Attch 2_PWS 5 Aug 21.pdf
PDF 219 KB Posted
- Attached to
- Biomedical Equipment Technician (BMET) Services Federal contract opportunity
- Solicitation number
- FA561321R0009
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| COMBO BMET.pdf | ||
| Attch 4_PPQ BMET.pdf | ||
| Attch 1_Pricing Schedule.pdf | ||
| Attch 3_Applicable Clauses and Provisions BMET.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA5613-21-R-0009
PERFORMANCE WORK STATEMENT
FOR
BIOMEDICAL EQIPMENT TECHNICIAN (BMET)
AT THE 86TH MEDICAL GROUP
5 August 2021
Table of Contents
SECTION Page Number
1.0. DESCRIPTION OF SERVICES 3
2.0. SPECIFIC REQUIREMENTS 3
3.0. SERVICES SUMMARY 5
4.0. GENERAL INFORMATION 6
5.0. APPENDICES 12
5.1. APPLICABLE PUBLICATIONS AND FORMS 12
5.2. SERVICE CONTRACT REPORTING 13
5.3. BUSINESS ASSOCIATE AGREEMENT (BAA) 14
6.0. ESTIMATED WORKLOAD DATA 22
PERFORMANCE WORK STATEMENT
1.0. DESCRIPTION OF SERVICES/GENERAL INFORMATION:
1.1. DESCRIPTION OF SERVICES. The purpose of this requirement is to provide non-personal services as Biomedical Equipment Technician (BMET) in support of the 86th Medical Group (86 MDG). The Contractor shall provide all management, supervision, training, and qualified personnel for biomedical equipment support services at the 86th Medical Group’s Medical Logistics Flight. Performance shall be according to the requirements contained in this Performance Work Statement (PWS), and professional standards of The Joint Commission (TJC), Unit Effectiveness Inspection (UEI), Health Insurance Portability & Accountability Act (HIPAA) and all applicable Department of Defense (DoD) military directives including Defense Health Agency (DHA), Air Force or Air Force Medical Readiness Agency (AFMRA) publications.
They may be amended or new ones may be published after contract start date. Tasks shall be performed accordingly.
1.2. Requested services are considered to be non-mission essential in accordance with (IAW) DODI 1100.22.
2.0. SPECIFIC REQUIREMENTS.
2.1. BIOMEDICAL EQUIPMENT TECHNICIAN. The duties include but are not limited to the following:
2.1.1 Perform scheduled and unscheduled services to include visual and electrical safety inspections, preventative maintenance, scheduled parts replacement, calibrations, repairs, acceptance, disposition and hazard, alert and recall procedures, test and calibrate components using manufacturer's manuals and troubleshooting techniques, test equipment, hand tools, power tools and measuring devices.
2.1.2 Keep records of maintenance, repair, and required updates of equipment.
2.1.3 Inspect and test malfunctioning medical and related equipment following manufacturers' specifications, using test and analysis instruments.
2.1.4 Disassemble malfunctioning equipment and remove, repair and replace defective parts such as motors, transformers, and circuit boards.
2.1.5 Perform preventive maintenance or service such as cleaning, lubricating and adjusting equipment in accordance with OEM specifications.
2.1.6 Test, evaluate, and classify excess or in-use medical equipment and determine serviceability, condition, and disposition in accordance with Air Force Instructions.
2.1.7 Examine medical equipment and facility's structural environment and check for proper use of equipment, to protect patients and staff from electrical or mechanical hazards. Ensures compliance with safety regulations and policies.
2.1.8 Study technical manuals and attend training sessions provided by equipment manufacturers or trained active duty BMETs as applicable to assigned duties.
2.1.9 Provide training to medical staff by explaining and demonstrating correct operation and operator preventive maintenance of medical equipment per the manufacturer’s recommendations.
2.2. EDUCATION AND TRAINING OF BIOMEDICAL EQUIPMENT TECHNICIAN. Contractor personnel shall meet the following minimum qualifications:
2.2.1 Have an associate degree in biomedical equipment technology or engineering or have 3 years of biomedical equipment technician experience.
2.2.2 Language Requirement. Have the ability to read, speak and write English. English shall be spoken with sufficient structural accuracy and vocabulary pronunciation effective in most formal and informal conversations on practical and professional topics.
2.2.2.1 The contractor shall provide personnel who meet the language proficiency level at the beginning of their performance under this contract. Demonstrations of ability to meet personnel language requirements may be requested and may be by any method determined reasonable by the Contracting Officer (CO). Contractor employees who fail to demonstrate the required proficiency may request one repeat demonstration of language capability within 30 calendar days. Failure to satisfy language proficiency requirements a second time shall require the Contractor to replace the employee within ten duty days after the second failure. The required minimum English language proficiency levels are as outlined in NATO Bureau for International Language Coordination (BILC) Standardization Agreement (STANAG) 6001 Edition 5 from February 2019.
ENGLISH
READ SPEAK WRITE
4 4 4
2.2.3 Knowledge of and skills in applying a wide range of specialized methods, principles, and techniques of electronics and complex medical system failures, recovery of systems, adjusting, modifying, and improving systems to include hardware and software components.
2.2.4 Knowledge of a wide range of electronic principles and practices, operating parameters, capabilities, and limitations of electronic systems associated with complex medical systems/equipment;
and of systems and component design, capabilities, configurations, limitations, and functional operation;
and of various types of electronic logic.
2.2.5 Knowledge of The Joint Commission, College of American Pathologists (CAP), Occupational Safety and Health Administration (OSHA), National Fire Prevention Association (NFPA), National Electrical Code (NEC), U.S. Food and Drug Administration (USFDA) and other DoD regulations, instructions or technical orders.
2.2.6 Skill in the interpretation of technical data such as drawings, schematics, blueprints, and specifications of complete electronic systems; in analyzing problems in integrated/interfacing systems involving numerous complex circuits; and in using complex electronic and electromechanical test and measuring equipment using integrated test functions for different purposes.
2.2.7 Ability to maintain, repair, and test biomedical equipment in accordance with strict manufacturer technical compliance. Ability to solve technical and performance problems for highly complex electronic systems. Ability to trace electronics logic from one system to another.
2.2.8 Ability to use standard computers and software to enter and extract data to maintain records and document actions.
2.2.9 Work Environment/Physical Requirements. Work will be accomplished in various departments of the medical treatment facility or logical extension of the facility (i.e., satellite clinic, health and wellness centers). Work areas may include isolated wards and in contaminated areas where personal protected equipment is required. Occasionally work on live electrical wires, switches and transformers of various voltage levels, exposing the worker to the possibility of shock, cuts, bruises, scrapes and serious burns.
Exposure to ionizing and non-ionizing radiation is possible, the contractor shall use appropriate safety procedures and devices as required by the Government.
2.2.10 Physical Requirements. The nature of the work requires moderate physical effort. The biomedical equipment technician frequently is required to lift, carry or otherwise, handle, items weighing up to 18 kilograms (40 pounds) with occasional encounters involving items greater than 18 kilograms. Frequent standing, walking, bending, crouching, reaching, stooping and working in cramped and awkward positions for prolonged periods is required. Carts, pallet jacks, elevators, lifts and forklifts will be used to transport heavy items that would otherwise cause injury to contractor personnel. In addition to health requirements in the contract, the individual must pass a color vision test.
3.0. SERVICES SUMMARY.
Biomedical Equipment Technician:
SS#
Performance Objective
PWS
Para
Performance Threshold
Method of Assessment
Documents work performed, parts used and attaches applicable service reports for assigned work orders
2.1.2
100% of completed monthly work orders are documented in the electronic system of record and accompanying required documentation filed per applicable regulations, instructions and technical orders.
Random Sampling per the established Work Order Quality Control Program instruction listed in Technical Order 13C7-34-2-1, Operations and Manual – Operational Medical Logistics
Performs medical equipment services in accordance with OEM and any applicable DoD, DHA or Air Force directives
2.1.5 0 Deficiencies
Monthly Inspection
3.1. Quality Control:
3.1.1. The Contractor shall have a planned and systematic quality control process for monitoring, analyzing and improving their contract performance.
3.1.2. The Contractor shall ensure that all contractor employees comply with the Military Treatment Facility (MTF) quality management/process improvement activities.
3.1.3. The Contractor shall implement a method of identifying deficiencies in the quality of service before the level of performance deteriorates to an unacceptable level. This method must also measure compliance with regulations referenced in the contract. Reviews shall be accomplished and recorded. Review results shall be made available to the 86 MDG Service Contract Manager (SCM) upon request by the Government.
3.1.4. Inspection: The inspection for all services rendered under this contract will be performed by the Functional Requirements Evaluator Designee (FRED). The performance by Contractor personnel, the quality of services rendered, and any documentation or written material in support of the same, shall be subject to continuous inspection, surveillance and review for acceptance by the CO, SCM and/or FRED. Quality assurance procedures established by the MTF will be used for continuous monitoring. Deficiencies will be documented on a Customer Complaint Form and sent to the CO.
4.0. GENERAL INFORMATION:
4.1. PERSONNEL:
4.1.1. The Contractor shall designate to the CO, in writing, a primary point-of-contact for contract implementation, coordination and administration not later than ten business days after receiving notice of contract award. The Contractor shall notify the CO of changes in the primary point-of-contact at least five duty days prior to any change. All notifications shall be in writing and shall state the name and contact information for the point-of-contact. The Contractor Representative may reside/be located outside of Germany (i.e. in the United States), but shall be available by telephone or email from 0700 to 1600 Monday through Friday excluding holidays Central European Time.
4.1.2. Contract personnel shall present a neat appearance commensurate with that required of a professional.
4.1.3. Neither uniformed personnel nor U.S. Government civilian employees shall be employed to perform services under this contract.
4.1.4. The Services provided under this contract are not approvable under NATO SOFA status accreditation Article 72 or 73. Therefore, services are subject to German labor and tax laws.
4.2. REGULATIONS. The Contractor shall abide by all MTF standards, rules, and procedures including requirements for any licensure, credentialing, and quality assurance requirements. Such regulations include, but are not limited to, general safety, fire prevention, waste disposal, infection control, TJC, UEI, HIPAA, and patient safety initiatives.
4.3. REMOVAL OF CONTRACTOR PERSONNEL. At any time during the performance of this contract, the CO may direct the Contractor to immediately remove any Contractor personnel whose actions or impaired state raises reasonable suspicion that clear and present danger of physical harm exists to a patient, other
Contractor personnel, and government personnel or to the impaired individual. This provision will be used in emergency situations only and not for the purpose of bringing performance issues or other non-urgent concerns to the attention of the Contractor. If the need for a removal occurs, the COR will contact the Contractor's point-of-contact and direct the Contractor to remove that individual from the MTF and to not use that individual to perform any services required under this contract until the issue has been resolved by the CO. A review of the basis for removal will be made by the CO within three business days after removal. If, after any investigation deemed necessary by the CO and discussions with the Contractor's representative, the CO concludes that the Contractor personnel’s impairment requires permanent removal from performance under the contract, the CO will notify the Contractor that permanent removal is required. In the event of disagreements between the Government and the Contractor's representative concerning matters of the impaired Contractor personnel, the decision of the CO will be final. During the period of time between the removal and the final decision of the CO, the Contractor shall provide back-up/replacement Contractor personnel IAW the terms and conditions of this contract.
4.4. CONFIDENTIALITY OF INFORMATION. Unless otherwise specified under this contract, all financial, statistical, personnel, and/or technical data which is furnished, produced or otherwise available to the Contractor during the performance of this contract are considered confidential business information and shall not be used for purposes other than performance of work under this contract. The Contractor shall not release any of the above information without prior written consent of the CO.
4.5. MEDIA AND OTHER INQUIRIES. The Contractor or Contractor personnel shall not respond to any media inquiries. Any inquiries from the media, third parties, or public agencies shall be immediately relayed to the SCM, who will relay them to the MTF Public Affairs Officer or, after duty hours, to the Administrative Officer of the Day. There shall be no interviews, comments, or any other response without the prior knowledge and approval of the MTF Commander. Other than routine inquiries from external agencies, all other inquiries and complaints shall be brought to the attention of the SCM.
4.6. All contractor employees shall give the highest regard to patient dignity and observe the precepts of the American Hospital Association’s “Bill of Rights for Contractor patients.” Performance shall be in accordance with the standards contained in this PWS and the terms and conditions of the contract. The contractor employees shall abide by MTF rules, regulations, and bylaws, including Medical Staff Bylaws and applicable Air Force regulations and Health Insurance Portability & Accountability Act (HIPAA) governing such things as medical records, etc. (See para 5.0).
4.7. OVERSEAS REQUIREMENTS (if applicable). The Contractor is responsible for ensuring all country clearances, passports, visas, and accreditations required by the Host Nation are obtained prior to employment of individuals under this contract. The Contractor shall be responsible for obtaining the appropriate country specific requirements, and shall coordinate this with the CO and/or SCM. All Contractor personnel shall have been, cleared, granted visas, work permits etc. The Contractor shall provide written notification to the CO and the SCM within 24 hours of becoming aware of Contract or personnel no longer performing duties requiring clearances/permissions. The Contractor shall recognize that Host Nation authorities may conduct on-site inspections at any time in the Contractor personnel’s work area for the purpose of verifying the status of positions and Contractor personnel and appropriate visas or permissions. The Contractor shall assume all costs related to submission of required documentation.
The contractor shall comply with all business registration requirements in Germany.
4.8. CONTRACTOR PERSONNEL HEALTH REQUIREMENTS. Contractor personnel shall be up to date on immunizations required or recommended by the U.S. Department of Health and Human Services for travel to the Host Nation. The U.S. Government will not reimburse the Contractor for this expense.
Contractor personnel providing services under this contract shall receive a pre-employment physical examination prior to commencement of work and annually thereafter. No later than seven (7) working days prior to commencement of work, certification shall be provided to the SCM that Contractor personnel have completed medical evaluation required above. This certification shall state the date on which the examination was completed, the doctor’s name that performed the examination, and a statement concerning the physical health of the individual. The certification shall also contain the following statement: “(name of contractor employee) is suffering from no contagious diseases to include but not limited to Tuberculosis and Hepatitis.”
Per Occupational Safety and Health Administration (OSHA) requirements, all Contractor personnel who will have occupational exposure to blood or body fluids, or other potentially infectious materials, shall receive Hepatitis B vaccine, sign a voluntary declination, or have documented proof of immunity to Hepatitis B infection. Personnel who sign declinations may change their minds at any time and receive the Hepatitis B vaccine without penalty. It is the Contractor’s responsibility to report all information necessary to assure hospital records can be maintained correctly, and therefore comply with the OSHA and CDC health records requirement.
4.9. ADMINISTRATIVE CHECKS AND REQUIREMENTS:
4.9.1. Tier 1 (T1) Background Investigation. Since personnel under this contract will have access to Non- Sensitive government information and/or process information requiring protection under the Privacy Act of 1974, these positions are considered Low Risk Positions. Compliance with DoD Manual 5200.2, AFMAN 16-1405 and Homeland Security Presidential Directive 12 (HSPD-12) is mandatory for these positions (See 5.1.–Applicable Forms and Publications). A Tier 1 (T1) background investigation is required for all personnel under this contract. The Contractor shall fully adhere with the provisions of referenced publications by having each of their employees, who are performing under this contract, initiate and complete a T1. T1 investigation requests for employee will be submitted through the Suitability/Fitness Security Office, Ramstein AB, Germany. Member will be fingerprinted and required to complete the appropriate forms (Standard Form 85, Questionnaire for Non-sensitive Positions, any state release forms, and OF 306 Declaration for Federal Employment. For local hire personnel, a Security Questionnaire for a Simple Security Check (AE Reg 604-1) shall be completed. (See 5.1.–Applicable Forms and Publications).
The contractor shall advise employee that a favorable suitability/fitness determination is required as a condition of employment under this specific contract. The employee shall apply for the T1 prior to start of performance. The government is solely responsible for the cost associated with the initiation, application and completion of the T1 investigation with exceptions for expenses incurred for Police Checks for “local hire” personnel.
4.9.2. PENDING COMPLETION OF T1. The Contractor personnel may provide contract services prior to completion of background investigation. The Contractor understands that the MTF Commander may allow the Contractor personnel to temporarily occupy non-sensitive positions pending T1. The Contractor personnel will be immediately removed from the position if at any time the T1 receives unfavorable adjudication, or if other unfavorable information that would affect the T1 becomes known. Pending completion of State Criminal History Records Check (SCHRC) the Air Force Surgeon General requires close clinical supervision and full compliance with existing DoD Directives, Instructions, and other guidance on quality assurance, risk management, licensure, personnel orientation and certification verification. The MTF Commander will determine what constitutes “close clinical supervision” for individuals whose T1/SCHRC are pending, either supervised practice ensuring protection of patients under the age of 18 or line-of-sight supervision (i.e., chaperoned by an individual whose background investigation has been successfully completed) at all times when caring for these patients.
4.9.3. The Contractor shall fully adhere with the provisions of referenced publications by having each of their employees, who are performing under this contract, initiate and complete a T1. T1 investigation requests for employee will be submitted through the Suitability/Fitness Security Office, Ramstein AB, Germany.
4.10. PLACE AND HOURS OF OPERATION. Services are to be performed at the 86th Medical Group, Ramstein Air Base, Germany during the following hours: 0700-1630 hours (to include a 1 hour lunch break daily): Monday through Friday, including German holidays, but excluding U.S. Federal holidays. Workdays will generally consist of eight hour days. Hours are subject to change as mutually agreed between the FRED and the Contractor, however, the total number of hours will not exceed 80 hours every two weeks.
4.11. HOLIDAYS. The following is a list of legal federal holidays. Any federal holiday falling on a Saturday will be observed on the preceding Friday, holidays falling on a Sunday will be observed the following Monday.
U.S. Holidays:
January 1 New Year’s Day 3rd Monday in January Martin Luther King, Jr. Day 3rd Monday in February Washington’s Birthday Last Monday in May Memorial Day June 19 Juneteenth July 4 Independence Day 1st Monday in September Labor Day 2nd Monday in October Columbus Day November 11 Veterans Day 4th Thursday in November Thanksgiving Day December 25 Christmas Day
4.11.1. ABSENCES. The contractor may request, and the FRED may approve, based upon the recommendation of the section chief or from personal knowledge, a reduction in contract performance requirements up to a maximum of 20 working days 8 hours per day, scheduled or unscheduled, due to illness, leave, and other justified reasons per 12-month contract performance period. The contractor shall notify the FRED of any absences that are justified and the FRED will track the number of days the contractor is absent. The number of consecutive days for scheduled or unscheduled absences will be at the discretion of either the MTF commander, section chief, or FRED based on workload with coordination through the FRED. It is the contractor‘s responsibility to approve any absences of the contractor personnel and to coordinate absences with the section chief and/or FRED. The contractor shall provide back-up coverage for all scheduled or unscheduled absences in excess of twenty (20) workdays per 12-month contract performance period at no additional cost to the government.
4.12. CLOSURES. There are USAFE-AFAFRICA Family Days, Presidential Executive Orders, Goal Days, or other command-declared closures, that the MTF will be closed and the Contractor will not be required to provide services. Therefore, the Contractor shall advise its personnel accordingly and treat these situations as determined appropriate. The USAFE-AFAFRICA Family Days are scheduled by the USAFE-AFAFRICA Commander. Goal Days are scheduled on the discretion of the 86AW Commander.
4.13. UNPLANNED CLOSURES. In the event of unplanned closure of the MTF due to natural disaster, military emergency, pandemic conditions, severe weather, security threat, or a facility-related problem that prevents contractor personnel from performing services under this contract, these contractor personnel shall follow the same departure and reporting directions given to Government personnel and the Contractor shall treat its personnel as they determine appropriate.
4.14. COMMANDER’S TOBACCO USE GUIDANCE. The MTF will have a smoke free medical campus with only one authorized smoking area for buildings 2114, 2121 and 2182. Details to the MDG smoking policy will be defined to contractor employee during initial orientation.
4.15. CONTRACTOR ORIENTATION AND NEW PERSONNEL REQUIREMENTS:
4.15.1. GENERAL TRAINING. The Contractor shall be responsible for ensuring personnel comply with health information privacy and security policies and procedures. The Government shall provide training on Government provided forms and equipment, Air Force directives, MTF policies and procedures. Contractor personnel shall participate in continuing education programs to update and/or maintain skills and knowledge to meet annual requirements.
4.15.2. ORIENTATION TRAINING. The Contractor shall ensure that all Contractor personnel participate in the government provided MTF orientation program for newly assigned personnel within the first two weeks of performance start. Orientation training will be conducted during normal hours of operation, and will be scheduled by the FRED. Orientation shall include training on regulations specific to clinic and Air Force policy and procedures, instructions on automation processing, quality assurance policies, Composite Healthcare Computer System (CHCS) (password protected system), Armed Forces Health Longitudinal Technology Application (AHLTA), and other information systems, local in-service, and safety briefings as they apply to the position.
4.15.3. GOVERNMENT PROVIDED TRAINING:
Alcohol and Drug Abuse Prevention and Treatment Program Annual Block Training Armed Forces Health Longitudinal Technology Application (AHLTA) Basic Life Support (BLS)
Composite Healthcare Computer System (CHCS) Cultural Diversity Defense Medical Human Resources System – internet (DMHRSi) (See 4.15.6. – DMHRSi) Infection Control Health Insurance Portability and Accountability Act (HIPAA) – initial and annual certification training. (See 5.1. – Applicable Forms and Publications) Military Health Care Computer Systems/Procedures New Personnel Orientation On-the-job-training (work center/patient safety, waste disposal, fire prevention etc.)
Personnel Reliability Program Total Force Awareness Training – DoD Information Assurance Awareness Total Force Awareness Training – Information Protection Training
4.15.4. CONTRACTOR PROVIDED TRAINING. It is the Contractor’s responsibility to ensure its employees receive all the required training IAW AFI 41-101 – current/continual certification (See 5.1. – Applicable Forms and Publications) to maintain their credentials.
4.15.5. COMPUTER TRAINING. Contractor personnel who have any interaction with the MTF computer systems must receive training for the applicable system(s). The FRED will coordinate the necessary computer training. The training will be on-site and during normal hours of operation. This training will be at no cost to the Contractor. Access to patient data systems is an “Automated Data Processing Sensitive” position requiring compliance with AFI 31-501. The Contractor shall comply with agency personal identity verification procedures that implement Homeland Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201. The Government will train and give access to contractor personnel on the following system: Defense Medical Logistics Standard Support (DMLSS). Access to this system is required to record work performed on equipment and to order parts, research work history and completion of required tasks in line with Air Force Technical Order 13C7-34-2-1, Operations and Manual – Operational Medical Logistics.
4.15.6. DEFENSE MEDICAL HUMAN RESOURCES SYSTEM-INTERNET (DMHRSi):
Contractor employee is required to report labor hours in DMHRSi. The contractor shall report ALL contractor labor hours (including subcontractor labor hours) bi-weekly in accordance to section NCOIC guidelines through DMHRSi, IAW AFI 41-102 Chapt 7.
4.16. CONFORMANCE WITH ENVIRONMENTAL MANAGEMENT SYSTEMS. The Contractor shall perform work under this contract consistent with the relevant environmental policy and objectives identified in the installation environmental management system (EMS) applicable for your contract. The Contractor shall perform work in a manner that conserves water, energy and other resources to the maximum extent feasible and ensure minimum production of waste as possible, giving preference to recycling and reutilization opportunities. Furthermore, the Contractor shall give preference to less toxic materials whenever available and still reliable for their work. In the event an environmental nonconformance or noncompliance of host nation and USAF environmental laws and regulations associated with the contracted services is identified, the contractor shall take corrective and/or preventative actions.
In the case of a noncompliance, the Contractor shall respond and take corrective action immediately. In the case of a nonconformance, the Contractor shall respond and take corrective action based on the time schedule established by the EMS Coordinator. In addition, the Contractor shall ensure that their employees are aware of the environmental management system on base and how these requirements affect their work performed under this contract. All on-site contractor personnel shall receive the installation EMS awareness level information.
4.17. CONFORMANCE WITH ENVIRONMENTAL REQUIREMENTS. The Contractor shall perform all work in accordance with applicable German and US Air Force environmental laws, regulations and operating standards, including but not limited to the Final Governing Standards (FGS) for Germany.
The Contractor shall be immediately capable of understanding and addressing environmental laws and regulations as they pertain to work performed under this contract.
The FGS for Germany and other important environmental laws & requirements applicable for all contractors working on base can be found at the EMS SharePoint Website. Link for the website can be provided upon request.
4.18. U.S. GOVERNMENT-SHARED PROPERTY, INFORMATION AND SERVICES:
4.18.1. Contractor employees will be allowed to use Government shared property under this contract at no cost and shall be used only in performance of services under this contract.
4.18.2. The Government will provide the Contractor access to Air Force directives, MTF policies and procedures prior to start of contract performance date.
4.18.3 Facilities: During the hours of performance under this contract, the Contractor employees shall have the use of office space available.
4.18.4. Equipment and Supplies: Available equipment and office supplies for the performance of services under this contract, such as tools, test equipment, desk, chair, lighting, computer, printer, FAX machine, phone, copier, paper, folders, file cabinets, etc.
4.18.5. Electronic Documentation: As available at the local MTF, a standardized electronic documentation system or electronic medical record will be provided, such as, but not limited to CHCS and AHLTA.
5.0. APPENDICES.
5.1. APPLICABLE PUBLICATIONS AND FORMS. Supplements or amendments to listed publications and/or forms from any organizational level may be issued during the life of this contract. Should any publication or form revision cause a change in the contractor’s processes, procedures and/or standards of operation, the contractor shall advise the CO of such changes in writing within 30 days of receipt of the publication or form revisions.
5.1.1 Publications and forms are available electronically through the internet and are maintained by the Government.
5.1.2. DoD Directives can be found at http://www.dtic.mil/whs/directives/corres/dir.html . Regulations are followed by a “-R” (e.g., DoD 6025.18-R) and can be located on the website by clicking on “Publications” instead of “Directives.”
DoD REGULATIONS/MANUALS, INSTRUCTIONS/ DIRECTIVES, TECHNICAL ORDERS
PUB NO. TITLE
DoDD 5500.07 Standards of Conduct DoDD 8190.1E Defense Logistics Management Standards (DLMS) DoDD 3020.49 Program Management for the Planning and Execution of Operational Contract
Support DoDI 6025.20 Medical Management (MM) Programs in Direct Care Systems (DCS) & Remote
Areas
5.1.3. The Air Force’s E-Publishing site (http://www.e-publishing.af.mil) will be used to obtain Air Force Instructions.
AIR FORCE INSTRUCTIONS/MANUALS
PUB NO. TITLE
AFI 33-332 Air Force Privacy and Civil Liberties Program AFI 33-322 Communication and Information Records Management and Information
Governance Program AFI 31-501 Personal Security Program Management AFI 17-130 Cybersecurity Program Management AFI 40-102 Tobacco Use in the USAF
AFI 41-102 AIR FORCE MEDICAL EXPENSE AND PERFORMANCE REPORTING
SYSTEM (MEPRS) FOR FIXED MILITARY MEDICAL AND DENTAL
TREATMENT FACILITIES
AFI 41-201 Managing Clinical Engineering Programs AFI 44-119 Medical Quality Operations AFMAN 41-209 Medical Logistics Support AFMAN 41-216 Defense Medical Logistics Standard Support (DMLSS) User’s Manual AFMAN 91-203 Air Force Occupational Safety, Fire and Health Standards TO 13C7-34-2-1 Operations and Manual – Operational Medical Logistics
5.1.4. Other References
TITLE
Public Law 91-596, Occupational Safety and Health Act (OSHA) Public Law 99-661, Title 10 USC Section 1102, Privacy Act of 1974 Public Law 104-191, Health Insurance Portability and Accountability Act (HIPAA) of 1996 Access to Care Continuum https://static.e-publishing.af.mil/production/1/af_sg/publication/afi44- 176/afi44-176.pdf AE Reg 604-1, Security Questionnaire For a Simple Security Check
5.2. SERVICE CONTRACT REPORTING (SCR). The contractor is required to report ALL contractor labor hours (including subcontractor labor hours). While inputs may be reported at any time during the fiscal year (FY), all data must be reported no later than 31 October of each year.
5.3. BUSINESS ASSOCIATE AGREEMENT
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.
Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE (to be added at time of award)].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean 86TH Medical Group.
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD
5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html.
The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested.
Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .