Attachment No. 1 - Performance Work Statement.pdf

PDF 271 KB Posted

Attached to
IHS Agency-wide Instruction For Use Software Subscription Federal contract opportunity
Solicitation number
75H70426Q00049
Issued by
Department of Health and Human Services Indian Health Service

About this file

This is a Performance Work Statement for subscription services providing Manufacturers' Instructions for Use (IFU) and Safety Data Sheet (SDS) software for Indian Health Service (IHS) federal healthcare facilities.

The Contractor shall provide a commercial off-the-shelf (COTS), web-based IFU and SDS repository system accessible to all IHS facilities, ensuring compliance with Joint Commission, CMS, and other accrediting medical organization requirements. The solution must be delivered as either a fully operational Software-as-a-Service (SaaS) solution accessible 24/7 or software capable of hosting on IHS-acquired Infrastructure as Service (IaaS) secure federal networks. All required sites must have access within 30 calendar days of contract award. The contract period consists of one 12-month base period and four 12-month option periods, plus an up to 6-month services extension.

Core system requirements include: minimum 99% uptime with 72-hour advance notice for scheduled maintenance; real-time access to current, validated manufacturer documentation retrievable within one minute per query, or within 24 hours if unavailable; centralized, searchable repository containing IFUs for medical/surgical/dental instruments, equipment, implantable devices, tissues, biologics, Safety Data Sheets, MSDS archives, preventive maintenance manuals, service documentation, consumables documentation, facility maintenance equipment documentation, and manufacturer notices/recalls/alerts. The system must support search by manufacturer, device name, model number, product type, or keyword; enable document viewing, downloading, printing, and saving; support organization by facility, department, or user-defined categories; and integrate with instrument tracking systems, asset management systems, and computerized maintenance management systems (CMMS). Role-based access controls must support tiered access aligned with IHS organizational hierarchy (Headquarters, Area, Service Unit/Facility levels) with appropriate administrative capabilities at each level. The Contractor shall provide comprehensive training including minimum four onboarding sessions recorded for ongoing use, on-demand training modules, user guides, and helpdesk support with 2-3 business day response times. The system must comply with Section 508 of the Rehabilitation Act and WCAG 2.1 Level AA accessibility standards, FISMA, NIST SP 800-53, FedRAMP certification (Moderate or higher) if applicable, DISA STIG configuration, HIPAA compliance, Privacy Act compliance, and ensure all data remains within the United States. Security incident reporting is required within one hour of discovery, and monthly vulnerability reporting is mandatory. Contractor performance will be evaluated against a Quality Assurance Surveillance Plan (QASP) with acceptable quality levels including 99% system uptime, timely document updates (2-3 business days), technical support response within 2-3 business days, and system usage reporting. Invoicing shall be processed through the Invoice Payment Platform (IPP) at www.ipp.gov.

View the file

Other files for this federal contract opportunity

Other files attached to IHS Agency-wide Instruction For Use Software Subscription, newest first.
File Type Posted
RFQ 75H70426Q00049 001.pdf PDF
Attachment No. 2 – RFO Provisions & Clauses.pdf PDF
RFQ 75H70426Q00049.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment No. 1

Page: 1

Performance Work Statement

Instructions For Use Software Services

Office of Quality

1. General: This is a non-personnel services contract to provide subscription services for Manufacturers’ Instructions for

Use (IFU) Software. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn, is responsible to the Government.

1.1. Background: IHS federal healthcare facilities are required by Joint Commission, Centers for Medicare and Medicaid Services (CMS) and other accrediting medical organizations to establish and maintain a safe and functional environment for everyone who enters the organization’s facilities. Manufacturers’ Instructions for Use

(IFU) and other critical infection control reference documents must be readily available to staff.

1.2. Objectives: The objective of this requirement is to provide a reliable, accessible solution for consistent access to subscription services for manufacturer Instructions for Use and related documentation across all Indian Health

Service (IHS) facilities. The software system shall ensure IFUs are readily available and consistently accessible to support patient safety, infection prevention, and regulatory compliance.

1.3. Scope: The Contractor shall provide a commercial off-the-shelf (COTS), automated, web-based Instructions for

Use (IFU) and Safety Data Sheet (SDS) repository system for use by federal Indian Health Service (IHS) healthcare facilities. The software must provide online access to all required Instructions for Use, service manuals, safety data sheets, and other manufacturer guidelines, and resources for instruments, equipment, and supplies related to dental, medical/surgical and biomedical instruments and equipment, and consumables, tissues and implants, and chemicals that are in use at each IHS federal facility.

1.4. Period of Performance: The period of performance is one twelve-month base period and four twelve-month option periods plus an up to 6-Month services extension per RFO 52.217-8.

1.5. General Information

1.5.1. Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP) identified in Technical Exhibit 1. This plan is focused on how the Government will monitor contract performance and to ensure that the contractor has performed in accordance to the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.5.2. Recognized Holidays: The contractor shall not be responsible for maintaining the helpdesk and other technical support functions during federally recognized holidays, as defined in 5 U.S. Code § 6103. The current holidays are listed below:

New Year's Day (January 1).

Birthday of Martin Luther King, Jr. (Third Monday in January).

Washington's Birthday (Third Monday in February).

Memorial Day (Last Monday in May).

Juneteenth National Independence Day (June 19)

Independence Day (July 4).

Labor Day (First Monday in September).

Columbus Day (Second Monday in October).

Veterans Day (November 11).

Thanksgiving Day (Fourth Thursday in November).

Page: 2

Christmas Day (December 25).

1.5.3. Place of Performance: The work to be performed under this contract will be performed virtually. Any meetings required under the terms of this contract will be held virtually, as determined by the COR.

1.5.4. Post-Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post-award conference convened by the contracting activity or contract administration office. The Contracting Officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the contractor to discuss project updates and review the contractor's performance and if any, appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.

1.5.5. Contracting Officer Representative (COR): The (COR) will be identified by a separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue specifications:

monitor Contractor's performance and notify both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially concerning changes in cost or price, estimates, or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.5.6. Information Security

1.5.6.1. Confidentiality and Nondisclosure of Information. Any information provided to the contractor

(and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only to carry out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary for the performance of the contract. The Contractor assumes responsibility for the protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor.

Each Contractor officer or employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such officer or employee can be used only for that purpose and to the extent authorized herein.

1.5.6.2. Records Management and Retention: The Contractor (and/or any subcontractor) shall maintain all information in accordance with Executive Order 13556 -- Controlled Unclassified Information, National Archives and Records Administration (NARA) records retention policies and schedules, and

HHS/IHS policies and shall not dispose of any records unless authorized by HHS/IHS. In the event that a contractor (and/or any subcontractor) accidentally disposes of or destroys a record without proper authorization, it shall be documented and reported as an incident in accordance with HHS/IHS policies.

1.5.6.3. Contractor Performance Evaluation Report: During the life of this contract, Contractor performance will be evaluated on an interim and final basis pursuant to FAR Subpart 42.15. This evaluation shall become a part of the contract file and shall be used as past performance information in evaluating the Contractor’s, and any significant subcontractors’ or affiliates, past performance on future contracts. Contractor Performance Assessment Report System (CPARS) is an online reporting system (https://www.cpars.gov/cparsweb/home). The Contractor Performance Report is completed by

Page: 3 the Project Officer electronically and sent to the Contractor for review and approval at the end of each performance period as an interim report and at the end of the contract performance as a final report.

After review by the Contracting Officer, the report becomes a permanent record of the Contractor’s past performance.

2. Definitions and Acronyms

2.1. Definitions

2.1.1. Contractor: A supplier or vendor awarded a contract to provide specific supplies or services to the government. The term used in this contract refers to the prime.

2.1.2. Contracting Officer (CO): A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. Note: The only individual who can legally bind the government.

2.1.3. Contracting Officer Representative (COR): An employee of the U.S. Government designated by the CO to monitor contractor performance. Such appointment will be in writing and will state the scope of authority and limitations. This individual has the authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have the authority to change the terms and conditions of the contract.

2.1.4. Defective Service: A service output that does not meet the standard of performance associated with the

PWS.

2.1.5. Deliverable: Anything that can be physically delivered and includes non-manufactured things such as meeting minutes or reports.

2.1.6. Physical Security: Actions that prevent the loss or damage of Government property.

2.1.7. Quality Assurance: The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.

2.1.8. Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.

2.1.9. Quality Control: All necessary measures taken by the Contractor to ensure that the quality of an end product or service shall meet contract requirements.

2.1.10. Subcontractor: One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.

2.2. Acronyms

AAAHC Accreditation Association for Ambulatory Health Care

AAMI Association for the Advancement of Medical

Instrumentation

AQL Acceptable Quality Level

ATO Authority to Operate

CAP Corrective Action Plan

CASB Cloud Access Security Broker

Page: 4

CFR Code of Federal Regulations

CD-ROM Compact Disc Read-Only Memory

CMMS Computerized maintenance management systems

CMS Centers for Medicare and Medicaid Services

CO Contracting Officer

COTS Commercial off-the-shelf

COR Contracting Officer’s Representative

CPARS Contractor Performance Assessment Report System

CVE Common vulnerability exposures

DISA Defense Information System Agency

FAR Federal Acquisition Regulation

FDA Food and Drug Administration

FedRAMP Federal Risk and Authorization Management Program

FIPS Federal Information Processing Standards

FISMA Federal Information Security Modernization Act

HHS Health and Human Services

HIPAA Health Insurance Portability and Accountability Act

HVAC Heating, Ventilation, and Air Conditioning

IFU Instructions for Use

IHS Indian Health Service

IT Information Technology

MCAS Microsoft Cloud App Security

MFA Multi-factor authentication

MSDS Material Safety Data Sheet

NACI National Agency Check and Inquiries

NARA National Archives and Records Administration

NDA Non-Disclosure Agreement

NIST National Institute of Standards and Technology

OCI Organizational Conflict of Interest

OMB Office of Management and Budget

OSHA Occupational Safety and Health Administration

P-ATO Provisional Authority to Operate

PM Preventive Maintenance

PoP Period of Performance

PWS Performance Work Statement

QASP Quality Assurance Surveillance Plan

SaaS Software as a Service

SAML Security Assertion Markup Language

SD Secure Digital

SDS Safety Data Sheet

SSP System Security Plan

STIG Security Technical Implementation Guide

TIC Trusted Internet Connections

TJC The Joint Commission

TOS Terms of Service

US United States

USB Universal Serial Bus

US-CERT United States Computer Emergency Readiness Team

WCAG Web Content Accessibility Guidelines

Page: 5

3. Specific Tasks: The contractor shall provide the following:

3.1. Solution Requirements: The contractor’s proposed solution shall be provided in one of two ways:

3.1.1. The Contractor shall provide a fully operational Software-as-a-Service (SaaS) solution accessible 24 hours per day, 7 days per week, excluding scheduled maintenance periods.

3.1.2. Or, provide the software in a format capable to be hosted within the IHS acquired Infrastructure as Service

(IaaS) secure federal network.

1.1.1. Contractor shall ensure all required sites have access to the subscription no later than the first 30 calendar days after contract award.

1.2. System Requirements:

1.2.1. Availability:

1.2.1.1. The system shall maintain a minimum of 99% uptime.

1.2.1.2. Scheduled maintenance shall be communicated to the COR and CO at least 72 hours in advance.

1.2.1.3. Unscheduled outages shall be reported within 1 hour of discovery, with status updates provided hourly until resolution.

1.2.2. Real-Time Manufacturer Documentation Access

1.2.2.1. The Contractor shall provide users with real-time access to current, validated manufacturer documentation for the following but not limited to dental, medical/surgical and biomedical instruments and equipment, and consumables, tissues and implants, and chemicals, without needing to supply

Contractor with a list of instruments.

1.2.2.2. Documentation shall be retrievable within one (1) minute per query.

1.2.2.2.1. If documentation is not available, the Contractor shall obtain and provide the requested document within 24 hours.

1.2.2.2.2. The Contractor shall have a process to obtain and make available on urgent, rapid turn-around availability of documents for compliance purposes.

1.2.2.3. The system shall ensure access to the most current version of all IFUs, manuals, and SDS documents.

1.2.3. Content Coverage and Database Requirements:

1.2.3.1. The Contractor shall provide a centralized, searchable repository that includes, at a minimum:

1.2.3.1.1. Instructions for Use (IFUs) for medical, surgical, and dental instruments and equipment, IFUs and documentation for implantable and non-implantable devices, tissues, and biologics,

1.2.3.1.2. Safety Data Sheets (SDS) and archived MSDS documents, Page: 6

1.2.3.1.3. Preventive maintenance (PM) manuals, service manuals, and technical documentation for biomedical and non-medical equipment,

1.2.3.1.4. Documentation for consumables, including single-use items and chemical products,

1.2.3.1.5. Facility maintenance equipment documentation (e.g., HVAC, fire safety systems),

1.2.3.1.6. Manufacturer notices, recalls, alerts, and letters of obsolescence,

1.2.3.2. The Contractor shall ensure that all documentation supports compliance with applicable regulatory and accreditation standards.

1.2.4. Search, Retrieval, and Usability:

1.2.4.1. The Contractor shall provide direct access to manufacturer Instructions for Use (IFUs), Safety

Data Sheets (SDS), and related documentation within the system. IHS users must be able to retrieve

IFU results inclusive of a list identifying multiple manufactures and products when querying the software for similar product type, at the time of award and through performance period.

1.2.4.2. The system shall not require users to navigate to external third-party websites to obtain required documentation.

1.2.4.3. The Contractor shall be responsible for obtaining, maintaining, and updating documentation within the system to ensure users have timely and reliable access to current manufacturer information.

1.2.4.4. The Contractor shall provide robust system functionality that enables users to efficiently locate and use documentation.

1.2.4.5. The system shall include search functionality by manufacturer, device name, model number, product type, or keyword.

1.2.4.6. Users shall be able to view, download, print, and save documents.

1.2.4.7. The system shall allow documents to be organized by facility, department, or user-defined categories.

1.2.4.8. The user interface shall be intuitive and require minimal training for effective use.

1.2.5. System Integration and Interoperability:

1.2.5.1. The Contractor shall ensure the system supports interoperability with Government systems and workflows.

1.2.5.2. The system shall support integration with instrument tracking systems, asset management systems, and computerized maintenance management systems (CMMS).

1.2.6. Updates, Alerts, and Notifications:

1.2.6.1. The Contractor shall provide automated notifications to ensure users are aware of critical updates.

Page: 7

1.2.6.1.1. Notifications shall include, at a minimum:

1.2.6.1.1.1. Manufacturer updates to IFUs

1.2.6.1.1.2. Product recalls and safety alerts

1.2.6.1.1.3. Changes to instructions, warnings, or product usage

1.2.6.1.2. Notifications shall be delivered in real time or near real time to designated users.

1.2.6.1.3. The Contractor shall provide regular update reports summarizing database changes.

1.2.7. User Access Control and Security:

1.2.7.1. The Contractor shall provide secure, role-based access controls and user management capabilities.

1.2.7.2. The system shall support a tiered access structure aligned with the Indian Health Service (IHS) organizational hierarchy, including Headquarters, Area (or equivalent), and Service Unit/Facility levels.

1.2.7.2.1. Headquarters users shall have enterprise-wide visibility and access to all documentation across all Areas and Service Units/Facilities.

1.2.7.2.2. Area users shall have access to all documentation within their respective Area, including associated Service Units/Facilities.

1.2.7.2.3. Service Unit/Facility users shall have access limited to their assigned facility or facilities.

1.2.7.3. The system shall include administrative roles with the following capabilities:

1.2.7.3.1. System Administrator (Headquarters-level): Establish and maintain enterprise-wide user roles, permissions, and organizational structure. Headquarters shall retain overarching authority and visibility across all levels, while enabling delegation of user management responsibilities to

Area and Facility Administrators.

1.2.7.3.2. Area Administrator: Manage user accounts and permissions within their assigned Area and associated Service Units/Facilities, in alignment with enterprise-level roles and policies established by Headquarters.

1.2.7.3.3. Facility Administrator: Manage user accounts and organize documentation at the local facility level, within the permissions and structure defined by Area and Headquarters administrators.

1.2.7.4. The system shall enforce appropriate access restrictions to prevent unauthorized access outside assigned levels while allowing higher-level users to maintain oversight.

1.2.7.5. All access shall comply with applicable federal security requirements, including secure authentication and multi-factor authentication (MFA).

1.2.8. Training and User Support

Page: 8

1.2.8.1. The Contractor shall provide comprehensive training and support services to ensure effective system adoption and use across all IHS facilities.

1.2.8.2. The Contractor shall provide comprehensive training and support services.

1.2.8.2.1. Initial onboarding synchronous training sessions shall be provided for all designated user groups

1.2.8.2.2. The Contractor shall coordinate with the Government to develop the onboarding sessions

1.2.8.2.3. A minimum of four (4) onboarding sessions shall be provided

1.2.8.2.4. Training shall address all user groups (e.g. software administrators and users)

1.2.8.2.5. Sessions shall be recorded and made available for use.

1.2.8.2.6. Ongoing training shall include:

1.2.8.2.6.1. On-demand training modules and recorded sessions

1.2.8.2.6.2. User guides, job aids, and reference materials

1.2.8.2.7. Where system changes make portions of the training documents, videos, or tutorials obsolete:

1.2.8.2.7.1. For changes that make the training material less than 30% obsolete, a disclosure and errata notice will be posted in conjunction with the training material to alert users, account holders, and managers before viewing.

1.2.8.2.7.2. For changes that make the training material or tutorial 30% obsolete or more, the content will be revised in its entirety for further use.

1.2.8.3. The Contractor shall provide a helpdesk or equivalent support mechanism for user inquiries and technical assistance, with responses to inquiries within 2-3 business days

1.2.9. Data Management and Ownership

1.2.9.1. The Contractor shall ensure proper handling of Government data.

1.2.9.2. The Government retains ownership of all data entered into the system.

1.2.9.3. The Contractor shall provide data export capabilities in a structured, machine-readable format upon request.

1.2.9.4. Upon contract expiration or termination, the Contractor shall support transition of data to the

Government or a successor system.

1.3. Regulatory and Accreditation Compliance Support

1.3.1. The Contractor shall ensure the system supports compliance with applicable healthcare regulations and standards, including but not limited to:

Page: 9

1.3.1.1. The Joint Commission (TJC)

1.3.1.2. Centers for Medicare & Medicaid Services (CMS)

1.3.1.3. Accreditation Association for Ambulatory Health Care (AAAHC)

1.3.1.4. Association for the Advancement of Medical Instrumentation (AAMI)

1.3.1.5. Occupational Safety and Health Administration (OSHA)

1.3.1.6. Other applicable federal, state, and local medical regulatory authorities

1.3.2. The system shall provide documentation and functionality necessary to support audits, surveys, and compliance reviews.

1.4. Information Technology and Accessibility Requirements

1.4.1. The system will comply with all applicable federal IT security requirements.

1.4.2. The SaaS solution shall comply with Section 508 of the Rehabilitation Act and WCAG 2.1 Level AA accessibility standards. The Contractor shall also comply with applicable federal IT security requirements, including FISMA and NIST SP 800-53.

1.4.3. The solution shall meet FedRAMP certification requirements, per Appendix 1 – FedRAMP Technical

Approach Requirements, if the solution meets Task 3.1.1 requirements and is hosted on a third-party non-federal FedRAMP cloud. If the solution is hosted on an acquired Infrastructure as Service (IaaS) secure federal network server or cloud, per Task 3.1.2, Technical Exhibit 1 is not applicable to this contract.

1.4.4. If applicable, solution must disclose the physical location of processing sites where the Government data is stored.

1.4.5. The solution shall be securely configured using Defense Information System Agency (DISA) Security

Technical Implementation Guide (STIG). All common vulnerability exposures (CVE) must be reported and remediated.

1.4.6. Government data stored within the system must not leave the United States.

1.4.7. The solution must produce security logs which will be made available for monitoring by the appropriate federal personnel as required by federal IT standards.

1.4.8. Report all security incidents to the Government within 1 hour of discovery.

1.4.9. Report all known vulnerabilities within the system to the Government on a monthly basis at a minimum.

2. Contractor Quality Control Plan

2.1. The Contractor shall monitor and report system performance to ensure compliance with contract requirements. The Contractor shall provide quarterly and annual performance reports to the Government that include, at a minimum:

2.1.1. System uptime and availability metrics

2.1.2. Timeliness of document updates and alerts issued

2.1.3. Helpdesk ticket volume and response times

Page: 10

2.1.4. System usage reports to include:

2.1.4.1. number of times users have logged into the system both Agency-Wide and per facility

2.1.4.2. number of searches per type of document e.g. SDS/IFU/Tissue.

2.1.4.3. number of new IFUs added to the system based on Government’s request.

2.2. Where these metrics are not available within the proposed solution, the Contractor shall provide the Government with a Quality Control Plan (QCP) with alternative and comparable metrics.

2.3. The Government will evaluate performance based on established Acceptable Quality Levels (AQLs).

2.4. Failure to meet performance standards may require corrective action in accordance with contract terms.

2.5. Contractor shall submit required annual reports no later than one (1) week after the Period of Performance

(PoP) end date.

2.6. Performance Review and Corrective Action

2.6.1. If the Contractor fails to meet any performance standard, the Government may require the Contractor to submit a Corrective Action Plan (CAP) within five (5) business days. The CAP shall identify root cause, proposed corrective actions, and timeline for resolution.

3. Applicable Publications:

3.1. The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures

3.2. Publications:

3.2.1. FDA Device Label/Labeling Requirements (21 CFR 801): Device Labeling | FDA

3.2.2. FDA Quality System Regulation Labeling Requirements (21 CFR 820): Quality System Regulation

Labeling Requirements | FDA

3.2.3. FDA Reprocessing Medical Devices in Health Care Settings: Validation Methods and Labeling:

Reprocessing Medical Devices in Health Care Settings: Validation Methods and Labeling | FDA

3.2.4. Cornell Law School, Legal Information Institute (21CFR 820.30- Design Controls):

https://www.law.cornell.edu/cfr/text/21/820.30?utm_

3.2.5. CMS CFR 482.42 Condition of participation: Infection prevention and control and antibiotic stewardship programs eCFR :: 42 CFR 482.42 -- Condition of participation: Infection prevention and control and antibiotic stewardship programs.

3.2.6. Centers for Medicare & Medicaid Services. Hospital Infection Control Worksheet. Cite at 42 CFR

482.42(a) (Tag A-0749)

3.2.7. The Joint Commission, Standards FAQs: Manufacturers Instructions for Use - Expectations Regarding

Access To IFUs for Medical Instruments and Devices | Joint Commission

Page: 11

3.2.8. The Joint Commission, Standards FAQs: Manufacturers Instructions for Use - Addressing Conflicts

Amongst IFUs for Different Equipment and Products | Joint Commission Attachment/Technical

Exhibit List:

3.3. Technical Exhibit 1 – Quality Assurance Surveillance Plan

3.4. Appendix 1 – FedRAMP Technical Approach Requirements

Page: 12

Technical Exhibit 1

Quality Assurance Surveillance Plan

Performance

Standard

Acceptable Quality

Level

Surveillance

Methods

Frequency IHS Point of Contact

System Availability

(Uptime)

≥99% system uptime

System-related report

Quarterly IHS Contracting

Officer’s

Representative

System Retrieval

Results

IHS users must be able to retrieve IFU results inclusive of a list identifying multiple manufactures and products when querying the software for similar product type, at the time of award and through performance period.

Random sampling At time of award and Periodic monitoring.

Program Office and

IHS Contracting

Officer’s

Representative

Timeliness of

Document Updates

Updates, corrections, or requested documents provided within 2-3 business days

Review of ticketing system/ request logs

Quarterly IHS Contracting

Officer’s

Representative

Technical Support

Response Time

Responses provided within 2-3 business days

Helpdesk ticket tracking and response logs

Quarterly IHS Contracting

Officer’s

Representative

System

Usage Reports

Updates System-related report

Quarterly and

Annual

IHS Contracting

Officer’s

Representative

Page: 13

Appendix 1

FedRAMP Technical Approach Requirements

The Federal Risk and Authorization Management Program (FedRAMP) is a mandatory government-wide program for Federal Agency cloud deployments. The FedRAMP program provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. The IHS may only use cloud services that have obtained a FedRAMP Moderate or High Impact Authority to Operate

(ATO), also referred to as a FedRAMP-certified cloud service. The Contractor shall provide evidence in its proposal that the proposed solution is FedRAMP Moderate certified or meets the requirements to become

FedRAMP certified within 60 days of the contract period of performance start date, or a determination by the CIO for an exception for an extended timeline to acquire FedRAMP. In addition to requirements specified in the Performance Work Statement, the following technical requirements must be met by offerors who propose a FedRAMP-certified cloud-based technical approach:

1. Ensure that Federal information, other than unrestricted information, being transmitted from

Federal government entities to external entities using cloud services is inspected by Trusted

Internet Connections (TIC) processes.

2. Provide security mechanisms for handling data at rest and in transit in accordance with FIPS 140- 2

Level 2 security requirements.

3. Be a FedRAMP Moderate or higher Certified Cloud Service (or equivalent).

4. Be Health Insurance Portability and Accountability Act (HIPAA) Compliant.

5. Be compliant with The Privacy Act of 1974, which prohibits the disclosure of a record about an individual from a system of records absent the written consent of the individual.

6. Host all data and services within the United States. The vendor shall identify all data centers where the data at rest or data backup will reside. All data centers will be guaranteed to reside within the United States.

7. Provide support personnel (those who have access to IHS data) who are U.S. persons maintaining a

NACI clearance or greater in accordance with OMB memorandum M-05-24, Section C

(http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-24.pdf). The

Contractor shall furnish documentation reflecting favorable adjudication of background investigations for all personnel supporting the system.

8. Be accessible to people with disabilities and be compliant with Web Content Accessibility

Guidelines (WCAG) 2.1 technical standards and the requirements of Section 508 of the

Rehabilitation Act of 1973.

9. Provide labor to complete the System Security Plan (SSP) documentation within 30 days and meet all requirements outlined in the Indian Health Manual Chapter 12 - Information Technology

Security located at https://www.ihs.gov/ihm/pc/part-8/p8c12/ to obtain a Provisional Authority to

Operate (P-ATO) from IHS.

http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-24.pdf) http://www.ihs.gov/ihm/pc/part-8/p8c12/

Page: 14

10. The Contractor shall support a system in accordance with the requirement for Federal agencies to manage their electronic records in accordance with 36 CFR § 1236.20 & 1236.22, including but not limited to capabilities such as those identified in:

• NARA Bulletin 2008-05, July 31, 2008, Guidance concerning the use of e-mail archiving applications to store e-mail,

• NARA Bulletin 2010-05 September 08, 2010, Guidance on Managing Records in

Cloud Computing Environments;

11. Maintain records to retain functionality and integrity throughout the records’ full lifecycle including:

• Maintenance of links between records and metadata, and

• Categorization of records to manage retention and disposal, either through transfer of permanent records to NARA or deletion of temporary records in accordance with

NARA-approved retention schedules;

12. Provide a solution that can be monitored by the IHS Cloud Access Security Broker (CASB) –

Microsoft Cloud App Security (MCAS);

13. The vendor shall support a secure, multi-factor method of remote authentication and authorization to identified Government Administrators that will allow government-designated personnel the ability to perform management duties on the system. The vendor shall support a secure, multi-factor method of remote authentication and authorization to identified Vendor Administrators that will allow vendor-designated personnel the ability to perform management duties on the system.

14. Cloud Service Providers are required to report all computer security incidents to the United States

Computer Emergency Readiness Team (US-CERT) in accordance with US-CERT “Incident

Categories and Reporting Timeframes” in, Appendix J, Table J-1 of NIST SP 800-61 (as amended), Any incident that involves compromised Personally Identifiable Information (PII) must be reported to US-CERT within 1 hour of detection regardless of the incident category reporting timeframe. For further information, NIST published SP800-86 Guide to Integrating

Forensic Techniques into Incident Response. SP800-86 defines in a much more precise and specific way the procedures, issues, and technologies required to move an incident from the point of discovery through to resolution.

15. The vendor shall document activities associated with the transport of Federal agency information stored on digital and non-digital media and employ cryptographic mechanisms to protect the confidentiality and integrity of this information during transport outside of controlled areas.

Digital media, containing Federal agency information, that is transported outside of controlled areas must be encrypted using FIPS 140-2 level 2; non-digital media including but not limited to

CD-ROM, floppy disks, etc., must be secured using the same policies and procedures as paper.

Media, containing Federal agency information that is transported outside of controlled areas must ensure accountability. This can be accomplished through [appropriate actions such as logging and a documented chain of custody form]. Federal agency data that resides on mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards) must be encrypted. All

Federal agency data residing on laptop computing devices must be protected with NIST-approved encryption software.

Page: 15

16. Provide a solution capable of using SAML and OAuth 2.0 protocols for handling authentication to the IHS Active Directory and multi-factor authentication platform. The IHS currently uses Okta for multi-factor authentication.

4. Invoicing /Payment:

Invoicing under this order shall be processed through the Invoice Payment Platform (IPP), located at www.ipp.gov.

IPP is a secure, web-based electronic invoicing system provided by the U.S. Department of the Treasury's

Bureau of the Fiscal Service, in partnership with the Federal Reserve Bank of St. Louis (FRSTL). The Office of

Management and Budget (OMB) M-15-19 Memorandum "Improving Government Efficiency and Saving

Taxpayer Dollars Through Electronic Invoicing" directs Federal agencies to adopt electronic invoicing as the primary means to disburse payment to vendors.

If your organization is not currently utilizing IPP, following award of an order, your organization will be automatically enrolled by IHS. Your company's IPP POC will be determined by the information listed in your

SAM.gov account, and will receive two e-mails from the Bureau of Fiscal Service, one with a username and one with a temporary password. Please ensure your SAM.gov information is up to date.

If you are currently enrolled in IPP, either from a previous award with IHS or another Federal Agency utilizing

IPP- you may use your existing IPP credentials for this order.

If you require assistance registering or IPP account access, please contact the IPP Helpdesk at (866) 973-3131

(M-F 8AM to 6PM ET), or IPPCustomerSupport@fiscal.treasury.gov http://www.ipp.gov/ mailto:IPPCustomerSupport@fiscal.treasury.gov

File details come from the government source that posted it. Updated .