Solicitation - FA442720R0005 - Updated.pdf
PDF 541 KB Posted
- Attached to
- Perfusionist Services Federal contract opportunity
- Solicitation number
- FA4427-20-R-0005
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Answers.pdf | ||
| Attach 4 - Wage Determination 2015-5655 Rev 9.pdf | ||
| Attach 1 - PWS Cardiothoracic Perfusionist Services.pdf | ||
| Attach 3- Revised Past Performance Questionnaire (PPQ)1.pdf | ||
| Attach 2 Past Performance List of References.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER PAGE 1 OF
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. TELEPHONE NUMBER (No collect calls)
8. OFFER DUE DATE/
13b. RATING
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO 16. ADMINISTERED BY CODE
18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ IFB RFP
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QUANTITY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF. OFFER
DATED . . YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED
31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA - FAR (48 CFR) 53.212
10. THIS ACQUISITION IS UNRESTRICTED OR
NAICS:
SIZE STANDARD:
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
SET ASIDE: % FOR:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
ARE ARE NOT ATTACHED
ARE ARE NOT ATTACHED
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
8 (A)
EDWOSB
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SMALL BUSINESS
FA442720R0005
Adam Taylor 707 424-7788
LOCAL TIME
03/10/2020
1:00 PM PST
FA44279. ISSUED BY
FA4427 60 CONS LGC
ADMINISTRATIVE ONLY NO REQUISITIONS
350 HANGAR AVE
TRAVIS AFB, CA 94535-2632
United States Adam Taylor
621111
$11,000,000.00
See Schedule
SEE SCHEDULE
A004991
Solicitation/Contract Form
FA442720R0005
Supplies or Services and Prices/Cost Additional Information/Notes
Item Supplies/Service Quantity Unit Unit Price Amount
0001 CARDIOTHORACIC PERFUSIONIST
SERVICES, AFSC 42GXD, FAC 5232,
2 FTE WITH BACKUP
Product Service Code: Q524 Firm Fixed Price
6.0 Months
1001 CARDIOTHORACIC PERFUSIONIST
SERVICES, AFSC 42GXD, FAC 5232,
2 FTE WITH BACKUP
Product Service Code: Q524 Firm Fixed Price
12.0 Months
2001 CARDIOTHORACIC PERFUSIONIST
SERVICES, AFSC 42GXD, FAC 5232,
2 FTE WITH BACKUP
Product Service Code: Q524 Firm Fixed Price
12.0 Months
3001 CARDIOTHORACIC PERFUSIONIST
SERVICES, AFSC 42GXD, FAC 5232,
2 FTE WITH BACKUP
Product Service Code: Q524 Firm Fixed Price
12.0 Months
4001 CARDIOTHORACIC PERFUSIONIST
SERVICES, AFSC 42GXD, FAC 5232,
2 FTE WITH BACKUP
Product Service Code: Q524 Firm Fixed Price
12.0 Months
Description/Specifications/Statement of Work
Requirements
CARDIOTHORACIC PERFUSIONIST SERVICES, AFSC 42GXD, FAC
5232, 2 FTE WITH BACKUP
Packaging and Marking
Inspection and Acceptance
0001 Inspection and Acceptance Location
Both Other Instructions: DGMC
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
1001 Inspection and Acceptance Location
Both Other Instructions: DGMC
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
2001 Inspection and Acceptance Location
Both Other Instructions: DGMC
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Email:
Telephone: 704237640
3001 Inspection and Acceptance Location
Both Other Instructions: DGMC
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Email:
Telephone: 7074237640
4001 Inspection and Acceptance Location
Both Other Instructions: DGMC
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Deliveries or Performance
0001 Delivery Schedule Ship To Address
Partial Delivery Schedule Delivery Period
01 APR 2020
30 SEP 2020
6.0 Months
Place of Performance
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Period of Performance From
01 APR 2020
to
30 SEP 2020
1001 Delivery Schedule Ship To Address
Partial Delivery Schedule Delivery Period
01 OCT 2020
30 SEP 2021
12.0 Months
Place of Performance
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Period of Performance From
01 OCT 2020
to
30 SEP 2021
2001 Delivery Schedule Ship To Address
Partial Delivery Schedule Place of Performance
Delivery Period
01 OCT 2021
30 SEP 2022
12.0 Months
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Period of Performance From
01 OCT 2021
to
30 SEP 2022
3001 Delivery Schedule Ship To Address
Partial Delivery Schedule Delivery Period
01 OCT 2022
30 SEP 2023
12.0 Months
Place of Performance
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Period of Performance From
01 OCT 2022
to
30 SEP 2023
4001 Delivery Schedule Ship To Address
Partial Delivery Schedule Delivery Period
01 OCT 2023
30 SEP 2024
12.0 Months
Place of Performance
DoDAAC: F3Z453 Cage:
DunsNumber:
Duns4Number:
CountryCode: USA
60 MDG DGMC
101 BODIN CIR BLDG 777 RM 1A416
AF BPN NO MILSBILLS PROCESSES
TRAVIS AFB, CA 94535 1809
United States
OfficeCode:
Rebecca Drummond Telephone: 7074237640 Email:
Period of Performance From
01 OCT 2023
to
30 SEP 2024
Contract Administration Data
DFARS Clauses Incorporated by Reference
Number Title Effective Date 252.201-7000 Contracting Officer's Representative 1991-12 252.204-7006 Billing Instructions. 2005-10 252.232-7003 Electronic Submission of Payment Requests and Receiving Reports. 2018-12
DFARS Clauses Incorporated by Full Text
252.232-7006 Wide Area WorkFlow Payment Instructions. 2018-12 As prescribed in 232.7004(b), use the following clause:
WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)
(a) Definitions. As used in this clause- Department of Defense Activity Address Code (DoDAAC) is a six position code that uniquely identifies a unit, activity, or organization.
Document type means the type of payment request or receiving report available for creation in Wide Area WorkFlow
(WAWF).
Local processing office (LPO) is the office responsible for payment certification when payment certification is done external to the entitlement system.
Payment request and receiving report are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall-
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov;
and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the Web Based Training link on the WAWF home page at https://wawf.eb.mil/
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.
(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.
(Contracting Officer: Insert either Invoice 2in1 or the applicable invoice and receiving report document type(s) for fixed price line items for services.)
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial item financing, submit a commercial item financing request.
(2) ) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
(f) [Note: The Contractor may use a WAWF combo document type to create some combinations of invoice and receiving report in one step.]
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table*
| Field Name in WAWF || Data to be entered in WAWF | | Pay Official DoDAAC || __F87700__ | | Issue By DoDAAC || __FA4427__ | | Admin DoDAAC || __FA4427__ | | Inspect By DoDAAC || __F3Z453__ | | Ship To Code || ____ | | Ship From Code || ____ | | Mark For Code || ____ | | Service Approver (DoDAAC) || __F3Z453__ | | Service Acceptor (DoDAAC) || __F3Z453__ | | Accept at Other DoDAAC || ____ | | LPO DoDAAC || ____ | | DCAA Auditor DoDAAC || ____ | | Other DoDAAC(s) || ____ |
(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert See Schedule or Not applicable.)
(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)
(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.
(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.
(g) WAWF point of contact.
(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activitys WAWF point of contact.
(Contracting Officer: Insert applicable information or Not applicable.)
(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.
(End of clause)
Special Contract Requirements Travis AFB Security Requirement 5 Mar 19
1. Security Requirements. Travis Air Force Base is designated as a closed base. In order to promote security and safety, all contractors desiring access must adhere to installation entry requirements, to include, identity proofing and vetting. This includes a National Crime Information Center (NCIC) and California Law Enforcement Telecommunication System (CLETS) check. Identity proofing and vetting is not required for contractors if they have a current favorable government security clearance which can be verified through the Joint Personnel Adjudication System (JPAS).
2. The primary contractor will ensure all contractors possess proper credentials allowing them to work in the United States and ensure illegal aliens are not employed and/or transported onto the installation. At least one of the following forms of identification will be required for identity proofing:
United States Passport Permanent Registration Card/Alien Registration Receipt Card (Form I-1551) Foreign Passport with a temporary (I-1551) stamp or temporary (I-1551) printed notation on a machine readable immigrant visa.
Employment authorization document that contains a photograph (Form I-766) Current/valid Driver's License (see para. 3) Identification card issued by Federal, State or local Government U.S. Coast Guard Merchant Mariner Legacy Card U.S. Coast Guard New Merchant Mariner Credential
Additional supplemental sources of identity proofing which may be requested during increased Force Protection Conditions (FPCONs) or Random Antiterrorism Measures (RAMs) include, but are not limited to:
School identification card with photograph U.S. Military or draft record Native American Tribal Document U.S. Social Security Card issued by the Social Security Administration (SSA) Certification of Birth Abroad issued by the Department of State (Form FS-545 or Form DS-1350) Original or certified copy of a birth certificate issued by a state, county, municipal authority or outlying possession of the United States bearing an official seal U.S. Citizen ID Card (Form I-197) ID Card for use of Resident Citizen in the United States (Form I-179) Unexpired employment authorization document issued by the Department of Homeland Security (DHS) which includes,
a) Form I-94 identifying the holder as an asylee, or b) other documentation issued by DHS or the former Immigration and Naturalization Service that identifies the holder as an asylee, lawful permanent resident, refugee or other status authorized to work in the United States incident to status Foreign Military or Government Identification Credentials Foreign passport with a current arrival-departure record (Form I-94) bearing the same name as the passport and containing an endorsement of the alien's nonimmigrant status, if that status authorizes the alien to work for the employer In the case of a nonimmigrant alien authorized to work for a specific employer incident to status, a foreign passport with Form I-94 or Form I-94A bearing the same name as the passport and containing an endorsement of the alien's nonimmigrant status, as long as the endorsement has not yet expired and the proposed employment is not in conflict with any restrictions or limitations identified on the form.
The contractor shall not be entitled to any compensation for delays or expenses associated with complying with the provision of this clause. Furthermore, nothing in this clause shall excuse the contractor from proceeding with the contract as required.
3. The REAL ID Act of 2005 established minimum standards for the production and issuance of state-issued driver's licenses and ID cards which include requirements for a photograph and certain biographic information, such as name, date of birth, gender, height, eye color, & address. State-issued driver's licenses and ID cards from states not meeting the standards can no longer be used for accessing Federal facilities including Air Force installations unless the issuing state's compliance deadline has been extended by the Department of Homeland Security (DHS).
State compliance with the REAL ID Act can be found at: https://www.dhs.gov/current-status-states-territories.
Contractors with a CA driver licenses and ID cards without any markings in the upper left hand corner are sufficient for identity proofing without supplemental sources until 1 Oct 20.
Contractors with a CA driver licenses and ID cards with a gold bear in the upper left corner and are considered sufficient for identity proofing without supplemental sources indefinitely.
Contractors with a CA driver licenses and ID cards with "Federal Limits Apply" in the upper left corner is not considered sufficient for identity proofing without supplemental sources. Supplemented sources as specified in para. 2.
Contractors from states which are in compliance, or has an approved extension, may use their state-issued driver's license may be used for identity proofing.
Contractors from states which are not in compliance, must use an alternative identification credential for identity proofing as specified in para. 2.
Contractors from states which are not in compliance and do not have an alternative identification credential must be escorted or denied access.
4. Identity Proofing and Vetting. Contractors will be identity proofed and vetted each time a pass is issued. Security Forces may conduct random screenings at any time. If disqualifying base access information is found contractors may be denied base access or have passes currently issued revoked.
Following are the base access disqualifiers:
The individual is known to be or reasonably suspected of being a terrorist or belongs to an organization with known terrorism links/support.
The installation is unable to verify the individual's claimed identity.
The individual has previously been barred from access to a federal installation or stand-alone facility.
The individual is wanted to Federal, State, or other civil law enforcement authorities, regardless of offense or violation.
The individual has any conviction for espionage, sabotage, treason, terrorism, or murder.
The individual's name appears on any Federal or State agency's watch list, hit list or registration list for criminal behavior or terrorist activity.
The individual has been convicted of a firearms or explosive violation.
The individual has been convicted of sexual assault, armed robbery, rape, child molestation, child pornography or trafficking in humans.
Within the last 10 years, the individual has been convicted of drug possession with intent to sell or drug distribution.
The individual has knowingly and willfully engaged in acts or activities designed to overthrow the U.S. Government by force.
Within the past 10 years, the individual has been convicted of 2 or more felonies, or 2 or more violent misdemeanors, or 1 or more felonies and 1 or more violent misdemeanors.
There is reasonable basis to believe on an individual's extensive and systemic criminal behavior, that issuance of an access credential poses an unacceptable risk to the installation. Extensive criminal behavior is a large amount of police arrests and/ or convictions from age 18 to present. Systemic criminal history is a consistent interval of police arrests and/or convictions from age 18 to present.
Contractors with disqualifying base access information will be issued a denial access letter immediately revoking their base access privileges. Contractors requesting a denial modification must submit a written rebuttal/request within 10 business days of receipt of the denial of access letter to 60 SFS/CC, Attention: 60 SFS/S5R, Bldg. 381, 540 Airlift Drive, Suite C-101, Travis AFB 94535-2451.
5. Primary Contractor Responsibilities. The primary contractor will be responsible for the conduct of all contractors employed or sponsored. Additionally, the primary contractor will:
Coordinate base entry requirements with the 60th Contracting Squadron.
Advise contractors working on the installation they are subject to identity proofing and vetting against an authorized data base for criminal history as specified herein.
Advise contractors base passes are only valid for the purpose, person and vehicle for which it was issued. Use of the base pass for any other purpose or by any other person will result in personnel being denied access and the pass confiscated.
Additionally, contractors which misuse their pass may be subject to debarment actions.
If a pass is lost, notify the Pass and Registration Office immediately.
Provide written notification, within 24 hrs, to the 60th Contracting Squadron of any changes in employee's status. This includes, but is not limited to, the employee being fired or quitting their position with the company.
Retrieve passes from contractors which no longer need installation access. Passes will be turned into the 60th Contracting Squadron upon expiration. If a contractor was terminated for cause, notify the Pass and Registration Office immediately.
6. Obtaining a Base Pass. Provide an EAL (Entry Authority List) of all contractors on company letterhead which require a base pass. All requests for a base pass will be submitted through the Base Contracting Office NLT 45 days prior to the contract start date. Exceptions will be made for short-notice contracts where the award date and performance start date are less than 45 days. A base pass will be issued for the length of the contract, not to exceed one year. Prior to renewing a base pass, return the old base pass to the Pass and Registration Office for destruction. Ensure the EAL includes:
Contract number Work site or location Inclusive dates of the contract Work schedule (include days of the week and time periods contractors are on base) Employee's full name, date of birth, and social security number
7. Contractor Responsibilities. All contractors requiring reoccurring and unescorted access onto the installation must:
Have within their possession the identification used to obtain a pass and the pass issued.
Register privately owned vehicles in accordance with installation policies.
On request, present identification or installation pass to base police. Refusal may result in denial of installation access.
Turn in passes to the 60th Contracting Squadron when expired or no longer required. If a contractor was terminated for cause, notify the Pass and Registration Office immediately.
8. Increased Force Protection Condition (FPCON). During FPCON Normal, Alpha and Bravo; contractors without a base issued pass must be sponsored onto the installation. During FPCON Charlie and Delta the base will curtail non-essential operations/functions and non-essential contractors will be suspended at the direction of the installation commander. All contractors attempting installation access; thereafter, will be physically escorted unless FPCON Mission-Essential designation has been approved in advance and is indicated on the base pass.
9. Restricted Area Badges (RAB). Contractors may be submitted for unescorted entry into restricted areas if required for their contract. The security manager of the agency responsible for the project will assist, as appropriate.
10. Escort Requirements. The following escort requirements apply:
While on the installation, sub-contractors must be escorted at all times.
While within Restricted or Controlled Areas contractors not in possession of a restricted area badge will be escorted at all times. Escorts can be either the military agency responsible for the project or contractor in possession of a restricted area badge.
11. Lost Base Passes or Restricted Area Badges.
The Primary Contractor will investigate and provide written notification to the 60th Contracting Squadron anytime a base pass is lost. Notification should include an explanation from the employee on how, when, where and what steps have been taken to locate the missing pass. If a replacement is needed, forward the notification with the request for a base pass.
The Primary Contractor must immediately report the loss of RAB to the security manager of the military agency that submitted the RAB request. The individual who lost the RAB will provide a written explanation on how, when, where and what steps have been taken to locate the missing RAB. The security manager will conduct their own inquiry and forward a report of investigation [with squadron commander endorsement]; the member's written explanation and the original AF Fm 2586 to the Pass and Registration office. A new RAB will not be issued until the investigation is complete.
12. Information Protection Security Training. IAW DoDM 5200.01, Volume 3, Enclosure 5 and AFI 16-1404, para 2.8.3, Security Managers ensure initial orientation and refresher training is conducted for all personnel. This includes specialized security training. The security manager is required to track and document the completed training. The contractor will be required to participate in the government's in-house and web-based security training program under the terms of the contract.
The government will provide the contractor with access to the on-line system after appropriate vetting qualifications have been met.
13. Controlled Unclassified Information. Agency information marked "For Official Use Only" or bearing other sensitivity marking will be handled in accordance with agency information security program regulations and instructions. This information will not be divulged or disclosed without agency permission. Contractor personnel will ensure information that is considered sensitive or proprietary is not compromised.
14. Visitor Group Security Agreement (VGSA). IAW AFI 16-1406, Chapter 4. At the request of the Installation Commander (IC) the contracting officer reserves the right to execute a VGSA agreement with all contractor operations located on Travis
AFB that require access to classified information. Furthermore, at the discretion of the IC the VGSA execution requirement may be extended to contractors performing on contracts that require access to sensitive unclassified information, sensitive resources or frequent "entry" to the installation.
15. Antiterrorism Force Protection Training. IAW AFI 10-245 and Force Protection Plan 31-1, all employees with contracts over 90 days, will complete initial Level I Antiterrorism Awareness training at https://jkodirect.jten.mil/Atlas2/page/login/ Login.jsf.
To ensure security measures, at a minimum, shall address elements such as contractor screening, access control, favorable fingerprint or National Crime Information Center (NCIC) results, circulation control special security concerns, and training.
Thereafter, Level I Antiterrorism Awareness training will be completed annually. All personnel will be responsible to provide proof (copy of training certificates) of training to the Antiterrorism Representative (ATRs) responsible for the unit they are contracted.
16. Operations Security (OPSEC). IAW AFI 10-701, 60 AMW will consider OPSEC for all contractual requirements and determine if any contract contains any form of critical and/or sensitive information or activities. These requirements will be defined on the contract and SOW/PWS. If OPSEC requirements exist, the organization's OPSEC Coordinator or the 60 AMW OPSEC Program Manager will be contacted to review the SOW/PWS. This review may result in possible training requirements, in addition to what is stated below. For unclassified contracts, the DD Form 254, Department of Defense Contract Security Classification Specification, can be used to specify OPSEC requirements in lieu of defining these requirements on the contract and SOW/PWS. For classified contracts, the DD Form 254 is mandatory. Additionally, the 60 AMW OPSEC Program Manager or functional Unit OPSEC Coordinator will provide OPSEC training or training materials to contract employees within 90 days of employees' initial assignment to the contract. (AFI 10-701, 5.2.4). The Installation (60 AMW) OPSEC Program Manager can be contacted at 424-4355 or 3261.
Business Associate Agreement This Business Associate Agreement (this "Agreement") is entered into this ___ day of ________, _____ (the "Effective Date") between DGMC and [NAME OF BUSINESS ASSOCIATE], a [type of business entity] ("Business Associate").
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, "DoD Health Information Privacy Regulation," January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the "HITECH Act" amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term "business associate" in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term "covered entity" in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS).
These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S.
Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the "HITECH Act" provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity's obligations under 45 CFR
164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule "minimum necessary" standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate's own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity's health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate's use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate's use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines "breach" to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate's discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate's Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/.
Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http:// www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that "single event" breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions
(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
(ii) The Business Associate's proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate's notification to the individuals, at a minimum, shall include the following:
(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC's Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY:
1-866-653-4261.
(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and
(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address
(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.
(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., "Important information - do not destroy," and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.
(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .