ATTACHMENT G - Security Requirements for Vendor Cloud Hosted Systems V1.3.6 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf

PDF 185 KB Posted

Attached to
Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
Solicitation number
RFP-758-2500000171-6
Issued by
Kentucky

About this file

This document is Attachment G from the Kentucky Cabinet for Health and Family Services (CHFS), specifically outlining detailed security requirements for vendor and cloud-hosted systems for the Kentucky Analytics Platform Solution (KAPS) Request for Proposal (RFP 758 2500000171). The documentation establishes comprehensive security protocols that vendors must follow when providing cloud-hosted systems or solutions to the Commonwealth of Kentucky, with a particular focus on protecting sensitive information such as electronic Protected Health Information (ePHI), Personally Identifiable Information (PII), and Federal Tax Information (FTI).

The security requirements mandate strict compliance with multiple federal and state regulations, including HIPAA, NIST Special Publication 800-53, and IRS Publication 1075. Vendors must implement robust security controls, conduct regular risk assessments, perform continuous security monitoring, and maintain detailed documentation of their security practices. The document outlines specific requirements such as multi-factor authentication, encryption of data in transit and at rest, background checks for personnel with privileged system access, and mandatory reporting of potential security incidents. Significant financial penalties are outlined for non-compliance, with the Commonwealth potentially reducing compensation up to $30,000 per security requirement violation, emphasizing the critical nature of these security standards.

View the file

Other files for this state and local contract opportunity

Other files attached to Kentucky Analytics Platform Solution (KAPS), newest first.
File Type Posted
ATTACHMENT J Minimum Contract Deliverables - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT U IAS Dashboard Examples Redacted - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT H - Solution Matrix- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT L - Penalties - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT D - Vendors' Question Form -RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT K- Proposed 1st Quarter Performance Report Card - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT M - Acronyms - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT S - MITA SSA 2022 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT A - Terms and Conditions - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT B - Cost Proposal Form - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT C - Annual Affidavit and Other Affidavits -RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT E-Personal Information Security & Breach Investigation Act-HB5- RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT F - Mandatory Requirements Checklist RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT N - CHFS TsCs_Version 110623 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT O CHFS-219V Form Version 2.7 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT P - Business Associate Agreement, Version 070623 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT Q - QHI White Paper, Version 3.0.4 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf PDF
ATTACHMENT T - Sources of Data - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
ATTACHMENT V - IAS Dashboards and Reports - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).xlsx XLSX spreadsheet
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment G Security Requirements for Vendor/Cloud-Hosted Systems

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

The Solution Provider/Vendor shall ensure compliance with all laws, regulations, and rules. Compliance is required for all applicable Cabinet for Health and Family Services (CHFS) IT Policies, Commonwealth Office of Technology (COT) Enterprise Policies, Internal Revenue Service (IRS) Publication 1075 requirements, and Social Security Administration guidelines and regulations.

The Solution Provider/Vendors shall implement security controls that comply with National Institute of Standards and Technology (NIST) special publication 800-53, rev 4, or later, which provides guidance for moderate baseline controls. The solution shall comply with all relevant Kentucky and local security and privacy regulations, and federal security and privacy standards adopted by the U.S. Department of Health and Human Services (HHS) for Medicaid Systems. The Solution Provider/Vendor shall be required to cooperate with any third-party Vendor that the Commonwealth engages to conduct a Certification and Accreditation audit of the system controls prior to go-live, in accordance with Enterprise Policies and CHFS Policies.

The requested solutions shall be built based upon leading best practices for secure application development, and shall protect the privacy and disclosure of sensitive, protected health information and personally identifiable information in accordance with Health Insurance Portability and Accountability Act (HIPAA) Security and Privacy Rules.

When a covered entity engages the services of a Solution Provider/Vendor/Cloud Service Provider (CSP) to create, receive, maintain, or transmit (electronic Protected Health Information (ePHI) (such as to process and/or store ePHI) on its behalf, the CSP is a business associate under HIPAA. Further, when business associate subcontracts with a CSP to create, receive, maintain, or transmit ePHI on its behalf, the CSP subcontractor itself is a business associate. This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data. Lacking an encryption key does not exempt a CSP from business associate status and obligations under the HIPAA Rules. As a result, the covered entity (or business associate) and the CSP shall enter into a HIPAA-compliant business associate agreement (BAA), and the CSP is both contractually liable for meeting the terms of the BAA and directly liable for compliance with the applicable requirements of the HIPAA Rules.

Vendor/Solution Provider/CSP responsibilities shall include, but not be limited to, the following:

1. Implementing a risk-based approach to integrating Security, Identity, and Access management into COT and/or Cabinet-specific initiatives, integration with the Kentucky Online Gateway (KOG) is required for Single Sign-On (SSO) (Active Directory Federation Services (ADFS) or Security Assertion Mark-Up Language (SAML) 2.0), user provisioning, and role-based authentication. The primary Identity store for all Commonwealth of Kentucky staff and Citizens shall only be the Commonwealth’s onsite Active Directory. Please review Attachment R KOG Integration for additional requirements.

RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS) https://technology.ky.gov/policies-and-procedures/Pages/policies.aspx https://www.chfs.ky.gov/agencies/os/oats/Pages/ITpolicies.aspx

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

2. Implementing a role-based, least-privileged approach to controlling access to the business-critical, confidential, protected, private, or otherwise sensitive data.

3. Developing and maintaining documents and artifacts required for state and federal compliance requirements, system security audits, security controls assessment, and distributed testing activities.

4. Documenting procedures for background checks on privileged access to servers, applications, or customer data. Vendor/Solution Provider Staff Background checks for privileged access shall include state and federal database criminal checks.

5. All users with privileged access such as full system and/or administrator level access shall use Commonwealth approved multi-factor authentication methods provided by the vendor.

6. All software and hardware components used to deliver this solution shall be supported by the original equipment manufacturer (OEM) of that particular software or hardware and all other technologies used shall be uncompromised/secure and current versions (example: Transport Layer Security [TLS] 1.2 or higher). The solution/application shall meet Commonwealth of Kentucky Information Technology Standards (such as Browsers, software installed on state computers, etc.).

7. The Vendor/Solution Provider staff shall include well-qualified security experts such as certified security architects, certified penetration testers, compliance resources, incident response resources, and audit personnel on this project throughout the life of the contract and available to Commonwealth of Kentucky security staff at all times.

8. If the proposed solution involves the storage, transmission, or processing of

Personally Identifiable Information (PII), Protected Health Information (PHI), or Federal Tax Information (FTI) of KY Citizens that is associated with the Affordable Care Act (ACA), the Vendor shall include a draft Minimum Accepted Risk Standards for Exchanges (MARS-E) 2.0 or higher System Security Plan (SSP) with complete Control Implementation Descriptions. (Just a template with no implementation descriptions is not acceptable.)

9. Vendor/Solution Provider shall provide a copy of the unaltered and unfiltered vulnerability and penetration test reports to CHFS Information Security as soon as the security assessments are completed. The Vendor/Solution Provider shall conduct the security assessments (i.e., vulnerability scans and penetration tests) regularly. The complete environment (i.e., Network, Storage, Server/Operating System (OS), Database, and Application vulnerability scans) shall occur at least once a month or sooner.

10. Vendor/Solution Provider shall provide a copy of the Statement on Standards for

Attestation (SSAE) 18 or higher SOC2 type 2 report to CHFS Information Security

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023 at least on annual basis unless the hosting vendor holds current FedRAMP certification.

11. Access to all sensitive information (such as Personally Identifiable Information (PII), Protected Health Information (PHI), etc.) shall be restricted to those vetted through a background check, and may be restricted to U.S. citizen support personnel only based on data type, which will be determined during contract award.

12. All data, including backups and archives, shall be located within the contiguous United States at all times. All sensitive data, as defined by Kentucky Information Technology Standards (KITS), shall be encrypted in-transit and at rest (i.e., on a file system, sever, database, backups, archives, Storage Area Network (SAN), Network Attached Storage (NAS), File Transfer Protocol (FTP, Removable media, etc.) at all times.

13. Vendor/Solution Provider shall provide to CHFS Information Security a copy of the

Implementation plan and Detailed System Architecture (aka. Service Maps, Hardware Architecture, Application and Network Maps), which includes each Infrastructure component such as Servers, Storage, Appliances, Firewalls, IDS/IPS systems, etc., with associated software details as part of the initial deliverables well before the go-live date.

14. Disaster Recovery and Business Continuity testing of the entire system performed at a frequency that is acceptable to Commonwealth of Kentucky, but no later than annually.

15. All databases in new solutions containing sensitive data, such as PII and PHI, shall be monitored continuously for any breaches. The Vendor/Solution Provider shall set up alerts based on triggers that fire when a predetermined threshold on metrics is reached, including, but not limited to, total number of sensitive records read by any user, session origin IP, day and time of the day, program reading the data, etc. The solution shall allow custom thresholds for different user roles for all authorized users. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.

16. The solution shall enable not only unsuccessful logins, but also successful logins based on predefined criteria acceptable to Commonwealth of Kentucky. The criteria shall include, but not be limited to total number of sensitive records read by any user, session origin Internet Protocol (IP), day and time of the day, program reading the data, etc. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.

17. The solution shall employ end-to-end application availability and accessibility of the entire system using synthetic transactions, and monitor from an external independent location to guarantee the uptime. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

18. All system components, including modules and sub-components delivered by Vendor/Solution Provider and/or sub-vendors, are subject to the Commonwealth and/or independent security review.

19. The Vendor/Solution Provider shall meet all mandatory security controls listed in

Section 4 of this RFP unless Commonwealth grants an exception.

20. Data Commingling

Commingled data at vendor-hosted or multi-tenant facilities results in security risks that shall be addressed. If the solution includes shared physical or computer facilities with other agencies, departments, or individuals not authorized to have PII, PHI, FTI, or SSA data, strict controls – physical and systemic – shall be maintained to prevent unauthorized disclosure of this information.

All computer equipment cabinets shall be locked in a vendor-hosted or multi-tenant environments, and all access to the cabinet shall be documented.

All access logs and signed visitor logs shall be retained for at least five (5) years in an easily accessible format. Reports of all failed logins shall be followed-up, verified, and documented by the vendor, and reported to CHFS Information Security on daily basis.

The Commonwealth of Kentucky shall report all potential breaches to appropriate federal entities within one (1) hour of discovery; for that reason, solution provider shall notify the Commonwealth within about thirty (30) minutes of discovery of any potential breach. Vendor/Solution Provider shall notify their CHFS point of contact and CHFS Information Security of all Security incidents as noted above.

21. Solution Response Time Response time shall be less than or equal to five (5) seconds for online transactions. The vendor shall continuously monitor the entire solution response time and report all SLA failures to authorized Commonwealth staff.

Exceptions to some of the above requirements may be granted in writing to the solution provided by authorized Commonwealth of Kentucky executives if the hosting facility maintains top-level FedRAMP certification at all times.

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

22. Independent Security Review

The Vendor shall perform an infrastructure (i.e., Network, Storage, Server/OS, Database, and Application) security assessments (i.e., vulnerability scans and penetration tests) shall be conducted by the Vendor/Solution Provider prior to implementation(s) and annually with an independent security assessment company that is agreed upon by the Commonwealth. The infrastructure vulnerability assessment shall follow NIST 800-115 guidelines. The Cabinet shall have an unfiltered copy of the application vulnerability assessment as generated by the tools within five (5) working days of its execution. The Solution Provider/Vendor shall provide a remediation plan of action and milestones (POA&M) that meets risk assignment and is in agreement with the Commonwealth.

The Solution Provide/Vendor shall cooperate with any Third-Party Vendor (TPV) that the Commonwealth engages to complete a Certification and Accreditation of the system controls prior to go-live, in accordance with CHFS standards and policies for Certification and Accreditation. Reviews shall be included in the Integrated Work Plan.

All system components, including modules and sub-modules, delivered by the vendor and/or sub-vendors are subject to the independent review.

The Solution Provide/Vendor shall meet the following requirements at a minimum:

1. Maintain an Inventory of Information Systems

The vendor shall have in place an inventory of information systems operated by or under the control of the vendor on behalf of the Commonwealth of Kentucky. The inventory shall include an identification of the interfaces between each system and all other systems or networks, including those not operated by or under the control of the Vendor and/or Commonwealth.

2. Categorize Information and Information Systems According to Risk Level

All information and information systems shall be categorized based on the objectives of providing appropriate levels of information security according to a range of risk levels defined by Federal Information Processing Standard (FIPS) 199 “Standards for Security Categorization of Federal Information and Information Systems.” The guidelines are provided by NIST SP 800-60 “Guide for Mapping Types of Information and Information Systems to Security Categories.”

3. Maintain System Security Plan

Vendor shall develop and maintain a system security plan (SSP) preferably in MARS-E 2.0 or higher template form, which is a living document that requires periodic review, modification, POA&M for implementing security controls. The system security plan is the major input to the security certification and accreditation process for the system.

4. Utilize Security Controls

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

Vendor-provided information systems shall meet the minimum-security requirements defined in FIPS 200 “Minimum Security Requirements for Federal Information and Information Systems.” Vendor shall meet minimum-security requirements by selecting the appropriate security controls and assurance requirements as described in NIST Special Publication 800-53, “Recommended Security Controls for Federal Information Systems.” The controls selected or planned shall be documented in the System Security Plan

5. Conduct Risk Assessments

Vendor shall conduct risk assessments to validate its security controls and to determine any additional controls needed to protect the Commonwealth of Kentucky operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, or the United States. The resulting set of security controls establishes a level of “security due diligence” for the Commonwealth of Kentucky.

6. Certification and Accreditation

Once the system documentation and risk assessment have been completed, the system’s controls shall be reviewed and certified to function appropriately. Based on the results of the review, the information system is accredited. The certification and accreditation process defined in NIST SP 800-37 “Guide for the Security Certification and Accreditation of Federal Information Systems.”

7. Conduct Continuous Monitoring

All accredited systems are required to monitor a selected set of security controls and the system documentation shall be updated to reflect changes and modifications to the system. Continuous monitoring activities include configuration management and control of information system components, security impact analyses of changes to the system, ongoing assessment of security controls, and status reporting.

8. Penalties The Vendor shall create and maintain security controls and services listed under the security requirements section at all times. Failure to deliver the security controls and services, including services as listed under section security requirements, but not limited to, will result in a penalty of $5,000 per occurrence as a result of the Solution provider/Vendor, their tools, or technology.

The Commonwealth shall reduce compensation up to thirty thousand dollars ($30,000.00) per event in which the Solution Provide/Vendor’s solution fails to meet a security requirement, control, or service. The Commonwealth may also pursue consequential or liquidated damages.

KAPS RFP

Kentucky Cabinet for Health and Family Services Version: 1.3.6

Office of Application Technology Services Updated: July 06, 2023

Acronyms

ADFS Active Directory Federation Services

BAA Business Associate Agreement

CHFS Cabinet for Health and Family Services

COT Commonwealth Office of Technology

CSP Cloud Service Provider ePHI electronic Protected Health Information

HHS Department of Health and Human Services

HIPAA Health Insurance Portability and Accountability Act

IP Internet Protocol

IRS Internal Revenue Service

KITS Kentucky Information Technology Standards

KOG Kentucky Online Gateway

MARS-E Minimum Accepted Risk Standards for Exchanges

NAS Network Attached Storage

NIST National Institute of Standards and Technology

OEM Original Equipment Manufacturer

OS Operating System

PHI Protected Health Information

PII Personally Identifiable Information

SAML Security Assertion Mark-Up Language

SAN Storage Area Network

SSAE Statement on Standards for Attestation

SSO Single Sign-On

SSP System Security Plan

TLS Transport Layer Security

File details come from the government source that posted it. Updated .