AFMS_Transition_PWS.pdf

PDF 218 KB Posted

Attached to
AFMS Transition Support Federal contract opportunity
Solicitation number
F1ATB18241AW01
Issued by
Department of the Air Force Materiel Command Installation and Mission Support Center Installation Contracting Agency

About this file

PWS

View the file

Other files for this federal contract opportunity

Other files attached to AFMS Transition Support, newest first.
File Type Posted
FBO_combo_post_revision_3.pdf PDF
Combo__Synopsis_-_Medical_-_Revision_1.pdf PDF
AFMS_Transition_WDOL.pdf PDF
AFMS_Transition_Combo.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

(PWS)

FOR

AIR FORCE MEDICAL SUPPORT AGENCY

(AFMSA)

AFMS TRANSITION SUPPORT

28 AUGUST 2018

TABLE OF CONTENTS

Item Description Page

1.0

Background Information

2.0 Contract Requirements 3

3.0 Personnel Requirements 4

4.0 Management Requirements 7

5.0 Government Furnished Equipment 9

6.0 Reports and Deliverables 9

7.0 Services Summary 12

8.0 List of Appendices 13

1.0 BACKGROUND INFORMATION

Section 702 of the FY17 National Defense Authorization Act (NDAA) requires that, beginning 1 Oct 18, the DHA Director will be responsible for the administration and management of healthcare delivery at MTFs. DoD leadership has selected and continues to refine a construct for phased-in implementation of Section 702 whereby DHA manages MTFs and Services remain responsible for operational mission support & readiness. Over the next couple of years the Air Force Medical Service (AFMS) will work to transition functions and capabilities to the DHA as part of this transition.

This is a performance based, non-personal, advisory and assistance services requirement to provide analysis and consulting support, training support, and project management support, and technical writing for the AFMS Transition Cell. The AFMS Transition Cell is tasked with transitioning the existing AFMS structure to a joint structure with the Defense Health Agency (DHA).

2.0 CONTRACT REQUIREMENTS

The Contractor shall support the Government’s AFMS Transition Cell by providing a Senior Technical Writer/Communications Specialist to the Defense Health Headquarters (DHHQ) in Falls Church, Virginia.

2.1 Overall Duties and Responsibilities.

2.1.1 Collect and collate data from respective SMEs, Action Officers or Office of Primary Responsibility/Office of Coordinating Responsibility.

2.1.2 Manage organizational email boxes, calendars, coordinate meetings, and transcribe meeting minutes.

2.1.3 Track progress updates from DCR Headquarters Air Force (HAF), AFMOA, and MTF transition efforts.

2.1.4 Assist in managing websites (i.e. Knowledge Exchange, Milsuite).

2.1.5 Design/revise monthly communication products.

2.1.6 Prepare presentations/briefings as required.

2.1.7 Prepare, develop, and present a wide variety of documents including letters, staff summary sheets, transmittals, bullet papers, spreadsheets, presentations as needed.

2.1.8 Provide managing resources across all Lines of Effort (LOEs) developing and managing schedules, defining and maintaining standards for consistency across LOE, prioritizing projects within LOE, communicating progress with AFMS leadership, and managing associated risks.

2.1.9 Shall work with leaders across the military health system including conducting interviews, facilitating discussions and reviewing documents to develop recommendations.

2.1.10 Prepare, develop, and present a wide variety of documents including letters, staff summary sheets, transmittals, bullet papers, spreadsheets, presentations as needed.

2.1.11 Helps identify gaps and recommend solutions for building and sustaining AFMS operations.

2.2 Travel Requirements.

The Government will be required travel as outlined in the table below. The lengths listed are inclusive of 2 travel days. Destinations in this table are subject to change according to different mission requirements throughout the year.

Purpose Time Period Destination Personnel Length Transition Visit October San Antonio, TX 1 7 days Transition Visit November Scott AFB, IL 1 7 days Transition Visit January WPAFB, OH 1 7 days Transition Visit February JB Langley-Eustis, VA 1 7 days Transition Visit March Macdill AFB, FL 1 7 days Transition Visit May Hanscom AFB, MA 1 7 days Transition Visit July San Antonio, TX 1 7 days Transition Visit August San Antonio, TX 1 7 days

2.2.1 The Contracting Officer’s Representative (COR) will notify the Contractor no later than

14 calendar days in advance of any scheduled travel requirements. Notification will include specific travel dates, tasks within the scope of work to be accomplished, and the personnel required to travel. The Contractor shall adhere to Force Protection Conductions (FPCONs) before proceeding with travel. The Contractor shall immediately notify the COR if any travel cannot be completed due to these requirements.

2.2.2 The Contractor shall provide the COR with a written Travel Itinerary outlining the travel to meet the Government’s travel needs no later than 10 calendar days prior to the start of travel.

2.2.3 The COR will grant or deny the Contractor to proceed with any travel no later than 7 calendar days prior to the travel start date. Without the approval to travel from the COR, the Contractor shall not proceed with travel and any costs associated with the travel will not be reimbursed. Only travel approved by the COR will be authorized under this contract.

2.2.4 The Contractor shall submit a Trip Report within 5 calendar days after each trip.

2.3 Mission Essential Services.

None of the services listed in this Performance are identified as mission or emergency essential.

2.4 Duty Hours.

Normal office hours are 0730 to 1630, but may be adjusted to fit between the hours of 0600 and 1800 for a 9-hour (8 hours plus 1 hour lunch) work day. Federal Offices are closed on the following holidays: New Year’s Day, Dr. Martin Luther King, Jr.’s Birthday, President’s Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.

3.0 PERSONNEL REQUIREMENTS.

3.1 Specific Qualifications/Experience Requirements.

Contractor personnel supporting this contract shall hold a Bachelor of Arts (BA) or Bachelor of

Science (BS) degree in Healthcare or health-related field, and shall have at least two years of experience as a technical writer.

3.2 General Personnel Requirements.

Contractor personnel supporting this contract shall possess the following abilities:

3.2.1 Communicates clearly in English, both orally and in writing.

3.2.2 Self-directed and possesses leadership, organizational, communication and interpersonal skills; with the ability to work independently with no supervision.

3.2.3 Must demonstrate the ability to motivate and mentor others through use of training and coaching skills and the ability to communicate information on programs and activities, both orally and in writing, to diverse audiences.

3.2.4 Contractor personnel shall be five (5) years hands on experience using standard software programs such as the Microsoft Office 2010 Professional Suite.

3.2.5 Have working knowledge of latest versions of office automation software and recognize potential enhancements or limitations of new software utilized within their area of expertise and or tasking.

3.2.6 Complete all tasks and subtasks by the suspense issued at the time the task is received.

3.2.7 Have working knowledge of Government regulations, policies, procedures, and limitations within their scope of responsibilities.

3.2.8 Coordinate with the management levels, as required by DoD policies or procedures.

3.2.9 Assist the Government in a smooth transition of services when a change of personnel is necessary, whether due to Contractor personnel’s notice of discontinuance of service or by Government cancellation of the contract. The transition service will entail providing familiarization, on-the-job training, and appropriate documentation required by replacement personnel. Provide this transition service to the replacement personnel, whether that person belongs to the current Contractor, another Contractor or is Contractor personnel.

3.2.10 Research, analyze and report data to support compelling, insightful and effective recommendations and presentations.

3.2.11 Develop and/or maintain existing tools for use by other team members to aid them in their ability to efficiently/effectively meet the team’s objectives.

3.2.12 Provide input to the AFMS Transition team for internal/external meetings, working groups, seminars and conferences.

3.2.13 Analyze problems, propose solutions, and meet programmatic goals

3.2.14 Provide information and communicate with internal/external AFMS customers.

3.2.15 Ensure coordination of all products/services provided with the appropriate management levels, as required by applicable policies or procedures

3.2.16 Provide input, edit, review, develop and/or present a wide variety of documents, including letters, bullet background papers, staff summary sheets, presentations, spreadsheets, forms, metrics, reports, briefings, procedural manual development, after action reports.

3.2.17 Prepare written business correspondence that is complete, coherent, grammatically accurate, effective, and professional and IAW DoD Tongue and Quill

3.2.18 Research information and provide answers to questions for internal/external AFMS customers

3.2.19 Provide coordination with Subject Matter Experts (SMEs) (e.g. to attend/announce meetings, to deliver products by established deadlines, etc.).

3.2.20 Update contact lists, prepare meeting agendas and capture meeting minutes for contain action items, issues, and risks for review.

3.2.21 Coordinate daily, weekly and quarterly on meetings

3.3 Conduct of Contractor Personnel.

Contractor personnel are expected to conduct themselves in a professional manner. The Contractor personnel shall present a neat, well-groomed appearance and shall wear neat, clean, casual business attire. Contractor personnel shall be required to observe Government facility parking, safety and traffic regulations that apply to all facility personnel. The Contracting Officer (CO) or designated Government representative may require the Contractor to remove from the job site Contractor personnel working under this contract. Removal from the job site or dismissal from the premises does not relieve the Contractor of the contract requirements.

3.4 Contractor Identification

All Contractor/Subcontractor personnel will identify themselves as Government Contractor personnel during all forms of communications such as business meetings, telephone conversations, electronic mail, attendance sheets, coordination documentations, reports, and the signature blocks utilized in all correspondence. If a contract requires Government workspace, any Contractor personnel shall wear a picture identification badge and identify their workspace area with their name and company affiliation.

3.5 Contractor Training

When directed by the CO or COR, contract personnel shall attend all such Government provided training in a paid status as part of normal services required and billed under the contract. The COR may direct required training other than the web-based training required below:

3.5.1 HIPAA and Privacy Act Training. Contractor is required to complete annual HIPAA and Privacy Act training. HIPAA and Privacy Act training is available through computer-based modules and shall be facilitated by the Contractor.

3.5.2 DoD IAA Cyber Awareness Challenge. Contractor is required to complete annual DoD IAA Cyber Awareness Challenge training. DoD IAA Cyber Awareness Challenge training is available through computer-based modules and shall be facilitated by the

Contractor.

3.5.3 Environmental Management Systems (EMS) General Awareness Training. The Contractor is required to complete the EMS General Awareness Training computer based module and shall be facilitated by the Contractor. This is a one-time training requirement.

3.5.4 Security Administration. The Contractor is required to complete the Security

Administration training computer based module and shall be facilitated by the Contractor.

This is a one-time training requirement.

3.5.5 Operations Security (OPSEC) Awareness Training. The Contractor is required to complete the latest OPSEC Awareness Training. This is a one-time training requirement.

4.0 MANAGEMENT REQUIREMENTS.

4.1 Contractor/Government Communication.

The Contractor shall identify a Focal Point responsible for the Contractor personnel under this contract. This Focal Point shall provide a clear and consistent written and/or verbal response to Government inquiries within 12 business hours of when the Government initiates communication (phone calls, email, etc.) The purpose of this Focal Point is to ensure the Government can reach out to the Contractor in the event of any performance issues that arise.

4.2 Meeting Agendas and Minutes.

The Contractor shall complete agendas of upcoming meetings and provide minutes to the COR after each meeting.

4.3 Security Requirements.

4.3.1 Security Clearance Requirements. The Contractor shall have an active favorable Tier 1 (T1) prior to performing work on this contract. The Government assumes costs and conducts investigations for confidential facility security clearances. The Contractor shall request personnel security clearances, at the company’s expense.

4.3.2 List of Contractor Personnel. The Contractor shall maintain a current listing of Contractor personnel working on this contract. This list shall be validated and signed by the Contractor’s Facility Security Officer and provided to the CO and Information Security Program Manager no later than 5 days prior to the service start date.

4.3.2.1 Information included in the List of Contractor Personnel shall include name, social security number, and level of security clearance for each Contractor personnel.

Updated lists shall be provided when any information about the status or information of the personnel occurs.

4.3.2.2 A Visit Request for all Contractor personnel with security clearances is required to be sent through the Joint Personnel Adjudication System and must be updated at least annually. The Contractor shall notify the Information Security Program Manager 5 calendar before on-base performance of the service. The notification shall include the following:

4.3.2.2.1 Name, address, and telephone number of the Contractor’s key management representatives.

4.3.2.2.2 Contract Number and the Contracting Agency.

4.3.2.2.3 The highest level of classified information to which the personnel require access.

4.3.2.2.4 The location(s) of service performance and future performance, if known.

4.3.2.2.5 The date performance under this contract begins.

4.3.2.2.6 Any changes to information provided under this paragraph.

4.4 Local Area Network (LAN).

All Contractor personnel requiring access to the Government unclassified computer network shall have a valid T1 verified through JPAS. No Contractor personnel will be provided access to unclassified computer network or its inherent capabilities (i.e., internet access, electronic mail, file and print services, etc.) without a valid T1. The Contractor shall be aware of and abide by all Government regulations concerning the authorized use of the Government’s computer network including the restriction against using the network to recruit Government personnel or advertise job openings.

4.5 Disclosure of Information.

In the performance of this contract, the Contractor may have access to data and information proprietary to a Government agency or to another Government Contractor, or of such nature that its dissemination or use, other than as specified in this contract, would be illegal or otherwise adverse to the interests of the Government or others. The Contractor and its personnel shall not divulge or release data or information developed or obtained under performance of this contract, except to authorize Government personnel or upon written approval of the CO. The Contractor and its Contractor personnel shall not use, disclose, or reproduce proprietary information bearing a restrictive legend, other than as specified in the contract.

4.6 Non-Disclosure Agreement (NDA).

All Contractor personnel shall sign the non-disclosure statement provided at Appendix C prior to beginning of contract performance. The Contractor must then provide a copy of the signed/dated NDA to the COR prior to beginning work.

4.7 Contractor Manpower Reporting Requirements Application (CMRA).

The Contractor shall report ALL contractor labor hours (including subcontracted labor hours) required for performance of services provided under this contract for the Air Force and Army via a secure data collection site. The Contractor is required to completely fill in all required data fields at http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September.

While inputs may be reported at any time during the FY, all data shall be reported no later than 31 October of each calendar year. Contractors may direct questions to the CMRA help desk.

4.7.1 Uses and Safeguarding of Information. Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor name and contract number associated with the data.

4.7.2 User Manuals. Data for Air Force service requirements must be input at the Air Force Contract Manpower Reporting Application (CMRA) link. However, user manuals for Government personnel and Contractors are available at the Army CMRA link http://www.ecmra.mil.

4.8 Quality Control Plan.

The Contractor is responsible for Contract Management and Quality Control, not the Government.

The Contractor shall maintain their Quality Control Plan and provide updates to the Government as required throughout performance of the contract.

4.9 Post-Award Meeting.

The Government will host a post-award meeting with the Contractor within 10 business days after contract award. Telecon/teleconference is permissible for the post-award meeting. The purpose of the post-award meeting is introduce the Contractor to the Government representatives (PM/COR) the Contractor will support, provide the Government and the Contractor to address any details as needed for successful performance, entertain questions from either party, and establish a timeline of when direct support will start (if not yet started).

5.0 GOVERNMENT FURNISHED EQUIPMENT.

The Government will provide the Contractor with the facilities, equipment, and information necessary to perform the tasks outlined in this Performance Work Statement. Equipment includes computers (unclassified), desks, chairs, access to printers, unclassified networks, copy machines, classified destruction equipment, telephones (secure, DSN, commercial access capabilities), basic office supplies, and Government vehicles, if necessary and available. These items are incidental to the place of performance and remain accountable to the Government. In addition, the Government shall require each individual Contractor personnel to sign hand receipts for all Information Technology Equipment (ITE) that they exclusively use (i.e., all equipment on their desks). This includes laptops for travel or out-of-office use. Contractor personnel are not required to sign for multiple users ITE such as network equipment, network printers, and servers. Information includes all reference material or documentation required to perform. All facilities, equipment, and information used by the Contractor will remain the property of the Government and the Contractor shall return all facilities, equipment, and information to the COR or other designated representative upon the request of the Government or at the end of the contract period of performance.

6.0 REPORTS AND DELIVERABLES.

6.1 Travel Itinerary.

The Contractor shall provide the COR with a written Travel Itinerary no later than 10 calendar days prior to the travel start date. The Travel Itinerary shall include the following information:

6.1.1 Names and roles of Contractor personnel travelling

6.1.2 Destination (where performance will occur)

6.1.3 Departure and arrival times, dates, and locations

6.1.4 Travel costs

6.1.5 Location and duration of lodging/hotel accommodations

6.1.6 Lodging/hotel costs

6.2 Trip Report.

The Contractor shall provide the COR with a written Trip Report no later than 5 calendar days after returning from each trip. The Trip Report shall include the following information:

6.2.1 Names and roles of Contractor personnel that travelled

6.2.2 Actual destination (where performance occurred)

6.2.3 Actual departure and arrival times, dates, and locations

6.2.4 Actual travel costs

6.2.5 Actual location and duration of lodging/hotel accommodations

6.2.6 Actual lodging/hotel costs

6.2.7 Purpose of travel

6.2.8 Individuals involved with performance relating to the trip

6.2.9 Brief synopsis of the events

6.2.10 Issues and challenges

6.2.11 Recommendations as appropriate

6.2.12 Signatures for each traveler

6.3 Monthly Status Report.

The Contractor shall provide a MSR that briefly summarizes, by task, the management and technical work conducted during the month, no later than the 5th business day of each month. The Contractor shall provide at a minimum the following information:

6.3.1 Summary of effort, progress and status of all activities/requirements by task linked to deliverables as appropriate.

6.3.2 New work added since the previous Monthly Status Meeting.

6.3.3 Brief summary of activity planned for the next reporting period.

6.3.4 Deliverables submitted for the period by task and linked to the milestone schedule.

6.3.5 All standards followed in support of the requirements.

6.3.6 Staffing (including staff changes since last report and anticipated in next 30 days, task assignments, and travel expense report).

6.3.7 Milestone updates and schedule changes, issues and/or variances.

6.3.8 Problems or issues with corrective or remedial action taken or proposed

6.3.9 Government action requested or required.

6.3.10 Reference to the applicable trip report if there was travel taken during the reporting period.

6.3.11 Administrative concerns to include Contractor personnel performing work on-site compared to off-site performance and anticipated actions for government sponsored e-mail accounts or Common Access Cards (CAC).

6.4 Meeting Minutes.

The Contractor shall provide meeting minutes as required by the COR, within the next business day following the meeting. The format will be mutually agreed upon between the COR and the Contractor. Minutes shall include the following information at a minimum, along with any other information identified by the COR:

6.4.1 Type, time, and date of the meeting.

6.4.2 Location of the meeting.

6.4.3 Purpose and objective of the meeting.

6.4.4 A summary of discussions, decisions, agreement reached, directions of members of the meeting, and action items resulting from the meeting.

6.4.5 A list of attendees by name, rank, grade, or position, the activity and activity symbol/code of each attendee, attendee phone numbers, and their email addresses.

6.4.6 Briefing charts for any presentations provided in the meeting.

6.4.7 Spaces for names and signatures of the preparer and COR.

6.5 Meeting Agendas.

The Contractor shall provide meeting agendas as required by the COR, no later than 5 business days prior to the meeting. The format will be mutually agreed upon between the COR and the Contractor.

The agenda shall include the following information, along with any other information identified by the COR:

6.5.1 Type, time, and date of the meeting.

6.5.2 Location of the meeting.

6.5.3 Chronological listing of each major topic and subtopic to be discussed and the time allotted to each major topic or subtopic.

6.5.4 A list of all activities to be represented and identification of their responsibilities.

6.5.5 A list of each group established during meetings and the proposed attendance of each group.

6.5.6 Reference to and brief descriptions of the results of previous meetings, as appropriate.

6.5.7 Location, schedule, and purpose to be covered by each group.

6.5.8 Name of the chairperson, co-chair, and subgroup chairs, as appropriate.

6.5.9 Information on any administrative services available to the proposed attendees.

6.5.10 A list of all of the documentation to be available to review by the attendees.

6.6 Additional Reports.

The Contractor shall provide any additional reports as required by the COR during performance under this contract, in a mutually agreed format and according to the deadline set by the COR.

7.0 SERVICES SUMMARY

Performance Objective Ref. Threshold Overall Duties and Responsibilities

2.1 2.4

Performance is acceptable when the Contractor is present according to the listed duty hours 100% of the time and performs all of the duties listed within the timeframes stated by the COR 100% of the time.

Travel Requirements 2.2 Performance is acceptable when the Contractor complies with all travel requirements and conforms to the travel processes outlined in paragraphs 2.2.1 through 2.2.4 100% of the time.

Personnel Qualifications and Training

3.1 3.2 3.5

Performance is acceptable so long as the Contractor meets all personnel qualifications and training requirements 100% of the time.

Contractor Conduct and Identification

3.3 3.4

Performance is acceptable so long as the Contractor meets all conduct and identification requirements 100% of the time.

Management Requirements

4.0 Performance is acceptable so long as the Contractor meets all management requirements 100% of the time.

Government Furnished Equipment

5.0 Performance is acceptable so long as the Contractor is accountable for all issued Government Furnished Equipment and meets all requirements regarding Government Furnished Equipment, 100% of the time.

Reports and Deliverables

6.0 Performance is acceptable when the Contractor provides all reports and deliverables according to their deadlines or otherwise coordinates with the COR for any extension to the deadline for any given report, 100% of the time. Reports and deliverables must be 100% accurate 99% of the time and corrected within 1 business day.

8.0 LIST OF APPENDICES.

8.1 Appendix A – Acronyms

8.2 Appendix B – Business Associated Agreement

8.3 Appendix C – HQ USAF/SG Non-Disclosure Agreement

8.4 Appendix D – Customer Complain Record

Appendix A

ACRONYM DEFINITIONS

AF Air Force AFMS Air Force Medical Service AFMOA Air Force Medical Operations Agency AF/SG Air Force Surgeon General BAA Business Association Agreement CAC Common Access Card CE Covered Entity CMRA Contractor Manpower Requirement Reporting Application CFR Code of Federal Regulations CO Contracting Officer CONUS Continental United States COR Contracting Officer Representative DoD Department of Defense DoDD Department of Defense Directive FAR Federal Acquisition Regulation HIPAA Health Insurance Portability and Accountability Act of 1996 HQ USAF/SG Headquarters United States Air Force Surgeon General IA Information Assurance IT Information Technology MHS Military Health System MTF Military Treatment Facility NDA Non-Disclosure Agreement OCI Organizational Conflict of Interest ODC Other Direct Cost PWS Performance Work Statement QCP Quality Control Plan SG Surgeon General SS Service Summary T1 Tier 1

Appendix B

BUSINESS ASSOCIATE AGREEMENT

This BAA can serve as a separate standalone agreement or may be used for new or existing contracts between the MTF and the business associate.

Business Associate Agreement

[USE FOR STANDALONE BAA ONLY] This Business Associate Agreement (this "Agreement") is entered into this ___ day of ________, _____ (the “Effective Date”) between [NAME OF MHS COVERED ENTITY] ("Covered Entity") and [NAME OF BUSINESS ASSOCIATE], a [type of business entity] ("Business Associate").

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate.

The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other Personally Identifiable Information (PII) (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE].

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate

(NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose Personal Health Information (PHI) other than as permitted or required by this Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY THIS

SECTION IF THE PURPOSE OF THE AGREEMENT/CONTRACT IS FOR THE BA TO

DEIDENTIFY PHI FOR THE CE].

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text.

Examples of updated information the Business Associate shall report include, but are not limited to:

confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so the individual clearly understands how the breach occurred.

(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.

(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and

(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address

(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.)

the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.

(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated point of contact to include, phone number, e-mail address, and postal address.

(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.

(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cybersecurity incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forth here.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.