Combined Synopsis HT941025Q2067-PERFORMANCE WORK STATEMENT_FINAL.docx

DOCX document 104 KB Posted

Attached to
Bronchoscope and OER-Elite Maintenance Federal contract opportunity
Solicitation number
HT941025Q2067
Issued by
Defense Health Agency

About this file

This Performance Work Statement (PWS) details a non-personal services contract for Bronchoscope and OER-Elite Maintenance for the Department of Defense Defense Health Agency at Naval Medical Center San Diego. The contract covers maintenance, repair, and preventative services for multiple bronchoscopes and an OER-Elite endoscope reprocessor, with a base period from 26 September 2025 to 25 September 2026 and four potential one-year option periods extending through 25 September 2030.

Key requirements include providing 24/7 technical support, responding to repair inquiries within four hours, offering next-day shipping for equipment repairs, and ensuring all maintenance is performed by fully qualified engineers trained by the original equipment manufacturer. The contract covers 13 specific bronchoscopes and one OER-Elite reprocessor, with annual preventative maintenance required every 12 months or 2,500 cycles. Technicians must submit detailed field service reports within 72 hours of completing service, and the contract emphasizes comprehensive repair coverage including accidental damage at no extra charge.

View the file

Other files for this federal contract opportunity

Other files attached to Bronchoscope and OER-Elite Maintenance, newest first.
File Type Posted
Combined Synopsis HT941025Q2067 Bronchoscope Services NMCSD-Final.docx DOCX document
HT941025Q2067-Past Performance_Questionnaire PPQ-Final.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense Defense Health Agency Performance Work Statement

Bronchoscope and OER-Elite Maintenance Contract

Directorate of Medical Services

Pulmonary Department

Solicitation Number:

Version:

Date:

PART 1

1.0 GENERAL INFORMATION

1.1 This is a non-personal services contract to provide Bronchoscope and OER-Elite Maintenance Contract

1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform [Bronchoscope and OER-Elite Maintenance Contract as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.

1.3 Background: The Pulmonary Department currently has bronchoscopes and an OER-Elite endoscopre reprocessor under service contract.

1.4 Objectives: The vendor shall provide the following:

· Repair/replace any bronchoscopes.

· Provide required preventative maintenance and repairs to OER-Elite endoscope reprocessor

· Perform Preventative Maintenance in accordance with OEM specifications.

· Ensure that only FULLY QUALIFIIED ENGINEERS and TECHNICIANS who have gone through original equipment manufacturer (OEM) or comparable third party service schools for the above-mentioned equipment, shall be employed in the performance of any and all work performed under this contract Upon request, the contractor shall provide training certificates (or notarized copies) to the Material Management Department.

1.5 Scope:

Description of Services. Contractor will, directly or through the original equipment manufacturer, perform the following services (the “Services”) pursuant to Schedule B-2 (Summary of Equipment Service Agreement) for the equipment identified on Schedule B-1 (Line Item Pricing of Equipment) (the “Equipment”) as issued by Contractor:

a) Provide Customer with unrestricted access to technical support twenty-four (24) hours a day, seven (7) days per week. Contact the Technical Assistance Center (“TAC”) at 1-800-848-9024, Option 1 (Monday through Friday between 7am and 8pm ET) or 1-877- 624-7267 (Weekends and Monday through Friday between 8pm and 7am ET).

b) Provide a telephone response to technical inquiries for repairs within four hours.

c) At no additional charge, provide Customer next-day, pre-paid shipping labels to send Equipment for repair and to return repaired Equipment to Customer via next day freight.

d) Provide all parts and labor necessary to complete the service then-current service specifications. Contractor may use reconditioned, refurbished, and/or serviceable used OEM parts that satisfy regulatory and quality standards.

e) Provide access to the Contractor online service portal to enable the management of various aspects of the service.

g) Full repair coverage with no cap for all contracted equipment, including accidental damage coverage at no extra charge

Contractor will provide annnual Reprocessor III preventative maintenance (“PM”) services, to occur twelve (12) months from the anniversary date of the prior PM or 2,500 cycles, whichever comes first (i.e. 1 year contract = 1 PM, 2 year contract = 2 PM, etc.).

The contractor shall service and maintain the equipment listed on the below table within the original equipment manufacturers (OEM) specifications, in accordance with the US, State, and Local laws and regulations, US Navy regulations, and Joint Commission requirements.

Model
Serial Number
Product Category
BF-UC180F
7621262
EBUS
BF-UC180F
7410317
EBUS
BF-UC190F
7413533
EBUS
BF-1TH190
2400952
Bronch Video
BF-H190
2129727
Bronch Video
BF-H190
2401195
Bronch Video
BF-H190
2401193
Bronch Video
BF-H190
2401086
Bronch Video
BF-MP190F
2301229
Bronch Video
BF-P190
2601063
Bronch Video
BF-P190
2711771
Bronch Video
BF-P190
2500481
Bronch Video
BF-P190
2500466
Bronch Video
BF-P190
2601122
Bronch Video
BF-XT190
2300581
Bronch Video
OER-ELITE
2302324
Reprocessor III

Field Service Reports: Contractor shall furnish a written or electronic vendor supplied Field Service Report (FSR) to the Duty Staff at NMCSD Biomed. All FSR's shall be submitted within 72 hours of completion of service and shall be sent to the following email address:

dha.san-diego.san-diego-nmc.list.nmcsd-biomed-contract@health.mil

The contractor or their representative shall complete the FSR to include, at a minimum, the following information:

1. Contractor Name
2. Technician's printed name, telephone number, and signature
3. Date and Time of Arrival
4. ECN (to be provided by Navy) and Serial Number of Equipment
5. Time Expended Repairing/Service: Labor Hours, Rate, Materials
6. Summary of Work Performed and Accepted by End-User, with Government
Representative's Printed name and Signature)

Completed Field Service Reports are required prior to acceptance of any invoice. Failure to submit a Field Service Report to NMCSD Biomed can result in delay of payment or rejection of invoice from Government. It is highly recommended that the contractor attach a copy of the Field Service Report to their Wide Area Workflow Invoice in addition to the required submission to NMCSD Biomed in order to expedite invoicing process.

1.6 Period of Performance (PoP):

Base - From: 26SEPT2025 To: 25SEPT2026 Option 1 - From: 26SEPT2026 To: 25SEPT2027 Option 2 - From: 26SEPT2027 To: 25SEPT2028 Option 3 - From: 26SEPT2028 To: 25SEPT2029 Option 4 - From: 26SEPT2029 To: 25SEPT2030

1.6.1 Transition: Not Applicable

1.7 Administrative specifications

1.7.1 Place of performance: The work shall be performed at The work shall be performed at

Naval Medical Center San Diego.

Pulmonary Department- BLDG 3, FLR 3 34800 Bob Wilson Drive San Diego, CA 92134 and/or

Biomedical Repair Department
Building One, Ground Floor
Naval Medical Center San Diego
34800 Bob Wilson Drive
San Diego, CA 92134-5000

1.7.2 Recognized Federal holidays: The contractor is not required to perform services on holidays.

New Year’s DayLabor Day
Martin Luther King Jr.’s BirthdayColumbus Day
President’s DayVeteran’s Day
Memorial DayThanksgiving Day
Juneteenth DayChristmas Day

Independence Day

1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.

1.7.4 Emergency Services:. NA

1.7.5 NMCSD Points of Contact: For all matters concerning performance of this contract, the primary point of contact shall be:

Biomedical Repair Division, Material Management Department
Building One, Ground Floor, Room GD-18H1
Naval Medical Center San Diego
34800 Bob Wilson Drive
San Diego, CA 92134
TEL:619-532-8010
Fax:619-532-8013

Email: usn.nmcsd-contractadministrator@mail.mil

For administrative matters, the contractor may contact the contracting officer as designated in blocks 7.a, 7.b, 8, and 9 as found on the Standard Form 1449 issued for the contract, or may contact:

Material Management Department
Naval Medical Center San Diego
34800 Bob Wilson Drive
San Diego, CA 92134
TEL: 619-532-8110
FAX: 619-532-5596

1.8 Contractor travel: Contractor shall be authorized travel expenses consistent with the cost principles and procedures in Federal Acquisition Regulation (FAR) Part 31.2, Travel Costs and the limitations of funds specified in this contract. All travel requires Government approval/authorization and notification to the Contracting Officer Representative (COR).

1.9 Other Direct Costs (ODC): N/A

1.10 Quality

1.10.1 Quality Control (QC): N/A

1.10.2 Quality assurance (QA): N/A

1.11 Contractor personnel

1.11.1 CAC requirements: N/A

1.11.2 Contractor onboarding and training; N/A

1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.

1.11.4 Key control: The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.

1.11.4.1 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon direction of the CO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.

1.11.4.2 The contractor shall prohibit the use of Government issued keys/key cards by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the CO.

1.11.5 Lock combinations: The contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the contractor’s QCP.

1.12 Key personnel (Contractor): N/A

1.13 Data rights: N/A

1.14 Reporting

1.14.1 Contractor Manpower Reporting (CMR): RESERVED.

1.14.2 Non-Disclosure Agreement (NDA): N/A

1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.

1.15 Contractor Identification

1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel. Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.

1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their contractor status known during introductions.

1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.

1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)

1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.

1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.

1.17 Personnel Security

1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM 5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:

1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 275-6038.

1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).

1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.

PART 2

2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE PUBLICATIONS/INSTRUCTIONS

2.1 Definitions:

2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-Services)

2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-Services)

2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.

2.1.6 Quality Assurance Surveillance Plan (QASP): N/A

2.2 Acronyms:

AISAutomated Information System
APLApproved Products List APL
AQLAcceptable Quality Level
ARRTAcquisition Requirements Roadmap Tool
ATOAuthority to Operate
B2BBusiness-2-Business
CACCommon Access Card
CAPCloud Access Point
CCEVSCommon Criteria Cybersecurity Evaluation and Validation Scheme
CDICovered Defense Information
CEComputer Environment
CDRLContract Data Requirement List
CIOChief Information Officer
CJCSMChairman of the Joint Chiefs of Staff Manual
CMMCCybersecurity Maturity Model Certification
CMRContractor Manpower Reporting
CNSSICommittee on National Security Systems Instruction
COContracting Officer(s)
CONUSContinental United States (excludes Alaska and Hawaii)
CORContracting Officer Representative
COTRContracting Officer's Technical Representative
CSPCloud Service Provider
CSSPCyber Security Service Provider
CUIControlled Unclassified Information
DAD-ADeputy Assistant Director for Acquisition
DC3DoD Cyber Crime Center
DD Form 254Department of Defense Contract Security Requirement List (if applicable)
DBDesign-Build
DBBDesign-Bid-Build
DFARSDefense Federal Acquisition Regulation Supplement
DHADefense Health Agency
DISADefense Information System Agency
DoDDepartment of Defense
DoDDDepartment of Defense Directive
DoDIDepartment of Defense Instruction
DSAsData Sharing Agreements
DSAAData Sharing Agreement Application
DMZDemilitarized Zone
DoDMDepartment of Defense Manual
DPCLODHA Privacy and Civil Liberties Office
DUAData Use Agreement
eMSMEnhanced Multi-Service Markets
EULAEnd User License Agreement
EVMEarned Value Management
FARFederal Acquisition Regulation
FCIFederal contract information
FEFacilities Enterprise
FedRAMPFederal Risk Authorization and Management Program
FISMAFederal Information Security Modernization Act
FRCSFacility Related Control Systems
FSOFacilities Security Officer
HAHealth Affairs
HIPAAHealth Insurance Portability and Accountability Act
HCAHead of the Contracting Activity
HITHealth Information Technology
IGCEIndependent Government Cost Estimate
IAInformation Assurance
IOInitial Outfitting
I/OIn/Out Processing Portal
IPvInternet Protocol Version
ISInformation System
ISPInternet Service Provider
ITInformation Technology
ISCMInformation Security Continuous Monitoring
IV&VIndependent Verification & Validation
MedCOIMedical Community of Interest
MHSMilitary Health System
MIL-STDMilitary Standard
MTFsMilitary Treatment Facilities
NCRNational Capitol Region
NDANon-Disclosure Agreement
NIAPNational Information Assurance Partnership
NISTNational Institute of Standards and Technology
OCONUSOutside Continental United States (includes Alaska and Hawaii)
ODCOther Direct Costs
OPMOffice of Personal Management
OSDOffice of the Secretary of Defense
P-ATOPersonal Authorization to Operate
P&RPersonnel and Readiness
PGIProcedures, Guidance and Information
PDTProject Delivery Team
PHIProtected Health Information
PIIPersonally Identifiable Information
PITPlatform Information Technology
PKPublic Key
PKIPublic Key Infrastructure
POA&MPlan of Action and Milestones
POCPoint of Contact
PMOProgram Management Office
PoPPeriod of Performance
PPPersonal Property
PPSMPorts, Protocols, and Services Management
PRSPerformance Requirements Summary
PSPPersonnel Security Program
PWSPerformance Work Statement
QAQuality Assurance
QAPQuality Assurance Program
QASPQuality Assurance Surveillance Plan
QCQuality Control
QCPQuality Control Plan
RFPRequest for Proposal
RFQRequest for Quotation
RMFRisk Management Framework
SPSpecial Publication
SPRSSupplier Performance Risk System
SRMSustainment, Restoration and Modernization
SRGSecurity Requirements Guides
STIGSecurity Technical Implementation Guides
TOSTerms of Service
USUnited States
UFCUnified Facilities Criteria
VPNVirtual Private Network
XMLExtensible Markup Language

2.3 Applicable Publications, DHA Administrative Instructions (AI), etc.

PART 3

3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:

3.1 Services: The Government:

☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below: provide

3.2 Facilities: The Government:

☒ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Facilities in support of this contract/task orders. The Government provided Facilities are described below

3.3 Utilities: The Government:

☒ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Utilities in support of this contract/task orders. The Government provided Utilities are described below:

3.4 Equipment: The Government:

☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Equipment in support of this contract/task orders. The Government provided Equipment is described below:

3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application The contractor shall be responsible for obtaining and maintaining access, training and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP. The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.

Contracting Office Responsibilities:

The Contracting Office shall ensure close coordination and validation of the GFP items with the COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.

The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the Contracting Office, and requested within the PIEE/GFP Module system.

Contractor Responsibilities:

A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.

The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation. Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise Environment Standards, DHA Administrative Instruction 094 and DHA Guidance. \

3.5 Materials: The Government:

☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ IS providing Materials in support of this contract/task orders. The Government-provided

PART 4

4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES

4.1 Services: The Contractor:

☒ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.

☐ WILL provide Contractor Furnished Services required in support of this contract/task orders.

4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.

4.3 Secret Facility Clearance: Not applicable

4.4 Materials: The contractor shall provide materials, supplies, and equipment necessary to meet the requirements under this PWS.

4.5 Equipment: N/A

4.6 Facilities: N/A

PART 5

5.0 SPECIFIC TASKS

5.1 Task Headings:

5.1.1 Subtask heading:

5.2 Special Qualifications: The contractor shall provide all personnel, equipment, supplies, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform maintenance and repairs for government owned bronchoscopes and preventive Maintenance services for government-owned OER Elite as defined in this Performance Work Statement (PWS)

5.2.1 When using education/certification in conjunction with labor categories, the COR in coordination with the CO must establish a review process of contractor personnel to ensure labor category requirements are met.

PART 6

6.0 INFORMATION TECHNOLOGY & SECURITY

6.1 All work under this contract is N/A

6.2 The TIER 1 or TIER 2 levels and position sensitivity designation for positions under this contract is: (Requirement must be checked in order to be a requirement for this PWS.)

6.2.1 TIER II: Non-critical sensitive position

6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:

6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office (DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data. After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.

6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.

6.4 Training

6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:

6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.

6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD 8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:

6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and

6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by DoD 8570.01–M.

6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.

6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.

6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.

6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS:

6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171), in accordance with DFARS clause 252.204-7012.

6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment Methodology requirement flows down to subcontractors.

6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)

6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order. See Attachment 2, Deliverable Schedule Table.

6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.

6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.

6.5.4 Cybersecurity Maturity Model Certification (CMMC) (When applicable): The CMMC (DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk. The CMMC requirement flows down to subcontractors.

6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization (3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.

6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.

6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.

6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.

6.5.8 Cyber Incident Reporting Requirement

6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:

6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and

6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/

6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.

6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/

6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.

6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.

6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.

6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.

6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.

6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).

6.5.15. The contractor shall mitigate supply chain risk to the government by complying with DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.6 Risk Management Framework (RMF) for DoD IT: All IS, Platform Information Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI 8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal Information Security Modernization Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.

6.6.1 All systems subject to RMF must present evidence of authorization in the System Security Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of CO request. Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions (ATO-C) by contract award.

6.6.2 The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework (RMF) and DoDI 8510.01, Risk Management Framework (RMF).

6.6.3 The contractor shall configure the information system in accordance with Defense Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).

6.6.4 The contractor shall ensure that the information system conforms to the requirements of DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.

6.6.5 The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.

6.6.6 The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK) Enabling”.

6.6.7 The contractor will be responsible for compliance with the Joint Force Head Quarters – Department of Defense Information Network issuances and IA Vulnerability Management (IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.

6.6.8 The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.

6.6.9 The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA Cybersecurity Architectures.

6.6.10 Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.

6.6.11 Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP 800-137.

6.6.12 The contractor shall mitigate supply chain risk to the government by complying with DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).

6.7. Facility Related Control Systems: The DHA’s Facilities Enterprise (FE) Program Management Office (PMO) establishes the processes for acquisition, installation and sustainment of FRCS in DHA Facilities. Requirements for cybersecurity of FRCS are developed and specified by the FHA FE FRCS PMO. The scope of PIT and Control Systems within the DoD includes building control systems such as Heating Ventilation and Air Conditioning, Utility Management Control System, Electronic Security Systems, Fire Alarm Systems, and other assets. The application of IT cybersecurity strategies is migrating into PIT and Control Systems in response to emerging threats. The requirements within this scope apply to all versions of Design-Build (DB); Design-Bid-Build (DBB); and facilities Sustainment, Restoration and Modernization (SRM) projects as well as Initial Outfitting (IO) requirements activities.

6.7.1 Applicability: Contractors shall agree to the DHA Cybersecurity requirements as outlined for those project-specific FRCS Systems selected from Military Standard (MIL-STD) 1691, (https://home.facilities.health.mil/military-standard-milstd-1691-equipment) and identified in the DBB design process, D-B RFP development, SRM procurement documentation, or IO requirements unless an exception has been granted for a system by the Government prior to project award or procurement order issuance.

6.7.2 Cybersecurity Design: Failure to meet the design requirements may result in Government non-acceptance of submittals or termination of the procurement delivery order for cause, in accordance with project documentation and FAR 52.212-4(m).

6.7.2.1 The contractor shall comply with Unified Facilities Criteria (UFC) 4-010-06 Cybersecurity of Facility-Related Control Systems, UFGS 25-05-11 Cyber Security for Facility-Related Control Systems, and referenced standards to develop a Cybersecurity program for their FRCS products to be installed in DoD facilities. The UFC system is prescribed by MIL-STD 3007 and provides planning, design, construction, sustainment, restoration, and modernization criteria, and applies to the Military Departments, the Defense Agencies, and the DoD Field Activities in accordance with Under Secretary of Defense Acquisition, Technologies, and Logistics Memorandum dated 29 May 2002. UFC will be used for all DoD projects and work for other customers where appropriate.

6.7.2.2 Contractors shall comply with the National Information Assurance Partnership (NIAP) Common Criteria Cybersecurity Evaluation and Validation Scheme (CCEVS) evaluation (https://www.niap-ccevs.org) which is published on the NIAP-CCEVS Products Compliance List. The NIAP-certified products have been assessed from a security perspective, helping to reduce the existence of potential vulnerabilities. Contractors are required to continually maintain their products, mitigate vulnerabilities, and distribute fixes to licensed users.

6.7.2.3 The contractor agrees to comply with security regulations and guidance listed in Attachment 3, Cybersecurity Regulations and Guidance, and all RMF requirements. The contractor shall establish appropriate administrative and technical safeguards to ensure the confidentiality, integrity, and availability of Government data under their control.

6.7.3 Funding of FRCS System/Device Requirements: Projects requiring new or replacement FRCS, or upgrade/extension of existing devices/systems, employ either SRM, DB, or DBB acquisition strategies. Many FRCS are categorized as Real Property and are project funded. Others are categorized through Military Standard 1691 as Personal Property (PP) requiring IO funding. The IO effort should preferably, and where feasible, be embedded in the SRM, DBB or DB contract through Contract Line Items or another vehicle. This will optimize coordination of project-funded infrastructure design/construction with FRCS device/system design, installation, testing and commissioning. Where the project delivery team (PDT) determines that acquisition of PP devices/systems will be through IO action entirely separate to the SRM, DBB, or DB contract, the same RMF-related activities are required. These activities shall be fully integrated into the project master schedule.

6.7.3.1 Pricing for Cybersecurity: If there are any additional costs associated with any element of the Cybersecurity lifecycle including a test/laboratory environment, the Contractor shall provide those costs as follows:

6.7.3.1.1 All costs to assist the Government to achieve a new ATO and maintain it during the equipment’s warranty shall be included in the initial quote/offer price for SRM, and in the proposal for DB/DBB projects.

6.7.4 FRCS Cybersecurity Requirements: The contractor shall provide a POC responsible for the cybersecurity of the contractor device or system, throughout the lifecycle of the product. The contractor shall provide Subject Matter Experts to support all assessments of contracted products and materials.

6.7.4.1 The contractor shall establish and utilize a test/laboratory environment that duplicates all contractor fielded equipment/product that falls within the FRCS system/device authorization boundary. The contractor shall ensure that all fielded equipment/product is maintained during the construction/installation period of performance, and for fifteen (15) years post acceptance or as long as the contractor commercially supports the equipment/product, whichever is longer.

6.7.4.2 The contractor’s test/laboratory environment shall be used to submit to the Government, either through the RFP response, procurement order offer/quote, or construction submittal process, with all sections of the FRCS Risk Assessment Questionnaire and a Nessus vulnerability assessment report.

6.7.4.3 Contractors must provide a fully credentialed Nessus scan of the laboratory environment utilizing the DoD policy template with the submission. In addition, Nessus scans shall be provided within ten (10) days of a request from the Government POC to ensure a continuous monitoring program. Nessus scanner must be procured by the contractor, at their own cost, in order to comply with RMF requirements. The contractor shall request the latest versions through the CO.

6.7.4.4 Contractors shall notify the assigned Government POC FRCS analyst of any updates/changes to the system and attain Government approval from the Military Treatment Facilities (MTFs) Change Control Board prior to installation. This should include operating system updates/patches; contractor application and database upgrades, updates, and patches; other software/firmware updates/patches; and addition/removal of components.

6.7.4.5 The contractor shall comply with DoDI 8500.01 Cybersecurity, Enclosure 3, paragraph 9.b.(11), requiring all cybersecurity products and IA-enabled products that require use of the product’s cybersecurity capabilities will comply with the evaluation and validation requirements of Committee on National Security Systems Policy 11, National Policy Governing the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .