PWS_ASC_Standardized_Quality_Benchmarking.doc

DOC document 221 KB Posted

Attached to
Ambulatory Surgery Quality Benchmarking Federal contract opportunity
Solicitation number
DoP-16-00145
Issued by
Defense Health Agency

View the file

Other files for this federal contract opportunity

Other files attached to Ambulatory Surgery Quality Benchmarking, newest first.
File Type Posted
RESPONSE_TO_OFFEROR_QUESTIONS_RE.pdf PDF
Amended_PWS_ASC_2016_06_16.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

Ambulatory Surgical Center Quality & Safety Standardized Benchmarking Program Part 1

General Information

1.0 General: This is a non-personal services contract to provide an Ambulatory Surgical Center Quality and Safety Standardized Benchmarking Program. The Government shall not exercise any supervision or control over the contract service company performing the services herein. Such contract service company shall be, in turn, responsible to the Government.

1.1 Description of Services/Introduction: The Contractor shall provide all personnel, equipment, supplies, facilities, tools, materials, supervision, and other items and non-personal services necessary to perform Ambulatory Surgical Center Quality & Safety Standardized Benchmarking Program as defined in this Performance Work Statement except for those items specified as government furnished property and services. The Contractor shall perform to the standards in this contract.

1.2 Background: As a result of the Secretary of Defense’s mandated 90 day review of access, safety and quality in the Military Health System (MHS), three surgical care focused recommendations were developed. They included:

· MHS governance should task the National Surgical Quality Improvement Program (NSQIP®) working group to assess surgical morbidity shortfalls to the Medical Operations Group for Tri-Service/Defense Health Agency (DHA) engagement, collaborative support, and facility action. (within 90 days)

· DHA Healthcare Operations Directorate should partner with the American College of Surgeons (ACS) NSQIP® staff to improve Military Treatment Facility (MTF) collaboration and the sharing of best practices from the top performing facilities, thereby decreasing overall direct care surgical morbidity and improving clinical outcomes. (within 90 days)

· MHS governance should explore expanding NSQIP® participation to all remaining direct care inpatient facilities performing surgery. In addition, ensure all ambulatory surgery platforms participate in a similar surgical quality improvement program.

A decision paper on ambulatory surgical center MTFs participation in a national surgical quality improvement benchmark program was drafted and approved by MHS senior leadership. (NSQIP®) is not available to Ambulatory Surgery Centers (ASCs) according to polices under the American Academy of Surgeons. The decision was to have all ambulatory surgical center MTFs in MHS participate in a consistent national benchmarking program to facilitate internal and external comparison for successful practice identification and collaborative learning.

1.3 Objectives: The Military Health Systems (MHS) will benefit from participating in a National Ambulatory Surgical Center (ASC) Benchmarking Program for many reasons. Most importantly, the program will contribute to the reduction of surgical morbidity and to enhance clinical quality and safety activities at Department of Defense (DoD) ASCs. A National ASC Benchmarking Program enhances the ability of the DoD to validate and/or improve the quality of surgical care provided by participating military treatment facilities while maintaining compliance with related DoD quality assurance and patient privacy directives. The Objectives to be met to satisfy the requirements of this program are:

1.3.1. To provide reliable, valid and accessible quality benchmarking data on ambulatory surgical care to surgical specialists, the facility, service and MHS leadership thus allowing for consistent monitoring of care to validate or improve surgical outcomes.

1.3.2. To provide a model for continuous quality improvement of ambulatory surgical care that leads to decreased variability and increased quality in patient care while reducing costs and increasing value.

1.3.3. To compare aggregated ambulatory surgical data and outcomes of participating DoD Military Treatment Facilities (ASCs) with each other and with comparable patient populations from across the nation through a continually accessible current data source.

1.3.4. To support a DoD system-wide surgical quality improvement program lead by surgical professionals and focused on improving processes, structures, and systems to ensure quality surgical care.

1.3.5. To support the DoD MTFs ASCs and Program Office in meeting quality assurance directives and patient privacy requirements throughout the implementation of a National ASC Benchmarking Program.

1.3.6. Provide on-going training, education, and support to facility Clinical Data Abstractors (CDAs) and other ASC staff.

1.4. Scope: This contract provides for MTF level memberships to participate in a national ambulatory surgical center benchmarking program and program support for designated MTFs with non-hospital affiliated ambulatory surgery centers. The designated program will provide for both quality and safety data collection systems and reporting platforms. MTFs (ASCs) supported by this effort will have the ability to compare their results to continuously current national benchmark standards, between same type (multiple or specialty) ASCs, and between participating MHS ASCs. The Service Headquarters and the Defense Health Agency (DHA) will also have access to this data. The memberships provide for the following key services:

1.4.1. Training of clinical data abstractors (CDA) on collection of data following the metrics established by the national ASC benchmarking company.

1.4.2 . Dashboards that allow for viewing of quality and safety data allowing MTFs to rapidly implement process improvement initiatives for identified quality and safety outliers.

Dashboards that allow for viewing of aggregated MTF data allowing for comparison between participating DoD MTFs. The Service Headquarters and DHA would also have access to this data upon publication.

1.4.3. Quarterly reports based on calendar year that provide MTFs with quality and safety data that allow for MTF and enterprise level oversight of quality and safety measures and initiatives inside the ASC.

1.4.4 Provide data for facilitating accreditation by The Joint Commission and AAAHC.

1.4.5 Provide data to maintain alignment with nationally recognized ambulatory surgery center metrics, such as those established by Centers for Medicare & Medicaid Services (CMS).

1.4.6 Provide membership support services to each MTF in areas specific to ASCs. Membership

Support Services shall be provided via blogs, emails and/or website access and should be inclusive of all other national ASC members’ scrutiny and input. Access to data entry must be available through a web based link. No software should be required for installation on government computer systems.

1.4.7 The web based system must already provide services to 100s of other ambulatory surgical center facilities in order to provide the relevant national benchmarking statistics that the Government requires.

1.5 Period of Performance: The period of performance shall be for one (1) Base Year of 12 months and four (4) 12-month option years. The Period of Performance reads as follows:

Base Period

30 September 2016 - 29 September 2017

Option Period 1

30 September 2017 - 29 September 2018

Option Period 2

30 September 2018 - 29 September 2019

Option Period 3

30 September 2019 - 29 September 2020

Option Period 4

30 September 2020 - 29 September 2021

1.6 General Information:

1.6.1 Quality Control: The Contractor shall develop and maintain an effective Quality Control Program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The quality control program is the means by which the Contractor ensures that their work complies with the requirements of the contract. The Quality Control Plan (QCP) (Deliverable 1) shall be included in the Offeror’s technical proposal submitted for this requirement.

1.6.2 Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.6.3 Recognized Holidays: Data shall be available online through web based access on a continual basis (24 hour, 7 days/week) without regard to federal holidays. The Government will recognize the Contractor’s holiday schedule regarding availability of personnel to provide membership support services, technical support services, and training.

1.6.4 Hours of Operation: Data shall be available online on a continual basis (24 hour availability). In regards to membership support services, technical support, or training, the contractor is responsible for conducting business between their published hours of operation. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS.

1.6.5 Place of Performance: The work to be performed under this contract will be performed in the Contractor’s web based operating environment.

1.6.6 Type of Contract: The government will award a firm fixed price contract.

1.6.7 Security Requirements: Contractor personnel attending periodic meetings will need security to be escorted into the Government facility as guests.

1.6.7.1 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. All data stored shall be kept secured.

1.6.7.2 Key Control: N/A

1.6.8 Special Qualifications: N/A

1.6.9 Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. Appropriate action shall be taken to resolve outstanding issues. These meetings are mandatory and shall be at no additional cost to the government.

1.6.10 Contracting Officer Representative (COR): The (COR) will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: Assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance, maintain written and oral communications with the Contractor concerning technical aspects of the contract, and issue written interpretations of technical requirements. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.6.11 Key Personnel: The Contractor shall provide a Contract Manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the Contractor when the Manager is absent shall be designated in writing to the Contracting Officer. The Contract Manager or alternate shall have full authority to act for the Contractor on all contract matters relating to daily operation of this contract.

1.6.12 Identification of Contractor Employees: All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.

1.6.13 Contractor Travel: Contractor may be required to travel CONUS and within the NCR during the performance of this contract to attend mandatory periodic meetings in support of this PWS. Any cost associated with the attendance of these meetings will be the responsibility of the Contractor.

1.6.14 Other Direct Costs: N/A

1.6.15 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose other than aggregated national benchmarking of ASCs. This right does not abrogate any other Government rights.

1.6.16 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may effect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.

Refer to Technical Exhibit 5 for OCI Language. The Contractor shall complete the OCI Certification (Deliverable 2) provided in Technical Exhibit 5 and submit to the Contracting Officer with their proposal. If a perceived OCI issue occurs at any time during performance of this contract, the Contractor shall notify the Contracting Officer and the COR and complete a new OCI form and OCI Mitigation Plan, as appropriate.

1.6.17 PHASE IN /PHASE OUT PERIOD: N/A

PART 2

DEFINITIONS & ACRONYMS

2. Definitions and Acronyms:

2.1. DEFINITIONS:

2.1.1. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.2. CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. Note: The only individual who can legally bind the government.

2.1.3. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.4. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.

2.1.5. DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

2.1.6. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.

2.1.7. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.

2.1.8. QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.

2.1.9. QUALITY ASSURANCE Surveillance Plan (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.

2.1.10. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

2.1.11. SUBCONTRACTOR. One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.

2.1.12. WORK DAY. The number of hours per day the Contractor provides services in accordance with the contract.

2.1.12. WORK WEEK. Monday through Friday, unless specified otherwise.

2.2. Acronyms:

ACOR

Alternate Contracting Officer's Representative

ASC

Ambulatory Surgical Center

CDA

Clinical Data Abstractor

CFR

Code of Federal Regulations

CONUS

Continental United States (excludes Alaska and Hawaii)

CO

Contracting Officer

COR

Contracting Officer Representative

COTR

Contracting Officer's Technical Representative

COTS

Commercial-Off-the-Shelf

DACA

Days after Contract Award

DD254

Department of Defense Contract Security Requirement List

DFARS

Defense Federal Acquisition Regulation Supplement

DHA

Defense Health Agency

DMDC

Defense Manpower Data Center

DOD

Department of Defense

FAR

Federal Acquisition Regulation

HIPAA

Health Insurance Portability and Accountability Act of 1996

MHS

Military Health System

MTF

Military Treatment Facility

NCR

Northern Capital Region

OCI

Organizational Conflict of Interest

OCONUS

Outside Continental United States (includes Alaska and Hawaii)

ODC

Other Direct Costs

PIPO

Phase In/Phase Out

POC

Point of Contact

PRS

Performance Requirements Summary

PWS

Performance Work Statement

QA

Quality Assurance

QAP

Quality Assurance Program

QASP

Quality Assurance Surveillance Plan

QC

Quality Control

QCP

Quality Control Program

TE

Technical Exhibit

PART 3

GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

3.0 Government Furnished Items and Services:

3.1. Services: Not Applicable

3.2 Facilities: Not Applicable

3.3 Utilities: Not Applicable

3.4 Equipment: Not Applicable

3.5 Materials: Not Applicable

PART 4

CONTRACTOR FURNISHED ITEMS AND SERVICES

4.0 Contractor Furnished Items and Responsibilities:

4.1 General: Web Based ASC National Benchmarking System and Web Based support information for all ASCs.

4.2 Secret Facility Clearance: Not Applicable

4.3. Materials: Not Applicable

4.4. Equipment: Not Applicable

PART 5

SPECIFIC TASKS

5.0 Specific Tasks:

5.1. Basic Services: The contractor shall provide membership to national ASC benchmarking program for clinical process and outcomes measures applicable to all MHS ASCs participation in order to assess the quality of ambulatory surgical services in comparison to other Ambulatory Surgery Centers nationwide.

5.2. Training of Clinical Data Abstractors (CDAs) on data collection, system specific metrics and entry into the web based system.

5.3. Data quality assurance, comparative analysis, and reporting of observed surgical process and outcomes based on a nationally recognized including CMS ASC measures. This includes:

5.3.1. Ensure ASC reports are available to access readily in the contractor database which provides for continual viewing of aggregated facility data for comparison with other participating sites as well as MHS system aggregated data through established reporting capabilities.

5.3.2. Data quality audits identifying unexpected outliers shall be conducted to enhance reliability and validity ASC data.

5.4. Quarterly reports for all ASCs shall be available for download, at minimum, every three (3) months by the COR and DHA.

5.5. Availability of Contractor Web Based system for data entry by the CDAs. The contractor web-based system is to be available 99% of the time excluding planned maintenance. The contractor shall acknowledge receipt of any technical support issue within eight (8) business hours and provide resolution within 48 hours of receipt. The correction of any deficiencies shall be at no cost to the Government. If the situation is not resolved at the ASC CDA level, the information will be sent to the COR.

5.6. Support Services for participation in a national ASC benchmarking program membership shall be available to support staff and address questions and issues related to the participation and use of the products/database. There should be support available for situation based ASC questions, such as a blog/user interface to allow for sharing of best practices and data acquisition from other like facilities. Questions and support requests will be responded to or resolved within three business days.

PART 6

OTHER TERMS, CONDITIONS, AND PROVISIONS

6.0 Other Terms, Conditions, and Provisions 6.1 Non-Disclosure /Non-Use Agreement The Contractor shall ensure that the Non-Disclosure/Non-Use Agreement (provided in Technical Exhibit 6) is signed by the contracting company representative. The Contractor shall also ensure that all staff understand and adhere to the terms of the Non-Disclosure Statement.

6.2 Information Assurance/General Security Requirements

The contractor shall comply with DoD Directive 8500.1, "Information Assurance (IA)," DoD Instruction 8500.2, "Information Assurance (IA) Implementation," DoD Directive 5400.11, "DoD Privacy Program," DoD 6025.18-R, "DoD Health Information Privacy Regulation," and DoD 5200.2-R, "Personnel Security Program Requirements." Follow the Defense Health Agency (DHA) Privacy Office guidelines for submittal of Automated Data Processor/Information Technology (ADP/IT) security clearances and ensure all contractor personnel are designated as ADP/IT-I, ADP/IT-II, or ADP/IT-III where their duties meet the criteria of the position sensitivity designations. Contact the DHA Privacy Office for guidance on the appropriate ADP/IT levels for personnel on the contract. The DHA Privacy Office procedures for personnel security are listed on the following website: www.tricare.mil/tma/privacy. (Technical Exhibit 3) 6.3 Enterprise Architecture (EA) – N/A 6.4 Protection of Information 6.4.1 Dissemination of Information/Publishing

There shall be no dissemination or publication, except within and between the Contractor and any subcontractors or specified Integrated Product/Process Team (IPT) members who have a need to know, of information developed under this order or contained in the reports to be furnished pursuant to this order without prior written approval of the TMA TM or the Contracting Officer. TMA approval for publication will require provisions which protect the intellectual property and patent rights of both TMA and the Contractor.

6.4.2 Contractor Employees

6.4.2.1 Contractor Identification

The Contractor shall ensure that Contractor personnel identify themselves as Contractors when attending meetings, answering Government telephones, providing any type of written correspondence, or working in situations where their actions could be construed as official Government acts.

6.4.2.2 Attendance at Meetings

Contractor personnel may be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel make their Contractor status known during introductions.

6.4.2.3 Use of Military Rank by Contractor Personnel

Contractor personnel, while performing in a Contractor capacity, are prohibited from using their retired or reserve component military rank or title in all written or verbal communications associated with the contract under which they provide services.

6.4.3 Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws: The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data. The Contractor shall also ensure the confidentiality, integrity, and availability of Government data in compliance with all applicable laws and regulations, including data breach reporting and response requirements, in accordance with Defense Federal Regulations Subpart 224.1 (Protection of Individual Privacy), which incorporates by reference current versions DoDD 5400.11, “DoD Privacy Program,” and DoD 5400.11-R, “DoD Privacy Program.” The Contractor shall also comply with federal laws relating to freedom of information and records management. The Contractor shall analyze any breach of PII/PHI for which it is responsible under the terms of this Contract under both the Privacy Act and Health Insurance Portability and Accountability Act (HIPAA), if applicable, to determine the appropriate course of action under each requirement, if any.

DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties. The HIPAA Rules require a Business Associates Agreement (BAA) between covered entities and business associates. Upon award of this contract, the DoD Military Health System (MHS) component, will act as a HIPAA covered entity, and the DoD contractor, will act as a HIPAA business associate. A signed BAA will be a requirement upon award (Deliverable 3).

6.4.4 Health Insurance Portability and Accountability Act: The Contractor shall comply with all requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104-191), as implemented by the HIPAA Privacy and Security Rules codified at 45 Code of Federal Regulations Parts 160 and 164, and as further implemented within the Military Health System (MHS) by DoD 6025.18-R, "DoD Health Information Privacy Regulation," January 24, 2003, and DoD 8580.02-R, “DoD Health Information Security Regulation, July 12, 2007. The Contractor shall also comply with all applicable HIPAA-related rules and regulations as they are published and as further defined by later-occurring Government requirements and DoD guidance, including current and forthcoming DoD guidance implementing applicable amendments under the American Recovery and Reinvestment Act of 2009. Any rules and regulations that are published, and/or requirements that are defined after the award date of this contract, and that require expenditure of additional Contractor resources for compliance, may be considered “changes” and will be subject to the “changes” clause under the contract. In addition, specific HIPAA requirements, including but not limited to, HIPAA breach responses in Section 1.36.3.

6.4.5 Privacy Act Breach Response: Current version DoD 5400.11-R, “DoD Privacy Program,” incorporated herein by reference, defines a breach as the “actual or possible loss of control, unauthorized disclosure, or unauthorized access of personal information where persons other than authorized users gain access or potential access to such information for other than authorized purposes where one or more individuals will be adversely affected.” Within one hour of discovery, the breach must be reported to the US Computer Emergency Readiness Team (US CERT), the DHA Privacy Office, and the DHA Contracting Officer.

The Contractor shall adhere to the reporting and response requirements set forth in the Office of the Secretary of Defense Memorandum 1504-07, “Safeguarding Against and Responding to the Breach of Personally Identifiable Information,” June 5, 2009; DoD 5400.11-R, also incorporated herein by reference, and consult DHA Privacy Office for guidance.

6.4.6 Federal Information Security Management Act (FISMA) – Deliverable 23: N/A

6.4.7 Data at Rest: N/A

6.4.8 Systems of Records: In order to meet the requirements of 5 U.S.C. 552a, the Privacy Act of 1974, and its implementation within the Military Health System (MHS) under DoD 5400.11-R, “ DoD Privacy Program,” May 14, 2007, the Contractor shall identify to the Contracting Officer Representative (COR) systems of records that are maintained or operated for DHA where records of personally identifiable information (PII) collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the COR, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete Systems of Records Notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy Office, and as required by DoD 5400.11-R.

Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by DoD 5400.11-R, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, and OMB Circular A-130.

6.4.9 Privacy Impact Assessment (PIA): The Contractor shall provide for the completion of a PIA for any applicable systems that collect, maintain, use or disseminate PII or PHI about members of the public, federal personnel, contractors, or in some cases foreign nationals.

To begin the PIA process, the Contractor is responsible for the completion of the PIA Determination Checklist. This Checklist provides basic system information to the DHA Privacy Office and ensures that the appropriate decision concerning PIA requirements is made. The current mandatory Checklist is available from the DHA Privacy Office.

The Contractor is responsible for the employment of practices that satisfy the requirements and regulations of: Section 208 of E-Government (E-Gov) Act of 2002, (Pub. L. 107-347); DoDI 5400.16, “DoD Privacy Impact Assessment (PIA) Guidance,” February 12, 2009; and, Office of Management and Budget (OMB) Memorandum 03-22, “OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002,” September 26, 2003. These documents are incorporated by reference. When completing PIA, the Contractor is responsible for using DoD-approved PIA Template, DD Form 2930.

Completed PIA Determination Checklists and DD Form 2930s will be sent to the DHA Privacy Office.

6.4.10 Data Sharing Agreement (DSA): A DSA which may be referred to in other sources as a Data Use Agreement (DUA), is currently used to control the disclosure, use, storage and/or destruction of MHS data that is managed by DHA to ensure compliance with privacy and security requirements applicable to PII, including but not limited to PHI. In addition, research requests for MHS data that include PHI must be reviewed for HIPAA compliance by the DHA Privacy Board.

Under DoD 6025.18-R, “DoD Health Information Privacy Program,” January 24, 2003, C8.3.4, a DSA is required to establish permitted uses for certain types of data IAW HIPAA requirements to prevent the unauthorized use and/or disclosure of any PII or PHI. Likewise, all uses, disclosures, and destruction of PII and PHI data are generally subject to DoD 5400.11-R, “DoD Privacy Program,” May 14, 2007, as well as DoDI 8500.2, “Information Assurance (IA) Implementation,” Feb. 6, 2003, and DoD 8580.02-R, “DoD Health Information Security Regulation,” July 12, 2007.

To begin the data sharing request process, the Contractor shall complete and submit a Data Sharing Agreement Application (DSAA) or contact the DHA Privacy and Civil Liberties Office (Privacy Office), and copy the Contracting Officer, If the application is approved, the requestor will enter into one of the following agreements, depending on the data involved:

· DSA for De-Identified Data

· DSA for PHI

· DSA for PII Without PHI

· Data Use Agreement for Limited Data Set.

After receiving DSA approval, anyone needing access to information system applications or data sources must contact the responsible system program office. DSAs are active for one year, or until the end of the current option year, whichever comes first. If the DSA will not be renewed, the Contractor shall provide a Certificate of Data Disposition (CDD) to the Privacy Office.

6.4.11 Privacy Act and HIPAA Training: The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act of 1974 (5 U.S.C. 552a) and Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191). The training requirements are mandated by OSD Memorandum 15041-07, “Safeguarding Against and Responding to the Breach of Personally Identifiable Information”: DoD 6025.18-R, “DoD Health Information Privacy Regulation”, January 24, 2003; and the DHA Workforce Training Policy Memorandum, dated May 28, 2008, on the subject, “Workforce Training Policy Pursuant to the Department of Defense Privacy Act Regulations and the Department of Defense Health Insurance Portability and Accountability Act Privacy and Security Regulations”.

All required Privacy Act and HIPAA training will be conducted online through Military Health System Learn (MHS Learn) or the current DHA learning management system (LMS) in place to deliver training to meet the above requirements. The Contractor shall ensure all employees and subcontractors supply a certificate of Privacy Act and HIPAA training completion to the COR within 30 days of being assigned to the Task Order and on an annual basis based on the trainee’s birth month thereafter.

6.4.12 Records Management: When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (USC), 41 USC, 36 Code of Federal Regulations, Department of Defense Administrative Instruction No. 15 (DOD AI-15), “Records Management, Administrative Procedures and Records Disposition Schedules,” and Chapter 2 of the TRICARE Operations Manual.

6.4.13 Freedom of Information Act (FOIA) Office: DHA Freedom of Information (FOIA) procedures require a written request under the Act to be addressed to the FOIA Officer, DHA, 16401 East Centretech Parkway, Aurora, Colorado 80011-9066. The request shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. No more than ten working days shall elapse after a request has been received by the Freedom of Information Officer before notification is sent that the request has been granted or denied. The administrative time limit for responding to FOIA requests does not begin until the request is received by DHA.

In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference the Freedom of Information Act shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between DHA contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves under the Privacy Act procedures when those procedures are more advantageous to the requestor.

6.5 Enterprise-wide Contractor Manpower Reporting Application, Policy Alert 13-38 dated 13 May 2013, DPAP Memorandum dated 28 November 2012 and Policy Alert 13-59 dated 14 Aug 2013.

N/A

PART 7

APPLICABLE PUBLICATIONS

7.0 Applicable Publications (Current Editions)

7.1. The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures.

PART 8

TECHNICAL EXHIBIT LISTING

8. Technical Exhibit List:

Technical Exhibit 1 – Performance Requirements Summary Technical Exhibit 2 – Standard HIPAA Language Technical Exhibit 3 – Deliverables Schedule Technical Exhibit 4 – Organizational Conflict of Interest (OCI) Technical Exhibit 5 – DHA Contractor Non-Disclosure Agreement (NDA)

Technical Exhibit 6 – DHA Business Associate Agreement (BAA)

TECHNICAL EXHIBIT 1

PERFORMANCE REQUIREMENTS SUMMARY

Performance standards define desired services. The Government performs surveillance to determine if the Contractor exceeds, meets or does not meet these standards.

The Performance Requirements Summary Matrix below includes performance standards. The Government will use these standards to determine Contractor performance and will compare Contractor performance to the Acceptable Quality Level (AQL).

Performance Requirement
Standard
Acceptable Quality Level
Surveillance Method

1.

ASC national quality benchmarking Membership Participation Agreements annual renewal

Maintain current participation agreements for all participating Ambulatory Surgical Center or otherwise known as a Military Treatment Facilities (MTFs)
Participation agreements are required to be completed annually
100% completion
100% inspection
2. Training
Training of Clinical Data Abstractors
Electronic/web or telephonic based training available continuously
Training available within two business day of request
Validated through Clinical Data Abstractor with reports to COR
3. ASC national quality benchmarking web based system
Availability of ASC national quality benchmarking web based system for data entry by Clinical Data Abstractors
ASC Database available for data entry and reports 99% of the time excluding planned maintenance
ASC Database available for data entry and reports 99% of the time excluding planned maintenance
Validated through Clinical Data Abstractor, ASC leaders, COR, Service leaders and DHA leadership
4. Technical Support
Contractor response time for any technical support issues
The contractor shall acknowledge receipt of any technical support issue within eight (8) business hours and provide resolution within 48 hours of receipt.
The contractor shall acknowledge receipt of any technical support issue within eight (8) business hours and provide resolution within 48 hours of receipt.
Validated through Clinical Data Abstractor, ASC leaders, COR, Service leaders and DHA leadership
5. Membership Support Services
Availability of ASC national quality benchmarking membership support staff to address questions and issues.
Questions and support requests responded to and/or resolved within three (3) business days
Questions and support requests responded to and/or resolved within three (3) business days
Validated through Clinical Data Abstractor, ASC leaders, COR, Service leaders and DHA leadership comments/ complaints

TECHNICAL EXHIBIT 2

STANDARD HIPAA LANGUAGE

Personally Identifiable Information (PII), Protected Health Information (PHI), and Federal Information Requirements (Revised April 2, 2014)

1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Privacy and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and DoD issuances. In general, the Contractor shall comply with the specific requirements set forth in this section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.

This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives. For purposes of this Section, the following definitions apply.

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (May 8, 2007 thru Change 1 September 1, 2011) and DoD 5400.11-R (May 14, 2007).

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, 78 FR 5566-5702 (January, 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD 6025.18-R (January 24, 2003), DoDI 6025.18 (December 2, 2009), and DoD 8580.02-R (July 12, 2007).

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

Service-Level Privacy Office means a privacy office of one of the military Services (Army, Navy, or Air Force). The Service-Level Privacy Offices have authority over Privacy Act and HIPAA compliance by the military Services. [This definition is applicable to this Contract if the Government party to this Contract is one of the Services or a Service component. In that case, this Section may need Service-specific provisions in addition to this definition.] Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of a breach in 45 CFR 164.402.

2. Records Management When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 U.S.C. Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DOD AI-15), “OSD Records and Information Management Program” (May 3, 2013).

3. Freedom of Information Act (FOIA) The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:

The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101 (or email requests addressed to FOIARequests@tma.osd.mil), and that the request shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible.

In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference the Freedom of Information Act shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.

4. Systems of Records In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy and Civil Liberties Office, and as required by the DoD Privacy Act Issuances.

Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, and OMB Circular A-130. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.

5. Privacy Impact Assessment (PIA) The Contractor shall provide for the completion of a PIA for any applicable systems that collect, maintain, use or disseminate PII or PHI about members of the public, federal personnel, contractors, or in some cases foreign nationals. The Contractor shall establish practices that satisfy the requirements of DoDI 5400.16, “DoD Privacy Impact Assessment (PIA) Guidance.” (February 12, 2009). To begin the PIA process, the Contractor shall use the DoD-approved PIA Template, DD Form 2930. The Contractor shall use the DHA PIA Guide to complete the DD Form 2930. The Contractor should send completed DD Form 2930s to the DHA Privacy Office for review and approval, with a copy to the CO.

6. Data Sharing Agreement (DSA) (Applies if contract requirements involve PII/PHI or de-identified data that would be PII/PHI) The Contractor shall consult with the DHA Privacy Office to determine if the Contractor must obtain a Data Sharing Agreement (DSA) or Data Use Agreement (DUA), when MHS data that is managed by DHA will be accessed, used, disclosed or stored, to perform the requirements of this Contract. The Contractor shall comply with requests for additional documentation by the DHA Privacy Board when requesting PHI for research.

In addition, the Contractor shall submit any research requests for MHS data that include PHI to the DHA Privacy Board in order to be reviewed for HIPAA compliance.

The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and the DoD HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.

To begin the data sharing request process, the Contractor shall submit a Data Sharing Agreement Application (DSAA) to the DHA Privacy Office. If the application is approved, the requestor shall enter into one of the following agreements, depending on the data involved:

DSA for De-Identified Data

DSA for PHI

DSA for PII without PHI

Data Use Agreement for Limited Data Set.

DSAs are active for one year, or until the end of the current option year, whichever comes first. If the DSA will not be renewed, the Contractor shall provide a Certificate of Data Disposition (CDD) to the DHA Privacy Office.

7. Privacy Act and HIPAA Training The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, and HIPAA.

8. HIPAA Business Associate Provisions

8.1 Business Associate – General Provisions

The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. This paragraph 8 serves as the required BAA. As a Business Associate, the Contractor shall comply with the HIPAA Rules and the DoD HIPAA Issuances applicable to a business associate performing under this Contract.

8.1.1 Catch-All Definition: The following terms used, but not otherwise defined in paragraph 8.1, shall have the same meaning as those terms have in the DoD HIPAA Issuances: Data Aggregation, Designated…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .