D.1 STATEMENT OF WORK.pdf
PDF 257 KB Posted
- Attached to
- Patient Satisfaction Survey Federal contract opportunity
- Solicitation number
- 36C25723Q0736
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| D.1 SOW Revised.pdf | ||
| D.1 SOW Revised.pdf | ||
| S02 36C25723Q0736 0001.pdf | ||
| S02 36C25723Q0736_.pdf | ||
| D.2 - WAGE DETERMINATION.pdf | ||
| D.3 Attachment 4 - Contractor Rules of Behavior 2019.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK (SOW)
El Paso VAHCS Patient Satisfaction Survey Contract
PART 1: GENERAL INFORMATION
1. Introduction: The Department of Veterans Affairs requires non-personnel services contract to provide the
El Paso Veterans Affairs Health Care System (EPVAHCS) with systematic surveys of patient experiences.
EPVAHCS will develop and implement a process to provide timely, actionable, and accessible patient satisfaction data from the facility to the unit/clinic-level to prioritize improvement efforts throughout the EPVAHCS catchment area. The primary goal is to improve patient satisfaction by having a survey service provide real-time feedback, identify, root cause of dissatisfaction and offer solutions for progress. The EPVAHCS serves more than 30,000 enrolled Veterans residing in the states of Texas and New Mexico.
Health care services are delivered through an integrated system of the EPVAHCS, 4 community outpatient or outreach clinics (CBOCs), 1 Behavioral Health Wellness Center, a 1 Sleep Center.
The service will consist of the utilizing current outpatient satisfaction survey instruments that includes customized questions for each Health Care System as well as questions that permit comparison to other VA, non-VA facilities, and teaching facilities. The primary goal is to improve patient satisfaction by having a service that provides real-time feedback and identifies the root cause of dissatisfaction and offers solutions for progress.
2. Background: A comprehensive outpatient satisfaction measurement service is necessary to successfully meet Veteran expectations as measured by VA Performance Measures and Monitors.
3. Scope: The contractor shall provide all necessary personnel, supervision, labor, equipment, materials, and disposal necessary to perform systematic surveys of patient experience as defined in this Statement of Work except for those items specified as government furnished property and services. The contractor shall perform to the standards in this contract. The primary objective of this contract is to increase patient satisfaction in the EPVAHCS, outpatient clinics and services, by providing clinic staff with real time feedback on patient perceptions that will enable employees to improve their performance and deliver excellent care.
• The Contractor shall provide systematic surveys to key service areas including:
o Customization of survey instrument (from existing vendor surveys and/or CAHPS instruments), including a process for survey administration and collection, o An interactive platform for survey response data that does not require local software installation, o A response data analytics and reporting system, o Support/training/coaching
4. Period of Performance:
• Base Year: 06/01/2023 – 05/31/2024
• Option Year 1: 06/01/2024 – 05/31/2025
• Option Year 2: 06/01/2025 – 05/31/2026
• Option Year 3: 06/01/2026 – 05/31/2027
• Option Year 4: 06/01/2027 – 05/31/2028
5. Specific Tasks and Deliverables:
• Schedule: The Contractor shall contact each patient by the location’s preferred method of delivery.
This contact may occur by text/electronic survey, email, or point in time surveys to patients within 3 business days of receipt of the patient information from EPVAHCS. The contractor will perform all necessary tasks to provide the quarterly reports within 10 days of the end of each quarter.
• Scanned surveys shall be viewable by EPVAHCS staff electronically within 48 hours of receipt of the completed survey.
• Federal Holidays: Contractor shall not be required to perform services on Holidays (and any other day specifically declared by the President of the United States to be a national holiday).
New Year’s Day 1 January* Martin Luther Kind, Jr. Day 3rd Monday in January President’s Day 3rd Monday in February Memorial Day Last Monday in May Juneteenth Day 19 June* Independence Day 4 July* Labor Day 1st Monday in September Columbus Day 2nd Monday in October Thanksgiving Day 4th Thursday in November Veterans Day 11 November* Christmas Day 25 December* o *Note if the Holiday falls on a Saturday or Sunday, then our office is closed on the closest weekday
(Friday or Monday).
o Service Point of contact (POC): The responsibilities of the person named as the COR will be explicitly stated in the COR Delegation of Authority memorandum to be issued at time of award.
• The Contractor must use collected data to benchmark using information gathered from other health care institutions that use the same survey instruments. The service must include a point in time (kiosk) survey tool that allows for immediate feedback (within 24 hours), accessible through an on-line Contractor portal. The database used must include information gathered from both commercial and VA hospitals, including the University Health Consortium teaching facilities and must allow for inclusion of customized questions for each location. This service must fulfill the American Nurses Credentialing Center (ANCC) guidelines for survey instruments that allow for hospitals to achieve Magnet Status.
Guidance given on the ANCC website states that hospitals should “choose the highest quality tool that is statistically significant, at the broadest level nationally, with largest cohort to get the greatest comparative value.” Contractors must ensure all survey benchmarking, reporting, and analysis will allow Hospital to acquire/maintain Magnet Status. The results will be used to gain insight on the opinions of veterans who use our services. The information will include a detailed, comprehensive assessment of patient satisfaction within EPVAHCS.
• Assembly of data collected, and professional analyses of the data is included in the services. The
Contractor will provide quarterly reports of patient satisfaction in written form, also available through Contractor on-line web portal, within 10 days of the end of each quarter for each facility. The information will include quarterly comprehensive, detailed assessments of our patient’s experiences while they are served at individual the medical center and clinics. The quarterly reports will also include a summary for all outpatient clinics and services, department surveyed. A sample of the quarterly report must be included the Contractor’s proposal. The on-line web Contractor portal must allow for the creation of customized Ad Hoc reports created by EPVAHCS staff using collected data EPVAHCS outpatient clinics and services. They require full customization and specialty comparisons, including detailed findings and a full set of data queries available on-line and in hard copy.
• The Contractor will provide the ability to query on-line data to evaluate satisfaction of services by stop code, patient care unit, site/specialty, survey receipt date, dates of services clinician, and demographics in a timely manner. Government is not allowed to download a Contractor program to our information technology network.
• Specific deliverables are as follows:
o Type setting of EPVAHCS outpatient clinics and services, with customized questions for each facility location. Survey questions must be approved by each participating facility prior to distribution.
o Conduct patient experience surveys for Medical Practice (Primary Care and Specialty Care) of 507 providers through text/electronic survey.
o Conduct patient experience surveys for Outpatient Behavioral Health of 85 providers through text/electronic survey.
o Provide estimated 200,000 text/electronic surveys to Ambulatory Surgery over the life of this requirement.
o Digital surveying o Scanning of all surveys for daily viewing by selected EPVAHCS staff o Contractor on-line web portal that allows for the creation of customized Ad Hoc reports created by
EPVAHCS staff using collected data and Contractor created quarterly reports o Access to program for on-line data analysis of EPVAHCS patient data by defined queries o A survey tool that measures patient satisfaction with the following indices:
Front-line staff courtesy and helpfulness Scheduling ease and accuracy Speed of registration process and length of wait Nursing staff (LPN, RN) courtesy Provider courtesy, quality of explanations, amount of face-to-face time with patient Office operations (hours of operations, cleanliness, etc.)
Sensitivity to the patient’s needs (scheduling, privacy concerns, convenience of office hours) Ability to add custom questions to the survey tools for each location o On-line and/or in person education sessions/training for staff working with the program and accessing the data and reports.
o Unlimited customer service phone support during business hours o Patient comments will be transcribed verbatim and available to EPVAHCS via the Contractor on-line portal
6. Schedule for Contract Tasks and Deliverables:
• The Contractor will be expected to contact each patient by the location’s preferred method of delivery.
This contact may occur by text/electronic survey, email, or point in time surveys to patients within 3 business days of receipt of the patient information from EPVAHCS. The contractor will perform all necessary tasks to provide the quarterly reports within 10 days of the end of each quarter. Scanned surveys can be viewed by EPVAHCS staff electronically within 48 hours of receipt of the completed survey.
• Method of Evaluating Deliverables:
o EPVAHCS medical center staff will evaluate all deliverables and review the resulting data. These reviews will involve scrutiny of the data, viability of the information, and utility of the service in helping improve service to our veterans, as well as the concurrence and/or changes required to proceed with the work as noted in the contractor’s submissions. EPVAHCS staff will access the clinic account that checks the number of names/contacts sent from the outpatient clinics and services to the number of surveys delivered, and analyze data from returned and processed surveys.
o Part III: Miscellaneous Place of Performance: Analysis and input of all survey data will be performed by the Contractor at their respective work site.
Period of Performance: The term of the resulting contract will be active for one year. Four option years are to be included.
Government Furnished Property: Government furnished property will not be provided to the contractor. All equipment required by the contractor will provided at their expense.
Qualification of Key Personnel: Vendor key personnel involved in execution of the surveying service will be required to demonstrate appropriate knowledge, experience, and expertise regarding survey methodology and data analysis. Key personnel will also be required to participate and pass a Government administered security review.
7. Key Personnel and Temporary Emergency Substitutions
• During the first ninety (90) days of performance, the Contractor shall make NO substitutions of key personnel unless the substitution is necessitated by illness, death, or termination of employment. The Contractor shall notify the Contracting Officer, in writing, within 15 calendar days after the occurrence.
• The Contractor shall provide a detailed explanation of the circumstances necessitating the proposed substitutions, complete resumes for the proposed substitutes, and any additional information requested by the Contracting Officer. Proposed substitutes shall have comparable or better qualifications to those of the persons being replaced. The Contracting Officer will notify the Contractor within 15 calendar days after receipt of all required information of the decision on the proposed substitutes. The contract will be modified to reflect any approved changes of key personnel.
PART 2: GENERAL/TECHNICAL REQUIREMENTS
1. General Requirements:
• The contractor shall provide a project management plan with their solicitation that will include, but is not limited to:
o work breakdown structure, o schedule, o risk management plan, o configuration management plan, o implementation plan, o information security/privacy plan, o training/coaching plan, o quality assurance and control plan, o transition plan, o close-out plan.
• Any solution that is proposed by the contractor must be based on a Commercial off-the-shelf (COTS) platform (or cost-effective customized platform) that can be customized for specific needs.
• The platform(s) shall be hosted by the contractor’s server(s).
• Any system maintenance shall be performed outside of business hours.
• The expected volume of individuals to be surveyed at full implementation is estimated to be approximately 40,000 per year based on volume of eligible encounters.
• Benchmarking capabilities within the healthcare industry
• The contractor shall have the ability to administer surveys in multiple languages.
• On-line and/or in person education sessions/training for staff working with the program and accessing the data and reports.
• Unlimited customer service phone support during business hours.
2. Technical Requirements:
• The Contractor will provide all services associated with preparation, distribution and collection of the survey instruments and data. The contractor will be expected to use quantitative and qualitative data analyses in accomplishing the tasks and provide quarterly written reports which will include action plans and recommendations to improve patient satisfaction. The Contractor must make information available through a Contractor on-line web portal.
• A sampling of the patient population to ensure statistical significance will be surveyed at each outpatient clinic; however, an individual patient that has visited an outpatient clinic within one year of each other will not be surveyed again in the same time frame.
• Up to 25% increase in the number of patients that require survey services may occur during the anticipated 5-year contract period. The historical number of unique patients and clinics follows for the 8 separate EPVAHCS locations follows.
3. Systematic Survey Development:
• The Contractor shall provide a systematic process based on industry standards to survey patients, family members and Care Givers regarding their healthcare experience. The Contractor shall propose existing surveys, including the use of CAHPS-based tools where applicable. The Contractor solution shall provide:
o The ability to add VA specific questions.
o The ability to modify survey tool(s).
o The ability to collect, input and report comments (free text) from respondents.
4. Systematic Survey Platform:
• The Contractor shall provide a platform based on COTS industry standards to allow collection of respondent’s healthcare experience. As part of the platform, the Contractor solution shall provide:
o The ability to administer surveys through multiple modes of collection (e.g., phone, email, text/electronic survey).
o A process to contact the respondent within 3 business days of obtaining the list of potential respondents.
o Rigorous quality assurance and quality control processes on sampling, response collection, mailing, data entry, and reporting.
o Survey responses shall be uploaded into a vendor-managed database within 3 business days of response receipt to be accessed by the Government (see Section 5 below for more details).
o The vendor-managed database system will be refreshed at least daily to display newly received responses.
5. Systematic Reports and Analytics:
• The Contractor shall provide the assembly and professional analysis of the data collected.
• The Contractor shall provide quarterly reports of patient satisfaction in written form, also to be available through the Contractor online web portal within 10 days of the end of each quarter.
Information includes, but is not limited to:
o Comprehensive, detailed assessments of patient experience(s) at VA facilities.
o Summary of all outpatient clinics and services.
o The Contractor shall provide an online web portal with the ability to query online data to evaluate satisfaction of services by patient care unit, site/specialty, survey receipt date, date(s) or service(s), clinician, and patient demographics in a timely manner.
o The Government is not allowed to download a Contractor program to our information technology network.
• The Contractor provided online web portal will allow reporting process of real-time, on-demand, 24/7 accessible data that includes:
o Benchmarking (i.e., a system that compares) with non-VA and other VA hospitals o Benchmarking data that is updated at least every 6 months o Aggregated standard summary reports (we will need to define what this means) by facility, division, and a work unit levels (in accordance with VA-provided Organization Charts), o Access rights and restriction permissions for VA employees (as designated by Government), o The ability for VA staff to customize and generate Ad Hoc reports according to selected parameters, e.g., work unit, facility, gender, respondent type, etc., o The ability to drill down on individual survey responses, o The ability to extract the raw data into Microsoft Excel and Comma-Separated Values formats, o The ability to trend and compare the data over a specific time period (i.e., day, week, month, year, etc.), o A “dashboard” capability that provides an overview of aggregated and ranked scores, with the ability to drill down to specific parameters, and o A process to survey the respondent within 3 business days of obtaining the list of potential respondents.
6. Evaluation of Deliverables:
• EPVAHCS staff will evaluate all deliverables and review the resulting data.
• Reviews shall involve close scrutiny of the data, viability of the information, and utility of the service in helping improve service to our veterans, as well as the concurrence and/or changes required to proceed with the work as noted in the contractor’s submissions.
• EPVAHCS staff will access the clinic account that checks the number of names/contacts sent from the outpatient clinics and services, compare to the number of surveys delivered, and analyze data from returned and processed surveys.
7. The Role of the Government will include:
• Dedicate FTEE at each site to coordinate the patient experience program including interfacing with the Contractor and working with government teams to make data-driven improvements
• Use robust in-house qualitative approaches to complement surveys
• Standardize data review and reporting structure of results
• Share information with patients and families in a standardized manner
8. Quality Control:
• The contractor shall develop and maintain an effective quality control (QC) program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract and shall be submitted for review upon request.
9. Quality Assurance:
• The government shall evaluate the contractor’s performance under this contract in accordance with the established procedures. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards and defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
10. Post Award Conference/Periodic Progress Meetings:
• Post-Award Kick-Off Meeting shall be scheduled for no later than 10 business days after award.
Attendance shall be via telephone and include the CO, Service POC, and contractor POC and other relevant personnel.
• The Contractor shall attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5.
• The Contracting Officer, Service Point of contact (POC), and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the Contracting Officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues.
• These meetings shall be at no additional cost to the government.
11. Data Rights:
• The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government.
• These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer.
• All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose.
• This right does not abrogate any other Government rights.
12. Security:
• All information must be safeguarded according to all federal, state, and local guidelines.
• VA Directive and Handbook, 6500 Managing Information Security Risk: VA Information Security
Program; VA Directive 6515, Use of Web-Based Collaboration Technologies; and VA Directive 6102, Internet, and Intranet Services, shall be in compliance prior to activating any web portal.
13. Reporting:
• Routine communication between the Contractor and the Government will be through the service point of contact (POC).
• The POC shall work with EPVAHCS staff to determine completeness of the reports. EPVAHCS staff will review the quarterly reports and notify the POC of any discrepancies or issues.
• The Contractor’s Project Manager will be available to address areas of concern as needed when directed by the Contracting Officer.
• The Service POC is not authorized to change any of the terms and conditions of the resulting order.
o The Service POC shall monitor all technical aspects of the contract and assists in contract administration o The Service POC is authorized to perform the following functions:
Assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance.
Maintain written and oral communications with the Contractor concerning technical aspects of the contract.
Issue written interpretations of technical requirements.
Monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies.
Provide site entry of Contractor personnel.
Attachment A
VA information should not be co-mingled, if possible, with any other data on the contractors/ subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s QASP - Performance Monitors:
The Government shall use the standards below to determine contractor performance and shall compare contractor performance to the Acceptable Quality Level (AQL) in our Quality Assurance Surveillance Plan
(QASP).
Task Indicator Standard Acceptable
Quality Level
Incentive / Disincentive
Patient Satisfaction
Patient satisfaction reports are sent via text/electronic survey
Patient satisfaction reports are sent out within 3 business days of receipt of patient file data 95% Past
Performance
Real-time feedback Surveys received by patients will be scanned and analyzed within 48 hours 95% Past
Performance
Quarterly reports The contractor provides quarterly reports within 10 days of the end of the quarter 95% Past
Performance
Attachment B
VA Information and Information System Security/Privacy Language for Inclusion into Contracts, as Appropriate
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
b. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
c. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
d. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
2. VA INFORMATION CUSTODIAL LANGUAGE
a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
b. sanitization requirements. VA reserves the right to conduct on-site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations, and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations, and policies in this contract.
e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
g. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
i. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA Contracting Officer for response.
j. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/ subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA Contracting Officer for response.
k. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/ subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.
3. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks.
This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.
b. Adequate security controls for collecting, processing, transmitting, and storing of Personally
Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
c. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.
d. The contractor/subcontractor’s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA Contracting Officer and the ISO for entry into VA’s POA&M management process. The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.
e. The contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.
f. VA prohibits the installation and use of personally owned or contractor/subcontractor owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW, or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.
g. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.
h. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.)
with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:
1) Vendor must accept the system without the drive;
2) VA’s initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or
3) VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.
4) Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then:
a) The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact.
b) Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be preapproved and described in the purchase order or contract.
c) A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed.
The ISO needs to maintain the documentation.
4. SECURITY INCIDENT INVESTIGATION
a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.
b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
c. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach.
Notifications need to be made in accordance with the executed business associate agreement.
d. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
5. LIQUIDATED DAMAGES FOR DATA BREACH
a. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.
b. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the
Security Incident Investigation section above. Upon such notification, VA must secure from a non- Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.
c. Each risk analysis shall address all relevant information concerning the data breach, including the following:
1) Nature of the event (loss, theft, unauthorized access);
2) Description of the event, including:
a) date of occurrence;
b) data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;
3) Number of individuals affected or potentially affected;
4) Names of individuals or groups affected or potentially affected;
5) Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;
6) Amount of time the data has been out of VA control;
7) The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);
8) Known misuses of data containing sensitive personal information, if any;
9) Assessment of the potential harm to the affected individuals;
10) Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy
Incidents, as appropriate; and
11) Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.
d. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $202 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:
1) Notification;
2) One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;
3) Data breach analysis;
4) Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;
5) One year of identity theft insurance with $20,000.00 coverage at $0 deductible; and
6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.
6. SECURITY CONTROLS COMPLIANCE TESTING
On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract. With 10 working-days’ notice, at the request of the government, the contractor must fully cooperate and assist in a government-sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.
7. TRAINING
a. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
1) Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;
2) Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;
3) Successfully complete the appropriate VA privacy training and annually complete required privacy training; and
4) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the Contracting Officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]
a. The contractor shall provide to the Contracting Officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
b. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.
File details come from the government source that posted it. Updated .