ATTM 8 _IT Security Affirmation.docx

DOCX document 27 KB Posted

Attached to
Federal Flexible Spending Account Program (FSAFEDS) Federal contract opportunity
Solicitation number
24322625R0004
Issued by
Office of Personnel Management

About this file

Attachment 8 is an IT and Security Compliance Affirmation document for RFP #24322625R0004 for the Federal Flexible Spending Account Program (FSAFEDS). The document outlines critical compliance requirements for the awarded contractor, including protecting private and personal information of federal employees and their families, maintaining HIPAA-compliant interfaces with federal benefit portals and health plans, and ensuring web-based materials are Section 508 compliant.

Key compliance obligations include developing interfaces with systems like Employee Express, OPM Macon data hub, National Finance Center, and BENEFEDS, with limited government assistance. The contractor must achieve Authorization to Operate (ATO) within the Start-Up Period (approximately 6 months from award through December 31, 2025) and certify all required transactions as HIPAA compliant. By signing this document, the contractor affirms understanding and commitment to these comprehensive IT security and data protection requirements for the federal benefits administration contract.

View the file

Other files for this federal contract opportunity

Other files attached to Federal Flexible Spending Account Program (FSAFEDS), newest first.
File Type Posted
9l. Appendix L WeeklyOperationalSummaryReport_04.23.2025_Sanitized.xlsx XLSX spreadsheet
9c. Appendix C Communication Vehicles.docx DOCX document
9d. Appendix D FEHB FEDVIP Brochures.docx DOCX document
9g. Appendix G Historical Enrollment.docx DOCX document
9h. Appendix H Definitions.docx DOCX document
9k. Appendix K FSAFEDS_Enrollment_by_Agency_04212025.pdf PDF
ATTM_XI_Amendment_Acknowledgement.docx DOCX document
ATTM 4_RFP_Questions Response Form_Combined .xlsx XLSX spreadsheet
9a. Appendix A FedFlex Plan Document Dec 2024.pdf PDF
9b. Appendix B FedScope.docx DOCX document
9f. Appendix F Participating Agencies.docx DOCX document
9j. Appendix J Enrollment by Agency 2020-2024.xlsx XLSX spreadsheet
Revised_ATTM X_ Proposal Instructions - Evaluation 5.7.25.docx DOCX document
Revised_ATTM 1a_PERFORMANCE WORK STATEMENT 2025-05-08.docx DOCX document
ATTM 4_RFP_Questions Response Form_Combined .pdf PDF
9e. Appendix E Intelligence Community Security.docx DOCX document
Attach 2_ Pricing Proposal Schedule.xlsx XLSX spreadsheet
ATTM 4_ RFP Question Response Form.xlsx XLSX spreadsheet
ATTM 5 _PASS-FAIL Forms and Questionnaires.docx DOCX document
ATTM 6 _ACKNOWLEDGMENT OF AMENDMENTS.docx DOCX document
ATTM X_ Proposal Instructions - Evaluation.pdf PDF
ATTM 3a _Provisions IBR and Full Text.pdf PDF
ATTM 3c _OPM Clauses IBR and Full Text.pdf PDF
ATTM 3b _FAR Clauses IBR and Full Text.pdf PDF
ATTM 7_SBPCD Template.docx DOCX document
ATTM 1a_PERFORMANCE WORK STATEMENT.pdf PDF
ATTM 1b_Appendices A through H and Exhibit J.pdf PDF
ATTM 9_ SB Subcontracting Plan Template.docx DOCX document
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP #24322625R0004

ATTACHMENT 8

IT AND SECURITY COMPLIANCE AFFIRMATION

Company Name:

UEI #:

In submitting our proposal package for evaluation, I certify on behalf of my company, that we have a clear and complete understanding of the requirements for IT and Security Compliance.

We (my company and I) understand that:

· The awarded contractor will have access to private and personal information of thousands of federal employees and their families, and must protect it as required by all applicable laws, rules, and regulations.

· The awarded contractor will have access to medical records and claims information of thousands of federal employees and their families, and must protect it as required by all applicable laws and regulations

· Additional requirements for protecting information may apply to employee participants from intelligence agencies beyond those stated explicitly in the solicitation, and those additional requirements must be complied with by the awarded contractor.

· The Government is responsible for issuance of the ATO as defined in the PWS, and the awarded contractor must complete all reviews and approvals necessary to achieve ATO within the Start-Up Period.

· The awarded contractor will be responsible for building and maintaining HIPAA-compliant interfaces with a number of Federal benefit portals (to include but not be limited to Employee Express, the OPM Macon data hub, and the National Finance Center); developing appropriate interfaces with BENEFEDS and/or multiple different Federal payroll systems; testing all interfaces; and certifying those transactions that must be HIPAA compliant before the end of the Start-Up Period (in order to achieve ATO).

· The awarded contractor must build and maintain HIPAA compliant interfaces with a number of OPM sponsored FEHB health plans and FEDVIP dental and vision plans to facilitate the transmission of eligible health care expenses from the carrier to the Contractor.

· There will be limited assistance from the Government in developing the required interfaces other than the provision of record layouts.

· The awarded contractor must also transfer information from BENEFEDS and/or various payroll systems on the same basis as the payrolls process paychecks.

· The awarded contractor will be responsible for certifying that web-based material provided to OPM that relates to the Federal Flexible Spending Account Program (FSAFEDS) is compliant with section 508 of the Rehabilitation Act of 1973 (as amended by the Workforce Investment Act of 1998).

We have addressed all of the above in detail in our submitted proposal, and intend to perform and comply if selected for award.

Signature:

Date:

Name:

Title:

Phone:

File details come from the government source that posted it. Updated .