EMSS Bridge Award PWS 12.16.22 .docx
DOCX document 2 MB Posted
- Attached to
- Synopsis/Special Notice for Sole Source award for Engineering Management Support Services. Federal contract opportunity
- Solicitation number
- HT001123R0009
- Issued by
- Defense Health Agency
About this file
This special notice announces a sole source award for a firm-fixed price bridge contract to provide engineering management support services. The contract will be awarded to Deloitte, LLP to provide systems and software engineering, information assurance, architecture, configuration management support, requirements definition and derivation, subject matter expertise advising, acquisition lifecycle efforts, systems integration support, deployment activities and other technical and administrative activities in support of the Electronic Health Record Core and Care Benefits Integrated Systems Program Management Offices product lines. The base systems supported include AHLTA, Composite Health Care System, Healthcare Artifact and Image Management Solution, Essentris and other smaller projects. The period of performance is a nine-month base period and a three-month option period. The place of contract performance will be conducted remotely within the continental United States.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Synopsis EMSS.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Defense Defense Health Agency Performance Work Statement
Engineering Management Support Services (EMSS)
DADIO J6/ Solution Delivery Division/Technology Support Branch
PRMD/SDD/SRMB
Solicitation Number:
Version:
Date: 12/16/2022
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide Engineering Management Support Services. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government. The purpose of this contract is to provide engineering management and technical support for the full range of DHA’s Electronic Health Record (EHR) systems and software, which are used to support DoD’s medical operations at globally located facilities and deployed locations. The required engineering management and support must keep the EHR systems and software running seamlessly through their current sustainment lifecycle phase and during the transition to the next generation EHR systems and software.
1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Engineering Management Support Services as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.
1.3 Background: The Military Health System (MHS) consists of a worldwide network of military hospitals, health clinics, the Department of Defense’s (DoD) private sector health business partners, and the Uniformed Services University of the Health Sciences. The primary mission of the MHS is to ensure the Nation has available at all times a healthy fighting force and the ability to support DoD missions worldwide. The Assistant Secretary of Defense for Health Affairs (ASD [HA]) oversees the MHS and is responsible for providing a cost effective, quality health benefit to 9.5 million active duty members, retirees, survivors and their families.
TRICARE is the DoD’s worldwide health care program for active duty and retired uniformed services members and their families. The Defense Health Agency (DHA) operates the MHS under the authority, direction, and control of the ASD (HA), who also serves as the Director of DHA.
Similarly, the Chief Information Officer (CIO) for the Office of Assistant Secretary of Defense for Health Affairs OASD (HA) also serves as the DHA Director for Health Information Technology. The CIO oversees numerous functional directorates and supports the MHS by applying the principles of DoD information and technology management through the development and implementation of the policies, procedures, programs, and technical standards necessary to acquire, manage, integrate, and secure information technology systems and capabilities that support the delivery of high quality, cost effective health care services across the operational continuum.
The Solution Delivery Division (SDD) includes two Program Management Offices (PMO) each led by designated Defense Acquisition Workforce Improvement Act (DAWIA) certified Program Managers: 1) Electronic Health Record (EHR) Core PMO; and 2) Care & Benefits Integrated Systems (CBIS) PMO. The engineering, architecture and information assurance/cybersecurity, testing and configuration management functions support the PMOs but are assigned within the Technology Support Branch (TSB) of SDD.
Electronic Health Record (EHR) Core PMO
The mission of the Electronic Health Record (EHR) Core Program Management Office (PMO) is to sustain the current DoD EHR suite of outpatient and inpatient IT applications and systems used in the garrison setting. The current EHR provides IT capabilities to over 96,000 users at 101 host sites and 400+ clinics, supporting 9.6M beneficiaries and averaging 775K outpatient encounters per week. The EHR Core PMO’s mission includes maintaining and ensuring stability of the AHLTA Clinical Data Repository (CDR) which contains data entered by AHLTA users, data constantly extracted and translated from the 101 Composite Health Care System (CHCS) host systems, and clinical data flowing from the theater of operations.
AHLTA
AHLTA is one of the world's largest clinical information systems, providing secure, 24/7 access to TRICARE beneficiaries’ medical records worldwide. AHLTA is a key enabler of military medical readiness, and the centerpiece of the Military Health System’s (MHS) EHR. AHLTA consists of the following components: a client application with which AHLTA end users interface; a local host database to aid in failover; and a central repository (i.e., the CDR). Currently deployed on a global scale, AHLTA supports Force Health Protection (FHP) for DoD Service members while serving abroad as well as health services for their family members and other beneficiaries in military medical facilities “back home.” AHLTA data is stored in a central location (i.e., the Clinical Data Repository [CDR]) to ensure healthcare providers have ready access to medical information when and where needed, to support the military's highly-mobile patient population. As military members move from location to location, AHLTA ensures information is readily available to support their continuing health care needs. AHLTA supports uniform, high-quality health promotion (i.e., population health, wellness, and disease management), as well as healthcare delivery to TRICARE beneficiaries across the DoD enterprise. AHLTA is fully deployed and in sustainment mode. In its current state, AHLTA leverages CHCS to perform routine patient appointment processes and scheduling, order laboratory tests, retrieve test results, authorize radiology procedures, and prescribe medications. AHLTA also integrates with HAIMS to associate images and artifacts to patient encounters and AHLTA Web Print to enable complete printing of a patient’s AHLTA record.
Composite Health Care System (CHCS)
CHCS, the MHS’ original Computer-based Provider Order Entry (CPOE) system, is one of the most broadly deployed medical information systems in the world and it serves as the core medical information system for the DoD.
CHCS continues to be one of the most broadly used CPOE systems in the Nation. This powerful system enables DoD providers to electronically order laboratory tests, retrieve test results, authorize radiology procedures and prescribe medications. Reducing the risk of illegible orders and completing drug interaction and appropriateness checks, the CPOE functionality of CHCS continues to safeguard care provided to our MHS beneficiaries. For patients, CHCS facilitates improvements in the delivery of health care that reduce wait time, increase access to medical and professional resources, and expedite diagnostic testing. For providers, CHCS promotes increased communication and supports near real-time access to local patient information.
CHCS is fully deployed and in sustainment mode. Functional capabilities include patient registration, admission, disposition, and transfer; outpatient administration data; appointment scheduling; laboratory data; drug interaction alerts; quality assurance, radiology results; clinical dietetic administration; pharmacy alerts; computerized order entry and results retrieval; ad hoc reporting; and managed care.
Clinical Information Systems (CIS)/ Essentris®
CIS/Essentris®, a Commercial off the Shelf (COTS) product, is a mission-critical clinical documentation system for use in Department of Defense (DoD) Military Treatment Facilities (MTFs). CIS/Essentris® has the following key components: a) patient charts that include flow sheets, treatment notes, medication administration, care plans and integrated order entry, b) automated collection and charting of physiologic data from monitors, and c) real-time reporting and analytics. Use of the CIS eliminates the majority of paper-based documentation because CIS/Essentris®, clinical documentation is created and stored electronically.
The system is used in MHS acute care hospitals and captures point-of-care data from physiological devices, fetal/uterine devices, ventilators and other patient care machines at the patient’s bedside. This clinical data may be aggregated, trended, and analyzed to manage care for a single patient or for an entire patient population. The key capabilities are:
| • | Information sharing with the VA; |
| • | Admissions, Discharge, and Transfer (ADT) Interface to CHCS (HL-7); |
| • | Inbound laboratory, microbiology, and radiology results from CHCS; and |
| • | Global Data Repository (GDR)—a relational database that is local to each site and contains data for all patients at the site in support of trending and analysis functions. |
CIS/Essentris® is fully deployed and in sustainment mode. As a deployed system, it requires operational support for software and hardware maintenance, technical and customer support, system monitoring and alerting, repair service, replacement parts, software updates, training and configuration assistance.
Enterprise Blood Management System (EBMS)
The Enterprise Blood Management System is a non-Major Automated Information System (MAIS), two increment IT acquisition program, consisting of Enterprise Donor Management System – Donor (EBMS-D) and Enterprise Blood Management System - Transfusion (EBMS-T). These COTS products improve blood management record keeping, record retrieval, and accountability thus expanding the enterprise management of blood and blood products worldwide, to include coordinating the delivery of care and benefits provided by the DoD and the VA to all eligible beneficiaries.
Care & Benefits Integrated Systems (CBIS) PMO
The CBIS PMO will collaborate with various Veterans Administration (VA) organizations to ensure data interoperability, e.g., accessibility and sharing of current and accurate medical data of service members as they transition to the VA. Current IT applications include the Health Artifact and Image Management System (HAIMS), integrated Health Registry Framework (iHRF) and Interagency Comprehensive Plan for Care Coordination Support (ICPCCS).
Health Artifact and Image Management Solution (HAIMS):
HAIMS is a web-based solution that provides DoD healthcare providers global access and awareness of artifacts and Digital Imaging and Communications in Medicine (DICOM) images generated during the healthcare delivery process. HAIMS consists of eight Healthcare Artifact & Image Repositories (HAIRs) and eleven HAIMS External Repository Adapters (HERA). HAIR is the regional repository for artifacts and metadata for global visibility, access, and retrieval and the HERA which ingests metadata from the Picture Archiving and Communications System (PACS) for global visibility and retrieval. DICOM Viewers are an integral part of the PACS.
HAIMS architecture is built on Microsoft technologies, specifically MS SharePoint, MS SQL Server, MS Windows Servers, and MS ASP.Net. HAIMS uses the open source Mirth Connect product to listen and receive the Health Level (HL7) messages, and then transform the message into XML, and store the XML message in the HERA database. HAIMS uses CommVault encryption data backup solution and Storage Area Network (SAN) for its data storage and backup solution. HAIMS systems have been deployed and require engineering sustainment support for system operation and maintenance.
The HAIMS architecture employs the Service Oriented Architecture (SOA) to exchange messages with external systems as well as within the HAIMS systems. HAIMS message exchanges leverage Simple Object Access Protocol (SOAP), XML, and ESBs.
HAIMS Service Treatment Records (STRs) integration service uses Agile methodology to deliver the capability in a constraint schedule. The HAIMS application makes available the STRs to the Department of Veterans Affairs (VA).
Interagency Comprehensive Plan for Care Coordination Support (ICPCCS):
In the 2008 National Defense Authorization Act (NDAA), Department of Defense (DoD) and the Veterans Administration (VA) were directed to provide uniform standards and procedures for a comprehensive plan covering post-recovery rehabilitation and reintegration. The Interagency Comprehensive Plan for Care Coordination Support (ICPCCS) is the initiative that will facilitate care coordination among Care Management Team (CMT) members between the DoD and VA by allowing bi-directional care coordination activities among all CMT members in the DoD and VA. ICPCCS will be a web-based solution. The CBIS PMO is looking for engineers with experience in specific areas in order to support the ICPCCS system. ICPCCS support will include market research and analysis of solutions, incorporating case management processes and business process workflow, and working closely with users to develop the final solution. The solution is expected to integrate Commercial of the Shelve (COTS) product to existing MHS network infrastructure utilizing Enterprise Service Bus (ESB) technologies.
DoD Medical Exam Review Board
DoD Medical Exam Review Board (DoDMERB) implements life cycle management of the medical qualification records, and/or medical information related to the Military Services accessions. DoD MERB IT product supports the electronic medical, dental, and mental health documentation required to ensure continued medical, dental, and mental health care given to a Service member during their military service.
Other CBIS Initiatives:
CBIS PMO is also looking to expand efforts in Cloud Computing and Web Services with the desire to design and deliver a cloud solution for applications in development, test, pre-production, and production environment.
1.4 Objectives: Under this Performance Work Statement (PWS) the contractor must provide skilled personnel and structure in support of the two (2) PMOs, Technology Support Branch (TSB) and Cloud Broker Services (CBS) team to perform engineering management support activities.
The objectives of this effort are to obtain management and technical expertise to supplement and support the Government to:
1) Support the oversight and technical management of all SDD Product activities across the entirety of the System Development Life-Cycle (SDLC).
2) Support the execution of Software Quality Assurance across all SDD products.
3) Provide Engineering Management Support to include the planning, execution and follow up for conduct of SDLC Milestone Reviews and Acquisition Requirements and Activities.
4) Support the SDD/PSB Requirements Analysis and Management (RA&M) and Configuration Management (CM) processes to ensure compliance with Federal and DoD regulations and standards required by the IT Directorate, and maintain requirements baselines for the PMO products.
5) Monitor and manage SDD/TSB development, testing, and operations to include the systems interface processes and oversee all SDD/TSB Engineering functions, processes and activities.
6) Serve as experts for Architecture aligning SDD components to the MHS architecture.
7) Conduct technical project planning, develop project plans and documentation, define and manage project resources, and provide general project monitoring oversight.
8) Provide CyberSecurity/Information Assurance support to achieve and maintain Interim Authority to Operate (IATO) and Authority to Operate (ATO) for all SDD products.
9) Provide technical IA support throughout a product’s lifecycle. Emphasis is placed on ensuring IA and security requirements are identified early and built into the design of the product.
10) Provide technical input to and support developing and editing programmatic technical acquisition documentation such as System Engineering Plans (SEP), Information Support Plans (ISP), Program Protection Plans (PPP), Test and Evaluation Master Plans (TEMP) and Life Cycle Sustainment Plans (LCSP).
11) Provide Clinical Subject Matter Expert (SME) support to interject clinical perspective. across the entire SDLC and to rapidly address Patient Safety Issues across all SDD products. Provide SME support in the areas of clinical business practices and supporting very large databases.
12) Provide project management and coordination expertise across all SDD products.
13) Provide database and Oracle SME support to the maintenance, sustainment and migration efforts of the clinical data repository.
14) Provide technical support for new initiatives including leading in research and analysis and providing recommendation for technical solutions that apply current technology trends, such as, Enterprise Service Bus (ESB), web services and cloud computing.
| 15) | Maintain Personnel in the Ektropy Database. |
| 16) | Provide Strategic Planning and Support: |
| 17) | Provide Portfolio Management Activities |
| 18) | Provide program and project management activities in support of the Cloud Broker Services (CBS) team |
| 19) | Support Business Process Reengineering across the MHS enterprise |
| 20) | Serve as Agreements SME |
1.5 Scope: Services include support of SDD and the two (2) Program Management Offices’ (PMOs); 1) CBIS and 2) EHR Core, business and technical functions necessary for sustaining all PMO’s Clinical product-lines. Services includes support to TSB for technical and engineering functions for common services and to the CBS team in managing DHA cloud services. The contractor shall accomplish a variety of functions, such as, but not limited to: systems and software engineering, information assurance, architecture, configuration management support, requirements definition and derivation, subject matter expert (SME) advising, acquisition lifecycle efforts, systems integration support, deployment activities and other business, technical and administrative activities, all supporting the PMOs’ product-lines. Base systems supported are: AHLTA, Composite Health Care System (CHCS), Healthcare Artifact and Image Management Solution (HAIMS), Essentris and other smaller projects.
1.6 Period of Performance (PoP): The period of performance shall be for one (1) Base Period, twelve-months,and a -8 optional extension period, six-months. The Period of Performance reads as follows:
| Base Period | 1 January 2023 – 31 December 2023 |
| -8 Option Period | 1 January 2024 – 20 June 2024 |
1.6.1 Transition: Transition-in/transition-out period
1.6.1.1 Transition-in period: Reserved
1.6.1.1.1
1.6.1.2 Transition-out period: The transition-out plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract. See Part 10, Technical Exhibit 1.
1.6.1.2.1 The contractor shall comply with transition-out requirements of the DHA for contractors who have been issued a CAC or who generate “records”, as defined by DoD (records manual), including DoD-directed disposition of records, and others displayed on the In/Out (I/O) Processing Portal.
1.7 Administrative specifications
1.7.1 Place of performance: The work to be performed under this contract will be performed at the contractor’s facility or at any location established by the contractor. The contractor should note the Government occupies office space within the Skyline Complex, Falls Church, VA, 22041.
1.7.2 Recognized Federal holidays: The Contractor is not required to perform services on the following federal holidays:
| New Year’s Day | Labor Day | ||
| Martin Luther King Jr.’s Birthday | Columbus Day | ||
| President’s Day | Veteran’s Day | ||
| Memorial Day | Thanksgiving Day | ||
| Independence Day | Christmas Day |
Juneteenth National Independence Day
1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.7.4 Emergency ServicesOn occasion, services may be required to support an activation or exercise of contingency plans outside the normal duty hours.
1.8 Contractor travel: The Contractor may be required to travel to CONUS and OCONUS locations during the performance of this contract. To support travel costs, the Government has established a Not-To-Exceed amount of $4,000 for each performance period. The contractor will notify the COR when expenditures have reached seventy-five percentage (75%) of the total amount. The contractor shall not exceed this amount unless authorized by the contracting officer. Contractor shall be authorized travel expenses consistent with the cost principles and procedures in Federal Acquisition Regulation (FAR) Part 31.2, Travel Costs and the limitations of funds specified in this contract. All travel requires Government approval/authorization and notification to the Contracting Officer Representative (COR).
1.9 Other Direct Costs (ODC): This category does not include any travel costs or expenses. Based on historical information, there are no miscellaneous Other Direct Costs associated with this requirement.
1.10 Quality
1.10.1 Quality Control (QC): The contractor shall develop and maintain an effective QC program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure nonrecurrence of defective services. The contractor’s QC program is the means by which the work complies with stated requirements. The Quality Control Plan (QCP) shall be included in the offeror’s technical proposal submitted for this requirement. After acceptance of the Quality Control Plan (QCP) the contractor shall receive the CO’s acceptance in writing of any proposed change to his QC system. See Part 7, Technical Exhibit 1 - CDRL A001.
1.10.2 Quality assurance (QA): The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.11 Contractor personnel
1.11.1 CAC requirements: For all contractors who will work in Government facilities, the Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the PWS. A CAC is the standard identification for eligible DoD contractor personnel.
1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).
1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements:
1.11.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx
1.11.2.2 The DHA’s contractor training instructions embedded at Part 7 Section 7.1.2.
1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at: https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure (PKI)-restricted, printed versions available).
1.11.2.4 The DHA’s new employee handbook at Part 7 Section 7.1.4.
1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
1.11.4 Key control: The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.
1.11.4.1 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon direction of the CO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.
1.11.4.2 The contractor shall prohibit the use of Government issued keys/key cards by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the CO.
1.11.5 Lock combinations: Reserved
1.12 Key personnel (Contractor): The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO. The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between 8:00 a.m. to 5:00 p.m., Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons. Qualifications for all key personnel are listed below:
· One (1) Software Engineer – Senior, with Cache programming experience or knowledge
· EHR Core CHCS Lead Engineer, PWS 5.6
· Three (3) Systems Engineers – Senior– at least two with Enterprise Service Bus experience
· CBIS SOA SME, PWS 5.5.5.11
· CBIS DoD MERB lead engineer, PWS 5.5
· CBIS SPORTS lead engineer, PWS 5.5
· Three (3) Open Systems Engineers– Principle
· EHR Core database SME, PWS 5.13
· EHR Core EBMS lead engineer, PWS 5.5
· CBIS HAIMS lead engineer, PWS 5.5
· One (1) Open Systems Engineer – Middle
· EHR Core Essentris lead engineer, PWS 5.5
· One (1) Systems Architect – Senior
· Lead Architect shared between PMOs, PWS 5.8
· One (1) Program Manager – Advanced Technology identified as Contract Task Manager
1.13 Data rights: The Contractor shall coordinate with Government representatives to review, evaluate and develop an approach to transition current support services, including but not limited to transitioning historic data to new contractor system understanding Government-approved training and certification process, transferring hardware warranties and software licenses (if applicable), transferring all business and/or technical documentation, transferring compiled and un-compiled source code, to include all versions, maintenance updates and patches (if applicable).
The Contrator shall plan an orientation phase to cover activities such as, introducing Government personnel and relevant stakeholders to the Contractor’s team, tools, methodologies, and business processes, disposition of Contractor purchased Government owned assets, including facilities, equipment, furniture, phone lines, computer equipment to the contractors.
1.14 Reporting
1.14.1 Contractor Manpower Reporting (CMR): RESERVED.
1.14.2 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.
1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.14.4 Post award conference/periodic progress meetings: The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with FAR Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.15 Contractor Identification
1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel. Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their contractor status known during introductions.
1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.
1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.17 Personnel Security
1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM 5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 275-6038.
1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-Services)
2.1.3 Contractor: A supplier or vendor awarded a contract to provide specific supplies or service to the Government. “Contractor”, as used herein, refers to the prime contractor for this effort.
2.1.4 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.5 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.6 Defective Service: A service output that does not meet the standard of performance associated with the Performance Work Statement.
2.1.7 Deliverable: Work products identified throughout this PWS and in Technical Exhibit 2, which can take the form of written products or work efforts provided to the Government to demonstrate completion of the main tasks of this PWS.
2.1.8 Garrison: This refers to Continental United States (CONUS) and fixed bases/posts not in an operational theater or combat zone. This typically refers to the medical treatment facilities (MTFs) or hospitals and clinics in this setting. These facilities use AHLTA and CHCS today.
2.1.9 Key Personnel: Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.10 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.11 Physical Security: Actions that prevent the loss or damage of Government property.
2.1.12 Quality Assurance: The Government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
2.1.13 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.
2.1.14 Quality Control: All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.
2.1.15 Subcontractor: One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.
2.1.16 Work Day: The number of hours per day the Contractor provides services in accordance with the contract.
2.1.17 Work Week: Monday through Friday, unless specified otherwise.
2.2 Acronyms:
| ACAS | Assured Compliance Assessment Solution | ||
| AO | Authorizing Official | ||
| AODR | Authorizing Official Designated Representative | ||
| AHLTA | Armed Forces Health Longitudinal Technology Application | ||
| AIS | Automated Information System | ||
| AM | Acquisition Manager | ||
| API | Application Program Interfaces | ||
| AQL | Acceptable Quality Level | ||
| ATAM | Architecture Tradeoff Analysis Method | ||
| ATO | Authority to Operate | ||
| BYOD | Bring Your Own Device | ||
| C&A | Certification and Accreditation | ||
| CAP | Contractor-Acquired-Government Owned Property | ||
| CASE | Computer-Aided Software Engineering | ||
| CBIS | Care & Benefits Integrated Systems | ||
| CBS | Cloud Broker Services | ||
| CDR | Contract Discrepancy Report, Critical Design Review, Clinical Data Repository | ||
| CDSP | Cyber Defense Service Provider | ||
| CFR | Code of Federal Regulations | ||
| CFSR | Contract Funds Status Reports | ||
| CHCS | Composite Health Care System | ||
| CM | Configuration Management | ||
| CMM | Capability Maturity Model | ||
| CO | Contracting Officer | ||
| COD-FC | Contract Operations Division - Falls Church | ||
| CONOPS | Concept of Operations | ||
| CONUS | Continental United States (excludes Alaska and Hawaii) | ||
| COR | Contracting Officer’s Representative | ||
| COTR | Contracting Officer’s Technical Representative | ||
| COTS | Commercial Off-The-Shelf | ||
| CPARS | Contractor Performance Assessment Reporting System | ||
| CPFF | Cost Plus Fixed Fee | ||
| CMRS | Continuous Monitoring and Risk Scoring | ||
| CS | Contract Specialist, CyberSecurity | ||
| CSC | Computer Software Components | ||
| CSCI | Computer Software Configuration Items | ||
| CTO | Chief Technology Officer | ||
| CyDef | Cyber Defense | ||
| DA | Days after | ||
| DACA | Days after contract award (award of this order) | ||
| DAEOM | Days after end of month | ||
| Days | Calendar days, unless otherwise specified | ||
| DARS | Defense Architecture Repository | ||
| DBA | Database Administration | ||
| DBITC | Defense Business IT Certification | ||
| DCAA | Defense Contract Audit Agency | ||
| DCS | Defense Collaboration Services | ||
| DFARS | Defense Federal Acquisition Regulation Supplement | ||
| DFAS | Defense Finance and Accounting Services | ||
| DHA | Defense Health Agency | ||
| DIACAP | Department of Defense Information Assurance Certification and Accreditation Process | ||
| DID | Data Item Description | ||
| DII COE | Defense Information Infrastructure/Common Operation Environment | ||
| DMDC | Defense Manpower Data Center | ||
| DOA | Date of Award | ||
| DoD | Department of Defense | ||
| DoDAF | DoD Architecture Framework | ||
| DoD IS | DoD Information Systems | ||
| DoD MERBS | DoD Medical Exam Review Board | ||
| DT&E | Development, Test and Evaluation | ||
| DOM | Defense Operational Medicine | ||
| DTRS | Deployable Tele-Radiological Systems | ||
| E | Electronic Copy | ||
| EHR | Electronic Health Record | ||
| EIT | Electronic and Information Technology | ||
| eMASS | Enterprise Mission Assurance Support Service | ||
| ESB | Enterprise Service Bus | ||
| EVM | Earned Value Management | ||
| FAR | Federal Acquisition Regulation | ||
| FAT | Factory Acceptance Tests | ||
| FFP | Firm Fixed Price | ||
| FISMA | Federal Information Security Management Act | ||
| G&A | General and Administrative | ||
| GFE | Government Furnished Equipment | ||
| GFI | Government Furnished Information | ||
| GOTS | Government-Off-the-Shelf | ||
| GPO | Government Printing Office | ||
| GSA | U.S. General Services Administration | ||
| HAIMS | Healthcare Artifact and Image Management Solution | ||
| HIPAA | Health Insurance Portability and Accountability Act of 1996 | ||
| IA | Information Assurance | ||
| IAO | Information Assurance Officer | ||
| IATO | Interim Authority to Operate | ||
| IATT | Interim Authority to Test | ||
| IAVM | Information Assurance Vulnerability Management | ||
| ICCB | Internal Configuration Control Board | ||
| IDE | Integrated Development Environment | ||
| IDIQ | Indefinite Delivery-Indefinite Quality | ||
| IEEE | Institute of Electrical and Electronics Engineers | ||
| IMP | Integrated Master Plan | ||
| IPPSRS | Integrated Program Planning, Scheduling, and Reporting System | ||
| IPR | Interim Progress Report | ||
| IPT | Integrated Product/Process Team | ||
| ISP | Information Support Plan | ||
| ISSM | Information System Security Manager | ||
| JAC | Joint Application Configuration | ||
| JDES | Joint Disability Evaluation System | ||
| JMIS | Joint Medical Information System | ||
| JTA | Joint Technical Architecture | ||
| KPI | Key Performance Indicators | ||
| KPP | Key Performance Parameters | ||
| KO | Contracting Officer | ||
| KSS | Knowledge Sharing Site | ||
| LPO | Local Processing Office | ||
| M&H | Material and Handling | ||
| MAAG | MHS Application Access Gateway | ||
| MCMS | Master Cluster Management Server | ||
| MedCOI | Medical Community of Interest | ||
| MHSRR | MHS Requirements Repository | ||
| MHS | Military Health System | ||
| MIS | Management Information Systems | ||
| MPR | Monthly Progress Report | ||
| NLT | Not Later Than | ||
| OCI | Organizational Conflict of Interest | ||
| OCONUS | Outside Continental United States (includes Alaska and Hawaii) | ||
| ODC | Other Direct Costs | ||
| OT&E | Operation Test and Evaluation | ||
| PC | Project Coordinator | ||
| PDR | Preliminary Design Review | ||
| PEO | Program Executive Office | ||
| PHI | Protected Health Information | ||
| PII | Personally Identifiable Information | ||
| PIPO | Phase In/Phase Out | ||
| PKI | Public Key Infrastructure | ||
| PM | Program Manager | ||
| PMC | Project Monitoring and Control | ||
| PMO | Program Management Office (Refers to CBIS PMO and EHR Core) | ||
| PMP | Program Management Plan, Project Management Professional | ||
| POA&M | Plan of Action and Milestones | ||
| POC | Point of Contact | ||
| PPBE | Planning, Programming, Budgeting and Execution | ||
| PPP | Program Protection Plan | ||
| PPS | Ports, Protocols, and Services | ||
| PPSM | Ports, Protocols, and Services Management | ||
| PR | Production Review | ||
| PRS | Performance Requirements Summary | ||
| PWS | Performance Work Statement | ||
| PWS Ref | Performance Work Statement Reference (paragraph number) | ||
| QA | Quality Assurance | ||
| QAP | Quality Assurance Program | ||
| QASP | Quality Assurance Surveillance Plan | ||
| QC | Quality Control | ||
| QCP | Quality Control Plan | ||
| RA&M | Requirements Analysis and Management | ||
| REST | Representational State Transfer | ||
| RFQ | Request for Quote | ||
| RM&A | Reliability, Maintainability, and Availability | ||
| RMF | Risk Management Framework | ||
| ROI | Return on Investment | ||
| RPO | Recovery Point Objective | ||
| RTM | Requirements Traceability Matrix | ||
| RTO | Recovery Time Objectives | ||
| SCA | Security Control Assessor | ||
| SCQC | Software Code Quality Checking | ||
| SDD | Solutions Design Documents or Solution Delivery Directorate | ||
| SDLC | Software Development Lifecycle, Software Development Lifecycle | ||
| SEI | Software Engineering Institute | ||
| SEP | Systems Engineering Plan | ||
| SIPRNet | Secret Internet Router Protocol Network | ||
| SME | Subject Matter Expert | ||
| SOA | Service Oriented Architecture | ||
| SOAP | Simple Object Access Protocol | ||
| SOO | Statement of Objectives | ||
| SOP | Standard Operating Procedure | ||
| SOW | Statement of Work | ||
| SPORTS | STR Processing Operations Reporting Tracking Solution | ||
| SRF | Service Request Form | ||
| SRG | Security Requirements Guide | ||
| SRR | System Requirements Review | ||
| SSR | System Specification Review | ||
| STIG | Security Technical Implementation Guide | ||
| STR | Service Treatment Record | ||
| SW/HW | Software/Hardware | ||
| T&M | Time and Materials | ||
| TE | Technical Exhibit | ||
| TEAMS | TRICARE Evaluation, Analysis, and Management Support | ||
| TED | Training Evaluation and Demonstration Center | ||
| TEMP | Test and Evaluation Master Plan | ||
| TEPP | Test Evaluation Program Plan | ||
| TM | Task Manager | ||
| TRR | Test Readiness Review | ||
| TSB | Technology Support Branch | ||
| TSE | Training Server Environment | ||
| UDDI | Universal Description Discovery and Integration | ||
| VLDB | Very Large Database | ||
| VMS | Virtual Memory System | ||
| WAWF | Wide Area Work Flow | ||
| WBS | Work Breakdown Structure | ||
| WDA | Working Days After | ||
| WSDL | Web Services Description Language | ||
| XML | Extensible Markup Language |
2.3 Applicable Publications, DHA Administrative Instructions (AI), etc.
The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures.
The following documents provide specifications, standards, or guidelines that must be complied with in order to meet the requirements of this order:
· MHS Information Management (IM)/ Information Technology (IT) Strategic Plan, May, 2002 (update in progress)
· MHS IM/IT Program Plan, Volume I and II, August 1996 (on TRICARE web site)
· Defense Data Dictionary System (DDDS), May 29, 2002
· EIA649, “National Consensus Standard for Configuration Management”
· DoDD 8320.1, “DOD Data Administration,” September 26, 1994
· DoDD 5000.01, Defense Acquisition System, November 20, 2007
· DoDI 5000.02, Operation of the Defense Acquisition System, January 7, 2015
· DoDD 5200.2-R, “DoD Personnel Security Program,” April 9, 1999
· DoD Regulation 5000.2-R, “Mandatory procedures for Major Defense Acquisition Programs (MDAP) and Major Automated Information System (MAIS) Acquisition Programs, April 5, 2002
· 52.246-1 Contractor Inspection Requirements, April 1984
· Principal Deputy Assistant Secretary for Health Affairs (PDASD-HA Memo, “Use of DoD Standards in MHS Migration Systems,” 11 March 1996) (on TRICARE web site)
· MHS Architectural Framework, Version 2.1, July 1998 (on TRICARE web site)
· Deputy Assistant Secretary of Defense for Health Budgets and Programs (PDASD-HBP Memo) “FY97 Defense Health Program (DHP) Funding Guidance – (updated annually)
· MHS System Architecture and Design Guidance
· MHS Enterprise Architecture Modeling Guidebook, December 6, 2012
· Configuration Management Master Plan (CMMP), Version 1.0, 29 September 2000
· DoD 5136.1-P, DoD Medical Readiness Strategic Plan, 1998-2004
· The DoD Architecture Framework, Version 2.0, May 28, 2009
Security References:
Federal
· Public Law 93-579, Privacy Act of 1974 (Section 552a of title 5, United States Code)
· Public Law 100-235, Computer Security Act of 1987 (Section 278g-3 of title 15, United States Code)
· OMB Circular A-130, "Management of Federal Information Resources, Transmittal 4," November 30, 2000
· Public Law 104-191, Health Insurance Portability and Accountability Act of 1996 (HIPAA (Security [proposed] and Privacy)
· FISMA (New awaiting OMB or DoD implementation guidance)
· FIPS 31, Guidelines for Automatic Data Processing Physical Security and Risk Management, June 1974
DoD
· DoD 5200.1-R, Information Security Program, January 1997
· DoD 5200.8-R, Physical Security Program, May 1991
· DoDD 8500.)1E, Information Assurance (IA), April 23, 2007
· DoD 8570.01-M Information Assurance Workforce Improvement Program, Change 2, April 20, 2010.
MHS
· MHS Information Assurance (IA) Policy/Guidance Manual, Version 1.2, January 2003
· MHS Enterprise Architecture Contract Language for Information Technology, 110706v1 PM. Reference http://www.tricare.mil/jmis/enterprise-pm.cfm for information and requirements
· MHS Information Assurance (IA) Implementation Plan, Version 1.0, January 2003
DISA
· DISA WESTHEM Security Handbook, Version 3, December 2000 NIST
· SP 800-14 Generally Accepted Principles and Practices for Securing Information Technology Systems, September 1996
· SP 800-18 Guide for Developing Security Plans for Information Technology Systems, December 1998
· NIST SP 800-26 Security Self-Assessment Guide for Information Technology Systems, August 2001
· SP 800-27 Engineering Principles for Information Technology Security (A Baseline for Achieving Security), June 2001
· SP 800-31 Intrusion Detection System (IDS), November 2001
Security Matrices
· Eight Information Assurance guidance matrices
· Federal Information Processing Standards Publication FIPS87 Guidelines for Automatic Data Processing (ADP) Contingency Planning
· Federal Preparedness Circular, FPC 67, Acquisition Alternative Facilities for Continuity of Operations (COOP)
· Policy Guidance for Use of Mobile Code Technologies in Department of Defense (DoD) Information Systems, November 7, 2000
·…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .