Clinical Psychologist - PWS - 01 December 2023.pdf
PDF 238 KB Posted
- Attached to
- Clinical Psychologist Federal contract opportunity
- Solicitation number
- FA441724R0002
About this file
This performance work statement outlines clinical psychologist services required by the 25th Intelligence Squadron located at Hurlburt Field, Florida. The contractor must provide one full-time clinical psychologist with a doctoral degree in clinical or counseling psychology, current state licensure, three years of post-doctoral experience, and top secret security clearance. Services include patient diagnosis, counseling, treatment plans, therapy, monitoring progress, maintaining records, and processing referrals. The clinical psychologist must complete all military healthcare training and be proficient in applicable systems. The contractor must also provide monthly service reports and comply with all security, HIPAA, personnel, and oversight requirements detailed in the appendices.
This sources sought notice requests information to determine the market capabilities of potential contractors to provide the clinical psychologist services outlined in the attached performance work statement. Interested firms must submit response packages by January 26, 2024 including business information, capabilities statement not exceeding five pages, and past performance references. The response will be used for market research and does not guarantee a contract award.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
FOR
25 IS Psychologist Support
AT
25th Intelligence Squadron, Hurlburt Field, Florida
1 Dec 2023
TABLE OF CONTENTS
1. DESCRIPTION OF SERVICES 3
2. SERVICES SUMMARY 6
3. GOVERNMENT FURNISHED RESOURCES 7
4. GENERAL INFORMATION 8
APPENDIX A - PERSONALLY IDENTIFIABLE INFORMATION (PII), PROTECTED 13
HEALTH INFORMATION (PHI) AND FEDERAL INFORMATION REQUIREMENTS
APPENDIX B - HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY 21
(HIPAA) CLAUSES
APPENDIX C – PUBLICATIONS 26
1.0. DESCRIPTION OF SERVICES
1.1 General Task Description
The Contractor shall provide readiness, recovery, and resiliency support for the 25th Intelligence Squadron in accordance with the terms outlined in this Performance Work Statement (PWS). The Contractor shall optimize and sustain Intelligence, Surveillance, and Reconnaissance (ISR) operators’ resiliency against physical and mental stressors, and quickly return ISR Airmen to mission ready status. The Contractor shall provide a clinical psychologist support to prevent physical and mental health-related mission degradation and speed up recovery and reconditioning process to return the operator to peak mental and physical performance. The provided clinical psychologist service shall augment ISR operator resiliency, helping them to effectively withstand, recover, and/or grow in the face of stressors and changing operational demands.
1.2 Specific Requirements
The Contractor shall provide a full-time Clinical Psychologist to the 25th Intelligence Squadron (25 IS) and obtain credentialing and system access from the 1st Special Operations Medical Group (1 SOMDG) no later than 60 days after award of contract or employee replacement.
1.2.1 Clinical Psychologist Responsibilities
The Clinical Psychologist shall provide the following services in accordance with all applicable military healthcare systems and procedures:
• Patient diagnosis
• Physical, emotional, mental, and behavioral counseling
• Identify behavioral health trends/issues and provides command consultation
• Develop therapy and treatment plans
• Administer therapy and treatment plans
• Monitor patient progress
• Maintain patient records
• Process patient referral and appointment requests
• Provides psychoeducation and human performance classes
1.2.2 Clinical Psychologist shall ensure all referrals/appointments are submitted in the appropriate military healthcare system and accomplished within the Access to Care standards no later than 72 hours after patient encounter and in compliance with 1 SOMDG guidance.
1.2.3 Educate patients on their behavioral health condition and treatment regimen.
1.2.4 Provide follow-up appointments and monitor patient treatment progress.
1.2.5 Provide physical, emotional, mental, and behavioral counseling and interventions.
1.2.6 Provide detailed documentation of recommended and/or provided patient care, treatment, and therapy. All documentation shall be entered into the patient’s electronic medical record in accordance with the policies and procedures of 1st Special Operations Medical Group (1
SOMDG).
1.2.7 Provide patient status and/or progress to medical personnel, legal authorities, and military commanders, as required.
1.2.8 Provide classes/training that would mitigate the effects of high operational tempos and physical and mental health stressors (i.e. stress management, sleep enhancement, chronic pain management, etc.)
1.2.9 Brief behavioral health trends/issues, as required, and recommend action plans to mitigate adverse effects of the identified trends/issues.
1.2.10 Complete military-specific training and be proficient on all applicable military health care systems and procedures.
1.2.11 Contractors will complete the customer-provided Intelligence Oversight training as required by customer requirements and will report any Questionable Intelligence Activity (QIA), Significant/Highly Sensitive Matter (S/HSM), and/or Federal Crimes IAW procedures established in DoD Directive 5148.13, Intelligence Oversight, and AFI 14-104, Intelligence Oversight. For contracts involving cryptographic matters in addition to DoDD and AFI reference, USSID 18, Legal Compliance and U.S. Persons Minimization Procedures
1.2.12 Track and document all services rendered and submit a monthly report to the Contracting Officer Representative (COR) no later than 5 days after the end of each month.
1.2.13 The Contractor shall not receive more than 3 substantiated customer and peer complaints during each period of performance (1 Year).
1.3 Clinical Psychologist Qualifications
1.3.1 Hold a Doctor of Philosophy (PhD) or Psychology Doctoral (PsyD) degree in clinical or counseling psychology from an American Psychological Associated (APA) accredited psychology program.
1.3.2 Completed an APA-accredited internship/residency in Clinical Psychology.
1.3.3 Have a current license to practice Psychology in any one of the 50 states, the District of Columbia, Puerto Rico, or the U.S. Virgin Islands.
1.3.4 Have at least three (3) years post-doctoral experience in the independent practice of Clinical Psychology within the past five (5) years. This experience must incorporate the full scope of clinical practice, to include assessment, treatment planning, therapy, and treatment completion and/or referral to additional resources or higher-level care within the last two years. Individuals who have not practiced the full scope of clinical practice within the last two years will not meet credentialing requirements as published by the Defense Health Agency.
1.3.5 The work requires the incumbent to obtain and maintain a Top Secret/Sensitive Compartmentalized Information (TS/SCI) Clearance upon the performance start date through the end of performance.
1.3.6 Have a working knowledge of professional standards and ethics regarding the delivery of clinical psychology programs.
1.3.7 Able to operate a personal computer utilizing psychological tests, word processing, databases and data analysis software, spreadsheet programs, and electronic medical records, and possess basic typing skills sufficient to efficiently produce the psychologist’s own reports and correspondence.
1.3.8 Have a current certification in Basic Cardiac Life Support (BCLS) from the American Heart Association (AHA). Documentation of such training shall be provided to the Contracting Officer Representative (COR) prior to starting performance. The front and back of the BCLS shall also be provided to the SOMDG MTF Credentialing Department.
1.3.9 The Contractor shall ensure that the Clinical Psychologist is fully qualified and proficient in the latest technological and professional developments to ensure continual quality support and credentialing standards IAW Defense Health Agency Procedure Manual Number 6025.13, Volume 4.
1.4 Clinical Psychologist Substitute/Replacement.
1.4.1 If Clinical Psychologist will be unavailable for more than 15 consecutive calendar days, the Contractor shall provide a substitute or replacement that meets the qualification standards and health requirements stated in this PWS.
1.4.2 Contractor shall identify and provide a fully qualified substitute or replacement prior to any planned absence, or departure, of the current Clinical Psychologist to avoid service interruptions.
1.4.3 In the event of unplanned employee absences or departure, the Contractor shall provide a substitute or replacement no later than 30 days after the unplanned departure or absence of the current Clinical Psychologist.
1.5 Deliverables
TITLE As of Date Submission Date Distribution
Monthly Service Report
End of month No later than 5 days after the end of each month
COR
Quality Control Plan (QCP) Contract start date; or QCP change date.
No later than 15 days after contract award; or 10 days after any changes made to previously approved
QCP.
COR CO
BCLS
Certification IAW para.
1.3.8
Prior to Clinical Psychologist performance start
Prior to Clinical Psychologist performance start
COR SOMDG
Proof of immunization IAW para.
4.7.2
Within the last 12 months
Prior to Clinical Psychologist performance start
COR
TS/SCI
IAW para. 4.9.2.1
Contract start date
Prior to Clinical Psychologist performance start
COR CO
2.0 SERVICES SUMMARY
2.1 The service requirements are summarized into performance outcomes that relate directly to mission essential items outlined in the PWS. The performance thresholds describe the minimum acceptable levels of service required for each requirement. The thresholds are critical to mission success and acceptable (satisfactory) performance:
SS Performance Objective Level PWS Para
Performance standard and threshold to receive a Satisfactory Rating
1 Contractor maintains licensing and credentialed Psychologist
1.3 Psychologist must be credentialed and
maintain clinical privileges from the 1SOMDG, as well as BLS certification, and all other requirements outlined in the
PWS
2 Unique Military Health Care Systems/Procedures
1.2 Must learn and be proficient in all health
care systems and procedures listed in this section. All encounters with unit members that require documentation in the electronic medical record must be entered within 72 hours of the encounter.
No more than 3 deviations from this standard will acceptable; documentation must be error free 90% of the time.
3 Ensures all submitted referral/appointments are submitted in the appropriate system, and accomplished within the Access to Care standardsContractors are available for all scheduled shifts
1.2.2.4.5 100% of all referrals/appointments must be submitted in the appropriate system within 72 hours of the encounter prompting the referral/appointment.Contractors meet scheduled times 95% of the time
4 Complied with all security requirements
4.9 App.
A.
100% of employee clearances are submitted to COR and CO prior to performance start date. All security requirements must be met and maintained 100% of the time
Zero security violations identified during performance
5 Compliance with HIPAA requirements
App B. 100% compliance with HIPAA rules and regulations, zero violations identified during performance
3.0 GOVERNMENT FURNISHED RESOURCES
3.1 Facilities
3.1.1 The Government will provide a workspace at the 25th Intelligence Squadron. The Government retains the authority to modify or realign facilities and space provided to the contractor based on current or future Air Force guidelines for space utilization, mission requirements, and personnel requirements of the contractor as necessary. Government facilities have been inspected for compliance with Occupational Safety and Health Administration (OSHA); no hazards have been identified in the work center. Should a hazard be subsequently identified, the Government will correct the hazard according to base-wide Government developed and approved plans of abatement taking into account safety and health priorities. A higher priority for correction will not be assigned to the facilities provided to the contractor merely because of this contracting initiative. The fact that no such conditions have been identified does not warrant or guarantee that no possible hazard exists, or that workaround procedures will not be necessary, or that the facilities as furnished will be adequate to meet the responsibilities of the contractor. Compliance with OSHA and other applicable laws and regulations for the protection of employees shall be exclusively the obligation of the contractor.
3.1.2 All utilities will be furnished by the Government to include water, telephone, internet, and electricity. These services are provided for official use only. All healthcare workers will be required to participate in Government conservation programs.
3.2 Automatic Data Processing Equipment (ADPE)/Computer Equipment
3.2.1 The Government will provide computer equipment required to document and maintain appropriate electronic medical information required to support hard copy medical records.
The Government host unit will grant access to ADPE and training to the maximum extent necessary for mission accomplishment.
3.2.2 The Contractor employees shall use ADPE for controlling and tracking data and information as well as any other duties related to contract performance. The Contractor employees shall not use Government furnished ADPE or services for non-contractual related purposes.
3.2.3 The Contractor employees shall comply with all computer system security procedures required by the Government.
4.0 GENERAL INFORMATION
4.1 Quality Control Plan (QCP)
4.1.1 The Contractor shall have a planned and systematic QCP that outlines the quality control process covering every aspect of the Contractor’s performance under this contract. The Contractor shall submit a QCP to the Contracting Officer (CO) for approval no later than 15 days after contract award. The Contractor shall submit any proposed QCP changes to the CO for approval.
4.2 Quality Assurance
4.2.1 The COR will conduct contractor surveillance in accordance with the Government’s Quality Assurance Surveillance Plan (QASP). The COR will inform the contractor’s representative and CO of any performance discrepancies. The CO will use a Corrective Action Report (CAR) to notify the contractor of performance discrepancies and request remedies no later than the time established in the CAR.
4.3 Contractor Personnel
4.3.1 The Contractor shall not employ persons for work on this contract if such employee is identified to the contractor as a potential threat to the health, safety, security, general well-being, or operational mission of the installation and its population.
4.3.2 The Contractor shall not employ any person who is an employee of the US Government if employing that person would create a conflict of interest. Additionally, the contractor shall not employ any person who is an employee of the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to Department of Defense (DoD) Regulation 5500.7-R, Joint Ethics Regulations (JER). The contractor shall not employ any person who is an employee of the Department of the Air Force if such employment would be contrary to the policies in AFI 64-106, Air Force Industrial Labor Relations Activities.
4.3.3 Dress and Appearance. Contractor personnel shall present a clean, neat, and professional appearance appropriate for the performance of their duties. Contractor personnel shall not wear cut off shorts, clothing with tears, revealing clothing or clothing with obscene or inflammatory designs, slogans, or remarks.
4.3.4 The Contractor shall adhere to the designated areas for smoking, eating, and drinking.
4.3.5 On-base Driving Requirements. Contractor employees shall comply with base traffic regulations at all sites. The Contractor shall ensure employees have a current and valid state/country driver’s license and Government license for the type of vehicle being driven before allowing the employee to operate a Government vehicle or personal vehicle on Hurlburt Filed, FL.
4.3.6 The Government will provide the Clinical Psychologist with a Common Access Card (CAC) to use only in performance of this PWS. Contractor personnel shall maintain positive control of their CAC at all times. Contractor personnel shall immediately report lost or stolen CAC to the COR and CO.
4.4 Place of Performance
The primary place of performance will be at Hurlburt Field, FL. Work will occasionally require travel away from the normal duty station. Contractor personnel shall comply with all installation and facility safety and security regulations, as well as the health, safety, and security provisions of the contract. Contractor personnel shall immediately report security or safety concerns to the COR and CO.
4.5 Hours of Work
4.5.1 Normal duty hours are Monday through Friday, 0730 to 1630. Hours may be changed as mission requires; however, Contractor on-site employees shall not work more than 80 hours per two weeks, or per pay period.
4.5.2 The Contractor shall notify the COR of all appointments and leave of their personnel working on-site, no later than 2 weeks before the scheduled appointment or leave.
4.5.3 Federal Holidays. Contractor will not be required to work on the following federally recognized holidays:
New Year's Day January 1 Martin Luther King Day Third Monday of January
President's Day Third Monday of February
Memorial Day Last Monday in May Juneteenth June 19 Independence Day July 4 Labor Day First Monday of September Columbus Day Second Monday in October Veterans Day November 11 Thanksgiving Fourth Thursday in November Christmas December 25
4.5.3.1 If the holiday falls on a Saturday, it is observed on the preceding Friday. If the holiday falls on a Sunday, it is observed on the following Monday. If the holiday falls with an associated down day, goal day, family day, weekend, or holiday granted by the Commander, the Contractor employees will not be expected to work.
4.5.3.2 Planned closures: Contractor personnel will not be required to work on planned closures. The Government will notify the Contractor of anticipated planned closures (e.g., federal holidays, family days, goal days, or safety days) as soon as they are known. Typically, the Government will have 8-12 planned closures per calendar year.
4.5.3.3 Unplanned closures: In the event of an unplanned closure of the facility due to natural disasters, military emergency, or severe weather, Contractor will be allowed to account for those hours as billable to the Government if the following two conditions exist:
(1) local base policy and base access procedures prevented the Contractor employees from performing duties at the place of performance; and, (2) the Contractor employees were scheduled to work, but unable to work because of the unplanned closure.
4.5.3.4 Contractor shall not bill the Government for hours not performed on the contract (i.e. leave, appointment, holidays, base family/goal/safety days, vacant position) unless the conditions set forth in paragraph 4.5.3.3 are met.
4.6 Safety. Contractor is solely responsible for compliance with Occupational Safety and Health Administration (OSHA) standards and the protection of their employees.
4.7 Health Requirements.
4.7.1 In accordance with AFI 48-105, the Contractor shall follow the methods for controlling and preventing disease as described in the American Public Health Association publication, Control of Communicable Diseases Manual, and the Centers for Disease Control and
Prevention publication, Morbidity and mortality Weekly Report, and its supplements. Where applicable, the most recent guidelines from these publications are utilized as the standard.
4.7.2 Before start of performance, the Contractor shall provide Clinical Psychologist’s proof of immunizations from the following diseases according to the CDC guidelines: Hepatitis B, measles, mumps, rubella, varicella, and influenza. The Contractor shall also provide Clinical Psychologist’s proof of a negative TB skin test performed within the last 12 months; if positive, a negative chest x-ray shall also be provided. All documentation shall be provided to the COR prior to starting performance.
4.7.3 Contractor employees performing work under this contract may be required to climb stairs, climb ladders, and enter/exit an aircraft without assistance in order to accommodate patients.
4.8 All contractor employees shall be able to read, understand, speak, and write English fluently.
4.9 Security Requirements
4.9.1 Computer Security. Contractor employees shall maintain computer systems security integrity in accordance with the Air Force Computer Security (COMPUSEC) program (AFSSI 5102). Contractor personnel will be required to complete testing IAW AFI 33-204, Information Assurance Awareness Program and satisfy any other local requirements set forth by the 1st Special Operations Communications Squadron (1 SOCS).
4.9.2 Classified access is required for the performance of this contract.
4.9.2.1 The provided Clinical Psychologist requires access to Top Secret/Sensitive Compartmented Information (TS/SCI) pertaining to patient operations, therefore, a Top Secret/Sensitive Compartmented Information (TS/SCI) clearance is required prior to the contractor performing work.
4.9.2.2 A Department of Defense Contract Security Classification Specification, Form (DD 254), will be issued upon contract award.
4.9.2.3 The Contractor shall submit a DD Form 254 for all assigned subcontractors.
Contractors and all associated sub-contractors who will handle or have access to Classified Information shall adhere to FAR 52.204-2, Security Requirements.
4.9.3 Neither the Contractor nor any of its subcontractors shall disclose or disseminate any information concerning operations of military activities. Such action(s) could result in violation of the contract and possible legal actions.
4.9.4 All inquiries, comments, or complaints arising from any matter observed, experienced, or learned of as a result of, or in connection with the performance of this contract, which may require the dissemination of official information shall be directed to the CO for appropriate action.
4.9.5 Facility Clearance Requirement. The vendor must possess a Top-Secret Facility Clearance. The contractor must have the ability to obtain and maintain a TS/SCI Clearance and Secret safeguarding capabilities within 9 months of start.
APPENDIX A PERSONALLY IDENTIFIABLE INFORMATION (PII), PROTECTED
HEALTH
INFORMATION (PHI) AND FEDERAL INFORMATION REQUIREMENTS
1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws
This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.
This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.
For purposes of this Section, the following definitions apply.
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (October 29, 2014) and DoD 5400.11-R (May 14, 2007).
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E (Enforcement), as amended. Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (January 24, 2003), Department of Defense Instruction (DoDI) 6025.18 (December 2, 2009), and DoDI 8580.02 (August 12, 2015).
Defense Health Agency (DHA) Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
2. Records Management When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records Management requirements outlined in the current TRICARE Operations Manual (TOM).
3. Freedom of Information Act (FOIA)
The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:
The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101 (or email requests addressed to DHA.FOIA@mail.mil), and that the request shall describe the desired record as completely as possible (ideally with Contract or modification number) to facilitate its retrieval from files and to reduce search fees which may be generated by the requestor. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible.
In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria.
All other requests from the public for release of DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.
4. Systems of Records – Not applicable to this contract.
5. Privacy Impact Assessment (PIA) – Not applicable to this contract.
6. Data Sharing Agreement (DSA) - Not applicable to this contract.
7. Privacy Act and HIPAA Training
The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of alcohol and drug abuse patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with PHI and its regulatory responsibilities as either a Covered Entity, or Business Associate.
The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.
8. HIPAA Business Associate Provisions
8.1 Business Associate – General Provisions
The Contractor meets the definition of Business Associate, and 1 SOMDG meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. The contractor shall use the DoD BAA in Appendix C, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD Components”.
9. Breach Response
9.1 Definitions Related to Breach response
9.1.2 Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar term referring to situations where persons other than authorized users and for other than an authorized purpose have access or potential access to PII, whether physical or electronic. The foregoing definition is based on the definition of breach in DoDD 5400.11. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral PII/PHI).
9.1.3 A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the contractor does not initially know whether or not the PII/PHI was encrypted, then the incident must initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the contractor. In determining whether unauthorized access should be suspected, the contractor shall consider at least the following factors:
• How the event was discovered;
• Did the information stay within the covered entity’s control?;
• Was the information actually accessed/viewed; and
• Ability to ensure containment (e.g., recovered, destroyed, or deleted).
9.1.4 A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the contractor knows that the PII/PHI is unencrypted, then the contractor should classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the contractor knows this even without knowing whether or not unauthorized access to the PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the contractor should re-classify the incident as a non-breach incident.
9.1.5 A HHS breach is an incident that satisfies the definition of breach in Section 164.402 of the HIPAA Breach Rule. The text of the HHS definition states:
Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.
HHS breach excludes:
Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the HIPAA Privacy Rule.
Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy Rule.
A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.
Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
The unauthorized person who used the PHI or to whom the disclosure was made;
Whether the PHI was actually acquired or viewed; and The extent to which the risk to the PHI has been mitigated.
9.1.6 A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI.
A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.
9.2 General
9.2.1 The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.
9.2.2 Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation (which includes individual notification), eradication, recovery, and follow-up.
9.2.3 The contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The contractor should consult with 1st Special Operation Communications Squadron Cybersecurity Office, where guidance is needed, such as when the contractor is uncertain whether a discovered breach is the contractor’s responsibility (e.g., if the contractor discovers a breach not caused by the contractor), or how the contractor is to classify an incident (breach vs. non-breach, confirmed vs. possible, cyber vs. non-cyber). Under no circumstances will a contractor delay reporting a confirmed or possible breach to 1 SOCS Cybersecurity Office beyond the 24-hour deadline. In conjunction with its initial investigation, the contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.
9.2.4 In the event of a cybersecurity incident not involving a PII/PHI breach, the contractor shall follow applicable DoD cybersecurity and NIST requirements, which include United States- Computer Emergency Readiness Team (US-CERT) reporting (see paragraph 9.3). If at any point a contractor finds that a cybersecurity incident involves a PII/PHI breach (possible or confirmed), the contractor shall immediately initiate the reporting procedures set forth below. The contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.
9.2.5 Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the contractor immediately after discovery. The time of that report to the contractor shall trigger the contractor’s reporting deadline (24 hours) under paragraph 9.3.2. If a cybersecurity incident is involved, the contractor’s deadline for US-CERT reporting (1 hour) runs from the time the incident is confirmed. The contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the contractor to complete the breach response requirements herein. Alternatively, the contractor and subcontractor may agree that the subcontractor shall report directly to US-CERT and 1 SOCS Cybersecurity Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the contractor of the incident and the subsequent response actions.
9.2.6 Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the outcome. Investigations identifying unauthorized disclosures must be logged for HIPAA and Privacy Act disclosure accounting purposes, whether or not individual notification is required under the HIPAA Breach Rule.
9.2.7 Contractors, when acting as HIPAA-covered entities (rather than as business associates), are not subject to the breach response requirements herein. However, such contractors are subject to both the HIPAA Breach Rule (applicable to them in their capacity as covered entities) and DoD cybersecurity requirements (applicable to them in their capacity as DoD contractors).
9.3 Reporting Provisions
9.3.1 Immediately upon discovery of a possible or confirmed breach or cybersecurity incident, the contractor shall initiate an investigation. If the incident involves electronic PII/PHI, and if the investigation finds a confirmed breach or cybersecurity incident, the contractor shall report it, within 1 hour of confirmation, to the US-CERT Incident Reporting System at https://forms.us-cert.gov/report/, as required by the Department of Homeland Security (DHS).
Note: DHS no longer requires US-CERT reporting of non-cyber breaches or unconfirmed electronic breaches. However, DHS permits US-CERT reporting of unconfirmed cyber-related incidents on a voluntary basis. Thus, if a contractor is uncertain whether a possible cyber-related incident should be treated as confirmed and thus reportable, the contractor may voluntarily report the incident.
Before submission to US-CERT, the contractor shall save a copy of the on-line report. After submitting the report, the contractor shall record the US-CERT incident reporting number, which shall be included in the initial report to the DHA Privacy Office as described in paragraph 9.3.2.
Note: Regardless of whether or not an incident is confirmed as a breach, the contractor must also investigate whether or not the incident impacts data integrity or availability of PII/PHI. If such impact is confirmed, then the incident is reportable to US-CERT as a cybersecurity incident. For guidance on investigating the impact on data integrity and availability, refer to DoD cybersecurity and NIST guidance.
The contractor shall provide any updates to the initial US-CERT report by email to soc@us-cert.gov, with the Reporting Number in the subject line. The contractor shall provide a copy of the initial or updated US-CERT report to 1 SOCS Cybersecurity Office if requested. Contractor questions about US-CERT reporting shall be directed to 1 SOCS Cybersecurity Office , not the US- CERT office.
9.3.2 In addition to US-CERT reporting, the contractor shall report to 1 SOCS Cybersecurity Office by submitting the form specified below within 24 hours of discovery of a breach (possible or confirmed), unless the breach falls within a category that the Privacy Office has determined to be not reportable. This 24-hour period runs from the time of discovery, unlike the 1-hour US- CERT reporting period, which runs from the time a cybersecurity incident is confirmed. Thus, depending on the time period needed to confirm, the report to 1 SOCS Cybersecurity Office may be due either before or after the US- CERT report.
The breach report form required within the 24-hour deadline shall be emailed to the CO and the COR. Encryption is not required, because reports and notices shall not contain PII/PHI. If electronic mail is not available, telephone notification is also acceptable but all notifications and reports delivered telephonically must be confirmed in writing as soon as reasonably feasible.
Contractors shall prepare the breach reports required within the 24-hour deadline by completing the Breach Reporting Department of Defense (DD) Form DD 2959 (Breach of PII Report), available at the Breach Response link on the DHA Privacy Office web site, http://www.health.mil/Military-Health-Topics/Privacy-and-Civil-Liberties/Breachesof-PII-and- PHI. For non-cyber incidents without a US-CERT number, the contractor shall assign an internal tracking number and include that number in Box 1.e of the DD Form 2959. The contractor shall coordinate with 1 SOCS Cybersecurity Office for subsequent action, such as beneficiary notification, and mitigation. The contractor must promptly update the DD Form 2959 as new information becomes available.
When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Contractor shall submit a revised form or forms promptly after the new information becomes available, stating the updated status and previous report date(s) and showing any revisions additions in red text. The Contractor shall provide updates to the same parties as required for the initial Breach Report Form.
9.4 Individual Notification Provisions
If 1 SOCS Cybersecurity Office determines that individual notification is required, the Contractor shall provide written notification to beneficiaries affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the beneficiaries are ascertained. The 10-day period begins when the Contractor is able to determine the identities (including addresses) of the beneficiaries whose records were impacted. If notification cannot be accomplished within 10 working days, the contractor shall notify 1 SOCS Cybersecurity Office .
9.4.1 The Contractor’s proposed notification to be issued to the affected beneficiaries shall be submitted to 1 SOCS Cybersecurity Office for approval. The notification to beneficiaries shall include, at a minimum, the following:
• Specific data elements,
• Basic facts and circumstances,
• Recommended precautions the beneficiary can take,
• Federal Trade Commission (FTC) identity theft hotline information, and
• Any mitigation support services offered, such as credit monitoring.
Contractors shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Contractor and/or subcontractor organization that suffered the breach.
If media notice is required, the contractor shall submit a proposed notice and suggested media outlets for 1 SOCS Cybersecurity Office review (which will include coordination with the 1 SOW Public Affairs) and approval.
9.5 In the event the Contractor is uncertain on how to apply the above requirements, the Contractor shall consult with the CO, who will consult with 1 SOCS Cybersecurity Office as appropriate when determinations on applying the above requirements are needed.
The Contractor shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Contractor has caused or is otherwise responsible for addressing.
APPENDIX B
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY (HIPAA)
CLAUSES
In accordance with DoDi 6025.18-R and AFI 41-217, Military Treatment Facilities (MTFs) are responsible to ensure overall compliance with HIPAA requirements, which includes incorporation of certain requirements in contracts entered or amended after the respective implementation dates.
1. Department of Defense Business Associate Agreement
1.1. In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy
Regulation,” January 24, 2003, the Contractor meets the definition of Business Associate. Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Contractor agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause, and in DoD 6025.18-R and DoD 8580.02-R, as amended.
Additional requirements will be addressed when implemented.
1.2. Definitions. As used in this clause generally refer to the Code of Federal Regulations
(CFR) definition unless a more specific provision exists in DoD 6025.18-R or DoD 8580.02-R.
Individual has the same meaning as the term “individual” in 45 CFR 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).
Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.
Protected Health Information has the same meaning as the term “protected health information” in 45 CFR 160.103, limited to the information created or received by the Contractor from or on behalf of the Government pursuant to the Contract.
Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.
Required by Law has the same meaning as the term “required by law” in 45 CFR 164.103.
Secretary means the Secretary of the Department of Health and Human Services or his/her designee.
Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part 164, subpart C.
Terms used, but not otherwise defined, in this clause shall have the same meaning as those terms in 45 CFR 160.103, 164.501 and 164.304.
1.3. The contractor shall not use or further disclose Protected Health Information other than as permitted or required by the Contract or as Required by Law.
1.4. The contractor shall use appropriate safeguards to prevent use or disclosure of the Protected Health Information other than as provided for by this Contract.
1.5. The contractor agrees to use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Contract.
1.6. The contractor agrees to mitigate, to the extent practicable, any harmful effect that is known to the Contractor of a use or disclosure of Protected Health Information by the Contractor in violation of the requirements of this Clause.
1.7. The contractor shall report to the Government any security incident involving protected health information of which it becomes aware.
1.8. The contractor shall report to the Government any use or disclosure of the Protected Health Information not provided for by this Contract of which the Contractor becomes aware.
1.9. The contractor shall ensure that any agent, including a subcontractor, to whom it provides
Protected Health Information received from, or created or received by the Contractor, on behalf of the Government, agrees to the same restrictions and conditions that apply through this Contract to the Contractor with respect to such information.
1.10. The contractor shall ensure that any agent, including a subcontractor, to whom it provides electronic Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.
1.11. The contractor shall provide access, at the request of the Government, and in the time and manner reasonably designated by the Government to Protected Health Information in a Designated Record Set, to the Government or, as directed by the Government, to an Individual in order to meet the requirements under 45 CFR 164.524.
1.12. The contractor shall make any amendment(s) to Protected Health
1.13. Information in a Designated Record Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government, and in the time and manner reasonably designated by the Government.
1.14. The contractor shall make internal practices, books, and records relating to the use and disclosure of Protected Health Information received from, or created or received by the Contractor, on behalf of the Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner reasonably designated by the Government or the Secretary, for purposes of the Secretary determining the Government’s compliance with the Privacy Rule.
1.15. The contractor shall document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.
1.16. The contractor shall provide to the Government or an Individual, in time and manner reasonably designated by the Government, information collected in accordance with this Clause of the Contract, to permit the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.
2. General Use and Disclosure Provisions
2.1. Except as otherwise limited in this Clause, the Contractor may use or disclose Protected
Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health Information would not violate the HIPAA Privacy Rule, the HIPAA Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .