited to, unwanted disruption or denial of service, unauthorized use of a system for processing or storing ePHI, or changes to system hardware, firmware, or software without Business Associate’s consent.

C.13 REQUIRED INSURANCE COVERAGE

Supplier shall obtain and maintain

a. Commercial General Liability Insurance with a limit of liability of

$2,000,000.00 per occurrence.

b. Directors and Officers Insurance which shall include Employment Practices

Liability with a policy limit of $2,000,000 in the aggregate; and

c. Security and Privacy Liability insurance, including coverage for failure to protect confidential information and failure of the security of the Supplier’s computer systems that results in the unauthorized access to data with limits $10,000,00.00 per occurrence.

d. Supplier shall provide the OHCA with evidence of such insurance and renewals.

e. Any insurance coverage amounts listed here that exceed the insurance coverage amounts listed in Attachment B are mandatory additional requirements connected to this specific Acquisition.

C.14 DECEPTIVE TRADE PRACTICES; UNFAIR BUSINESS PRACTICES

Supplier represents and warrants that Supplier has not been found liable in any administrative hearing, litigation, or other proceeding of Deceptive Trade Practice violations as defined under the Oklahoma Consumer Protection Act, 15 O.S. § 15-751 and has no outstanding allegations of any Deceptive Trade Practice pending in any administrative hearing, litigation, or other proceeding.

C.15 MEDIA OWNERSHIP (DISK DRIVE AND/OR MEMORY CHIP OWNERSHIP)

In accordance with the State of Oklahoma Information Security Policy, Procedures, Guidelines set forth online at https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf.

(“Electronic Media Retention Requirements”), any disk drives and memory cards purchased with, or included for use in, leased or purchased equipment under this Contract remain the property of OHCA.

Personal Identification Information and Protected Health Information may be retained within electronic media devices and components; therefore, OHCA shall not allow the release of electronic media either between State Entities or for the resale of refurbished equipment that has been in use by State Entities, by the Supplier to the general public or other entities. Electronic Media Retention Requirements shall also be applied to replacement devices and components, whether purchased or leased, the Supplier may supply during the downtime (repair) of equipment purchased or leased through this Contract. If a device has to be removed from a location for repairs, OHCA shall have sole discretion, prior to removal, to determine and enforce sufficient safeguards (such as a record of hard drive serial numbers) to protect Personal Identification Information and Protected Health Information that may be stored within the hard drive or memory of the device.

C.16 INFORMATION TECHNOLOGY ACCESS CLAUSE

1. State procurement of information technology is subject to certain federal and State laws, rules and regulations related to information technology accessibility, including but not limited to Oklahoma Information Technology Accessibility Standards (“Standards”) set forth at https://omes.ok.gov/services/information-services/accessibility-standards.

Supplier shall provide a Voluntary Product Accessibility Template (“VPAT”) describing accessibility compliance via a URL linking to the VPAT and shall update the VPAT as necessary in order to allow a Customer to obtain current VPAT information as required by State law. If products require development or customization, additional requirements and documentation may be required and compliance shall be necessary by Supplier.

2. Such requirements may be stated in appropriate documents including but not limited to a statement of work, riders, agreement, purchase order or Addendum.

3. All representations contained in the VPAT provided will be relied upon by the State or a Customer, as applicable, for accessibility compliance purposes.

4. Supplier shall indemnify and hold harmless the State of Oklahoma and any Oklahoma

Government entity purchasing the product, system or application developed and/or customized by Supplier from any claim arising out of Supplier's failure to comply with applicable Oklahoma Information Technology Accessibility Standards subsequent to providing certification of compliance to such Standards.

C.17 SYSTEM SECURITY as Applicable

1. The Supplier shall support and ensure all relevant compliance with Federal and State

Medicaid and Health Benefit Exchange laws, regulations, and policies relevant to System security, confidentiality, and safeguarding of information. External Supplier responsibilities include, but are not limited to:

a. Patient Protection and ACA (ACA), Public Law 111–148;

b. HIPAA Privacy Rule, 45 CFR Part 160 and Subparts A and E of Part 164, established under the Health Insurance Portability and Accountability Act, Public Law 104-191 (42 USC 1320d);

c. HIPAA Security Rule, 45 CFR Part 160 and Subparts A and C of Part 164;

d. Health Insurance Portability and Accountability Act of 1996 (HIPAA), pursuant to sections 1104 and 1501 of ACA, including the privacy, security, and transaction requirements;

e. Federal Information Security Management Act (FISMA) of 2002;

f. Health Information Technology for Economic and Clinical Health Act of 2009

(HITECH);

g. Minimum Acceptable Risk Safeguards for Exchanges (MARS-E) Ver.2.2;

h. Federal Enterprise Architecture Security and Privacy Profile, version 3.0; and

i. Federal Information Processing Standards (FIPS), Publication 140-3.

2. The most recent versions for standards and specifications shall be applicable. Where policies overlap, the System shall always strive to attain the more stringent policy. Supplier may email securitygovernance@okhca.org requesting the most recent CMS MASR-E release control standards template and provide your security contact for distribution of OHCA Security communications.

3. If Supplier handles OHCA protected health information (PHI) the Supplier shall maintain systems, policies and procedures that ensure State and federal standards for compliance and security are met and to protect the integrity of all business and technical components of the Supplier’s operations under this Contract. This includes, but is not limited to, a requirement that Supplier must comply with the most current version of the suite of mailto:securitygovernance@okhca.org documents entitled the Minimum Acceptable Risk Safeguards for Exchanges (“MARS-E”) or the new upcoming version being retitled to Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (“ARC-AMPE”), once made available and required by CMS.

Alternatively, Supplier agrees to implement and maintain equivalent standards that meet or exceed these requirements should an alternative be approved. For example, HiTrust Common Security Framework (CSF)/R2 will be considered an acceptable framework and certification in place of the current MARS-E framework. Supplier further agrees to maintain a level of security that is commensurate with the risk and magnitude of the harm that could result from, but not limited to, the loss, misuse, disclosure, or modification of the information contained within the system. If at any time, Supplier plans to implement and maintain security standards other than MARS-E, the Supplier must submit the specific details of the planned change to OHCA for approval not later than sixty (60) Days before the date of planned implementation. Supplier is prohibited from implementing different security standards that would reduce the level of protection provided or that would cause OHCA to fall out of compliance with any applicable laws, regulations, or requirements of government agencies with jurisdiction or enforcement authority over OHCA.

4. Even if supplier does not handle OHCA PHI supplier shall minimally maintain a comprehensive information security program that includes industry best practices with a third-party major industry certification approved by OHCA. MARS-E control standards shall be considered for controls where relevant. Approved Major industry certifications for this paragraph includes ISO 27001, MARS-E, NIST SP 800-171, NIST CSF, SOC 2 Type 2 (5 Trust Services Criteria), HiTrust CSF/R2, FedRAMP, and StateRAMP. Alternatives certifications may be approved upon formal request to OHCA Security at OHCA's discretion. Certifications shall be a maintained as a continuous process with a reassessment cycle not to exceed 3 yrs. Supplier further agrees to maintain a level of security that is commensurate with the risk and magnitude of the harm that could result from the loss, misuse, disclosure, or modification of information with the highest reasonable security standards.

5. The Supplier shall ensure access to data systems is restricted using Minimum Necessary Rule concepts and employing automated access management functions to ensure individual identities are properly authenticated and logged when accessing the data. The Supplier shall ensure access to information is based on job functions with the overarching concept of access to information across development and operational cycles required for adequate performance of the job function (e.g., users permitted inquiry privileges only will not be permitted to modify information if not applicable to the requirements of the job the individual is performing).

6. Insofar as Supplier hosts, stores, or maintains OHCA data the Supplier shall ensure data at rest or in motion has all appropriate protections employed for confidentiality, integrity, and availability. The Supplier shall be responsible for providing physical safeguards to its data processing center, operations center and any related information or systems. These safeguards shall remain in place for the duration of the Supplier’s relationship with OHCA.

The Supplier shall grant authorized OHCA and CMS personnel and any designees access to its facilities upon request.

7. The Supplier shall maintain data history readily accessible for no less than three (3) years;

and shall retain additional archive history for no less than ten (10) years and the Supplier shall ensure such data is retrievable within 48 Hours.

8. The Supplier agrees to provide OHCA Security reasonable access to review security related materials upon request and in a timely manner for the purpose of confirming security posture and monitoring performance of this agreement. OHCA agrees to keep information confidential and not disclose to third-parties without prior mutual agreement, unless required by law. The Supplier further agrees to accept any comments made by OHCA reviews and appropriately address any concerns raised in accordance with regulations and best practices.

9. The Supplier shall abide by the current State of Oklahoma Security Standards at:

https://oklahoma.gov/content/dam/ok/en/global/cio/documents/infosecppg.pdf and any updates thereto.

10. The Supplier recognizes that it may be necessary for OHCA to require the Supplier to adhere to additional or modified security standards which may be more stringent than the State of Oklahoma Security Standards, in order to maintain compliance with applicable laws, rules, regulations, legal requirements, and industry best practices. In the event OHCA determines additional or modified security standards to be necessary, it will give the Supplier at least sixty (60) Days advance written notice of any changes in requirements, and the Supplier agrees to timely implement and comply with the same.

11. The Supplier must sign OHCA Acceptable Use/Rules of Behavior, Non-Disclosure Agreements, Access Agreements, or other organization/user level security requirements in a timely manner as a condition of maintaining OHCA system and data access.

12. The Supplier shall complete State of Oklahoma Security and Accreditation Assessment(s) located in the Bidder’s Library, based on the proposed system environment, as a part of Proposal submission. If State data is to be stored or hosted by the vendor, the Supplier shall complete and execute OMES Hosting Agreement and meet or exceed the terms therein. To the extent the Supplier requests to use a third-party hosting vendor, that vendor is subject to OHCA’s approval and must satisfactorily complete the State’s Certification and Accreditation Review and any supplemental requests by OHCA. Supplier agrees not to migrate OHCA’s data or otherwise utilize a different third-party hosting vendor in connection with key business functions that are Supplier’s obligations under the Contract until OHCA approves the third-party hosting vendor’s State Certification and Accreditation Review. In the event the third-party hosting vendor is not approved by OHCA, Supplier acknowledges and agrees it may not utilize such third-party vendor in connection with key business functions that are Supplier’s obligations under the Contract, until such third-party meets OHCA requirements.

13. Supplier shall maintain a Security and Privacy Program in accordance with the Contract, associated requirements, and industry best practices at all times.

C.18 DISASTER PREPARATION AND DATA RECOVERY

1. The Supplier shall submit a plan that addresses disaster recovery and business continuity related to emergency situations to OHCA during Readiness and annually for review and approval as specified in the Reporting Manual.

2. The plan shall align with best practices and content identified under the latest revision of NIST SP 800-34 Contingency Planning Guide for Federal Information Systems, Moderate Impact, or better.

3. Each aspect included within the disaster recovery plan must describe both the Supplier and OHCA’s responsibilities. For purposes of this requirement, “disaster” means an occurrence of any kind that adversely affects, in whole or in part, the error-free and continuous operation of the Supplier’s or its Subcontractors’ IS or affects the performance, functionality, efficiency, accessibility, reliability or security of the system.

Disasters may include natural disasters, human error/malfeasance/neglect, computer virus or malfunctioning hardware or electrical supply.

4. The Supplier shall take all steps necessary to fully recover the data or system from the effects of a disaster and to reasonably minimize the recovery period. OHCA and the Supplier will jointly determine when unscheduled system downtime will be elevated to a “disaster” status.

5. The Supplier shall notify OHCA via phone and email to critical OHCA contacts identified for your emergency communications plan within two (2) Hours of discovering a disaster or other significant disruption to continuity of normal business operations. If there is no response from OHCA, the Supplier shall also contact the twenty-four (24) Hour OMES Help Desk to create an appropriate ticket to OHCA of the event. Such notification shall include a detailed explanation of the impact of the disaster, particularly related to mission critical business processes, such as claims processing, eligibility and Enrollment processing, PA management, Provider enrollment and data management, Encounter Data management, and any other processing affecting the Supplier’s capability to interface with OHCA or OHCA’s contractors. If all information required herein is not available within the required time frame for reporting, Supplier shall not delay the initial report, but shall provide as much information as is available at the time and shall continue to update OHCA with additional information at least every four (4) Hours until complete information is provided. OHCA, in its discretion, may require the Supplier to provide a detailed plan for resuming operations.

6. The Supplier shall develop Information system contingency planning in accordance with the requirements of this Section and with 45 C.F.R. § 164.308, which relates to administrative safeguards. Contingency plans shall include data backup plans; disaster recovery plans; and emergency mode of operation plans. Application and Data Criticality analysis and testing and revisions procedures shall also be addressed within the Supplier’s contingency plan documents. The Supplier shall be responsible for executing all activities needed to recover and restore operation of information systems, data, and software at an existing or alternative location under emergency conditions within forty-eight (48) Hours of identification of a business continuity or disaster event, or as mutually agreed upon with OHCA based on details of the event. The Supplier shall protect against hardware, software, and human error. The Supplier shall maintain appropriate checkpoint and restart capabilities and other features necessary to ensure reliability and recovery, including telecommunications reliability, file back-ups and disaster recovery. The Supplier shall maintain full and complete back-up copies of data and software and shall back up on tape or optical disk and store its data in an off-site location approved by OHCA.

7. In the event of a catastrophic or natural disaster, including, but not limited to fire, flood, earthquake, storm, hurricane, war, invasion, act of foreign enemies, or terrorist activities, the Supplier shall resume normal business functions at the earliest possible time, not to exceed thirty (30) Calendar Days from the date of the catastrophic event or natural disaster.

8. The Supplier may include resources outside Oklahoma but within the United States as part of this plan. The plan must satisfy all requirements for State and federal certification.

9. The plan shall be maintained and updated by the Supplier throughout the term of this Contract and shall be available for review by State or Federal officials on request. The Supplier shall certify to OHCA that the disaster recovery plan has been tested at least annually and has passed all aspects of testing.

10. The Supplier shall have a contingency plan specific to operating information systems in a disaster situation.

11. The data system shall be accessible remotely and offsite. The offsite system shall be capable of providing basic system functions in the event of a disaster incapacitating another system site.

12. The Supplier and its Subcontractors’ responsibilities include, but are not limited to:

a. Supporting immediate restoration and recovery of lost or corrupted data or software;

b. Establishing and maintaining, in an electronic format, a weekly back-up and a daily back-up that are adequate and secure for all computer software and operating programs; database tables; files; and system, operations and user documentation;

c. Demonstrating an ability to meet back-up requirements by submitting and maintaining data backup and disaster recovery plans that address:

i. Checkpoint and restart capabilities and procedures;

ii. Retention and storage of back-up files and software;

iii. Hardware back-up for the servers;

iv. Hardware back-up for data entry equipment;

v. Network back-up for telecommunications; and

vi. Developing coordination methods…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .