DRAFT CP3 Addendum to 52.212-4.pdf
PDF 364 KB Posted
- Attached to
- MHS EITS Geographic Service Provider (GSP) Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Defense Health Agency
About this file
This special notice document provides information on the Military Health System Enterprise Information Technology Services Geographic Service Provider requirement. The Defense Health Agency is developing three related requirements: the Enterprise Information Technology Service Integrator, the Capability Service Provider, and the Geographic Service Provider. This special notice posting will serve as an ongoing communication platform for the government to provide updates and solicit feedback on the GSP requirement from industry partners. The initial response date for feedback on the problem statement, scope document, and list of potential GSP facilities is August 9, 2021. The documents uploaded with this special notice include a problem statement on the GSP requirement, a general scope document, and a list of potential GSP facilities for industry response.
View the file
Other files for this federal contract opportunity
Show all 50
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation Attachment # CP3
HT0015-22-R-0030
Addendum to 52.212-4 Contract Terms and Conditions -- Commercial Items
1. 52.212-4(s) is tailored as follows:
52.212-4(s), Order of Precedence. Any inconsistencies in this solicitation or contract shall be resolved by giving precedence in the following order:
(1) The basic Indefinite Delivery Indefinite Quantity (IDIQ) Contracts (if this is an IDIQ).
(2) The Assignments, Disputes, Payments, Invoice, Other Compliances, Compliance with Laws Unique to Government Contracts, Unauthorized Obligations, and Commercial Supplier Agreements-Unenforceable Clauses paragraphs of this clause.
(3) The clause at 52.212-5.
(4) Addenda to this solicitation or contract, including any commercial supplier agreements as amended by the Commercial Supplier Agreements - Unenforceable Clauses provision.
(5) Solicitation provisions (if this is a solicitation).
(6) Other paragraphs of this clause.
(7) The Standard Form 1449.
(8) Other documents, exhibits, and attachments.
(9) The specification.
2. New subsection 52.212-4(w) is added to 52.212-4 as follows:
52.212-4(w), Commercial Supplier Agreements - Unenforceable Clauses.
(1) “Commercial supplier agreements” means terms and conditions customarily offered to the public by vendors of supplies or services that meet the definition of “commercial item” set forth in FAR 2.101 and intended to create a binding legal obligation on the end user. Commercial supplier agreements are particularly common in information technology acquisitions, including acquisitions of commercial computer software and commercial technical data, but they may apply to any supply or service. The term applies–
(i) Regardless of the format or style of the document. For example, a commercial supplier agreement may be styled as standard terms of sale or lease, Terms of Service (TOS), End User License Agreement (EULA), Commercial Software License Agreement, or another similar legal instrument or agreement;
(ii) Regardless of the media or delivery mechanism used. For example, a commercial supplier agreement may be presented as one or more paper documents or may appear on a computer or other electronic device screen during a purchase, software installation, other product delivery, registration for a service, or another transaction.
(2) When any supply or service acquired under this contract is subject to a commercial supplier agreement (as defined herein), the following language shall be deemed incorporated into the commercial supplier agreement. As used herein, “this agreement” means the commercial supplier agreement:
(3) Notwithstanding any other provision of this agreement, when the end user is an agency or instrumentality of the U.S. Government, the following shall apply:
(i) Applicability. This agreement is a part of a contract between the commercial supplier and the U.S.
Government for the acquisition of the supply or service that necessitates a license or other similar legal instrument (including all contracts, task orders, delivery orders, or call orders under FAR Part 12).
(ii) End user. This agreement shall bind the ordering activity as end user but shall not operate to bind a Government employee or person acting on behalf of the Government in his or her personal capacity.
https://www.law.cornell.edu/cfr/text/48/part-12
HT0015-22-R-0030
(iii) Law and disputes. This agreement is governed by Federal law.
(A) Any language purporting to subject the U.S. Government to the laws of a U.S. state, U.S. territory, district, or municipality, or a foreign nation, except where Federal law expressly provides for the application of such laws, is hereby deleted.
(B) Any language requiring dispute resolution in a specific forum or venue that is different from that prescribed by applicable Federal law is hereby deleted.
(C) Any language prescribing a different time period for bringing an action than that prescribed by applicable Federal law in relation to a dispute is hereby deleted.
(iv) Continued performance. The supplier or licensor shall not unilaterally revoke, terminate or suspend any rights granted to the Government except as allowed by this contract. If the supplier or licensor believes the ordering activity to be in breach of the agreement, it shall pursue its rights under the Contract Disputes Act or other applicable Federal statute while continuing performance as set forth in subparagraph (d) (Disputes).
(v) Arbitration; equitable or injunctive relief. In the event of a claim or dispute arising under or relating to this agreement, a binding arbitration shall not be used unless specifically authorized by agency guidance, and equitable or injunctive relief, including the award of attorney fees, costs or interest, may be awarded against the U.S. Government only when explicitly provided by statute (e.g., Prompt Payment Act or Equal Access to Justice Act).
(vi) Updating terms.
(A) After award, the contractor may unilaterally revise terms if they are not material. A material change is defined as:
(1) Terms that change Government rights or obligations;
(2) Terms that increase Government prices;
(3) Terms that decrease overall level of service; or
(4) Terms that limit any other Government right addressed elsewhere in this contract.
(B) For revisions that will materially change the terms of the contract, the revised commercial supplier agreement must be incorporated into the contract using a bilateral modification.
(C) Any agreement terms or conditions unilaterally revised subsequent to award that are inconsistent with any material term or provision of this contract shall not be enforceable against the Government, and the Government shall not be deemed to have consented to them.
(vii) No automatic renewals. If any license or service tied to periodic payment is provided under this agreement (e.g., annual software maintenance or annual lease term), such license or service shall not renew automatically upon expiration of its current term without prior express consent by an authorized Government representative.
(viii) Indemnification. Any clause of this agreement requiring the commercial supplier or licensor to defend or indemnify the end user is hereby amended to provide that the U.S. Department of Justice has the sole right to represent the United States in any such action, in accordance with 28 U.S.C. 516.
(ix) Audits. Any clause of this agreement permitting the commercial supplier or licensor to audit the end user's compliance with this agreement is hereby amended as follows:
(A) Discrepancies found in an audit may result in a charge by the commercial supplier or licensor to the ordering activity. Any resulting invoice must comply with the proper invoicing requirements specified in the underlying Government contract or order.
(B) This charge, if disputed by the ordering activity, will be resolved in accordance with subparagraph (d) (Disputes); no payment obligation shall arise on the part of the ordering activity until the conclusion of the dispute process.
https://www.law.cornell.edu/topn/prompt_payment_act https://www.law.cornell.edu/topn/equal_access_to_justice_act https://www.law.cornell.edu/topn/equal_access_to_justice_act https://www.law.cornell.edu/uscode/text/28/516
HT0015-22-R-0030
(C) Any audit requested by the contractor will be performed at the contractor's expense, without reimbursement by the Government.
(x) Taxes or surcharges. Any taxes or surcharges which the commercial supplier or licensor seeks to pass along to the Government as end user will be governed by the terms of the underlying Government contract or order and, in any event, must be submitted to the Contracting Officer for a determination of applicability prior to invoicing unless specifically agreed to otherwise in the Government contract.
(xi) Non-assignment. This agreement may not be assigned, nor may any rights or obligations thereunder be delegated, without the Government's prior approval, except as expressly permitted under subparagraph (b) of this clause.
(xii) Confidential information. If this agreement includes a confidentiality clause, such clause is hereby amended to state that neither the agreement nor the contract price list, as applicable, shall be deemed “confidential information.” Issues regarding release of “unit pricing” will be resolved consistent with the Freedom of Information Act. Notwithstanding anything in this agreement to the contrary, the Government may retain any confidential information as required by law, regulation or its internal document retention procedures for legal, regulatory or compliance purposes; provided, however, that all such retained confidential information will continue to be subject to the confidentiality obligations of this agreement.
(4) If any language, provision, or clause of this agreement conflicts or is inconsistent with the preceding paragraph (w)(1), the language, provisions, or clause of paragraph (w)(1) shall prevail to the extent of such inconsistency.
3. New subsection 52.212-4(x) is added to 52.212-4 as follows:
52.212-4(x), Copyright & License Notice on works created under federal contract.
The Contractor shall, where applicable, place the following copyright and license notice language on all works delivered under this contract that are created wholly or in part with funds from this contract:
COPYRIGHT STATUS: This work, authored by ______________ employees, was funded in whole or in part by the Defense Health Agency under U.S. Government contract _______________, and is, therefore, subject to the following license: The Government is granted for itself and others acting on its behalf a paid-up, nonexclusive, irrevocable worldwide license in this work to reproduce, prepare derivative works, distribute copies to the public, and perform publicly and display publicly, by or on behalf of the Government. All other rights are reserved by the copyright owner.
4. New subsection 52.212-4(y) is added to 52.212-4 as follows:
52.212-4(y), Additional terms and conditions.
The terms and conditions of this multiple award IDIQ shall apply to all purchases made pursuant to it. In the event of an inconsistency between the provisions of the IDIQ and a later-issued task order, the provisions of this IDIQ will take precedence.
(End of Provision) https://www.law.cornell.edu/topn/freedom_of_information_act
HT0015-22-R-0030
DHA Local Provision Language:
Improper Business Practices and Personal Conflicts of Interest
1. The Offeror’s attention is directed to FAR, Part 3 and DFARS, Part 203, “Improper Business Practices and Personal Consultant Conflicts of Interest.”
2. 252.203-7005 Representation Relating to Compensation of Former DoD Officials (Nov 2011)
(a) Definition. “Covered DoD official” is defined in the clause at 252.203-7000, Requirements Relating to Compensation of Former DoD Officials.
(b) By submission of this offer, the offeror represents, to the best of its knowledge and belief, that all covered DoD officials employed by or otherwise receiving compensation from the offeror, and who are expected to undertake activities on behalf of the offeror for any resulting contract, are presently in compliance with all post-employment restrictions covered by 18 U.S.C. 207, 41 U.S.C. 2101-2107, and 5 CFR parts 2637 and 2641, including Federal Acquisition Regulation 3.104-2.
(End of provision)
Use of Former DoD/Defense Health Agency (DHA) Employees and Uniformed Service Members in Proposal Preparation.
The involvement of a former DoD/DHA employee/member in a offeror’s quotation preparation may give rise to an unfair competitive advantage or the appearance thereof, if the former DoD/DHA employee/ member acquired non-public, competitively-useful information in his or her former position. Such knowledge could include proprietary information of competitor’s performance on past or current contracts with similar requirements or source selection sensitive information pertaining to this procurement. Consequently, the Offeror must notify the Contracting Officer prior to the involvement in the quotation preparation by a former DoD/DHA employee/member reasonably expected to have had access to such information. Based on the notification, the Contracting Officer will make a determination whether involvement of the former DoD/DHA employee/member in quotation preparation could create an unfair competitive advantage or appearance thereof. The Contracting Officer will further determine whether any mitigation measures taken or proposed by the offeror are adequate to alleviate this concern or whether the offeror will be disqualified from the competition. Failure to comply with these procedures may result in the offeror’s disqualification for award.
Agency Level Protest Information
An interested party filing a protest with Defense Health Agency (DHA) has the option of requesting review by either the Contracting Officer (CO) or an Independent Review Official (IRO), who is a DHA official at a level above the CO.
Alternately, an interested party may request IRO review as an appeal of the CO’s protest decision.
Where applicable, an interested party must clearly state in the protest that IRO review is requested, and must specify the nature of the independent review sought – whether as an alternative to CO review or as an appeal of the CO’s decision.
Regardless of which review is requested, all protests must be complete and submitted to the CO within the timeframes specified in FAR Subpart 33.1.
(End of Requirements Language)
HT0015-22-R-0030
Organizational Conflicts of Interest (OCIs)
1. The offeror’s attention is directed to FAR, Subpart 9.5, “Organizational and Consultant Conflicts of Interest.”
2. For the purpose of these provisions, the term “offeror” means the offeror, its subsidiaries, affiliates, partners, and/or marketing consultants, as defined by FAR, Subpart 9.501, or any of its successors or assignees.
3. It is the position of DHA that certain companies, due to the nature of their performance with DHA, have an actual organizational conflict of interest, which must be avoided. The companies listed below are ineligible to perform work in connection with a GSP MA-IDIQ. Offerors may not propose any of these companies in any role under this solicitation, including as partners, team members, subcontractors, consultants, etc.:
- Perspecta Enterprise Solutions, LLC EITSI Prime
- Capgemini Government Solutions LLC EITSI (Prime Teammate)
- Guidehouse LLP EITSI Major Subcontractor
- Tenacity Solutions EITSI Major Subcontractor
Additionally, the following companies are providing acquisition support services to DHA and therefore are precluded from participating in teaming arrangements for MHS IT requirements:
- Zygos Consulting, LLC
- Sourcing Advisory Services, LLC dba Integris Applied
- TDC Consulting, LLC
Please be advised that this list is current only as of the date of this solicitation. Both the MHS EITSI contract and the MHS GSP MA-IDIQ contracts have a 10-year ordering period, and the list of ineligible companies deemed to be EITSI Major Shareholders may change over time. It is the GSP MA-IDIQ holders responsibility to remain aware of whether any of its team members, affiliates, subcontractors, etc. are performing, or have performed, work in any capacity in connection with the MHS EITSI contract and comply with this section.
In the event an Offeror intends to use a company as a team member or subcontractor that will, or may, also perform on the MHS EITSI effort as other than an EITSI Major Subcontractor (i.e., minor EITSI subcontractors), the Offeror shall provide an OCI mitigation plan to the Contracting Officer that effectively demonstrates how the Offeror will avoid, neutralize, or mitigate any potential OCIs that may arise as a result of performing on both the GSP and the EITSI efforts. If applicable, such OCI mitigation plans may be provided with proposals or directly to the Contracting Officer at any time prior to the due date for receipt of proposals.
In the event an Offeror is not proposing to use a company that will, or may perform work in connection with the MHS EISTI effort and has not otherwise identified any potential OCIs, the Offeror shall represent in writing within their proposal that, to the best of the Offeror’s knowledge, there are no relevant facts or circumstances concerning any past, present, or potential contracts or financial interest relating to the work to be performed, which could give rise to an organizational conflict of interest, as described in FAR, Subpart 9.5.
4. The Offeror is hereby notified that the nature of the work to be performed may create an actual or potential organizational conflict of interest in future acquisitions.
5. It may become necessary in the performance of this contract to review proprietary information from other contractors.
The Contractor shall protect all proprietary information from unauthorized use or disclosure and refrain from using the information for any purpose other than that for which it was furnished. At the request of the Contracting Officer, the Contractor agrees to execute agreements with third party companies furnishing data in connection with work performed
HT0015-22-R-0030
under this contract. Safeguards shall be implemented to restrict access to proprietary information and to avoid, neutralize, or mitigate potential conflicts of interest. Non-disclosure agreements shall be completed by the Contractor, all employees, and subcontractors who obtain access to proprietary information, and provided to the Contracting Officer.
6. The Contractor agrees that if an actual or potential organizational conflict of interest is discovered after the award of this contract, the Contractor will immediately notify the Contracting Officer, in writing, of the nature of the conflict.
The Contractor shall submit a mitigation plan to the Contracting Officer within 30 days of notification, outlining the actions the Contractor has taken or proposes to take to avoid, neutralize, or mitigate the actual or potential organizational conflict of interest.
7. The above restrictions shall be included in all subcontracts, teaming arrangements, and other agreements calling for performance of work which is subject to the organizational conflict of interest restrictions identified in these clauses.
8. The Contractor acknowledges the full force and effect of the above clauses. The Government reserves the right, in case of a breach, misrepresentation or nondisclosure, to terminate this contract, disqualify the Contractor from subsequent related contractual efforts, or pursues any remedy permitted by law or this contract.
9. The offeror shall represent in writing within the quotation that, to the best of the offeror’s knowledge, there are no relevant facts or circumstances concerning any past, present, or potential contracts or financial interest relating to the work to be performed, which could give rise to an organizational conflict of interest, as described in FAR, Subpart 9.5.
In the event an actual or potential organizational conflict of interest exist, the offeror shall submit a mitigation plan to the Contracting Officer, no later than the phase 2 quotation submissions due date, that effectively demonstrates how the Offeror will mitigate any actual or potential organizational conflict of interest while supporting this contract and any other DHA contract. As a part of the quotation, the offeror shall provide the Contracting Officer with information of previous or ongoing work that is in any way associated with this solicitation.
10. The Contracting Officer will review all mitigation plans to determine whether award to the Offeror is consistent with FAR, Subpart 9.5. If the Contracting Officer determines that no conflict would arise or that the mitigation plan adequately protects the interest of the Government, the Offeror will be eligible for award. If the Contracting Officer determines that the mitigation plan is inadequate, remedial actions will be considered, including elimination from the solicitation process, termination of related contract efforts already awarded, or negotiation of the mitigation plan.
11. The above restrictions shall be included in all subcontracts, teaming arrangements, and other agreements calling for performance of work which is subject to the organizational conflict of interest restrictions identified in these provisions.
12. The Offeror acknowledges the full force and effect of these provisions. The above provisions may be modified or deleted at the discretion of the Government. The Government reserves the right, in case of a breach, misrepresentation or nondisclosure, to terminate the resultant contract, disqualify the Offeror from subsequent related contractual efforts, or pursues any remedy permitted by law, regulation or the terms and conditions of this solicitation.
DHA Local Clause Language:
IMPROPER BUSINESS PRACTICES AND PERSONAL CONFLICTS OF INTEREST (AUGUST 21, 2014)
1. DFARS 252.203-7000, Requirements Relating to Compensation of Former DoD Officials (Sep 2011)
(a) Definition. “Covered DoD official,” as used in this clause, means an individual that—
(1) Leaves or left DoD service on or after January 28, 2008; and
(2) (i) Participated personally and substantially in an acquisition as defined in 41 U.S.C. 131 with a valuein excess of $10 million, and serves or served—
(A) In an Executive Schedule position under subchapter II of chapter 53 of Title 5, United States Code;
(B) In a position in the Senior Executive Service under subchapter VIII of chapter 53 ofTitle 5, United States
Code; or
(C) In a general or flag officer position compensated at a rate of pay for grade O-7 or above under section 201 of Title 37, United States Code; or
(ii) Serves or served in DoD in one of the following positions: program manager, deputy program manager, procuring contracting officer, administrative contracting officer, source selection authority, member of the source selection evaluation board, or chief of a financial or technical evaluation team for a contract in an amount in excess of $10 million.
(b) The Contractor shall not knowingly provide compensation to a covered DoD official within 2 years after the official leaves DoD service; without first determining that the official has sought and received, or has not received after 30 days of seeking, a written opinion from the appropriate DoD ethics counselor regarding the applicability of post-employment restrictions to the activities that the official is expected to undertake on behalf of the Contractor.
(c) Failure by the Contractor to comply with paragraph (b) of this clause may subject the Contractor to rescission of this contract, suspension, or debarment in accordance with 41 U.S.C. 2105(c).
(End of clause)
Proper Identification of Contractor Personnel
1. Contractors, including subcontractors at all tiers, shall provide for a clear distinction from Government personnel.
Contractor employees shall not act, advertise, or presume to be Government employees, agents, or representatives.
Contractor employees are required to appropriately identify themselves as contractor employees at all times, including in telephone conversations, formal and informal written correspondence, paper and electronic, and in any other situation where their actions could be construed as acts of Government officials, unless, in the judgment of the Government, no harm can come from failing to identify themselves. Contractor employees shall be introduced as contractor personnel and display distinguishing visible identification at all times whether in conversations, meetings, or other forms of communication with Government personnel.
2. Contractor personnel, while performing in a contractor capacity, shall refrain from using their retired or reserve component military rank or title (if applicable) in written or verbal communications associated with the contracts for which they provide services.
3. The Contractor shall incorporate the substance of this requirement in all subcontracts awarded under this contract.
(End of requirements language)
HT0015-22-R-0030
Personally Identifiable Information, Protected Health Information, and Federal Information Requirements (Revised May 23, 2017)
1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws
This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.
This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.
For purposes of this Section, the following definitions apply.
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (October 29, 2014) and DoD 5400.11-R (May 14, 2007).
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S.
Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E (Enforcement), as amended. Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part
162) are not addressed in this Section and are not included in the term HIPAA Rules.
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (January 24, 2003), Department of Defense Instruction (DoDI) 6025.18 (December 2, 2009), and DoDI 8580.02 (August 12, 2015).
Defense Health Agency (DHA) Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
2. Records Management
When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records Management requirements outlined in the current TRICARE Operations Manual (TOM).
• Freedom of Information Act (FOIA)
The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:
The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101 (or email requests addressed to DHA.FOIA@mail.mil), and that the request shall describe the desired record as completely as possible (ideally with Contract or modification number) to facilitate its retrieval from files and to reduce http://www.dtic.mil/whs/directives
HT0015-22-R-0030
search fees which may be borne by the requestor. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible.
In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.
• Systems of Records
In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil Liberties, and Transparency Division, and as required by the DoD Privacy Act Issuances.
Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, and OMB Circular A-130. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.
• Privacy Impact Assessment (PIA)
Contractors are not required to submit PIAs to DHA.
• Data Sharing Agreement (DSA)
6.1 (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de-identified data)
The Contractor shall consult with the DHA Privacy Office to determine if the Contractor must obtain a DSA or Data Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.
The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and DoD HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.
Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor must gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA Privacy Board requests for additional documentation.
To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the DHA Privacy Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data http://www.defenselink.mil/privacy/documents/pa1974.pdf mailto:DHA.PrivacyAct@mail.mil http://www.tricare.mil/tma/privacy/Templates.aspx
HT0015-22-R-0030
involved:
• DSA for De-Identified Data
• DSA for PHI
• DSA for PII Without PHI
• DUA for Limited Data Set
DSAs executed for contract support will expire after 1 year or at the end of the contract option year, whichever comes first. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.
6.2 (Applies if contract requirements may include human subject research) This Contract incorporates by reference the Protection of Human Subject Research clause in the Defense Federal Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235-7004. A separate DFARS provision, 48 CFR 235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR 219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a contractor participates in a study or demonstration project or other activity that involves human subject research, then the contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If contractor activity appears to involve human subject research, then the contractor shall consult the DHA Privacy Office, which may contact the Research Regulatory Oversight Office in the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)).
7. Privacy Act and HIPAA Training The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of alcohol and drug abuse patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a Covered Entity, or Business Associate.
The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.
8. HIPAA Business Associate Provisions
8.1 Business Associate – General Provisions
The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. This paragraph 8 serves as the required BAA. As a Business Associate, the Contractor shall comply with the HIPAA Rules and the DoD HIPAA Issuances applicable to a business associate performing under this Contract.
8.1.1 Catch-All Definition
The following terms used, but not otherwise defined in paragraph 8.1, shall have the same meaning as those terms have in the DoD HIPAA Issuances: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information (Unsecured PHI), and Use.
• The Contractor shall not use or further disclose PHI other than as permitted or required by the Contract or as Required by Law.
• The Contractor shall use appropriate safeguards, and comply with the HIPAA Security Rule with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Contract.
HT0015-22-R-0030
• The Contractor shall report to DHA any breach of which it becomes aware, and shall proceed with breach response steps as required by paragraph 9 (if this Contract incorporates by reference the TOM, then all references to paragraph 9 shall be deemed to refer to the breach response provisions of the TOM, Ch. 1, Sec.
5, paragraphs 2.1- 2.2). With respect to electronic PHI, the Contractor shall also respond to any security incident of which it becomes aware in accordance with any applicable DoD cybersecurity and National Institute of Standards and Technology (NIST) requirements. If at any point the Contractor becomes aware that a security incident involves a breach, the contractor shall immediately initiate breach response as required by paragraph 9.
• In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), respectively, as applicable, the Contractor shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Contractor agree to the same restrictions, conditions, and requirements that apply to the Contractor with respect to such PHI.
• With respect to individual rights of access to PHI, the Contractor shall make available PHI in a designated record set to the individual or the individual’s designee as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding 45 CFR 164.524. If the Contractor intends to deny the individual’s request, the Contractor shall forward it (within seven working days of receipt) to the CO. The CO shall make a determination within 20 calendar days (50 calendar days for justified delays) of the request. The CO shall notify the individual, with a copy to the Contractor, of any approved or denied access determinations and the reason for any denial. The individual may appeal the denial determination to the DHA Privacy Office.
• The Contractor shall make any amendment(s) to PHI in a designated record set as directed or agreed to by
DHA, or take other measures as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding 45 CFR 164.526.
• The Contractor shall maintain and make available to the Government the information required to provide an accounting of disclosures to the MHS or to the individual as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding 45 CFR 164.528.
• To the extent the Contractor is to carry out one or more of DHA’s obligation(s) under the HIPAA Rules, the
Contractor shall comply with the requirements of the HIPAA Rules.
• The Contractor shall make its internal practices, books, and records available to the HHS Secretary for purposes of determining compliance with the HIPAA Rules.
Permitted Uses and Disclosures
8.2 General Use and Disclosure Provisions
The Contractor may only use or disclose PHI as necessary to perform the services set forth in this Contract or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA Issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by the Contract or directed by DHA. The Contractor agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances. The Contractor shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the covered entity, except uses and disclosures for the Contractor’s own management and administration and legal responsibilities or for data aggregation services as set forth in paragraphs
8.3.1 – 8.3.3.
8.3 Specific Use and Disclosure Provisions
HT0015-22-R-0030
8.3.1 Except as otherwise limited in this Section, the Contractor may use PHI for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
8.3.2 Except as otherwise limited in paragraph 8.3, the Contractor may disclose PHI for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor, provided that disclosures are required by law, or the Contractor obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Contractor of any instances of which it is aware in which the confidentiality of the information has been breached.
8.3.3 Except as otherwise limited in this Section, the Contractor may use PHI to provide Data Aggregation services relating to DHA’s health care operations.
8.4 Contractor Compliance with DHA Notices and Restrictions
8.4.1 DHA will provide the Contractor with the notice of privacy practices that DHA produces in accordance with the DoD HIPAA Issuances and the corresponding 45 CFR 164.520.
8.4.2 Upon notification by DHA of any changes in, or revocation of, permission by an individual to use or disclose his or her PHI, the Contractor shall comply to the extent that such changes may affect the Contractor’s use or disclosure of PHI.
8.4.3 Upon notification by DHA, the Contractor shall comply with any restriction on the use or disclosure of PHI that the Government has agreed to or is required to abide by under the DoD HIPAA Issuances or the corresponding 45 CFR 164.522, to the extent that such restriction may affect Contractor’s use or disclosure of PHI.
8.5 Permissible Requests by DHA
The Government will not request the Contractor to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this Contract.
8.6 Termination
8.6.1 Effect of Noncompliance
Noncompliance by the Contractor (or any of its staff, agents, or subcontractors) with any requirement in these HIPAA Business Associate Provisions (paragraph 8) may subject the Contractor to termination under any applicable default or other termination provision of this Contract.
8.6.2 Effect of Termination
8.6.2.1 If this Contract has records management requirements, the Contractor shall handle such records in accordance with the records management requirements. If this Contract does not have records management requirements, the Contractor shall handle such records in accordance with paragraphs 8.6.2.2 and 8.6.2.3 below. If this Contract has provisions for transfer of records and PII/PHI to a successor contractor, or if DHA gives directions for such transfer, the Contractor shall handle such records and information in accordance with such Contract provisions or DHA direction.
8.6.2.2 If this Contract does not have records management requirements, except as provided in paragraph 8.6.2.3 below, upon termination of the Contract, for any reason, the Contractor shall return or destroy all PHI received from the Government, or created or received by the Contractor on behalf of the Government that the Contractor still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Contractor. The Contractor shall retain no copies of the PHI.
HT0015-22-R-0030
8.6.2.3 If this Contract does not have records management provisions and the Contractor determines that returning or destroying the PHI is infeasible, the Contractor shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Contractor that return or destruction of PHI is infeasible, the Contractor shall extend the protections of the Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such PHI.
8.7 Miscellaneous
8.7.1 Survival
The obligations of the Contractor under the “Effect of Termination” provision of Paragraph 9 shall survive the termination of this Contract.
8.7.2 Interpretation
Any ambiguity in this Contract shall be interpreted in a manner to permit compliance with the HIPAA Rules and the DoD HIPAA Issuances.
9. Breach Response
[This paragraph 9 is inoperative, and all references herein to “paragraph 9” shall be deemed to refer to the TOM breach responses provisions, if the contract incorporates the TOM by reference. See paragraph 8.1.4 above]
9.1 Definitions Related to Breach response
9.1.1 Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar term referring to situations where persons other than authorized users and for other than an authorized purpose have access or potential access to PII, whether physical or electronic. The foregoing definition is based on the definition of breach in DoDD 5400.11. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral
PII/PHI).
9.1.2 A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the contractor does not initially know whether or not the PII/PHI was encrypted, then the incident must initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the contractor. In determining whether unauthorized access should be suspected, the contractor shall consider at least the following factors:
• How the event was discovered;
• Did the information stay within the covered entity’s control;
• Was the information actually accessed/viewed; and
• Ability to ensure containment (e.g., recovered, destroyed, or deleted).
9.1.3 A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the contractor knows that the PII/PHI is unencrypted, then the contractor should classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the contractor knows this even without knowing whether or not unauthorized access to the PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the contractor should re-classify the incident as a non-breach incident.
9.1.4 A HIPAA breach is an incident that satisfies the definition of breach in 45 CFR 164.402.
9.1.5 A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI. A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.
9.2 General
9.2.1 The breach response requirements set forth in this paragraph 9 are designed to satisfy both the DoD Privacy Act Issuances and the HIPAA Breach Rule, 45 CFR Part 164, Subpart D, as applicable. The definition of breach above is based on the definition of breach in the DoD Privacy Act Issuances. This Privacy Act definition is broader than a HIPAA breach as defined above. Thus, a Privacy Act breach would not constitute a HIPAA breach if the PII involved does not include PHI or if it involves PHI but is excluded from the definition of HIPAA breach. If a breach is not a HIPAA breach, then the Contractor has no HIPAA breach response obligations. In such cases, the Contractor must still comply with breach response requirements under the DoD Privacy Act Issuances, as stated in this paragraph 9.
9.2.2 Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation (which includes individual notification), eradication, recovery, and follow-up.
9.2.3 The contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The contractor should consult with the DHA Privacy Office where guidance is needed, such as when the contractor is uncertain whether a discovered breach is the contractor’s responsibility (e.g., if the contractor discovers a breach not caused by the contractor), or how the contractor is to classify an incident (breach vs. non-breach, confirmed vs. possible, cyber vs. non-cyber).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .