DRAFT ELP VA SOW_Security Systems for Bldgs 116 _ 117_ Warehouse _ Sleep Center.docx
DOCX document 51 KB Posted
- Attached to
- 5963-- Security System Camera Surveillance Federal contract opportunity
- Solicitation number
- 36C25723Q0472
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sources Sought_.docx | DOCX document | |
| 36C25723Q0472.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
El Paso Veterans Affairs Health Care System (ELPVAHCS) Physical Security Systems for Bldg. 116 & 117, VA Warehouse & Sleep Center Statement of Work (SOW)
1. GENERAL INFORMATION
0. El Paso VA Health Care System (EPVAHCS), Police Services, requires the purchase, installation, and initial reprogramming to upgrade their physical security systems for Bldgs. 116 & 117, Sleep Center & Warehouse with equipment compatible with, or similar to the Bosch B8512G and CCure9000 type of devices to allow all motion intrusion equipment to mitigate risk based off Unauthorized Entry – Forced & Surreptitious and Breach of Access Control Point – Covert & Overt.
0. The ELP VA Police Services is required by the Physical Security and Resiliency Design Manual revised March 1-2022, the RCS 10-1 manual, OSLE Inspection Guide and 0730-4 VA Handbook to have a motion intrusion alarm system. It is also required that the motion intrusion be monitored. The motion intrusion allows Police Services the ability to mitigate risk based off the 33 Undesirable Events (UEs), including Unauthorized Entry – Forced & Surreptitious and Breach of Access Control Point – Covert & Overt.
1. EQUIPMENT LOCATIONS /DESCRIPTION AND SALIENT CHARACTERISTICS
1. BUILDINGS 116 & 117
1. El Paso VA Health Care System (EPVAHCS), Police Services, requires the purchase, installation, and reprogramming of Two digital communicators compatible with, or similar to with Bosch B8512G devices to allow motion intrusion equipment to communicate with all existing devices (6 panels and 17 motion intrusion sensors) within Bldg. 116 & 117 located on Pershing Rd, Fort Bliss Texas 79916
1. This digital communicators must be able to monitor and detect any entry into Bldgs. 116 & 117 after hours and notify VA Police Services and the Fort Bliss Military Police to respond to the alarm. This motion intrusion system shall provide a deterrent to theft, and unauthorized entry.
1. The communicator links control panel's digital dialer to an Ethernet connection on a local area or wide area network or to an optional cellular module to send reports to a receiver at the central monitoring station, who contact the VA Police and Fort Bliss Military Police in the event of an incident. This communicator shall have the following salient characteristics:
· Must be Compatible with the Bosch B8512G control panel and all the connected motion sensors and door contacts.
· Must supports Ethernet directly and optional plug-in cellular communication technologies in single, or multi-path configurations
· Must Supports four configurable inputs and three configurable outputs
· Approved for Commercial Burglary applications as sole, primary, or secondary communication path
· It must fully integrates the motion intrusion systems to one notification system instead of requiring someone on site at all times.
· Equipment shall provide up to 99 points using a combination of hardwired or wireless devices for installation flexibility, and up to 8 areas and 8 doors for up to 500 users ?
· On-board Ethernet port for Conettix IP alarm communication and remote programming, compatible with modern IP networks including IPv6/IPv4, Auto-IP, and Universal Plug and Play.
1. WAREHOUSE
1. El Paso VA Health Care System (EPVAHCS), Police Services, requires the purchase, installation, and reprogramming of Access Control system, a Camera Surveillance and a motion intrusion systems. All of the systems need to be compatible with, or similar to the CCure9000 system used at the El Paso VA Main Facility. The warehouse is located at 6 Founders Blvd, El Paso, TX 79906
1. The ELP VA Police Services is required by the Physical Security and Resiliency Design Manual revised March 1-2022, the RCS 10-1 manual, OSLE Inspection Guide and 0730-4 VA Handbook to have an access control system, a camera surveillance system and a motion intrusion alarm system. The access control system, camera surveillance system and the motion intrusion system allows Police Services the ability to mitigate risk based off the 33 Undesirable Events (UEs), including Unauthorized Entry – Forced & Surreptitious and Breach of Access Control Point – Covert & Overt
1. The motion intrusion system must be able to monitor and detect any entry into Warehouse after hours and notify VA Police Services and the El Paso Police Department to respond to the alarm. This motion intrusion system shall provide a deterrent to theft, and unauthorized entry. The access control system must be HSPD-12 compliant. And must be able to control who is able to enter the facility. The Camera Surveillance system must be able to monitor the interior and exterior of the building. This Camera surveillance system shall provide a deterrent to theft, and unauthorized entry. It will also allow VA Police to determine who committed the theft, unauthorized entry or vandalism.
1. The warehouse will need the following equipment with salient characteristics:
· Motion Intrusion System:
· 4 Motion Detectors
· Must be Passive infrared and microwave Doppler radar detection
· 1 Control Panel with Key Pad
· 2 Zone Expanders
· 1 Alarm Communicator
· 1 Power Supply/Charger Kit
· 3 Back Up Battery
· 1 of the backups must be compatible with DSC
· 1 DSC Integration Modules for CCURE Integration
· 4 Door Contacts
· 2 Overhead Door Contacts
· 4 Hardwired Panic Buttons
· 4 Sirens
· Must be at least 80db with a max of 90db
· Must have all the supplies, cables and conduits required to install and properly run the equipment
· Approved for Commercial Burglary applications as sole, primary, or secondary communication path
· Camera Surveillance System:
· 1 Network Video Recorder (NVR)
· Must have at least 18TB, capable of storing 30 days worth of video from all the cameras
· Must include Software licenses
· Must be compatible with CCure9000
· Must include 1 C-Video NVR
· 1 Desktop Monitor
· Must be at least 24”
· 1 POE+ Switch
· Must have 24 Ports
· Must use Cat6 cables
· 3 POE Injectors
· 3 Conduit Adapters
· 4 Cat6 Plenum Cable
· 3 Multisensor Cameras
· Each Multisensor camera must have 4 cameras in it
· Must be 20MP (5MP x4)
· 8 MiniDome, Indoor/Outdoor Cameras
· Must be at least 4MP
· 2 MiniDome, Indoor/Outdoor Cameras
· Must be at least 2MP
· Must have all the supplies, mounts, hooks, adaptors, cables and conduits required to install and properly run the equipment
· Access Control System:
· 1 C•CURE 9000-Series L Bundled Tower System
· Must include tower
· Must be able to integrate with the Camera Surveillance system and motion intrusion system
· 1 Innometriks High Assurance Software Suite
· Must include Enrollment Server, Panel Server, Enrollment Plug-in, for Series L, M, N and SiteServers
· Must be HSPD-12 compliant
· 1 Innometriks Stand-Alone Enrollment Client
· Must be valid for PIV card validation and enrollment into ID Server, per client
· 1 USB enrollment reader, contact interface
· 1 USB PIN Pad
· 1 Desktop Monitor
· Must be at least 24”
· 1 iSTAR Ultra
· Must have 8-Reader Board
· Must have in wall mount enclosure
· Wall mount enclosure must be 20”x16” with lock and tamper
· Must have low battery disconnect switch
· Must be capable of holding three 14AHr batteries
· 6 Door Position switches
· 2 Battery Back ups
· 2 Magnetic locks
· 3 request to exit buttons
· 3 Request to exit sensors
· 3 Rim Strikes
· 1 Recessed Strike
· 2 Plenum Composite Cables
· Cat6 Cable
· At least 150ft
· 6 Card Readers
· Must be pin pad
· Must be HSPD-12 compliant
· 1 One day of Professional Services
· For initial setup
· Must be accomplished via remote access
· 1 Tripp Lite SU2200RTXL2UA Smartonline 120V
· Must have all the supplies, mounts, hooks, adaptors, cables and conduits required to install and properly run the equipment
SEE ATTACHED DIAGRAMS WITH EXACT LOCATIONS AND EQUIPMNENT LITERATURE
2.10. SLEEP CENTER
2.11. El Paso VA Health Care System (EPVAHCS), Police Services, requires the purchase, installation, and reprogramming of Access Control system, a Camera Surveillance system and a motion intrusion system. All of the systems need to be compatible with, or similar to the CCure9000 system used at the El Paso VA Main Facility. The Sleep Center is located at 1250 E Cliff Dr, El Paso, TX 79902
2.12. The ELP VA Police Services is required by the Physical Security and Resiliency Design Manual revised March 1-2022, the RCS 10-1 manual, OSLE Inspection Guide and 0730-4 VA Handbook to have an access control system, a camera surveillance system and a motion intrusion alarm system. It is also required that the motion intrusion be monitored. The access control system, camera surveillance system and the motion intrusion system allows Police Services It is also required that the motion intrusion be monitored. The motion intrusion allows Police Services the ability to mitigate risk based off the 33 Undesirable Events (UEs), including Unauthorized Entry – Forced & Surreptitious and Breach of Access Control Point – Covert & Overt.
2.13. The motion intrusion system must be able to monitor and detect any entry into Sleep Center after hours and notify VA Police Services and the El Paso Police Department to respond to the alarm. This motion intrusion system shall provide a deterrent to theft, and unauthorized entry. The access control system must be HSPD-12 compliant. And must be able to control who is able to enter the facility. The Camera Surveillance system must be able to monitor the interior and exterior of the building. This Camera surveillance system shall provide a deterrent to theft, and unauthorized entry. It will also allow VA Police to determine who committed the theft, unauthorized entry or vandalism.
2.14. The Sleep Center will need the following equipment with salient characteristics:
· Motion Intrusion System:
· 6 Motion Detectors
· Must be Passive infrared and microwave Doppler radar detection
· 4 Glass Breaks
· Must include 1 Glass Break testing device
· 1 Control Panel with Key Pad
· 1 Zone Expanders
· 1 Alarm Communicator
· 1 Power Supply/Charger Kit
· 3 Back Up Batteries
· 1 of the back ups must be compatible with DSC
· 1 DSC Integration Modules for CCURE Integration
· 2 Door Contacts
· 2 Hardwired Panic Buttons
· 2 Sirens
· Must be at least 80db with a max of 90db
· Must have all the supplies, cables and conduits required to install and properly run the equipment
· Must include the removal of all existing motion intrusion equipment
· Approved for Commercial Burglary applications as sole, primary, or secondary communication path
• Camera Surveillance System
· 1 Network Video Recorder (NVR)
· Must have at least 18TB, capable of storing 30 days worth of video from all the cameras
· Must include Software licenses
· Must be compatible with CCure9000
· Must include 1 C-Video NVR
· 1 Desktop Monitor
· Must be at least 24”
· 1 POE+ Switch
· Must have 24 Ports
· Must use Cat6 cables
· 5 POE Injectors
· 4 Conduit Adapters
· 4 Pendant Cap
· 4 Short Wall Mounts
· 4 Corner adapter for use w/RHOxW
· 1 Patch Panel
· 14 Patch cords
· 4 Cat6 Plenum Cable
· 5 Multisensor Cameras
· Each Multisensor camera must have 4 cameras in it
· Must be 20MP (5MP x4)
· 1 Ceiling Tile mounted Multisensor camera
· Multisensor camera must have 4 cameras in it
· Must be 20MP (5MP x4)
· 9 MiniDome, Indoor/Outdoor Cameras
· Must be at least 2MP
· Must have all the supplies, mounts, hooks, adaptors, cables and conduits required to install and properly run the equipment
• Access Control System:
· 1 C•CURE 9000-Series L Bundled Tower System
· Must include tower
· Must be able to integrate with the Camera Surveillance system and motion intrusion system
· 1 Innometriks High Assurance Software Suite
· Must include Enrollment Server, Panel Server, Enrollment Plug-in, for Series L, M, N and SiteServers
· Must be HSPD-12 compliant
· 1 Innometriks Stand-Alone Enrollment Client
· Must be valid for PIV card validation and enrollment into ID Server, per client
· 1 USB enrollment reader, contact interface
· 1 USB PIN Pad
· 1 Desktop Monitor
· Must be at least 24”
· 1 iSTAR Ultra
· Must have two 8-Reader Board
· Must have in wall mount enclosure
· Wall mount enclosure must be 20”x16” with lock and tamper
· Must have low battery disconnect switch
· Must be capable of holding three 14AHr batteries
· 4 Door Position switches
· 2 Battery Back ups
· 10 request to exit buttons
· 10 Request to exit sensors
· 4 Recessed Strike
· Cat6 Cable
· At least 150ft
· 2 Plenum Composite Cables
· 10 Card Readers
· Must be pin pad
· Must be HSPD-12 compliant
· 1 One day of Professional Services for initial setup
· Must be accomplished via remote access
· 1 Tripp Lite SU2200RTXL2UA Smartonline 120V
· Must have all the supplies, mounts, hooks, adaptors, cables and conduits required to fully installed and properly run the equipment
SEE ATTACHED DIAGRAMS WITH EXACT LOCATIONS AND EQUIPMNENT LITERATURE
2.2. INSTALLATION AND DELIVERY COORDINATION:
1. Installation and or training shall include minimum five (5) days on-site in installation and specialized training for Administrator/s, supervisors as needed within the Police Service.
1. Installation date/ time shall be coordinated in advanced with logistics and the Police Services.
1. Entry to Fort Bliss to install security equipment must have an escort and shall be coordinated in advance with COR Mr. Conklin, Roger at 915-564-6100 Ext 6465 or 6600 from the ELP VA’s Police services.
1. Equipment will be delivered to the Supply Chain Management Service located at:
| 5001 N Piedras St, |
| El Paso, |
| TX 79930 |
| Phone: 915-564-6100. Extensions: 6194, 6095 |
3. WORK HOURS:
3.1. Normal Work Hours: The service schedule shall be developed between the contractor and Contractor’s Representative (COR) prior to any service being performed.
3.2. The following is a list of U.S. Government holidays. If the holiday falls on a Saturday, the proceeding Friday is observed as the holiday; if the holiday falls on a Sunday, the following Monday is observed as the holiday and any other day specifically declared by the President of the United States to be a national holiday.
HOLIDAY DATE
| New Year’s Day | Jan 1 | |||
| Martin Luther King’s Birthday | 3rd Monday in Jan | |||
| President’s Day | 3rd Monday in Feb | |||
| Memorial Day | Last Monday in May | |||
| Juneteenth National Independence | Day June 19th | |||
| Independence Day | July 4 | |||
| Labor Day | 1st Monday in Sep | |||
| Columbus Day | 2nd Monday in Oct | |||
| Veterans Day | Nov 11 | |||
| Thanksgiving Day | 4th Thursday in November | |||
| Christmas Day | December 25 |
4. PERSONNEL
4.1. The contractor shall provide in writing the personnel name and phone number within (10) ten calendar days of the award of the contract. Personnel shall be a qualified and experienced to oversee the personnel assigned to perform the installation. The contractor’s personnel shall correspond with the logistics department and Police Service on a regular basis to discuss any problems related to equipment characteristics, compatibility with systems in place, delivery and installation. Unresolved problems shall be referred to the Contracting Officer for resolution.
4.2. Contractor Service Personnel (CSP). All subcontractors performing work for primary contractor shall meet all specifications and standards that apply to CSP under this agreement. CSP shall maintain clean and neat appearance and shall wear an identification badge at all times when performing services at the Government site. Identification badges shall be worn in a clearly visible area of the outer garment. The COR shall furnish this badge. Due to conflict of interest, the contractor shall not employ a current DOD employee, military or civilian to provide services under this contract.
4.3. Government point of contact (POC). The COR shall be the Government’s POC. If required, the COR shall be designated in writing to the Contractor and the scope of authority shall be set forth therein. Contractor shall respond only to calls from COR or a designated representative from the Medical Center.
5. SECURITY STATEMENT:
5.1. The Vendor shall not transfer any VA information to a location outside the VA and only to VA locations determined by the VA System Administrator. The information in these systems may be covered by the Privacy Act 1974 which contains criminal penalties of abuse of information.
5.2. The Vendor and all VA employees are required to immediately report any security violations to the Information Security Officer. No other security statements are required.
5.3. Information Security & Privacy.
0. The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract.
0. Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
0. A contractor/sub-contractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
0. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
0. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
0. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
0. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
0. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
0. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
0. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.
0. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.
Each risk analysis shall address all relevant information concerning the data breach, including the following:
10. Nature of the event (loss, theft, unauthorized access);
10. Description of the event, including:
1. date of occurrence;
1. data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code.
1. Number of individuals affected or potentially affected.
1. Names of individuals or groups affected or potentially affected.
1. Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text.
1. Amount of time the data has been out of VA control.
1. The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons).
1. Known misuses of data containing sensitive personal information, if any.
1. Assessment of the potential harm to the affected individuals.
1. Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate.
1. Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.
1. The contractor/subcontractor agrees to comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act.
1. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
10. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems.
10. Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training.
10. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and
10. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]
5. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
5. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.
1. VA sensitive information is to be transferred between the device and VISTA only, will not go outside the VA network or information system.
6. ACRONYMS AND DEFINITIONS
6.1. Contracting Officer (CO). A person duly appointed with the authority to enter into and administer contracts on behalf of the U.S. Government.
6.2. Contracting Officer’s Representative (COR). An individual designated in writing by the Contracting Officer to act as an authorized representative of the Contracting Officer to perform specific contract administrative functions within the scope and limitations as defined by the Contracting Officer.
7. EQUIPMENT OWNERSHIP.
7.1. Title to equipment shall remain with the contractor until installed and established. After completion, a satisfactory inventory and inspection is completed by Contractor, COR, and Maintenance personnel. Upon approved inspection, title, equipment, accessories and ownership shall be released to EL Paso Veterans Affairs Health Care System (ELPVAHCS).
8. LIMITED WARRANTY.
8.1. All equipment listed to the attached quote, shall be fit and sufficient for the purpose intended as set forth in the user manuals; and merchantable, of good quality and free from defects in materials or workmanship; for a period of one (1) year from the date of the first invoice under this agreement.
9. VHA PRIVACY AWARENESS
9.1 Pursuant to the Veteran Health Administration (VHA) Privacy principles and practices, Contractors shall comply with VA’s privacy, policies, and legal requirements found in this link: https://www.va.gov/privacy-policy/
9.2 The contractor must contact the education program manager at 915-564-6100 ext. 7600 to take the following Privacy Awareness Training that meets the requirements of the Health Insurance Portability and Accountability Act (HIPAA), Privacy Rule as determined by VHA, and the VA’s Privacy Training Monitoring SOP:
| a.VA 10176 – VA Privacy and Information Security Awareness | Training and Rules of Behavior |
| b.VA 10203 – Privacy and HIPAA Focused Training | |
| c.VA 3185966 – VHA Mandatory Training for Trainees | |
| d.VA 3192008 – VHA Mandatory Training for Trainees – Refresher |
10. NARA RECORDS MANAGEMENT
10.1 Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
10.2 In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
10.3 In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
10.4 El Paso Veteran Affairs Health Care System (EPVAHCS) and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of EPVAHCS or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.
In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to EPVAHCS. The agency must report promptly to NARA in accordance with 36 CFR 1230.
10.5 The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to EPVAHCS control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
10.6 The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and EPVAHCS guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
10.7 The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with EPVAHCS policy.
10.8 The Contractor shall not create or maintain any records containing any non-public EPVAHCS information that are not specifically tied to or authorized by the contract.
10.9 The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
10.10 The EPVAHCS owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which EPVAHCS shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
10.11 Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take VHA-provided records management training, Talent Management System (TMS) Item #10176, Privacy and Information Security, Rules of Behavior. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
10.12 References. VHA Directive 6300(1) National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a).
Security Statement. - The C&A requirements do not apply, and a Security Accreditation Package is not required.
File details come from the government source that posted it. Updated .