CPI-393-2019-0173_SOW_COTS_Software_Pilot_Support_Services.docx
DOCX document 10 MB Posted
- Attached to
- Data Governance/Management COTS Software Pilot Support Services Federal contract opportunity
- Solicitation number
- CPI-393-2019-0173
About this file
Statement of Work for COTS Software Pilot Support Services
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment J-1
Department of Health and Human Services (HHS) Centers for Medicare & Medicaid Services (CMS) Center for Program Integrity (CPI) Division of Analytics and Systems Group (DASG)
Section C – Description of Requirements / Specifications / Statement of Work (SOW)
Metadata Management & Data Governance (DM/DG) COTS Software Pilot and Support Services Contract
Version 3.0 June 11, 2019
INFORMATION NOT RELEASABLE TO THE PUBLIC UNLESS AUTHORIZED BY CONTRACTING OFFICER:
This information has not been publicly disclosed and may be privileged and confidential. It is for internal government use only and must not be disseminated, distributed, or copied to persons not authorized to receive the information.
SOURCE SELECTION INFORMATION (See FAR 2.101 and 3.104)
Table of Contents
| 1. | Purpose | 4 |
| 2. | Background | 4 |
| 2.1 Current Environment | 5 | |
| 2.2 Concept and Context | 5 | |
| 3. | Scope | 7 |
| 3.1 | Performance Objectives | 8 |
| 3.2 | Project Timeframe | 8 |
| 3.3 | Assumptions and Constraints | 8 |
| 3.3.1 | Assumptions: | 8 |
| 3.3.2 | Constraints: | 9 |
| 3.3.3 | Risks: | 9 |
| 4. | Description of Requirements | 9 |
| 4.1 Task 1 – Project Management | 10 | |
| 4.1.1 | Contractor Organization | 10 |
| 4.1.2 | Project Management Plan | 10 |
| 4.1.3 | Kickoff /Post-Award Meeting | 11 |
| 4.1.4 | Coordination with CMS and other CMS Contractors | 11 |
| 4.1.5 | Status Meetings and Reports | 11 |
| 4.2 | Task 2 – General IT Requirements | 12 |
| 4.3 | Task 3 – COTS Software License Procurement | 13 |
| 4.4 | Task 4 – COTS Software Professional Services Support | 13 |
| 4.5 | Task 5 – COTS Software User Training | 14 |
| 5. | Deliverables and Schedule | 14 |
| 6. | Performance Standards, Quality Assurance, and Monitoring | 18 |
| 7. | Government Furnished Information and Property | 18 |
| 7.1 | Information | 18 |
| 7.2 Equipment | 18 | |
| 7.3 Access to Systems and Facilities | 19 | |
| 8. | Other Compliance Requirements | 19 |
| 8.1 | Key Personnel | 19 |
| 8.2 | Period of Performance | 20 |
| 8.3 | Place of Performance | 20 |
| 8.4 | Hours of Operation/Location | 20 |
| 8.5 | Financial Reports | 20 |
| 9. | Security and Privacy and/or Legislative and Executive Mandates, Regulations, and Guidance | 21 |
| 9.1 | CMS Information Security (APR 2013) and Audits | 21 |
| 9.2 | Section 508 – Accessibility of Electronic and Information Technology | 22 |
| Appendix A: Reference Documents | 26 | |
| Appendix B: Abbreviations and Acronyms | 27 | |
| Appendix C: Record of Changes | 28 | |
| Appendix D: Approvals & Signatures | Error! Bookmark not defined. |
List of Figures and Tables
Figure 1: Context Diagram: Data Catalog and Data Governance (DG) Dependencies 6
| Table 1: SOW Scheduled Deliverables | 17 |
| Table 2: Service Level Agreement (SLA) | 18 |
| Table 3: SOW Key Personnel | 19 |
CMS SOW - Attachment J
DASG DM/DG COTS Pilot - Statement of Work (SOW) v3.0 Page 6 of 28
1. Purpose The purpose of this requirement is to acquire and deploy a commercial-off-the shelf (COTS) Metadata Management and Data Governance software solution, consultation services and software user training necessary to support the Data and API strategies of the Centers for Medicare & Medicaid Services (CMS) Center for Program Integrity (CPI) Data Analytics and Systems Group (DASG).
The Contractor, acting independently and not as an agent of the government, shall furnish all the necessary services, qualified personnel, material, equipment, supplies, and facilities except as otherwise specified herein, and otherwise do all things necessary for or incident to performance of requirements described in this work statement, also referred to as the Contractor’s Statement of Work (SOW).
2. Background
The Center for Program Integrity (CPI) Data Analytics and Systems Group (DASG) manages multiple information systems that are critical to the integrity and detecting fraud, waste and abuse (FAW) within the Medicare program. At CPI, information is vital not only for ensuring normal business operations but also for enabling new program integrity opportunities. In order for CPI business to deliver consistently good results, its data must be managed consistently across applications, well understood, accurate and its use governed through policy and monitoring.
To facilitate the realization of CPI’s mission, DASG has embarked on establishing a data strategy initiative to define the approach that will be taken to manage and use its provider related data and information assets to achieve its business and technology goals. The DASG baseline data strategy will incorporate and operationalize the following data strategy key components:
· Construct well-defined goals and data management practices for data assets under DASG management control,
· Define guiding principles, values and management perspectives to address various business use cases,
· Define data management and strategy metrics and measures of success,
· Meet short and long-term CPI program and project objectives, and
· Articulate defined and well understood data governance roles and responsibilities.
By investing in a Metadata Management and Data Governance system that supports the DASG Data and API strategies, CMS expects a range of benefits, including but not limited to, enhanced data insights and business value, alignment of data requirements with organizational strategic goals, improvement and simplification of the current as-is data landscape, improved data sharing capabilities, rationalization of reporting requirements across DASG information systems and the promotion of stakeholder and data stewardship engagement.
More detailed information about CMS PI activities is available at www.cms.gov; fighting Medicare Fraud, https://www.medicare.gov/forms-help-resources/help-fight-medicare-fraud ; the CMS Internet-Only Manual Publication 100-08, Medicare Program Integrity Manual (PIM); and CMS Internet-Only Manual Publication 100-15, Medicaid Integrity Program (MIP).
2.1 Current Environment
DASG is currently responsible for the oversight and management of approximately twelve (12) information systems and the corresponding data assets/artifacts generated by these systems. These information systems span multiple CMS on-premise and cloud hosted data centers and are supported by a number of different database management systems (DBMS) platforms, Business Intelligence (BI) reporting tools, Extract Transform Load (ETL) tool suites as well as a variety of real-time, near real-time and batch data exchange protocols. In most cases, these systems do not follow a common set of data/metadata standards, formats, structures, data management or data governance practices.
Currently there is a lack of awareness among the analytics users, business owners and system maintainers about the various data assets available to users or guidelines on how to use them. There is also considerable data duplication across information systems due to data exchanges that were established over time, which only adds to the confusion about the underlying purpose of each set of data and the actual source of truth.
In addition to supporting today’s needs, the data needs to be ready to support the next generation of tools and techniques such as advanced predictive analytics, machine learning (ML), and artificial intelligence (AI) which will empower future program integrity efforts at CPI.
2.2 Concept and Context
CPI requires a real-time, accurate picture of its data landscape, including “data at rest” in databases, data warehouses and data lakes and “data in motion” as it is integrated with and used by key applications. Consistent and structured control of the data landscape is necessary to facilitate collaboration and limit risk. In order to accomplish this goal, an automated approach to two data disciplines is required: Data Management and Data Governance. Figure 1 is a context diagram of the dependencies of these two disciplines and what CPI’s data strategy must incorporate and support.
Figure 1: Context Diagram: Data Catalog and Data Governance (DG) Dependencies
DATA MANAGEMENT (erwin.com Inc, 2019) From a data management perspective, knowing what data exists and where it lives is complicated. An enterprise-wide view of and easy access to underlying metadata must be created and sustained, but that’s a tall order with numerous data types and data sources that were never designed to work together and data infrastructures that have been cobbled together over time with disparate technologies, poor documentation and little thought for downstream integration. Information systems and initiatives that depend on a solid data infrastructure may be compromised, and analysis of data can result in faulty insights. These issues can be addressed with a strong data management strategy and technology to enable the data quality required by the business, which encompasses data cataloging (integration of data sets from various sources), mapping, versioning, business rules and glossaries maintenance and metadata management (associations and lineage).
DATA GOVERNANCE (erwin.com Inc, 2019) Being able to pinpoint what data exists and where must be accompanied by an agreed-upon business understanding of what it all means in common terms that are adopted across the enterprise. Having that consistency is the only way to assure that insights generated by analyses are useful and actionable, regardless of business department or user exploring a question. Additionally, policies, processes and tools that define and control access to data by roles and across workflows are critical for security purposes. These issues can be addressed with a comprehensive data governance strategy and technology to determine master data sets, discover the impact of potential glossary changes across the enterprise, audit and score adherence to rules, discover risks, and appropriately and cost-effectively apply security to data flows, as well as publish data to people/roles in ways that are meaningful to them.
An automated, real-time, high-quality data pipeline is established for all stakeholders, and it serves as a key element for standing up data governance in agile, efficient and cost-effective ways. Data scientists, data stewards, data governance council members, ETL developers, enterprise architects, business analysts, compliance officers, executive leadership can access the data they’re authorized to use and base strategic decisions on what is now a full inventory of reliable information.
To achieve this goal, DASG intends to purchase, deploy and configure the following COTS software suite of products from erwin.com Inc.:
· erwin Mapping Manager – Permits ingestion, data governance and oversight of metadata associated with cataloged data assets,
· erwin Glossary Manager – Permits ingestion, data governance and oversight of business define terms and relationships with cataloged data assets,
· erwin Business User Portal – Provides read-only access to data catalog and business glossary to business and non-technical stakeholder
· Business Intelligence (BI) Connectors – Permits ingestion of metadata associated with standard BI reporting tools such as Cognos, Business Objects, MicroStrategy, etc.
· Extract, Transform and Load (ETL) Connectors – Permits ingestion of metadata associated with ETL tools such as Informatica, IBM Data Stage, Teradata BTEQ, etc.
Additionally, CMS personnel will require technical and training support to provide the proper oversight and management of this software suite.
3. Scope
The scope of this project shall include the following items and activities performed by the Contractor:
· The Contractor shall procure all required licenses for the ERwin COTS products as part of the cost of the pilot project.
· The Contractor shall provide professional services support in deploying and configuring the COTS products in a designated CMS hosted environment (i.e. on-premise, virtual or AWS). CMS expects the COTS products will require customization, configuration and integration of other COTS-based products to perform access management, workflow processing, database management, reporting and allow for the data exchange and ingestion of metadata with other CMS systems.
· The Contractor shall provide a pre-designated amount of professional services support to assist CMS with implementing its data management and governance framework within the software tool suite.
· The Contractor shall provide software user training to designated CMS personnel responsible for providing oversight and management of the software tool suite.
3.1 Performance Objectives
The Contractor shall meet the following critical success factors in service to the overall performance objectives for the project:
· The Contractor shall ensure that the installed COTS software products meet or exceed all functionality requirements defined in the CMS software evaluation criteria as provided to the Contractor,
· The Contractor shall ensure that the installed COTS software products are technically sound, provide acceptable system performance and application security, and is stable and available to users in a designated CMS environment,
· The Contractor shall provide the necessary technical support and software training services to enable CMS staff to effectively ingest a pre-defined set of data assets and to automate pre-designated data governance processes as defined by CMS.
3.2 Project Timeframe
The pilot will be implemented between August 1, 2019 and July 31, 2020.
3.3 Assumptions and Constraints
It is important that the contractors and CMS have a common understanding regarding the conditions on which we shall build our relationship. The following subsections identifies the basic assumptions, constraints and risks concerning this effort.
3.3.1 Assumptions:
CMS has identified the following assumptions concerning this effort:
· All products, including software licensing and all utilities (proprietary and non-proprietary) developed to support the activities and deliverables of this contract, are the property of CMS.
· The software licensing is based on a 1-year subscription including all subsequent software upgrades/fixes, technical customer support within the designated subscription period.
· The software licensing shall support up to 5 CMS designated administrative users and up to 50 read-only Business Portal users.
· CMS will provide the necessary infrastructure and infrastructure contractor support to deploy and configure the licensed COTS software in a CMS approved environment. As such, the software and any components must be compliant with deployment requirements identified in CMS’s 3-tier architecture as defined in the CMS Technical Reference Architecture (TRA) documentation.
· The licensed software will not be installed or deployed in any CMS production environment which will render an Authorization to Operate (ATO) unnecessary.
· Where timeframes are stated, CMS may choose to give consideration to unforeseen circumstances. Therefore, deliverable due dates are as stated unless otherwise agreed to by CMS and the Contractor. Throughout the document, unless specifically denoted as workday(s), all timeframes are in calendar days, calendar weeks and calendar months,
3.3.2 Constraints:
CMS has identified the following constraints concerning this effort:
· The COTS software products will only be accessible through CMSNet via approved, dedicated connections or VPN.
· The CMS Technical Review Board (TRB) must approve all software and hardware technologies and products selected by CMS before implementation.
· The Contractor shall not have access to PHI/PII or any CMS application data.
· The Contractor shall not be required to have an CMS EUA.
· The Contractor shall not reproduce for private or commercial use any non-public data or other materials furnished to Contractor under this SOW.
3.3.3 Risks:
CMS has identified the following risks concerning this effort:
· Connectivity to other CMS data centers and access to metadata sources that are within the scope of the pilot is critical to the success of the project. Timely access to these artifacts and support from system and infrastructure maintainers across data centers is critical to project success.
4. Description of Requirements The following subsections describe the requirements for the Contractor’s performance of this SOW. The requirements consist of five (5) mandatory tasks and a description of the required capabilities that shall be met by the Contractor for this SOW.
· Task 1 – Project Management
· Task 2 – General IT Requirements
· Task 3 – COTS Software License Procurement
· Task 4 – COTS Software Professional Services Support
· Task 5 – COTS Software User Training
4.1 Task 1 – Project Management
The Contractor shall provide project management support for the project as delineated in the following subsections.
4.1.1 Contractor Organization
The Contractor shall establish and operate a formal organization/team responsible for executing the total effort required by this SOW. The Contractor is responsible for establishing and maintaining a clear line of authority among all Contractor organizational elements under this contract, including subcontractors. The Contractor shall establish and document all roles, responsibilities, and reporting requirements for each organizational element.
4.1.2 Project Management Plan
The Contractor shall perform all project management (PM) duties, including technical and business management functions, in order to plan, implement, track, report, deliver, maintain, support and update the required pilot. The Contractor shall manage all activities in alignment with project management standards defined by the latest publication of the Project Management Institute’s (PMI) The Guide to the Project Management Body of Knowledge (PMBOK®), except where directed otherwise by the CMS Contracting Officer’s Representative (COR). Adherence to a common set of best practice standards for project management will foster effective and integrated planning and control mechanisms and tools, significantly reduce the risk of schedule and cost overruns, reduce the likelihood and impact of negative risks and issues on the project, and increase the ability to communicate and share program implementation information between the Contractor, CMS, and other contractors and stakeholders as appropriate.
The Contractor shall develop and maintain a Project Management Plan (PMP) that describes the Contractor’s overall PM approach. The PMP shall include, at a minimum, the following elements:
· Assumptions and constraints for project management
· Schedule management plan and project schedule
· Human resource management plan, contact lists, organizational structure, organizational elements, and roles and responsibilities of project personnel
· Subcontract management plan, if applicable
4.1.3 Kickoff /Post-Award Meeting
The Contractor shall plan and participate in an initial post-award kickoff meeting between the CO, COR, and other participants identified by CMS. The kickoff meeting will be held at a CMS office located at the CMS Baltimore, Maryland location within ten (10) business days after contract award. At a minimum, the Contractor’s Key Personnel shall attend in person. The Contractor shall introduce its team and present its initial PMP and project schedule to CMS. CMS authorizes the necessary Contractor travel costs associated with the initial kickoff meeting. The Contractor shall include these travel costs in the cost proposal.
4.1.4 Coordination with CMS and other CMS Contractors
The Contractor shall demonstrate independent judgment while maintaining core relationships in a multi-contractor/government environment. The Contractor shall maintain communication and coordination of work with CMS and/or CMS-designated contractors to ensure the successful management of all work required for this contract. The Contractor shall participate in all applicable workgroups that relate to the mission, program, or project, whether these groups currently exist or are formed in the future, as required and agreed to by the COR.
The Contractor shall be proactive in notifying CMS of any developing situation that may impact service delivery or any other contractual issue. The Contractor shall immediately advise CMS of any indication that a potential problem may be developing. The Contractor shall work with CMS to address all risks and identify mitigation strategies. The Contractor shall monitor integration points and interdependencies with external projects or systems and assess impacts of external project interdependencies on the scope and schedule for work required under this contract.
4.1.5 Status Meetings and Reports
The Contractor shall be responsible for participating in project meetings and delivering periodic status reports to CMS. In addition to meetings and reports detailed in other SOW tasks, the Contractor shall:
· Participate in project meetings (by telephone or in person by mutual agreement) with the CMS COR and other CMS representatives and contractors as necessary to discuss current status of the project, key challenges and accomplishments, and upcoming activities,
· Arrange meetings (by phone or in person by mutual agreement) with CMS project stakeholders and contractors, and other CMS representatives as necessary to coordinate the proper workflow of activities to accomplish the SOW performance objectives,
· Develop agendas and electronic post-meeting summary notes for all regularly scheduled and ad hoc critical action meetings. Summary notes should specify critical action steps, outstanding issues, follow-up activities, and decisions, and be distributed to attendees and any CMS-approved distribution list,
· Deliver status and other project reports as directed by the COR.
4.2 Task 2 – General IT Requirements
This section presents the general IT requirements for performance for the pilot project:
1. The Contractor’s activities and deliverables shall comply with the CMS TRA and associated TRA supplements. The Contractor is bound to adhere to only those parts of the CMS TRA that apply to the work under this contract. The Contractor shall also comply with applicable CMS IT policies, procedures, and standards.
1. The Contractor’s activities and deliverables shall comply with CMS XLC Process identified in the Reference Documents, where appropriate.
1. The Contractor’s activities and deliverables shall comply with CMS Data Administration (CDA) and Database Administration (DBA) Standards and Guidelines identified in the Reference Documents, where appropriate and if required by the TRB.
1. The Contractor’s activities and deliverables shall be in accordance with CMS ARS identified in the Reference Documents.
1. The Contractor shall comply with the applicable security requirements related to its operation as defined in the Business Partner System Security Manual (BPSSM) (also known as IOM Publication 100-17) identified in the Reference Documents.
1. The Contractor shall produce all Design, Development, Testing, and Implementation documentation identified in the Deliverables Section of this SOW and in the Project Process Agreement (PPA) for Complexity Level 1 projects.
1. All Contractor personnel shall participate in CMS Information Security Awareness Training unless the following scenario exists:
0. Contractors are not required to have an EUA account if they don't access CMS systems. If they don't have an account, they are not required to take the CMS recertification training. If they do not touch CMS systems CMS does not give them training in the form of the CMS recertification trainings. However, contractors are still required to take Security and role-based training and it's up to the contractor to provide that training and the contractor should be able to provide proof of that training to CMS. This question comes up during the HR interview for all systems. The auditors ask HR, the supporting contractor, to provide proof of annual security, privacy, and role-based training for their employees. The Contractor is required to perform their own internal training.
1. Contractor personnel who are required to obtain a CMS badge shall undergo a background investigation at the Contractor’s expense.
1. The Contractor shall not reproduce for private or commercial use any non-public data or other materials furnished to Contractor under this SOW.
1. CMS retains all property rights, including publication rights, in the information and materials produced by the Contractor in connection with this SOW. Rights to Contractor-produced information and materials shall vest in the government; such information and materials shall include progress reports, XLC documentation, computer software applications/databases, software/ database documentation, plans, systems analyses, reports, extracts, test data and procedures, and output reports.
4.3 Task 3 – COTS Software License Procurement
This section presents the requirements for the COTS software licensing for the designated period of performance for the pilot project:
· The Contractor shall provide a 1-year subscription to the designated product software licensing and any utilities (proprietary and non-proprietary) on-going software maintenance covered under the subscription period and developed to support the activities and deliverables of this contract. The designated product software licensing shall include the following procurement:
1. erwin Mapping Manager
2. erwin Glossary Manager
3. erwin Business User Portal
4. Configurable Business Intelligence (BI) Connectors for standard BI reporting tools for Cognos, Business Objects, and MicroStrategy as deployed in designated CMS application environments.
5. Configurable Extract Transform and Load (ETL) Connectors – for Informatica PowerCenter, IBM Data Stage, and Teradata BTEQ as deployed in designated CMS application environments.
· The Contractor shall provide software licensing necessary to support up to 5 CMS designated administrative users and up to 50 read-only Business Portal users.
4.4 Task 4 – COTS Software Professional Services Support
This section presents the requirements for the COTS software professional services support for the designated period of performance for the pilot project:
· The Contractor shall provide at a minimum 5 days of on-site or remote software installation support services and deployment plan to enable a successful deployment of all designated software components.
· The Contractor shall provide an additional 30 days of on-site or remote configuration and implementation support services and plan necessary to facilitate the successful ingestion of CMS designated data assets.
· The Contractor shall collaborate with the designated CMS infrastructure data center personnel and designated pilot project team member(s) as needed.
4.5 Task 5 – COTS Software User Training
This section presents the requirements for the COTS software user training support for the designated period of performance for the pilot project:
· The Contractor shall provide CMS on-site or virtual instructor-led training as agreed upon with the CMS designated project team.
· The Contractor shall provide a training curriculum(s) that includes the following items: training pre-requisites, training objectives, training audience, training topics covered and training duration.
· The Contractor shall deliver the training as part of the 30-day configuration and implementation support services period.
5. Deliverables and Schedule The Contractor shall submit all required reports and deliverables in accordance with the schedule set forth in Table 1.
Draft/Final: All document deliverables require both a Draft and a Final version (see Delivery Schedule). The Final copy shall be a submission of the full document with all CMS comments resolved. The deliverable cover page shall be clearly marked Draft or Final.
Updates: Many of the deliverables require the Contractor to provide updates. Unless otherwise specified, the Contractor shall notify CMS when it foresees a change to the content and then provide a document update based upon CMS-approved content revisions and a mutually agreed upon delivery date. All documents shall contain a date and a version number. The Contractor shall maintain and keep all documents current.
Monthly Reports: The data collection period for each monthly report shall be based on a whole month (e.g., April 1 through April 30). The Contractor shall ensure that the data in the recurring monthly reports are accurate and consistent with one another and shall ensure that each monthly report also incorporates any subcontractor’s data for the same period.
Ad Hoc: The Contractor shall provide ad hoc documentation at CMS’ request.
The contractor must provide a draft product. If the product is provided after the due date, then the product is deemed “late”. CMS has 10 business days to provide comments unless otherwise deemed noted in the IMS. If no comments are received, then the product is deemed “accepted” and a final version does not have to be provided. If comments are provided by CMS, then the previously submitted product remains a draft version. The contractor then has five (5) business days to revise the product and provide a final version. If the contractor does not submit a revised version of the product within five (5) business days, then the product will be deemed “late”.
After receipt of the final version of the product CMS will have three (3) business days to accept or reject the product. If CMS does not provide any comments or feedback after three business days, then the final version of the product is deemed “accepted”; however, if CMS provides comments after receipt of the final version of the product, it is deemed “rejected”, and the contractor must make corrections and resubmit.
Where timeframes are stated, CMS may choose to give consideration to unforeseen circumstances. Therefore, deliverable due dates areas stated unless otherwise agreed to by CMS and the Contractor. All timeframes are in calendar weeks, calendar months, or calendar days.
For the structure of the deliverables, the Contractor’s format shall use the CMS standard desktop suite (i.e. Microsoft Office). Deliverables shall be distributed as follows: to the CMS Contracting Officer (CO), transmittal letter only; CMS COR/Government Task Leader, one (1) soft copy via email or as mutually agreed.
In performing the services and providing the support described in the SOW, the Contractor shall provide the deliverables NO LATER THAN the dates in the following schedule and within the period of performance:
· Days = Calendar Days
· IAW = In Accordance With
· DAGC = Days After Government Comments
No.
Item Description
SOW
Reference (Section)
Delivery Sequence
| 1 |
| Project Process Agreement (PPA) and Project Management Plan (PMP) and updates. |
| 4.1.2 |
4.2 Draft: 10 days after award Revised: As agreed with upon by COR Final: 5 days after review and approval by COR and designated pilot project team
| 2 |
| Microsoft Project 2010 or higher schedule and updates including percent completion, planned start and finish dates, and baseline variance for key tasks, deliverables, and milestones (an integrated project plan is expected to include required tasks of other system development stakeholders (i.e. Infrastructure contractor, CMS Shared Services). |
| 4.1.2 |
| Draft: 10 days after award |
Revised: As agreed with upon by COR and pilot project team.
Final: 5 days after review and approval by COR and designated pilot project team
| 3 |
| Risk Register, Issue List, Action Items, Decision Log, Lessons Learned Log |
| 4.1.2 |
| Draft: 10 days after award |
Revised: On-going as agreed with upon by COR and pilot project team.
Final: 5 days after review and approval by COR and designated pilot project team
| 4 |
| Meeting materials for Monthly Performance Reviews / Management Review Meetings |
| 6.0 |
| Monthly: Meeting materials due NLT ten (10) days before meeting. |
| 5 |
| Monthly Financial Invoice |
| 8/5 |
| Monthly: NLT the 15th of each month. |
| 6 |
| Kickoff Meeting Materials and Meeting Notes |
| 4.1.3 |
| Draft: 3 days after Kick-Off Meeting |
Revised: As agreed with upon by COR and pilot project team Final: Five (5) days after Kick-Off Meeting
| 7 |
| Status Meetings, Meeting Minutes and Reports |
| 4.1.5 |
| Draft: Status Meeting Agenda due 3 days prior to Status Meeting. |
Revised: As agreed with upon by COR and pilot project team.
Final: Status Meeting Minutes and due 5 days after Status Meeting.
| 8 |
| COTS Software Installation Modules & Licensing Agreement |
| 4.3 |
| Final: As agreed with upon deployment date by COR and CMS data center and personnel and designated infrastructure contractor and deployment date. |
| 9 |
| COTS Software Deployment and Configuration Plan |
| 4.4 |
| Draft: 10 days prior to scheduled CMS software deployment date. |
Revised: As agreed with upon by COR and pilot project team.
Final: 5 days prior to scheduled CMS software deployment date.
| 10 |
| COTS Software Training Curriculums and Training Plan |
| 4.5 |
| Draft: 10 days prior to scheduled CMS software training delivery date(s). |
Revised: As agreed with upon by COR and pilot project team.
Final: 2 days prior to scheduled CMS software training delivery date(s).
Table 1: SOW Scheduled Deliverables
6. Performance Standards, Quality Assurance, and Monitoring
CMS and the Contractor will establish service levels and delivery metrics that may be refined and finalized when the COTS software product(s) are initially deployed in a designated CMS data center environment. CMS and the Contractor shall update the criteria for performance, the metrics, and agreed-to targets prior to the award to ensure continuous process improvement and enhancement of the service levels delivered to CMS.
Table 2 presents the government-proposed performance standards and service level metrics to be agreed upon at the time of award.
| Measurement Area |
| Service Level Agreement (SLA) |
| Software Upgrades & Fixes |
| Initial delivery within 5 days of scheduled deployment date. |
Quarterly releases with occasional interim releases as needed.
| Software Installation & Deployment Support |
| As needed, until all software product(s) have been successfully deployed within the designated CMS data center environment. |
| User Training Support |
| Delivered as agreed upon in the software user training plan. |
| Customer Help Desk Support |
| Less than 2 hours for initial response; In most instances, near-immediate response. |
Resolution to issue within 48 hours.
| Management Performance Reviews |
| Monthly recurring meeting with assigned CMS COR to review contract compliance and contractor performance. |
Table 2: Service Level Agreement (SLA)
7. Government Furnished Information and Property
7.1 Information
The government will furnish the following types of Government Furnished Information (GFI) as information becomes available and when applicable to the Contractor’s work requirements:
1. When applicable, application documentation and metadata assets for designated systems with which the Contractor’s solution will ingest and exchange information.
2. When applicable, CMS TRA and all TRA supplements (which are not available on the public web)
7.2 Equipment
The government will furnish the following equipment and software:
1. Hardware and software in the configuration and build specifications that are required to support its software components as defined by the Contractor and as approved by the CMS Technical Review Board and designated CMS infrastructure/data center contractor.
7.3 Access to Systems and Facilities
The government will provide access to the following systems and facilities upon contract award:
1. The government will furnish access to the CPI Command Center or other meeting areas located at the CMS Ambassador Road facility in Baltimore, Maryland to support stakeholder, user meetings and training activities as required under this SOW.
8. Other Compliance Requirements
8.1 Key Personnel
CMS desires a balanced team of key personnel to ensure the successful performance of the operational and technical aspects of the work. The Contractor shall propose appropriate, qualified personnel who shall be designated as “key” and identify the relevant qualifications for these positions. The following positions are hereby designated as “key”:
| Key Personnel Position |
| Position Description |
| Relevant Qualifications |
| Project Manager |
| Provide overall project management responsibility under the SOW |
| · Minimum 5 years project management experience |
| COTS Software Support Engineer |
| Provide installation, deployment and technical software support |
| · Minimum 3 years support of COTS Product Solution(s) |
| COTS Software User Trainer |
| Deliver user training support |
| · Minimum 3 years COTS User Training support |
Table 3: SOW Key Personnel
The Contractor shall dedicate all key personnel as needed to this contract, unless otherwise agreed to by CMS. Key personnel may be assigned to more than one functional area of the SOW, but their time may not exceed one Full-Time Equivalent (FTE).
Any staff identified as key personnel shall have a backup who is properly trained and qualified to act as a fully functioning replacement in the temporary absence of the key person. The COR shall be notified when key personnel are out of the office for an extended period of time, e.g., more than five (5) business days. In these instances, the name and contact information, including telephone number and email address, of the backup shall be provided to the COR prior to the absence of the key personnel.
For this SOW, key personnel shall be assigned for a minimum period of twelve (12) months, barring circumstances outside the control of the Contractor, e.g., death, and disability. Should any key personnel choose to leave for another reason (e.g., higher pay, job dissatisfaction) prior to six (6) months in place on the contract, then any costs associated with either relocation, or replacement shall be the sole responsibility of the Contractor. When key personnel positions are vacated due to unforeseen circumstances, a proposed replacement shall be submitted in writing for approval no later than 30 calendar days from the date the position was vacated. Interim replacements should be identified and approved by CMS when a permanent replacement cannot be identified within the timeframe. CMS may consider a 60-day interim replacement until a permanent replacement is secured.
8.2 Period of Performance
The period of performance for this contract is projected to be 1 base year. The period of performance is as follows:
· Base Period: 08/01/2019 to 07/31/2020
8.3 Place of Performance
All work, with the exception of some meetings as prescribed by CMS, will be conducted either remotely or on-site at a designated CMS facility at the location(s) identified in this SOW.
8.4 Hours of Operation/Location
All work shall be conducted at a designated CMS location during regular business hours excluding federal holidays. Contractor personnel are not allowed to work outside the United States.
The Contractor’s Technical Support Desk shall be made available to designated CMS users from 7:00 a.m. to 6:00 p.m. in the Eastern Standard Time (EST), Monday through Friday, excluding federal holidays.
8.5 Financial Reports
The Contractor shall provide financial reports to reflect the work performed by both the Contractor and any subcontractors under this contract. The Contractor shall provide financial reports to reflect the cost in both hours and dollars of work performed by the Contractor and subcontractors. The Contractor’s financial reports shall include CMS’ Financial Status Report spreadsheet.
The Financial Report shall contain the following sections for both the Contractor and each subcontractor:
1. Contract Name
2. Contract Number
3. Authorized Contractor Representative
4. Period of Performance
5. Contract or Task Order Value
6. Total Amount Billed
7. Total Payment Received
8. Current Month Hours Expended by Service Category:
· Software Licensing Cost
· Professional Service Hours
· Training Service Hours
9. Burn Rate
9. Security and Privacy and/or Legislative and Executive Mandates, Regulations, and Guidance
9.1 CMS Information Security (APR 2013) and Audits
All CMS information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, in order to maintain the security, confidentiality, integrity, and availability of such information. Therefore, if this contract requires the Contractor to provide services (both commercial and non-commercial) for Federal Information/Data, to include any of the following requirements:
· Process any Information/Data; or
· Store any Information/Data (includes “Cloud” computing services); or
· Facilitate the transport of Information/Data; or
· Host/maintain Information/Data (including software and/or infrastructure developer/maintainers); or
· Have access to, or use of, Personally Identifiable Information (PII), including instances of remote access to, or physical removal of, such information beyond agency premises or control, the Contractor shall become and remain compliant with the requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS- Information-Security-Contract-Clause-Provision.html. The requirements cover all CMS contracts and associated deliverables, which are required on a “per contractor” basis.
The Contractor shall ensure that the following Federal information security standards are met for all of its CMS contracts:
· Federal Information Security Management Act (FISMA) – FISMA information can be found at http://csrc.nist.gov/groups/SMA/fisma/index.html. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source; and,
· Federal Risk and Authorization Management Program (FedRAMP) – FedRAMP information can be found at http://www.gsa.gov/portal/category/102371. The FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.
The Contractor shall include in all awarded subcontracts the FISMA/FedRAMP compliance requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security- Contract-Clause-Provision.html.
9.2 Section 508 – Accessibility of Electronic and Information Technology
SECTION 508 - ACCESSIBILITY OF ELECTRONIC AND INFORMATION TECHNOLOGY
(a) This task order is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the workforce Investment Act of 1998 (P.L. 105-220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.
(b) The EIT accessibility standards at 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001.
(c) Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194), as specified in the contract, as a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:
1. Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or
2. In the case of custom Electronic and Information Technology (EIT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant EIT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.
(d) The contractor must ensure that all EIT products that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.
(e) For every EIT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date; whichever shall occur first.
Section 508 Compliance for Communications The Contractor shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW shall take precedence.
Rehabilitation Act, Section 508 Accessibility Standards
1. 29 U.S.C. 794d (Rehabilitation Act as amended)
2. 36 CFR 1194 (508 Standards)
3. The U.S. Access Board’s technical standards
4. FAR 39.2 (Section 508)
5. CMS Standards, policies and procedures (Section 508)
6. Department of Health and Human Services Section 508 policies and standards In addition, all contract deliverables are subject to these 508 standards as applicable.
Regardless of format, all Web content or communications materials produced, including text, audio or video - must conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. All contractors (including subcontractors) or consultants responsible for preparing or posting content must comply with applicable Section 508 accessibility standards, and where applicable, those set forth in the referenced policy or standards documents above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW, shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the content or communications material identified in this SOW:
1. 36 CFR Part 1194.21 a - l
2. 36 CFR Part 1194.22 a - p
3. 36 CFR Part 1194.31 a - f
4. 36 CFR Part 1194.41 a – c The contractor shall provide a completed Section 508 Product Assessment Template (VPAT) which can be found at http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/Section508/Accessibility_Validation.html and the contractor shall state exactly how proposed EIT deliverable(s) meet or does not meet the applicable standards.
The following Section 508 provisions apply for software development material identified in this SOW:
For software development, the Contractor/Developer/Vendor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards:
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards)
a. 36 CFR Part 1194.21 (a – l)
b. 36 CFR Part 1194.31 (a – f)
c. 36 CFR Part 1194.41 (a – c)
(3) http://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-section-508-standards/section-508-standards (508 Standards)
(4) FAR 39.2 (Section 508)
(5) CMS/HHS Standards, policies and procedures (Section 508)
a. Information Technology – General Information
(6) Department of Health and Human Services Section 508 policies and standards
For web-based applications, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards)
a. 36 CFR Part 1194.22 (a – p)
b. 36 CFR Part 1194.41 (a – c)
(3) The U.S. Access Board’s Section 508 Accessibility Standards
(4) FAR 39.2 (Section 508)
(5) CMS Standards, policies and procedures (Section 508)
a. Information Technology – General Information
(6) Department of Health and Human Services Section 508 policies and standards
Appendix A: Reference Documents
The following table summarizes the documents referenced in this document.
| Reference Document |
| Name/Location |
CMS Internet-Only Manual (IOM) Publication 100-08, Medicare Program Integrity Manual (PIM) CMS Internet-Only Manual Publication 100-08, Medicare Program Integrity Manual (PIM)
CMS Internet-Only Manual (IOM) Publication 100-15, Medicaid Integrity Program (MIP)
CMS Internet-Only Manual Publication 100-15, Medicaid Integrity Program (MIP)
| CMS Technical Reference Architecture (TRA) This standard provides the authoritative technical architecture approach and technical reference standards for the CMS Enterprise IT architecture. |
| http://cmsnet.cms.hhs.gov/hpages/oisnew/foffice/ m/TRA.html |
Note: The CMS TRA and all supplements are not available on the public web site and therefore are also listed as GFI.
| Project Management Institute (PMI), A Guide to the Project Management Body of Knowledge (PMBOK) – Sixth Edition |
| https://www.pmi.org/pmbok-guide-standards/foundational/pmbok |
| CMS Expedited Life Cycle (XLC) Process |
| https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/XLC/index.html |
| CMS Data Administration (CDA) and Database Administration (DBA) Standards and Guidelines |
| https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/DataAdmin/index.html |
https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/DBAdmin/index.html
CMS Information Security (IS) Acceptable Risk Safeguards (ARS)
This document provides guidance to CMS and its Contractors as to the minimum level of required security controls that they must implement to protect CMS information and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.