PWS_-_Central_Appts.pdf

PDF 129 KB Posted

Attached to
CENTRALIZED APPOINTMENT CALL CENTER Federal contract opportunity
Solicitation number
FA2823-16-R-6001
Issued by
Department of the Air Force Materiel Command Test Center

About this file

CACC PWS

View the file

Other files for this federal contract opportunity

Other files attached to CENTRALIZED APPOINTMENT CALL CENTER, newest first.
File Type Posted
Amendment_3_-_FAR_52.222_42.pdf PDF
Amendment_2_-_Deadline_of_Offer.pdf PDF
Amendment_1_-_Questions_ _Answers.pdf PDF
Amendment_1_-_WD_05-3033_Rev_17.pdf PDF
Appendix_B_-_Instructions_to_Offerors__52.212-1.pdf PDF
Appendix_E_-_Technical_Evaluation_worksheet.pdf PDF
Appendix_D_-_PPQ_-_Central_Appointments.pdf PDF
Appendix_A_-_Bid_Schedule.pdf PDF
Appendix_C_-_Evaluation_52.212-2.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

FOR OPERATION OF THE

CENTRALIZED APPOINTMENT CALL CENTER (CACC)

REFERRAL MANAGEMENT CENTER (RMC)

REGISTRATION AND TRICARE PLUS ENROLLMENT CENTER (RTPEC)

INTERNAL MEDICINE CLINIC APPOINTMENT DESK (IMCAD)

SERVICES

Non-Essential Personnel

20 Nov 2015

SECTION TITLE PAGE

1 DESCRIPTION OF SERVICES 3

2 SERVICE DELIVERY SUMMARY 6

3 GOVERNMENT FURNISHED PROPERTY AND 7

SERVICES

4 GENERAL INFORMATION 8

5 APPENDICES 9

APPENDIX

A—WORKLOAD EST 9

B—HOURS OF OPERATION/LOCATION 9

C—Regulation Table 10

ATTACHMENT 3 – HIPPA 10-18

SECTION 1- DESCRIPTION OF SERVICES

1. SCOPE OF WORK. The contractor shall provide on-site services at Eglin AFB, Florida MTF where applicable.

Services shall cover the range of operation as stated in the Performance Work Statement (PWS) in the performance of assisting eligible medical beneficiaries with appointments, referrals, and registration. The contractor shall also provide necessary and accurate reports in accordance with hospital, Air Force, and Health Care regulations during the performance of their duties as related to the PWS. Services shall cover the range of operation of the:

CENTRALIZED APPOINTMENT CALL CENTER (CACC)

REFERRAL MANAGEMENT CENTER (RMC)

REGISTRATON AND TRICARE PLUS ENROLLMENT CENTER (TPEC)

INTERNAL MEDICINE CLINIC APPOINTMENT DESK (IMCAD)

1.1. SPECIFIC TASKS.

1.1.1. Operation of the Centralized Appointment Call Center (CACC)- EGLIN AFB Contractor shall book all direct care appointments according to furnished protocols and hospital policies (regulation AFI 44- 176 for appointing and referral management will be furnished as well as the Composite Health Care Systems (CHCS), Managed Care Program (MCP), AHLTA, and Booked Health Care Finder (BHCF) modules). The Contractor shall at a minimum:

(a) Verify beneficiary eligibility

(b) Identify the availability of appointments

(c) Review available appointments with the beneficiary

(d) Schedule the appointment selected by the beneficiary

(e) Cancel and reschedule appointments directed by beneficiary and/or the clinic POC for planned changes

(f) Enter/update patient demographics as per hospital policy

(g) Send telephone consults per clinic protocols

(h) Attend team huddles/ clinic meetings in relation to appointment scheduling

(i) Cancel / schedule patient’s appointments and referrals as necessary from the clinics check out desk if needed

(j) Provide stellar customer service as the patient’s first line of access into the Medical Group

(k) Respond within 1 business day to MiCare appointment and referral requests as per Medical Treatment Facility

(MTF) direction

(l) Answer any overflow calls from the MTF information desk

1.1.1.1. The contractor shall provide reports by the 15th of each month. Information on the reports shall contain all telephone statistics, all appointment activities, and all referral related statistics processed and tracked reports for Eglin CACC and RMC as required in AFI 44-176.

1.1.2. Operation of the Referral Management Center (RMC)- EGLIN AFB: The Contractor shall review the new consults picked up from the clinics, printed at the RMC, furnished from the Appointment Health Care Finder (AHCF) list, emailed, hand delivered, or faxed to the RMC or taken off the AHCF list to ensure that each includes the following minimum information:

Patient’s name FMP/Sponsor’s social security number Patient’s date of birth Home/work phone Originating clinic Specialty clinic being referred to Specific provider (if so requested) and contact number for that provider Originating provider’s name, phone number, and clinic Point of contact at the clinic, if the provider is not available

Provider’s facsimile number Status of patient (Prime, Standard, VA, Medicare) Number of visits authorized Time frame for consults Brief summary of reason for consult

1.1.2.1. Referral Appointing. The Contractor RMC staff shall book appointments for all TRICARE Prime beneficiaries within TRICARE Access To Care (ATC) standards and in accordance with the RMC Guide located on the AF Knowledge Exchange (except those referrals to network providers). The contractor shall book all non-TRICARE Prime patients according to the guidance given by the specific MTF clinics. The Contractor shall coordinate Right of First Refusal (ROFR) determination for specialty care that can be provided within the required timeline IAW AFI44-176, section10.4. Contractor appointing personnel shall use information systems that link the referral to the appointment, to the TRICARE ATC category and standard.

1.1.2.2. Referral Tracking. The Contractor shall chronologically track all referral requests/results going into/out of the MTF according to AF Referral Management Guide. The Contractor shall determine if patient has an appointment, with whom, either in or with another MTF, in the Network or with a non-network provider. The Contractor receives referral results directly from the consulting provider and knows which provider, MTF or network/non-network provider to follow-up with to get results returned and which PCM receives results. The Contractor will identify MTF providers who did not complete referral results within 72 hours of the referral episode at 4 working days after the referral episode. The Contractor shall ensure that results from the Direct Care System, Network, non-network providers, and Humana are returned to requesting provider via HAIMS within 3 business days .

1.1.2.2.1. The Contractor shall also scan all documents received by the RMC into HAIMS within 3 business days of receipt.

Documents will include but are not limited to: referral reports, follow up reports, labs, radiology tests, discharge summaries, and ER reports. Contracting Officer’s Representative (COR) shall be provided with a detailed list of all outstanding results (MTF and civilian) by ordering provider upon request.

1.1.2.3. Referral Review. The Contractor shall review referrals for medical and administrative appropriateness administrative and clinical completeness, covered benefit for the specific patient, and required tests and pre-work. Referrals will be submitted by the Eglin RMC to TSC/MCSC, civilian provider or other MTF via guidelines. The Contractor shall contact patient in event referral request is invalid, disapproved by second level review/MCSC. The Contractor shall reschedule patient, if necessary, for follow-up appointment or instruct patient of other health care options.

1.1.2.4. Coordination Functions. The Contractor shall ensure patient is notified about all necessary documentation required and appropriate for the referred episode of care, and shall ensure referring provider knows that results must be returned. The contractor shall act as administrative support to the Referral nurses in care and coordination of all referral issues. The contractor may assist in mailing radiology orders directly to patients if they are unable to schedule at the MTF.

1.1.2.5. Customer Service. The Contractor shall provide referring provider and PCM or designated surrogate with referral results, ensure that the patient is referred to the right service/provider within TRICARE ATC standards and shall serve as the point of contact for providers and patients needing help with referrals. The contractor shall staff and maintain the Referral Management Center and service all customers face to face and / or over the phone. Services include but are not limited to briefing the patient on referral process in its entirety, to include travel benefits, TRICARE coverage rules, necessary documentation for referral care, request authorization changes and extensions, and other portions of the referral process. The Contractor shall maintain the referral tracking database and provide reports from this as necessary.

1.1.2.5.1. The contractor shall route consults in accordance with provided clinic protocols. The contractor shall appoint/defer the consults utilizing the AHCF function in CHCS within 1 business day. Using the furnished Integrated Clinical Data Base (ICDB) or government-provided database, the contractor shall track all consults deferred outside the facility, and continue to track them until results are received and referral provider is notified. The contractor shall maintain monthly statistical reports and provide them to the COR by the 15th of the following month. These reports shall contain total consults received per specialty broken down into beneficiary category, disposition of consults, and reasons for deferral/denial, and shall include breakdown of time periods to assess each specialty, internally and externally.

1.1.2.6. Supervisor. The Contractor shall appoint an on-site supervisor to be on duty during operational hours. The supervisor shall establish and maintain active liaison with all MTF/clinic appointment coordinators; and shall be available to meet as required with MTF / MCSC staff as it pertains to appointments, registration, or referral processes. In absence of the COR the supervisor shall assist in enrollment issues, merging duplicate patients, process monthly reports for enrollment, PIT errors, provider profiling, and duplicate patients. The supervisor will complete the Air Force Medical Service feedback forms on each agent during 4 calls a month, submitting 2 of them to AFMS IAW AFI44-176 sec 9.1.2..The supervisor will monitor the key performance indicators IAW AFI44-176 section 9.2 monthly and submit those reports to the COR.

1.1.3. Operation of the Registration and TRICARE Plus Enrollment Center (RTPEC). The Contractor shall operate the 96th Medical Group RTPEC to ensure the registration in CHCS of all patients and the assignment of a PCM to each patient that a Primary Care Information Transfer (PIT) message is received on in accordance with local MTF guidelines. The contractor shall assist with processing PIT errors and function as the overall functional expert for hospital registration. The contractor will assist other departments with questions on registration or train other sections how to register patients. The contractor shall operate the RTPEC to ensure the assignment of a PCM to each patient that enrolls in the TRICARE Plus program. The contractor shall register / process all Foreign Nationals as well as collect a copy of their orders for billing purposes.

1.1.4. RECORDS. In accordance with AFI33-322, 10.1., and AFI33-364, 2.1., all records, files, documentation, working papers, and software provided by the Government or generated in the performance of this contract become and remain Government property. All such records, files, documentation, and working papers, which this contract requires the Contractor to maintain, shall be maintained in accordance with AFI 33-322 10.1, Records Management Program; AFI 33-364 2.1, Records Disposition-Procedures and Responsibilities; AF Electronic Records Management (ERM) Solution, AFRIMS, Records Disposition Schedule located at https://www.my.af.mil/gcss-af61a/afrims/afrims/ and all other pertinent directives, as supplemented. The contractor shall not dispose of any records without prior written approval of the Functional Area Records Manager (FARM) evidenced by the FARM's signature on the SF 135. If requested by the Government, the Contractor shall provide the original record or a reproducible copy of any such record within five working days of receipt of the request. The Contractor shall ensure Air Force Ancillary Training is completed annually by all of its employees. The Contractor shall ensure that its employees who are designated as the Functional Area Records Manager, Chief of Records and Records Custodian complete AF CBT Level 1, General Records Awareness, Level II, AF CBT, Records Management as well, and attend the local Records Management training course (FARM and RC).

1.1.4.1. The Contractor shall maintain one copy of the required training certificates in the training folder which shall be accessible to the COR.

SECTION 2 - SERVICE SUMMARY (SS)

Performance Objective PWS Reference Performance Threshold

Centralized Appointment Call Center SS 1: Percent of Abandoned Calls – less than or equal to 18% monthly

1.1.1 99%

SS 2: Calls Answered within 90 seconds monthly 1.1.1 90% SS 3: Average speed to answer less than or equal to 45 seconds monthly

1.1.1 99%

SS 4: Average Talk Time 3-5 minutes monthly 1.1.1. 90% SS 5: Utilization greater than or equal to 70% 1.1.1. 99% SS 6: Submit 2 AFMS feedback forms monthly. Reports due the 15th of month.

1.1.2.6. 99%

SS 7: Complete all MiCare messages within 1 business day 1.1.1. 99% SS 8: Submit required Automatic Call Distribution Key Performance Indicators reports to COR monthly per AFI44-176. Reports due by the 15th of the month.

1.1.2.6. 99%

Referral Management Center SS 9: Direct Care referral results tracked within 72 hours 1.1.2.2., 1.1.2.2.1 99% SS 10: Routine referral results tracked NLT 120 calendar days after the order date.

1.1.2.2. , 1.1.2.2.1 99%

SS 11: Referral results scanned into HAIMS with provider tcon notification within 3 business days

1.1.2.2., 1.1.2.2.1 80%

SS 12: ROFR Results processed to originating provider within 10 business days

1.1.2.2. , 1.1.2.2.1 95%

SS 13: ROFR form from MCSC processed within 1 business day 30 1.1.2.2., 1.1.2.2.1 95% minutes for ASAP referrals SS 14: Provide previous RMC monthly statistical report prior to the fifteenth day of the month.

1.1.1.1. 98%

SS 15Maintain ERSA spreadsheet, TRICARE Plus Registration 1.1.3. 98% SS 16: Appoint initial referral appoints within 1 business day 1.1.2.1 95% SS 17 Security, qualifications, and health and immunization requirements current and updated.

3.3.9, 4.6. 100%

SECTION 3 - GOVERNMENT FURNISHED PROPERTY AND SERVICES

3. Facilities Access and Resource Usage. The Government will provide, without cost to the Service Provider the facilities, equipment, supplies and services listed below.

3.1. Facility Usage. The Service Provider shall use general Government facilities, equipment, supplies, and services for the performance of this contract and return the facilities to the Government in the same condition as received, fair wear and tear and approved modifications excepted.

3.1.2. Automatic Data Processing Equipment (ADPE). The Government will furnish ADPE for mission accomplishment.

The Service Provider shall designate an ADPE custodian(s) in writing, for the equipment. The Service Provider shall use ADPE for controlling and tracking data and information, as well as, any other duties related to contract performance. The Service Provider shall not use Government furnished ADPE or services for non-contractual related purposes. The Service Provider shall adhere to AFI 33-112 Government Computer Systems para 19, AFI 33-119 Electronic Mail (E-mail) Management and Use as in paragraphs 1.1. through 1.1.3.and AFI 33-129 Transmission of Information Via the Internet Governing proper use of Government computers as in paragraphs 1.1. through 1.1.3.No later than five days prior to the start of the basic contract period, the Service Provider and a Government representative shall jointly inventory the listed equipment. The Service Provider shall comply with all computer system and ADPE accountability and security procedures required by the Government.

3.1.3. Office/Administrative Supplies. The Government shall provide the Service Provider the minimum amount of office/administrative supplies necessary to accomplish the requirements in this PWS. Office/Administrative supplies include but are not limited to computer disks, paper, toner and file folders. All supply requests shall be approved by the QAP prior to ordering. Appointment supervisor shall order through flight supply custodian.

3.2. The Government will provide the Contractor the Composite Health Care Systems (CHCS), Managed Care Program (MCP), and Booked Health Care Finder (BHCF) modules to book all direct care appointments according to furnished protocols and hospital regulation MGI 41-202 as in paragraphs 1.1. through 1.1.3.for appointing and referral management.

3.3. Services. The Government will provide utilities, postal, telephone, custodial services, refuse collection, fire protection, emergency medical service, security forces, computer services and rodent control services.

3.3.1. Utilities. The Government will furnish utility services including water, sewer, and electric for Service Provider use, in Government-furnished facilities. However, if Service Provider personnel require utility services that do not exist within a facility or area of work, it shall be the Service Provider’s responsibility to provide such utility service.

3.3.2. Postal Service. Official Government or Service Provider mail that is generated as a result of performance of this contract will be handled via the Base Information Transfer System (BITS) at Government expense.

3.3.3. Telephone Service. Government supplied phones shall be used solely for official business and shall not be used to transact personal business by the Service Provider or his/her employees. The Government will provide telephone instruments, telephone lines, data lines, and repair services for such instruments and lines for services outlined in this Performance Work Statement.

3.3.4. Custodial Service. Custodial services will be provided to the facilities to the extent of service listed in the current custodial contract.

3.3.5. Refuse Collection. Refuse collection services will be provided as listed in the current base refuse collection contract.

3.3.6. Fire Prevention and Protection. The Government will provide fire prevention protection, inspection, and maintenance of Government furnished fire extinguishers and systems. Fire Department telephone extension is 911 for emergencies.

3.3.7. Emergency Medical Service. In the event of an emergency, contact 911. If transport is necessary, the Service Provider employee shall reimburse the respective agency for any expenses for services incurred.

3.3.8. Security Forces. The Government will provide general security service. Security Forces phone extensions are 911 for emergencies, and 882-2502 for routine calls.

3.3.9. Computer Services. The Government will provide a LAN and E-mail account. This service will be strictly for conducting official business. Individuals must pass the Security Awareness Training Education (SATE) course and have a favorable National Agency Check (NAC) to gain access to the base Internet.

3.3.9.1. TRAINING. The government will provide training on all computer and information systems and all MTF required training.

3.4. BADGES. The on-site MTF will furnish an identifying badge and each employee shall wear the badge on the front outer clothing. The badge shall be visible at all times.

SECTION 4 - GENERAL INFORMATION

4.1. Service Provider Personnel.

4.1.1. Service Provider Manager. The Service Provider shall provide an on-site contract manager and alternate responsible for work performance and authority to make decisions on all contract matters. Submit their names and phone numbers to the Contracting Officer (CO) before the contract start date. The contract manager or alternate shall be available during normal duty hours.

4.1.2. Service Provider Employees. The Service Provider shall not employ persons identified as a potential threat to the health, safety, security, general well-being or operational mission of the installation or its population. Employees must be able to speak and understand English without an interpreter.

4.2. Contractor Manpower Reporting Application (eCMRA). The Contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract via the secure data collection site (i.e. Contract Manpower Reporting Application). The contractor is required to completely fill in all required data fields using the following web address http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year.

Contractors may direct questions to the above eCMRA help desk.

Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the contractor name and contract number associated with the data. Data for Air Force service requirements must be input at the Air Force CMRA link. However, user manuals for government personnel and contractors are available at the CMRA link at http://www.ecmra.mil.

4.2.1 Common Access Cards (CACs)

The Contractor’s PM or alternate shall complete all necessary documents for all Contractor personnel requiring access to Eglin AFB. Common Access Cards (CAC) shall be required for all on-site Contractor personnel. The Contractor’s PM shall ensure the Government representative in the local organization designated to authorize issuance of Contractor’s CACs (i.e.

Trusted Agent (TA) receives a Visitor Request for each employee through the Trusted Agent Security System (TASS).

Contractor personnel shall electronically submit application to the TA, once approved set up appointment at https://rapids-appointments.dmdc.osd.mil/ or go to the Eglin Military Personnel Section located in Bldg 210 to receive their CAC.

4.3. The Service Provider shall not employ any person who is an employee of the United States Government if the employment of that person would create a conflict of interest or the appearance of a conflict of interest. Additionally, the Service Provider shall not employ any person who is an employee of the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to DOD Regulation 5500.7, Joint Ethics Regulations (JER). The Service Provider is prohibited from employing off-duty QAPs who are managing any contracts or subcontracts http://www.ecmra.mil/ awarded to the Service Provider. The Service Provider shall not employ any person who is an employee of the Department of the Air Force if such employment would be contrary to the policies in AFI 64-106 sec 3, Air Force Industrial Labor Relations Activities.

4.4. Smoking, Eating and Drinking. The Service Provider shall permit smoking, eating and drinking only in designated areas.

4.5. Service Provider personnel shall present a neat appearance and be easily recognized as Service Provider employees.

Service Provider shall ensure personnel wear appropriate clothes suited for their job.

4.6. Security Requirements. Patient information shall not be used to create databases or any other product not intended for use specifically for the 96th Medical Group. The contractor shall adhere to the Privacy Act of 1974 and comply with all Health Information Portability Accountability Act (HIPAA) regulations when providing patient information. Patient information shall not be disclosed or revealed to unauthorized personnel.

4.7. Health Requirements. OSHA requires all contract personnel who have/or may have occupational exposure to blood products or body fluids, or any potentially infections materials, shall receive Hepatitis B vaccine or have documented proof of immunity to Hepatitis B infection. The government requires a current tuberculosis test, and proof of mumps, measles and rubella testing. Currency of immunizations must be reported annually and shall be furnished by the contractor. Successful completion of initial cardiopulmonary resuscitation training and annual refresher training for cardiopulmonary resuscitation training (provided by the government) are also required. Contractor shall also comply with annual safety training and security training guidelines.

4.8. Forms and Publications. The Service Provider is responsible for maintaining files for forms and publications. The Service Provider shall research publications to ensure all performance outputs meet Air Force publication guidelines. Air Force publications are located at http://www.e-publishing.af.mil/pubs/majcom.asp?org=AF on the Internet. The Service Provider may develop their own processes for accomplishing outputs for those areas not specified by a directive. The Service Provider is encouraged to use the most efficient method of producing work without sacrificing quality standards.

4.9. PERFORMANCE OF SERVICES DURING CRISIS DECLARED BY THE NATIONAL COMMAND

AUTHORITY. IAW DoDI 3020.37 (Continuation of Essential DoD Contractor Services During Crisis) and aforementioned Air Force implementation, unless otherwise directed by an authorized government representative, it is determined that services as identified in this PWS are NOT essential for performance during a crisis.

CONTINUATION OF ESSENTIAL DEPARTMENT OF DEFENSE (DOD) CONTRACTOR SERVICES DURING

CRISIS

All services to be performed under the contract have been determined to be non-essential for performance during crisis;

however, some services may be required to support an activation, exercise of contingency plans outside the normal duty hours, or crisis. The Base could be closed because of security problems or other events. Should one of these situations occur, the MFT or the CO would determine services required during the crisis. Unless otherwise notified by the government the contractor should listen to or watch one of the local television or radio stations for notification of a possible base closure.

4.9. Quality Control (QC)

In compliance with the contract clause 52.246-4 entitled "Inspection of Services -- Fixed-Price," the Contractor shall provide a Quality Control Plan that contains, as a minimum, the items listed in 4.9.1. to the contracting officer for acceptance not later than the pre-performance conference. The contracting officer will notify the Contractor of acceptance or required modifications to the plan before the contract start date. The Contractor shall make appropriate modifications and obtain acceptance of the plan by the contracting officer before the contract start date.

4.9.1. Quality Control Plan (QCP)

The Contractor shall be required to submit a QCP before contract start date. The Contractor’s quality control plan shall contain, as a minimum, the following items:

a. A description of the inspection system to cover all services. Description shall include specifics as to the areas to be inspected on a scheduled and unscheduled basis, frequency of inspections, and the title and organizational placement of the inspector(s).

b. A description of the methods to be used for identifying and preventing defects in the quality of service performed.

http://www.e-publishing.af.mil/pubs/majcom.asp?org=AF

c. A description of how the records will be kept. Records must document all inspections and corrective or preventive actions taken.

SECTION 5 - APPENDICES

APPENDIX A - WORKLOAD ESTIMATE

EGLIN AFB, FL

Currently the ACD routes calls to primary clerks in the skill set, any overflow calls are divided out. Clinics have a dedicated pod of clerks that answer for their clinic. Internal Med clerk maybe relocated with the CACC in the future if space allows.

CACC- The CACC receives approximately, 25,000 incoming calls and makes 10,000 outgoing calls monthly, while making approximately 20,000 appointment transactions.

RMC-New consults which historically amount to 7,000 a month, outgoing calls approximately 6,000 monthly, incoming calls of 4,000 monthly, walk in patients approximately 20 a month RTPEC-. The RTPEC enrollment / registration process estimates approximately 250 transactions.

The Tricare Plus enrollment figures are estimated to be approximately 20 a month.

IMCAD- The IMCAD estimates approximately 4,000 incoming calls monthly and estimates making 2,000 appointments (booking, canceling, changing and telephone consults).

APPENDIX B-HOURS OF OPERATION/LOCATION

EGLIN AFB FL

Monday-Friday 0700-1600 hours, except Federal holidays and Down Days as assigned. Federal holidays are: New Year’s Day, Martin Luther King Day, Washington’s Birthday, Memorial Day, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.

CACCD

IMCAD

RTPEC

RMC – hours can vary for Haims scanning.

LOCATIONS:

96 MDG, Eglin AFB, FL:

Centralized Appointment Call Center (CACC) Referral Management Center (RMC)

Primary Care Manager By Name Desk (PCMBND) Internal Medicine Clinic Appointment Desk (IMCAD)

APPENDIX C- Regulation Table

PWS paragraph Regulation

1.1.1, 1.1.2.1 AFI 44-176

1.1.2 MTF Referral Management Center

Users' Guide, version 9.0 1 May 2014

ATTACHMENT 3 - HIPAA

This Business Associate Agreement (this "Agreement") is entered into this XX day of XXX, 2014 between 96 MDG, Eglin AFB, FL ("Covered Entity") and XXX, a Profit Corporation ("Business Associate").

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.

Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean (Contractor’s Name).

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean 96 MDG.

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S.

Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR

164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity .

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines

“breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/.

Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the Covered Entity. Upon request, the Business Associate shall provide the Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.

(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1- 866-653-4261.

(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and

(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address

(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The Covered Entity will determine the appropriate level of support services.

(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.

(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .