Atch_2 _PWS.docx
DOCX document 75 KB Posted
- Attached to
- Medical Staff Credentialing Specialist Federal contract opportunity
- Solicitation number
- FA5613-16-Q-0001
About this file
Attachment 2 Performance Work Statement (PWS) Fa5613-16-Q-0001
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_01.docx | DOCX document | |
| Amd_01 _Exchange_Page_Atch_3.docx | DOCX document | |
| Atch_4 _PPQ.doc | DOC document | |
| Atch_5 _EMS_Flyer.pdf | ||
| Atch_1 _Pricing_Schedule.docx | DOCX document | |
| Atch_3 _Applicable_Clauses_ _Provisions.doc | DOC document | |
| Combined_Synopsis-Solicitation.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 2, PWS Solicitation FA5613-16-Q-0001
PERFORMANCE WORK STATEMENT
FOR
Chief of Medical Staff Support
Medical Staff Credentialing Specialist at the 86TH MEDICAL GROUP
21 Jun 2016
Table of Contents
SECTION Page Number
| 1.0. | DESCRIPTION OF SERVICES | 3 | |
| 2.0. | SPECIFIC REQUIREMENTS | 3 | |
| 3.0. | SERVICES SUMMARY | 5 | |
| 4.0. | GENERAL INFORMATION | 6 | |
| 5.0. | APPENDICES | 12 |
5.1. APPLICABLE PUBLICATIONS AND FORMS 12
5.2. CONTRACTOR LABOR HOUR REPORTING 13
5.3. BUSINESS ASSOCIATE AGREEMENT 13
6.0. HISTORICAL WORKLOAD DATA 22
PERFORMANCE WORK STATEMENT
1.0. DESCRIPTION OF SERVICES/GENERAL INFORMATION:
1.1. DESCRIPTION OF SERVICES. The contractor shall provide non-personal services in support of 86th Medical Group’s Chief of Medical Staff. The contractor shall provide all management, supervision, and personnel to obtain required credentialing for the Medical Treatment Facility (MTF) professional staff. Contractor personnel shall support the Chief of Medical Staff of the 86th Medical Group (MDG), service daily operations functions of Credentialing program. Performance shall be according to the requirements contained in this Performance Work Statement (PWS), and professional standards of the Joint Commission on Accreditation of Healthcare Organization (JCAHO), Accreditation Association for Ambulatory Health Care (AAAHC), Unit Effectiveness Inspection (UEI), and Health Insurance Portability & Accountability Act (HIPAA).
1.2. Requested services are considered non-mission essential as defined by DoDI 1100.22.
1.3. BACKGROUND INFORMATION. The Credentials Specialist ensures the Medical Group Credentials Program meets all regulatory standards and reports program status, changes and shortfalls to the Chief of the Medical Staff (SGH) and acts as a consultant to the respective Credentialing Authority and the Medical Group Commander in accordance with this Performance Work Statement (PWS).
2.0. SPECIFIC REQUIREMENTS.
2.1. SPECIFIC TASKS: The contractor personnel shall process credentialing and recredentialing applications of health care providers; review applications, prepare verification letters and maintain Centralized Credentials Quality Assurance System (CCQAS) database for the 86 MDG. The contractor personnel shall contact medical office staff, licensing agencies, and insurance carriers to complete credentialing and recredentialing applications. Contractor personnel are required to ensure compliance with regulatory requirements.
2.1.1. Establishes, manages, administers and maintains the database for the CCQAS, as DoD standardized information system designed to assist in the collection, tracking and reporting of the required data by military Credentialing Office on Health Practitioners within their facilities and the Composite Health Care System (CHCS) and /or Armed Forces Health Longitudinal Technology Application (ALTHA). Provides timely and accurate CCQAS processing (within 2 weeks when all documentation is received)
2.1.2. Develops, coordinates, implements and manages an effective healthcare provider’s credential program to meet JCAHO, AAAHC, and Air Force standards. Analyzes and evaluates the effectiveness of the credentials program to improve mission efficiency, effectiveness and productivity in meeting establish goals and objectives.
2.1.3. Provides drafts of and revisions to local directives, goals and objectives pertaining to the credentials program. Recommendations are used by SGH for developing new or improving existing local directives, goals and objectives.
2.1.4. Analyzes, validates and primary source verifies professional medical education and training of providers requesting delineated medical privileges for appropriateness, continuity and authenticity to ensure complete compliance with all credentialing policies established by higher authorities to include: Department of Health Affairs (HA), Defense Health Agency (DHA), JCAHO, AAAHC, Air Force Medical Operations Agency (AFMOA), USAF, or the DoD.
2.1.5. Primary Source verifies and reviews for applicability pertinent education, training, licensure, etc., of all perspective consultant Veterans Administration and civilian contract employees to ensure compliance with established guidelines prior to employment at the MTF.
2.1.6. Investigates, analyzes and authenticates all background information used in establishing a provider’s bonafide medical experience prior to recommending privileging at the medical treatment facility.
2.1.7. Functions as the POC/liaison to the Chief of the Medical Staff, base Judge Advocate JA and HQ USAFE regarding adverse action processes for credentialed and privileged healthcare professionals. Serves as the specialty advisor to the 86th Medical Group Commander, Deputy and Chief of the Medical Staff for credentialing problems untoward issues related to the privileging and credentialing program.
2.1.8. Provides, with the assistance of the MTF Risk Manager, oversight and tracking of the PEER REVIEW process for privileged providers.
2.1.9. Assists in the validation of licensure for special pays for privileged providers.
2.1.10. Sets the agenda, compiles slides/meeting minutes for the Credentials Committee, which is chaired by the Chief of the Medical Staff as required per regulation. Also coordinates/organizes ad hoc credentials meetings as needed in cases of quality of care, standard of care or adverse actions involving privileged providers.
2.2. PERFORMANCE QUALIFICATION. Contractor personnel shall meet the following minimum qualifications:
2.2.1. LANGUAGE REQUIREMENT. Contractor personnel shall be able to type with a minimum of 40 words per minute and have the ability to read, speak and write English. The language should be spoken with sufficient structural accuracy and vocabulary pronunciation effective in most formal and informal conversations on practical and professional topics. The 86 MDG requires contractor personnel to meet minimum English language proficiency levels of four (4), as proficiency levels outline in NATO Bureau for International Language Coordination (BILC) Standardization Agreement (STANGAG) 6001 Edition 4 dated 12 October 2010. The work is primarily sedentary. However, there may be some physical demands. Requirements include reading, speaking, prolonged walking, and standing, sitting or bending.
Reading Ability Level 4: Able to read all styles and forms of the language pertinent to professional needs. With occasional use of a dictionary, can read all material in his/her special field, including official and professional documents and correspondence. Can read reasonably legible handwriting without difficulty.
Speaking Ability Level 4: Able to use the language fluently and accurately on all levels normally pertinent to professional needs. Can understand and participate in any conversation within the range of his/her experience with a high degree of fluency and precision of vocabulary. Would rarely be taken for a native speaker but can respond appropriately even in unfamiliar situations. Errors of pronunciation and grammar are quite rare. Can handle formal interpreting from and into the language.
Writing Ability Level 4: Can draft all levels of prose pertinent to professional needs. Control of structure, vocabulary and spelling is board and precise. Sense of style is nearly native. Errors are rare and do not interfere with understanding. Nevertheless, drafts of official correspondence and documents need to be edited.
2.2.2. EDUCATION REQUIREMENT/SKILLS. High school diploma or General Educational Development (GED) equivalency. Training/certification in credentialing per AFMOA guidance and standards. Knowledge of medical terminology is desired. Contractor personnel performing this duty shall be able to perform computer operations to include, as a minimum, Microsoft Windows, Microsoft Office Word/Excel/PowerPoint/Outlook and spread sheet type applications, be knowledgeable in general medical ethics, telephone etiquette, office management methods, excellent communications and customer service skills, and have a strong organizational background.
2.3. UNIQUE MILITARY HEALTH CARE SYSTEMS/PROCEDURES. The contractor personnel has up to 30 Days after performance start date to complete Government provided training outlined in para 4.16.1 through 5 and become familiar with required health care systems. Contractor employees who fail to demonstrate the required proficiency may request one repeat demonstration of computer proficiency to the Medical Group Information Management Flight within 30 calendar days. Failure to satisfy proficiency requirements shall have the effect of the position being considered vacant and the contractor will be required to have a replacement within twenty duty days of the repeat demonstration failure.
2.3.1. Armed Forces Health Longitudinal Technology Application (AHLTA): DoD’s (Department of Defense) worldwide-automated medical information system that interfaces with 40+ external clinical and administrative systems
2.3.2. Composite Health Care Systems (CHCS): MTF’s appointment scheduling program, pharmacy, lab, and radiology ordering system and is interlinked with other departments in the MTF. In addition, it contains the electronic medical records for MHS beneficiaries and the Electronic Documentation System, which is a local MTF standardized method of filing electronic medical records.
3.0. SERVICES SUMMARY.
| ITEM |
| Performance Objective |
| PWS Para |
| Performance Threshold |
| SS# 01 |
| Provides timely and accurate CCQAS processing (within 2 weeks when all documentation is received) |
| 2.1.1 |
2.1.6 1 deficiency per month
| SS# 02 |
| Manages effective credentials program |
| 2.1.2 |
| 1 deficiency annually |
| SS# 03 |
| Oversees/administers PEER REVIEW process |
| 2.1.8 |
| 0 deficiencies passed 90 calendar days after performance start |
| SS# 04 |
| Arranges/organizes Credentials Committee Meetings required in cases involving quality and standard of care, or adverse actions of privileged providers. |
| 2.1.10 |
| 0 deficiencies |
3.1. QUALITY CONTROL:
3.1.1. The contractor shall have a planned and systematic quality control process for monitoring, analyzing and improving their contract performance.
3.1.2. The contractor shall ensure that all contractor employees comply with the MTF quality management/process improvement activities.
3.1.3. The contractor shall implement a method of identifying deficiencies in the quality of service before the level of performance deteriorates to an unacceptable level. This method must also measure compliance with regulations referenced in the contract. Reviews shall be accomplished and recorded. Review results shall be made available to the Service Contract Manager (SCM) upon Government request
3.2. QUALITY ASSURANCE: The inspection and acceptance point for all services rendered under this contract will be the Functional Requirements Evaluator Designee (FRED). The performance by the contractor employee, the quality of services rendered, and any documentation or written material in support of same, will be subject to continuous inspection, surveillance and review for acceptance by the CO, SCM or FRED. Quality assurance procedures established by the MTF will be used for continuous monitoring. Deficiencies will be documented on a Customer Complaint Form and sent to the CO.
4.0. GENERAL INFORMATION:
4.1. PERSONNEL:
4.1.1. The Contractor shall designate to the Contracting Officer (CO), in writing, a primary point-of-contact for contract implementation, coordination and administration not later than ten workdays after receiving notice of contract award. The Contractor shall notify the CO of changes in the primary point-of-contact at least five workdays prior to any change. All notifications shall be in writing and shall state the name and contact information for the point-of-contact. The Contractor Representative may reside/be located outside of Germany (i.e. in the United States), but shall be available by telephone or email from 0700 to 1600 Central European Time.
4.1.2. Contract personnel shall present a neat appearance commensurate with that required of a professional.
4.1.3. Neither uniformed personnel nor U.S. Government civilian employees shall be employed to perform services under this contract.
4.1.4. Services are non-credentialed/privileged. Services are not approvable under NATO SOFA status accreditation under Article 72 or 73. Therefore, services are subject to German income tax.
4.2. REGULATIONS. The Contractor shall abide by all Medical Treatment Facility (MTF) standards, rules, and procedures including requirements for any licensure, credentialing, and quality assurance requirements. Such regulations include, but are not limited to, general safety, fire prevention, waste disposal, infection control, AAAHC, JCAHO, UEI, HIPAA, and patient safety initiatives.
4.3. REMOVAL OF CONTRACTOR PERSONNEL. At any time during the performance of this contract, the CO or SCM may direct the Contractor to immediately remove any Contractor personnel whose actions or impaired state raises reasonable suspicion that clear and present danger of physical harm exists to a patient, other Contractor personnel, and government personnel or to the impaired individual. This provision will be used in emergencies only and not for bringing performance issues or other non-urgent concerns to the attention of the Contractor. If the need for a removal occurs, the COR will contact the Contractor's point-of-contact and direct the Contractor to remove that individual from the MTF and to not use that individual to perform any services required under this contract until the issue has been resolved by the CO. The CO will make a review of the basis for removal within three (3) working days after the SCM directed the removal. If, after any investigation deemed necessary by the CO and discussions with the Contractor's representative, the CO concludes that the Contractor personnel’s impairment requires permanent removal from performance under the contract, the CO will notify the Contractor that permanent removal is required. In the event of disagreements between the Government and the Contractor's representative concerning matters of the impaired Contractor personnel, the decision of the CO will be final. During the period of time between the removal and the final decision of the CO, the Contractor shall provide back-up/replacement Contractor personnel IAW the terms and conditions of this contract.
4.4. CONFIDENTIALITY OF INFORMATION. Unless otherwise specified under this contract, all financial, statistical, personnel, and/or technical data which is furnished, produced or otherwise available to the Contractor during the performance of this contract are considered confidential business information and shall not be used for purposes other than performance of work under this contract. The Contractor shall not release any of the above information without prior written consent of the CO.
4.5. MEDIA AND OTHER INQUIRIES. The Contractor or Contractor personnel shall not respond to any media inquiries. Any inquiries from the media, third parties, or public agencies shall be immediately relayed to the COR, who will relay them to the MTF Public Affairs Officer or, after duty hours, to the Administrative Officer of the Day. There shall be no interviews, comments, or any other response without the prior knowledge and approval of the MTF Commander. Other than routine inquiries from external agencies, all other inquiries and complaints shall be brought to the attention of the COR.
4.6. EMERGENCY HEALTHCARE FOR CONTRACTOR PERSONNEL. The MTF will provide emergency health care for injuries or life threatening medical emergencies occurring while on duty. The Contractor shall reimburse the U.S. Government for such services as billed by the MTF.
4.6.1. OVERSEAS EMERGENCY MEDICAL SERVICES. In emergencies, transportation in U.S. Government ambulances may be furnished by the U.S. Government on a reimbursable basis. Contractor employees may receive emergency first aid and medical treatment subsequent to employment related accidents, or injuries under the provisions of AFI 41-210 (See paragraph 5.0 – Appendices). These services will be chargeable to the contractor.
4.7. Contract personnel shall not introduce new procedures or services without prior approval of the Department Chief or representative. If disagreements or deviations from protocols or procedures occur, the Department Chief or representative shall be the deciding authority.
4.8. All contractor employees shall give the highest regard to patient dignity and observe the precepts of the American Hospital Association’s “Bill of Rights for Contractor patients”. Performance shall be in accordance with the standards contained in this PWS and the terms and conditions of the contract. The contractor employees shall abide by MTF rules, regulations, and bylaws, including Medical Staff Bylaws and applicable Air Force regulations and Health Insurance Portability & Accountability Act (HIPAA) governing such things as medical records, etc. (See paragraph 5.3. Business Associate Agreement).
4.9. OVERSEAS REQUIREMENTS (if applicable). The Contractor is responsible for ensuring all country clearances, passports, visas, and accreditations required by the Host Nation are obtained prior to employment of individuals under this contract. The Contractor shall be responsible for obtaining the appropriate country specific requirements, and shall coordinate this with the CO or SCM. All Contractor personnel shall have been cleared, granted visas, etc. The Contractor shall provide written notification to the CO and the SCM within 24 hours of becoming aware of Contract personnel no longer performing duties requiring clearances/permissions. The Contractor shall recognize that Host Nation authorities may conduct on-site inspections at any time in the Contractor personnel’s work area for verifying the status of positions and Contractor personnel and appropriate visas or permissions. The Contractor shall assume all costs related to submission of required documentation.
The contractor shall comply with all business registration requirements in Germany.
4.10. CONTRACTOR PERSONNEL HEALTH REQUIREMENTS. Contractor personnel shall be up to date on immunizations required or recommended by the U.S. Department of Health and Human Services for travel to the Host Nation. The U.S. Government will not reimburse the Contractor for this expense. Contractor personnel providing services under this contract shall receive a pre-employment physical examination prior to commencement of work and annually thereafter. No later than seven (7) working days prior to commencement of work, certification shall be provided to the SCM that Contractor personnel have completed medical evaluation required above. This certification shall state the date on which the examination was completed, the doctor’s name that performed the examination, and a statement concerning the physical health of the individual. The certification shall also contain the following statement: “(name of contractor employee) is suffering from no contagious diseases to include but not limited to Tuberculosis and Hepatitis.” Per Occupational Safety & Health Administration (OSHA) requirements, all Contractor personnel who will have occupational exposure to blood or body fluids, or other potentially infectious materials, shall receive Hepatitis B vaccine, sign a voluntary declination, or have documented proof of immunity to Hepatitis B infection. Personnel who sign declinations may change their minds at any time and receive the Hepatitis B vaccine without penalty. It is the Contractor’s responsibility to report all information necessary to assure hospital records can be maintained correctly, and therefore comply with the OSHA and CDC health records requirement
4.11. ADMINISTRATIVE CHECKS AND REQUIREMENTS:
4.11.1. SECURITY REQUIREMENTS: Since contract personnel under this contract will have access to critical government information and/or process information requiring protection under the Privacy Act of 1974, these positions are considered Public Trust Positions. Compliance with DoD Directive 5200.2-R, AFI 31-501, AFMAN 33-202 and Homeland Security Presidential Directive 12 (HSPD-12) is mandatory for these positions. A background investigation consisting of a National Agency Check with Inquiries (NACI) is required for all contract personnel under this contract. The Contractor shall fully adhere with the provisions of referenced publications by having each of their employees who are performing under this contract initiate and complete a NACI. Background investigation requests for employee will be submitted through the Personnel Security Office, Ramstein AB, Germany. Member will be fingerprinted and required to complete the appropriate forms (Standard Form 85, Questionnaire for Non-Sensitive Positions and OF 306, Declaration for Federal Employment). The contractor shall advise employee that a favorable suitability determination is required as a condition of employment under this specific contract. The employee shall apply for the NACI prior to start of performance. The government is solely responsible for the cost associated with the initiation, application and completion of the background investigation with exceptions for expenses incurred for Police Checks for “local hire” personnel.
4.11.2. PENDING COMPLETION OF NACI. The Contractor personnel may provide contract services prior to completion of background investigation. The Contractor understands that the MTF Commander may allow the Contractor personnel to temporarily occupy sensitive positions pending NACI. The Contractor personnel will be immediately removed from the position if at any time the NACI receives unfavorable adjudication, or if other unfavorable information that would affect the NACI becomes known.
4.12. PLACE AND HOURS OF OPERATION. Services are to be performed at the 86th Medical Group, Ramstein Air Base, Germany during the following hours from 0730 to 1630 hours: Monday through Friday, including German holidays but excluding U.S. Federal holidays. Contractor personnel shall be physically present during these days and hours. The number of days of nonperformance shall be deducted from the monthly invoice accordingly.
4.13. HOLIDAYS. The following is a list of legal federal holidays. Any federal holiday falling on a Saturday will be observed on the preceding Friday, holidays falling on a Sunday will be observed the following Monday.
U.S. Holidays:
| January 1 | New Year’s Day | |||
| 3rd Monday in January | Martin Luther King, Jr. Day | |||
| 3rd Monday in February | Washington’s Birthday | |||
| Last Monday in May | Memorial Day | |||
| July 4 | Independence Day | |||
| 1st Monday in September | Labor Day | |||
| 2nd Monday in October | Columbus Day | |||
| November 11 | Veterans Day | |||
| 4th Thursday in November | Thanksgiving Day | |||
| December 25 | Christmas Day |
4.14. USAFE FAMILY DAYS. For the base and each option period of this contract, there are five USAFE Family Days scheduled that the MTF will be closed and the Contractor will not be able to provide services. Therefore, the Contractor shall advise their personnel accordingly and treat these situations as determined appropriate. The USAFE Family days are scheduled by the USAFE Commander.
4.15. UNPLANNED CLOSURES. In the event of unplanned closure of the MTF due to natural disaster, military emergency, severe weather, security threat, or a facility-related problem that prevents contractor personnel from performing services under this contract, these contractor personnel shall follow the same departure and reporting directions given to Government personnel and the contractor shall treat its personnel as they determine appropriate.
4.16. CONTRACTOR ORIENTATION AND NEW PERSONNEL REQUIREMENTS:
4.16.1. GENERAL TRAINING. Contractor personnel shall abide by all MTF standards, rules, and procedures including quality assurance requirements. Such regulations include, but are not limited to, general safety, fire prevention, waste disposal, infection control, AAAHC, JCAHO, UEI, and patient safety initiatives. All Contractor personnel performing services at the MTF are required to complete initial and annual refresher Health Insurance Portability and Accountability Act of 1996 (HIPAA), Anti-terrorism/Force Protection (AT/FP), monthly safety training, and annual training requirements as provided by the MTF for its personnel. The Contractor will be held accountable for ensuring personnel comply with health information privacy and security policies and procedures. The Government will also provide training on Government provided forms and equipment, universal precautions, initial orientation, and continuing orientation. The Government will also train and provide access to Air Force directives, MTF policies and procedures prior to start of contract performance.
4.16.2. ORIENTATION TRAINING. The Contractor shall ensure that all Contractor personnel participate in the government provided MTF orientation program for newly assigned personnel within the first two weeks of performance start. Orientation training will be conducted during normal hours of operation, and will be scheduled by the FRED. Orientation shall include training on regulations specific to clinic and Air Force policy and procedures, instructions on automation processing, quality assurance policies, CHCS, AHLTA, and other information systems, local in-service, and safety briefings as they apply to the position.
4.16.3. GOVERNMENT PROVIDED TRAINING.
| Alcohol and Drug Abuse Prevention and Treatment Program | |
| Annual Block Training | |
| Armed Forces Health Longitudinal Technology Application (AHLTA) | |
| Composite Healthcare Computer System (CHCS) | |
| Cultural Diversity | |
| Defense Medical Human Resources System – Internet (DMHRSi) Training | |
| Infection Control | |
| Health Insurance Portability and Accountability Act (HIPAA) – initial and annual certification | training. (See 5.1 – Applicable Forms and Publications) |
| Military Health Care Computer Systems/Procedures | |
| New Personnel Orientation | |
| On-the-job-training (work center/patient safety, waste disposal, fire prevention etc.) | |
| Personnel Reliability Program Renewals (initial training is the Contractor’s responsibility prior to | contract start) of Basic Life Support (BLS) |
| Total Force Awareness Training – DoD Information Assurance Awareness | |
| Total Force Awareness Training – Information Protection Training |
4.16.4. If a personnel change occurs during the contract performance period, a 4-week overlap for orientation and training and pass over of duties is required without additional charge to the government.
4.16.5. COMPUTER TRAINING. Contractor personnel who interact with the MTF computer systems must receive training for the applicable system(s). The FRED will coordinate the necessary computer training. The training will be on-site and during normal hours of operation. This training will be at no cost to the Contractor. Access to patient data systems is an “Automated Data Processing Sensitive” position requiring compliance with AFI 31-501. The Contractor shall comply with agency personal identity verification procedures that implement Homeland Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201. The Government will train and give access to contractor personnel on the AHLTA and CHCS systems.
4.16.6. CONTRACTOR PROVIDED TRAINING. It is the contractor’s responsibility to ensure their employees are current on Basic Life Support (BLS) prior to start work in the MTF.
4.17. CONFORMANCE WITH ENVIRONMENTAL MANAGEMENT SYSTEMS. The Contractor shall perform work under this contract consistent with the relevant environmental policy and objectives identified in the installation environmental management system (EMS) applicable for your contract. The Contractor shall perform work in a manner that conserves water, energy and other resources to the maximum extent feasible and ensure minimum production of waste as possible, giving preference to recycling and reutilization opportunities. Furthermore, the Contractor shall give preference to less toxic materials whenever available and still reliable for their work. In the event an environmental nonconformance or noncompliance of host nation and USAF environmental laws and regulations associated with the contracted services is identified, the contractor shall take corrective and/or preventative actions. In the case of a noncompliance, the Contractor shall respond and take corrective action immediately. In the case of a nonconformance, the Contractor shall respond and take corrective action based on the time schedule established by the EMS Coordinator. In addition, the Contractor shall ensure that their employees are aware of the environmental management system on base and how these requirements affect their work performed under this contract. All on-site contractor personnel shall receive the installation EMS awareness level information.
4.18. CONFORMANCE WITH ENVIRONMENTAL REQUIREMENTS. The contractor shall perform all work in accordance with applicable German and US Air Force environmental laws, regulations and operating standards, including but not limited to the Final Governing Standards (FGS) for Germany. The contractor shall be immediately capable of understanding and addressing environmental laws and regulations as they pertain to work performed under this contract.
The FGS for Germany and other important environmental laws & requirements applicable for all contractors working on base can be found at the EMS SharePoint Website. Link for the website can be provided upon request.
4.19. CONTRACTOR MANPOWER REPORTING APPLICATION (CMRA). The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the Air Force via a secure data collection site. The contractor is required to completely fill in all required data fields at http://www.ecmra.mil.
Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year. Contractors may direct questions to the CMRA help desk.
Reporting Period: Contractors are required to input data by 31 October of each year.
Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the contractor name and contract number associated with the data.
User Manuals: Data for Air Force service requirements must be input at the Air Force CMRA link. However, user manuals for government personnel and contractors are available at the Army CMRA link at http://www.ecmra.mil.
4.20.. U.S. GOVERNMENTSHARED PROPERTY, INFORMATION AND SERVICES:
4.20.1. Government shared property under this contract will be furnished to Contractor employees at no cost and shall be used only in performance of services under this contract.
4.20.2. The Government will provide the Contractor access to Air Force directives, MTF policies and procedures prior to start of contract performance date.
4.20.3. Facilities: During the hours of performance under this contract, the Contractor employees shall have the use of office space available.
4.20.4. Equipment and Supplies: Available equipment and office supplies for the performance of services under this contract, such as desk, chair, lighting, computer, printer, FAX machine, phone, copier, paper, folders, file cabinets, etc.
4.20.5. Electronic Documentation: As available at the local MTF, a standardized electronic documentation system or electronic medical record will be provided, such as, but not limited to CHCS and AHLTA.
5.0. APPENDICES.
5.1. APPLICABLE PUBLICATIONS AND FORMS. Supplements or amendments to listed publications and/or forms from any organizational level may be issued during the life of this contract. Should any publication or form revision cause a change in the contractor’s processes, procedures and/or standards of operation, the contractor shall advise the CO of such changes in writing within 30 days of receipt of the publication or form revisions.
5.1.1. Publications and forms are available electronically through the internet and are maintained by the Government.
5.1.2. DoD Directives can be found at http://www.dtic.mil/whs/directives/corres/dir.html . Regulations are followed by a “-R” (e.g., DoD 6025.18-R) and can be located on the website by clicking on “Publications” instead of “Directives.”
DEPARTMENT OF DEFENSE (DoD) REGULATIONS/MANUALS
INSTRUCTIONS/DIRECTIVES
| PUB NO. |
| TITLE |
| DoD 5400.11-R |
| Department of Defense Privacy Program |
| DoDD 5200.2-R |
| Personnel Security Program |
| DoDD 5400.11 |
| DoD Privacy Program |
| DoDD 5500.07 |
| Standards of Conduct |
| DoDD 8190.1 |
| DoD Logistics Use of Electronic Data Interchange (EDI) Standards |
| DoDD 8500.01E |
| Information Assurance |
| DoDI 1402.5 |
| Criminal History Background Checks on Individuals in Child Care Services |
| DoDI 3020.41 |
| Contractor Personnel Authorized to Accompany the U.S. Armed Forces |
| DoDI 6025.20 |
| Medical Management (MM) Programs in Direct Care Systems (DCS) & Remote Areas |
| DoDI 6040.42 |
| Medical Encounter and Coding at Military Treatment Facilities |
5.1.3. The Air Force’s E-Publishing site (http://www.e-publishing.af.mil) will be used to obtain Air Force Instructions.
AIR FORCE INSTRUCTIONS/MANUALS
| PUB NO. |
| TITLE |
| AFI 31-501 |
| Personnel Security Program Management |
| AFI 33-332 |
| Privacy Act Program |
| AFI 33-322 |
| Records Management Program |
| AFI 33-364 |
| Records Disposition – Procedures and Responsibilities |
| AFI 33-200 |
| Information Assurance (IA) Management |
| AFI 33-129 |
| Web Management and Internet Use |
| AFI 41-210 |
| TRICARE Operations and Patient Administration |
| AFI 44-119 |
| Medical Quality Operations |
5.1.4. Other References
TITLE
AAAHC Accreditation Association for Ambulatory Healthcare www.aaahc.org
JCAHO Joint Commission on Accreditation of Healthcare Organization (JCAHO)
Public Law 91-596, Occupational Safety and Health Act (OSHA)
Public Law 99-661, Title 10 USC Section 1102, Privacy Act of 1974
5.2. CONTRACTOR LABOR HOUR REPORTING.
Contractor employee is required to report labor hours in DMHRSi. The contractor shall report ALL contractor labor hours (including subcontractor labor hours) bi-weekly in accordance to section NCOIC guidelines through DMHRSi.
5.3. BUSINESS ASSOCIATE AGREEMENT
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE (to be added at time of award)].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean 86TH Medical Group.
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs.. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .