Revised_SOW.pdf
PDF 207 KB Posted
- Attached to
- Hospital Wide Shredding Service Federal contract opportunity
- Solicitation number
- FA4427-19-Q-0097
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Updated_Combo.pdf | ||
| SOW_2.0.pdf | ||
| Q&A.pdf | ||
| FedBizOpps_Combo.pdf | ||
| FedBizOpps_Combo.pdf | ||
| 19-046_SOW1.pdf | ||
| Contract_Security_Clause.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
Shredding Service For
David Grant Medical Center Travis AFB, CA
6 MAY 2019
I. DESCRIPTION OF SERVICES
The contractor shall provide all labor, tools, materials and transportation for ON SITE document shredding services for the 60th Medical Group, David Grant Medical Center (DGMC), Travis Air Force Base, California, to include the Satellite clinics on Travis AFB as defined in this Statement of Work (SOW). The contractor shall perform these services and disposal requirements in accordance with the standards specified in this contract Health Insurance Portability and Accountability Act (HIPPA) IAW 45 CFR 160 and 164, and the Joint Commission for Accreditation of Health Care Organizations (JCAHO). The contractor shall submit reports and documentation as identified throughout this SOW.
Place of performance:
1. Initial order during phase in of contract, the Contractor shall provide at a minimum 73 each Standard locked console (bins), and 22 each 64 Gallon Tote, and 6 each of the mini-console to the following areas:
Current Location/Department Floor Standard
Consoles 64 Gallon Mini- Console
Contract Management 1 1
Warehouse / Logistics 1 2
Inpatient Records 1 2
Pediatrics 1 2
Internal Medicine 1 3
Orthopedics 1 2
Brace Shop 1 1
Dental Clinic 1 1
Hematology/Oncology 1 2
Radiation Therapy 1 2
Physical Therapy 1 1
Mental Health 1 2
Hemodialysis 1 2
Nutritional Medicine 1 1
Dining Hall 1
CIF 1 1
David Grant Medical Center Building 777 Travis AFB David Grant Medical Center Building 791 Travis AFB Pharmacy Satellite Center Building 650 Travis AFB Veterinary Clinic Building 543 Travis AFB
Medical Law 1 1
MRI 1 1
Education & Training 1 1
MEB Office 1 1
Audiology / ENT 1 1
Pharmacy Infusion 1 1
Physics 1 1 Diagnostic Radiology 2 3 2
Lab 2 2
Family Medicine 2 2 1
Family Health 2 1 1
MDOS Command Section 2 1
MDTS Command Section 2 1
Readiness 2 1
SGCS Command Section 2 1
Flight Medicine 2 1
ER 2 1 1
Main Pharmacy 2 1 1 6 Patient Services 2 1
Systems 2 1
A&D 2 1
RMO 2 1
Histology (2B405-5) 2 1
Public Health 2 1
Medical Standards 2 1
Optometry 2 1
Allergy/Immunizations 2 1
Dermatology 2 1
Inpatient Coders 2 1
Pathology 2 1
Surgery Center Inpatient 3 2 General Surgery Clinic - 3W (GI Clinic?) 3 2
Recovery Room 3 1
Heart Lung Vascular 3 2
ICU 3 1
Admin Tech - 3C503 3 1
Cath Lab 3 1
OR/Anesthesia 3C413 3 1
OR Hot Desk 3C413 3 1
Inpatient Pharmacy 4 1 Women’s Health 4 2 Oral Surgery 4 2
Ophthalmology 4 1
Labor & Delivery 4 1
Doctor's Office - 4A204 4 1
Nurses Station - 4A204 4 1
4C Room - 4A444 4 1
4 East Ward 4 1 4 West Ward 4 1
Satellite Pharmacy (Bldg. 650) Off Site 1 1
Bioenvironmental (Bldg. 791) Off Site 1
Facilities (Bldg. 791) Off Site 1
Vet Clinic Off Site 1
Total Containers (each) 73 22 6
TOTAL WEEKLY RATE $
BLDG 777: $681.20
BLDG 650: $51
BLDG 791: $51
BLDG 543: $51
TOTAL FY20 $43,378.40
1.1 Contractor must be able to adjust and increase services from original stated requirement by allowing for adjustment/growth in the number and size of bins and/or the frequency of shredding dependent on need. The Contractor shall provide the following types of bins and quantities to the following locations:
BLDG 777 with 70 each of the Standard Console bins with the capacity to increase to an amount of 70+ each of the Standard Console bins (approximate dimension: 36"H x 20.5"W x 16"D), 20 each of the 64 Gallon Tote (approximate dimension: 24" W x 28" D x 42" H) with the capacity to increase to an amount of 20+ 64 Gallon Tote’s and 6 each of the mini-console (approximate dimension: 26" H x 20 %" W x 19.6" D) for pharmacy windows staff with the capacity to increase to an amount of 6+ each.
BLDG 650 with 1 each of the Standard Console bins with the capacity to increase to an amount of 1+ each of the Standard Console bins and 1 each of the 64 Gallon Tote with the capacity to increase to an amount of 1+ 64 Gallon Tote’s to accommodate.
BLDG 791 with 1 each of the Standard Console bins with the capacity to increase to an amount of 1+ each of the Standard Console bins and 1 each of the 64 Gallon Tote with the capacity to increase to an amount of 1+ 64 Gallon Tote’s to accommodate.
BLDG 543 with 1 each of the Standard Console bins with the capacity to increase to an amount of 1+ each of the Standard Console bins to accommodate.
Requirements and adjustments will be determined by the Contract Management office located at DGMC, Travis AFB CA, Bldg 777;(707) 423-7972. Containers must be compliant in accordance with Section 19.7.5.7.2 of the 2018 edition of the Life Safety Code. The contractor shall provide an inventory of all containers, to include location. The contractor shall provide a certificate of destruction after each service. Fee/Cost will be based on total number of bins provided. All bins will be completely emptied, during each service call, which will be scheduled through DGMC Contract Management. Contractor must shred all documents ON-SITE in accordance with HIPPA standards, on a weekly basis.
1.2 Contractor shall sign in/out with representative at the Contract Management. The original service report must be signed by the clinic receiving the shredding services identifying service rendered, location of bins/cabinets. The service report is to be delivered to the DGMC Contract Management Office room 1C240 upon completion of the work and prior to departure of the facility.
1.3 Invoices WILL BE submitted on a monthly basis through Wide Area Work Flow. The invoice must include the following as a minimum:
Date and time of service.
Company and service representative names.
Contract number.
A detailed description of what clinic received the service, documenting quantity of bins serviced.
Total cost.
1.4 Contractor must be certified and HIPAA compliant (Health Insurance Portability and Accountability ACT) IAW 45 CFR 160 and 164.
II. GENERAL INFORMATION
1. Security Requirements. All personnel employed by the contractor in the performance of this contract, or any representative or subcontractor of the contractor entering the governmental installation, shall abide by all security regulations of the installation.
1.1. Security. Travis Air Force Base is designated as a closed base. In order to promote security and safety, all contractors desiring access must adhere to installation entry requirements, to include, criminal background history (CBH) checks, National Crime Information Center (NCIC) wants/warrants checks and California Law Enforcement Telecommunication System (CLETS) driver license history checks. A CBH check is not required for contractors if they have a current favorable government security clearance which can be verified through the Joint Personnel Adjudication System (JPAS). Contractors are divided into two categories to ensure proper screening and to minimize installation access delays as follows:
Category 1 (Cat-1) contractors are the primary and some sub-contractors who are identified against a contract prior to the contract performance start date.
Category 2 (Cat-2) sub-contractors and affiliate workers not previously identified against a contract prior to the contract performance start date.
Contractors will ensure all Cat-1 and Cat-2 contractors possess proper credentials allowing them to work in the United States. Additionally, contractors will ensure illegal aliens are not employed and/or transported onto the installation.
The contractor shall not be entitled to any compensation for delays or expenses associated with complying with the provision of this clause. Furthermore, nothing in this clause shall excuse the contractor from proceeding with the contract as required.
1.2. Criminal Background Checks. Cat-1 and Cat-2 contractors whose criminal background meets any of the following 12 disqualifiers will not be allowed installation access. All Cat-1 and Cat-2 contractors will be adjudicated based on the following disqualifying base access criteria:
U.S. citizenship, immigration status, or social security account number cannot be verified.
Barred from entry/access to any military installation or facility.
Wanted by federal or civil law enforcement authorities, regardless of offense or violation.
Name appears on any federal agency’s list for criminal behavior or terrorist activity.
Convicted of espionage, sabotage, treason or terrorism.
Incarcerated for 12 months or longer within the past three years, regardless of offense or violation.
Convicted of a firearms or explosives violation within the past three years.
Convicted of illegal possession or use of drugs/narcotics on more than one occasion within five years from the date access to Travis AFB is requested.
Convicted of an offense involving drug trafficking, possession with intent to sell or drug distribution within 10 years from the date access to Travis AFB is requested.
Convicted of a felony involving violence against a person, arson, robbery or burglary within five years from the date access to Travis AFB is requested.
Required to register as a sex offender under federal law or the applicable state law.
Convicted of any crime involving indecent acts with a minor or a felony that is sexual in nature.
Cat-1 and Cat-2 contractors adjudicated and cleared under the disqualifying criteria are considered cleared for installation access for a two-year period regardless of the number or length of contract; thereafter, a renewal is required. During the two-year period, Pass and Registration or the Visitor Control Center will perform random samplings of CBH, NCIC wants/warrants and CLETS driver license history checks of contractors already cleared.
Cat-1 and Cat-2 contractors with disqualifying base access information will be issued a barment letter immediately revoking their base access privileges. Cat-1 and Cat-2 contractors requesting to contest the adjudication, barment, or requesting a waiver/exception to policy must submit a written rebuttal/request within 10 business days of receipt of the barment letter to 60 AMW/CC, through 60 SFS/CC, Attention: 60 SFS/S5R, Bldg 381, 540 Airlift Drive, Suite C-101, Travis AFB 94535-2451.
1.3. Primary Contractor Responsibilities. The primary contractor will be responsible for the conduct of all Cat-1 and Cat-2 contractors working under that contract. Additionally, the primary contractor will:
Coordinate Cat-1 and Cat-2 base entry requirements with the 60th Contracting Squadron.
Advise Cat-1 and Cat-2 contractors requesting base access on requirement to complete, sign and submit a Travis Form 251, Consent for Background Check. Forms are available at Pass and Registration, Visitor Control Center or the AF Portal e-publishing website. Any Cat-1 or Cat-2 contractor who does not complete or sign the form will be denied installation access.
Advise Cat-1 and Cat-2 contractors that the badge/pass is only valid for the purpose, person and vehicle for which it was issued. Use of the badge/pass for any other purpose or by any other person will result in the pass being confiscated. Cat-1 and Cat-2 contractors that misuse their pass may face revocation of installation access privileges and/or barment actions. If a pass is lost, notify the Pass and Registration Office immediately.
To obtain a pass, personnel will need a valid state or government photo identification.
To obtain a vehicle pass, personnel will need a driver license, registration and insurance.
Provide written notification, within one week, to the 60th Contracting Squadron of any changes in Cat-1 or Cat-2 contractor status. This includes, but is not limited to, the contractor being fired or quitting their position with the company.
Retrieve government issued personal and vehicle passes from Cat-1 and Cat-2 contractors which no longer need installation access upon termination of the contract. Passes will be turned into the Pass and Registration Office, Bldg 599.
Processing Cat-1 Contractors. Provide an EAL (Entry Authority List) of all Cat-1 contractors on company letterhead which require a badge/pass. All requests for a badge/pass will be submitted through the Base Contracting Office NLT 45 days prior to the contract start date. Exceptions will be made for short-notice contracts where the award date and performance start date are less than 45 days. A badge/pass will be issued for a maximum of one year. Prior to renewing a badge/pass, return the old badge/pass to the Pass and Registration for destruction. Ensure the EAL includes:
Contract number Work site or location Inclusive dates of the contract Work schedule (include days of the week and time periods contractors are on base) Contractor’s full name, date of birth, and social security number
When the EAL is submitted, ensure a TAFB Form 251, Consent for Background Check, is attached for each person.
Processing Cat-2 Contractors. Only persons who have undergone a CBH and are clear of disqualifying base access information can serve as a sponsor. Persons appointed as sponsors will meet Cat-2 contractors at the Visitor Control Center, and ensure they complete Travis Form 251, Consent for Background Check.
1.4. Lost Badges/Passes. The supervisor of Cat-1 and Cat-2 contractors will investigate and provide written notification for a lost badge/pass to the 60th Contracting Squadron. Written notification should include an explanation from the contractor on how, when, where and what steps have been taken to locate the missing badge/pass. If a replacement is needed, forward the notification with the request for a badge/pass.
1.5. Escort Requirements. Cat-1 and Cat-2 contractors when working in a Controlled, Restricted or other sensitive areas must be escorted at all times. The military agency or unit responsible for the project or work is responsible for providing the escorts. The contractor shall follow existing procedures and instructions for obtaining entrance to Controlled, Restricted and sensitive areas. Additionally, Cat-2 contractors will be escorted while obtaining a pass and at all times while on the installation.
1.6. Increased Force Protection Condition (FPCON). During FPCON Normal, Alpha and Bravo; Cat-1 and Cat-2 contractors without a base issued badge/pass must be sponsored onto the installation. During FPCON Charlie and Delta the base will curtail non-essential operations/functions and non-essential Cat-1 and Cat-2 contractors will be suspended at the direction of the Installation Commander. All Cat-1 and Cat-2 contractors attempting installation access; thereafter, will be physically escorted unless FPCON Mission-Essential designation has been approved in advance and is indicated on the badge/pass.
2. Initial Inspection. All contractor owned equipment will be inspected and approved by the Biomedical Equipment Maintenance Section prior to use in the Medical Treatment Facility.
Contact QAP to schedule inspection.
3. Removal of Equipment. Should the equipment or any component listed herein require repair at the contractor’s plant, contractor shall be responsible to obtain/transport equipment.
Contractor shall provide a loaner/replacement on-site until original is fully repaired. Contractor shall be responsible for damage or loss of equipment while in contractor’s possession.
General Use and Disclosure Provisions Except as otherwise limited in this Clause, the Contractor may use or disclose Protected Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health Information would not violate the HIPAA Privacy Rule, the HIPAA Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the Government.
Obligations of the Government Provisions for the Government to Inform the Contractor of Privacy Practices and Restrictions
(a) The Government shall provide the Contractor with the notice of privacy practices that the Government produces in accordance with 45 CFR 164.520.
(b) The Government shall provide the Contractor with any changes in, or revocation of, permission by Individual to use or disclose Protected Health Information, if such changes affect the Contractor’s permitted or required uses and disclosures.
(c) The Government shall notify the Contractor of any restriction to the use or disclosure of Protected Health Information that the Government has agreed to in accordance with 45 CFR 164.522.
Permissible Requests by the Government The Government shall not request the Contractor to use or disclose Protected Health Information in any manner that would not be permissible under the HIPAA Privacy Rule, the HIPAA Security Rule, or any applicable Government regulations (including without limitation, DoD 6025.18-R and DoD 8580.02-R) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this clause.
Termination
(a) Termination. A breach by the Contractor of this clause, may subject the Contractor to termination under any applicable default or termination provision of this Contract.
(b) Effect of Termination.
(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below
(2) If this contract does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Contractor shall return or destroy all Protected Health Information received from the Government, or created or received by the Contractor on behalf of the Government. This provision shall apply to Protected Health Information that is in the possession of subcontractors or agents of the Contractor. The Contractor shall retain no copies of the Protected Health Information.
(3) If this contract does not have records management provisions and the Contractor determines that returning or destroying the Protected Health Information is infeasible, the Contractor shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Contractor that return or destruction of Protected Health Information is infeasible, the Contractor shall extend the protections of this Contract to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such Protected Health Information.
Miscellaneous
(a) Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule means the section currently in effect or as amended, and for which compliance is required.
(b) Survival. The respective rights and obligations of this contract under the “Effect of Termination” provision of this Clause shall survive the termination of this Contract.
(c) Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the Government to comply with DoD 6025.18-R, DoD 8580.02-R, the HIPAA Privacy Rule or the HIPAA Security Rule.
Business Associate Agreement
Business Associate Agreement
[USE FOR STANDALONE BAA ONLY] This Business Associate Agreement (this "Agreement") is entered into this ___ day of ________, _____ (the “Effective Date”) between [NAME OF MHS COVERED ENTITY] ("Covered Entity") and [NAME OF BUSINESS ASSOCIATE], a [type of business entity] ("Business Associate").
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.
Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph
C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS
ASSOCIATE].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD
5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY
THIS SECTION IF THE PURPOSE OF THE AGREEMENT/CONTRACT IS FOR THE BA TO
DEIDENTIFY PHI FOR THE CE].
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of
PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number.
Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions
(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:
(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.
(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and
(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address
(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.
(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.
(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.
(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber security incident involves a PII/PHI breach (suspected or confirmed), the Business
Associate shall immediately initiate the breach response procedures set forth here. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.
VI. Termination
(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors) with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the underlying Contract [FOR STANDALONE INSERT, REPLACE WITH “this Agreement”].
(b) Effect of Termination.
(1) If this Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If this Agreement does not have records management requirements, the records should be handled in accordance with paragraphs VI.(2) and (3) below. If this Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if the Covered Entity gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or the Covered Entity’s direction.
(2) If this Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of this Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.
(3) If this Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.
VII. Notices. Any notices to be given hereunder will be made in the most expedient manner, via e-mail, facsimile, U.S. Mail, or express courier to such party’s address given below.
If to the Business Associate: If to the Covered Entity:
Attn: Attn: Ms. Charlene Rodriguez Title: Title: MTF HIPAA Privacy Officer Company: Unit:
Address: Address: 101 Bodin Circle Travis AFB, Ca 94535
Phone: Phone: 707-423-2341 or 707-423-7916 Fax: Fax:
E-mail: E-mail: Charlene.rodriguez5.civ@mail.mil mailto:Charlene.rodriguez5.civ@mail.mil
With a copy to:
Name: Name:
Company: Title: Contracting Officer Address: Address:
Phone: Phone:
Fax: Fax:
Email: Email:
Each party named above may change its address and that of its representative for notice by the giving of notice thereof in the manner provided in this subsection.
VIII. Miscellaneous
(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of this Agreement.
(b) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA Issuances.
[USE FOR STANDALONE BAA ONLY] (c) Counterparts; Facsimiles. This Agreement may be executed in any number of counterparts, each of which shall be deemed an original. The parties acknowledge and agree that faxed and/or electronically affixed signatures shall act as original signatures that bind each faxing, or electronically affixing, signatory to the terms and provisions of this Agreement.
Delivery of an executed counterpart of this Agreement by facsimile or electronic mail shall be equally effective as delivery of a manually executed counterpart.
[USE FOR STANDALONE BAA ONLY] (d) Entire Agreement; Amendment. This Agreement embodies the entire understanding between the parties pertaining to the subject matter contained in it;
supersedes any and all prior negotiations, correspondence, understandings, or agreements of the parties with respect to its subject matter; and may be waived, altered, amended, modified, revised or repealed, in whole or in part, only on the written consent of the parties to this Agreement.
[USE FOR STANDALONE BAA ONLY] IN WITNESS WHEREOF, the parties have executed this Agreement as of the Effective Date.
[USE FOR STANDALONE BAA ONLY]
BUSINESS ASSOCIATE: COVERED ENTITY:
Signature: Signature:
Print name: Print name:
Title: Title:
Date: Date:
| STATEMENT OF WORK |
| Shredding Service |
File details come from the government source that posted it.