PEBLO_PWS_18_Feb_16.pdf

PDF 354 KB Posted

Attached to
Physical Evaluation Board Liason Officer (PEBLO) Services Federal contract opportunity
Solicitation number
FA5613-16-R-0014
Issued by
Department of the Air Force United States Air Forces in Europe - Air Forces Africa

About this file

Performance Work Statement (PWS)

View the file

Other files for this federal contract opportunity

Other files attached to Physical Evaluation Board Liason Officer (PEBLO) Services, newest first.
File Type Posted
MR_Questionnaire_PEBLO_18Feb16.pdf PDF
Sources_Sought_Notice_PEBLO_18Feb16.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

FOR

PHYSICAL EVALUATION BOARD LIAISON OFFICER

AT THE 86TH MEDICAL GROUP

18 February 2016

TABLE OF CONTENTS

Subject Page

1.0 DESCRIPTION OF SERVICES 3

2.0. SPECIFIC REQUIREMENTS 3

3.0. SERVICE SUMMARY (SS) 4

4.0. GENERAL INFORMATION 4

5.0. APPENDICES 9

6.0. HISTORICAL WORKLOAD DATA 20

1.0 DESCRIPTION OF SERVICES.

1.1 OVERVIEW OF SERVICES. The purpose of this requirement is to provide non-personal services contract for a Physical Evaluation Board Liaison Officer (PEBLO) in support of the 86th Medical Group (MDG)

Medical Evaluation Board (MEB) program. The Contractor shall provide all management, supervision, training, and qualified personnel to perform services in accordance with (IAW) this Performance Work Statement (PWS).

These services are considered to be non-mission essential. Relocation costs, if applicable, shall be included in the price of the service.

2.0 SPECIFIC REQUIREMENTS.

2.1 PHYSICAL EVALUATION BOARD LIAISON OFFICER SERVICES. The contractor shall perform: Counsel of individual military members on their rights and responsibilities when their cases go before medical/physical evaluation boards; provide liaison and administrative support and services for: MEBs and Review in

Lieu of (RILOs) MEBs conducted at the 86th MDG; coordinate patient travel requirements and/or aero medical evacuation, TDRL, fitness for duty determinations, and other program requirements related to the DES; provide FEB findings to service members and medical staff; and serve as the LOD representative responsible for completing, routing, tracking, and counseling members concerning LOD issues. Tasks that shall be performed include the following:

2.1.1 Provide notification of the need to the duty member undergoing the MEBs, plan, and complete necessary

MEB process activities to evaluate an Active Duty member’s fitness for duty.

2.1.2 Obtain, assemble, and forward all documents, and records required for MEB processing within 10 business days to appropriate agency as required. (i.e. scan and send via electronic means into the Clinical Informatics Branch

[CIB] to be reviewed by the Veteran’s Affairs department.)

2.1.3 Respond to inquiries from beneficiaries, Department of Defense (DoD) Components, and any other agencies within 48 hours. Coordinate with appropriate Points of Contacts (POCs) throughout the Military Health System

(MHS), Air Force agencies (i.e. Military Personnel Flight, Comptroller, Transportation, Aero medical Evacuation, etc.) and the Department of Veterans Affairs (i.e. Veteran’s Benefits Administration and Veteran’s Health

Administration ) to provide information or assistance to the member. Inquires/coordination may be made via telephone, email, or walk-in.

2.1.4 Assist the medical professional staff and other staff members on the regulatory and procedural aspects of profiling and disability processing.

2.1.5 Weekly monitor the effectiveness and efficiency of the local MEB, LOD, TDRL, and DES programs. Utilize the existing Patient Administration Self-Inspection Checklist in conjunction with extracted data. (See 5.1–

Applicable Forms and Publications)

2.1.6 Provide counseling to military or their next-of-kin on MEB procedures, findings, and recommendations one business day after notification from Air Force Personnel Center (AFPC).

2.1.7 Provide counseling and explain entitlements, benefits, and responsibilities to all customers one business day after notification from AFPC.

2.1.8 Maintain and apply knowledge, experience, and training to facilitate and address any “fitness for duty” or

“physical disability” evaluation issues, as they arise.

2.1.9 Maintain and apply knowledge of DES processing regulations, instructions, procedures, and policies to assure timely case processing.

2.1.10 Maintain practical knowledge and understanding of TRICARE: contract language, program policies, and reference manuals; regional healthcare issues and initiatives; and other federal health benefits programs.

2.1.11 Utilize the Disability Counseling Guide for PEBLO provided by the Government. (See 5.1–Applicable

Forms and Publications)

2.1.12 Attend annual PEBLO conference (Government funded), date and location to-be-determined.

2.2 EDUCATION AND TRAINING OF CONTRACTOR EMPLOYEE. Contractor employee shall meet the following minimum qualifications:

2.2.1 A high school diploma.

2.2.2 Three years of similar/equivalent work experience in the medical field (i.e. medical office management).

2.2.3 Maintain training and certification as it applies to the PEBLO position as outlined in section 4.15.

3.0 SERVICE SUMMARY (SS).

ITEM PERFORMANCE OBJECTIVE

PWS

SUBTASK(S)

PARA.

REFERENCE

PERFORMANCE

THRESHOLD

SS#

Provide proper notification of the need, plan, and accurately complete necessary MEB process activities to evaluate Active Duty member’s fitness for duty. 2.1.1 100%

SS#

Correctly obtain, assemble, and forward all documents, and records required for MEB processing within the prescribed timeframe. 2.1.2

No more than three validated discrepancies per month

SS#

Thoroughly monitor the effectiveness and efficiency of the local MEB, LOD, TDRL, and DES programs, utilizing the existing Patient Administration Self-

Inspection Checklist in conjunction with extracted data on a weekly basis 2.1.5

No more than three validated discrepancies per month

SS#

Provide timely counseling to military or next-of-kin on MEB procedures, findings, and recommendations after notification from AFPC. 2.1.6

No more than three validated discrepancies per month

SS#

Provide timely counseling and explain entitlements, benefits, and responsibilities to all customers after notification from AFPC. 2.1.7

No more than three validated discrepancies per month

4.0. GENERAL INFORMATION.

4.1 CONTRACTOR REPRESENTATIVE. The Contractor shall designate to the Contracting Officer (CO), in writing, a primary point-of-contact for contract implementation, coordination and administration not later than ten

(10) business days after receiving notice of contract award. The Contractor shall notify the CO of changes in the primary point-of-contact at least ten (10) work days prior to any change. All notifications shall be in writing and shall state the name and contact information for the point-of-contact. The Contractor Representative may reside/be located outside of Germany (i.e. in the United States), but shall be available by telephone or email from 0700 to

1600 Central European Time.

4.2 DOCUMENTATION. The Contractor shall provide the contracting office the required documentation for all support services personnel within ten (10) business days of contract award notification to comply with required performance periods of the contract by taking into consideration that the DoD Contractor Personnel Office

(DOCPER) process requires an average of eight (8) to ten (10) weeks for completion.

4.3 CONFLICT OF INTERESTS. Contractor personnel shall not bill patients for services rendered under this contract. Contractor personnel shall not request or accept compensation of any kind for patients treated, procedures performed, or any other actions performed. Contractor personnel shall not, while performing services under this contract, advise, recommend, or suggest to persons eligible to receive medical care at U.S. Government expense that such persons should receive care from the Contractor at any place other than as designated under this contract.

4.4 CONFIDENTIALITY OF INFORMATION. Unless otherwise specified under this contract, all financial, statistical, personnel, and/or technical data which is furnished, produced or otherwise available to the Contractor during the performance of this contract are considered confidential business information and shall not be used for purposes other than performance of work under this contract. The Contractor shall not release any of the above information without prior written consent of the CO. The Contractor shall not use patient care rendered pursuant to this contract as part of a study, research project, or publication.

4.5 MEDIA AND OTHER INQUIRIES. The Contractor or Contractor personnel shall not respond to any media inquiries. Any inquiries from the media, third parties, or public agencies shall be immediately relayed to the

COR, who will relay them to the Medical Treatment Facility (MTF) Public Affairs Officer or, after duty hours, to the

Administrative Officer of the Day. There shall be no interviews, comments, or any other response without the prior knowledge and approval of the MTF Commander. Other than routine inquiries from external agencies, all other inquiries and complaints shall be brought to the attention of the COR.

4.6 AUTHORIZATION OF CONTRACT PERSONNEL. An individual who has: (1) been hired as a consequence of this contract, (2) is a full-time (40 hours per week or more) contract employee, (3) is employed in a

Host Nation country (4) is a national (citizen) of or an ordinary resident of the United States provided that the contract employee is not also a Host Nation country (local) resident (i.e., a dual citizen), or (5) a U.S. citizen or a citizen of a

North Atlantic Treaty Organization (NATO) country other than the Host Nation and provided that the contract employee is not an ordinary resident of the Host Nation. The representative host country U.S. Government shall make the determination of a contract employee’s status with respect to being an ordinary resident. Authorized Contractor personnel and their authorized dependents will be granted privileges consistent with those granted members of the civilian component of the U.S. Forces.

4.6.1 AUTHORIZATION OF CONTRACT PERSONNEL DEPENDENTS. Authorized dependents shall include the Contractor personnel’s: lawful spouse, unmarried child, stepchild, or a lawfully adopted who will reside in the host country with the Contractor personnel. (Child is defined as: has not passed his/her 21st birthday or, if past, is incapable of self-support because of mental or physical incapability that existed before that birthday and is dependent on the contractor for over one-half of his/her support.) The benefits listed below, if available, are generally extended as noted without special financial consideration due to the U.S. Government. In such cases the U.S. Government does not charge for use of these benefits, and the contract price should not be inflated by the value of these benefits. Should any of the below needed benefits not be available, negotiations will be conducted with the Contractor and consideration determined.

4.7 LOGISTICAL SUPPORT. The U.S. Government will provide individual logistical support for Contractor personnel to the extent available and as authorized by NATO Status of Forces Agreement (SOFA) Supplementary

Agreement Article 72, and foreign regulations; by current applicable international agreements, arrangements, policies;

and the local Installation Commander. The duration of the initial individual logistic support authorization may be subject to a time limitation. Prior to expiration of the initial logistical support authorization (if and as applicable), the

COR and Contractor shall expedite/process the individual Renewal/Authorization in sufficient advance to ensure continuation of logistical support. Logistical support is provided only for those Contractor personnel that are providing services solely for U.S. Forces. Logistical support, if granted, will only be provided to authorized, full-time

(40 hours per week) Contractor and authorized dependents as defined in paragraphs 4.6 and 4.6.1. The following logistical support will be provided to applicable Contractor personnel:

1) Commissary

2) Army Air Force Exchange Service

3) Armed Forces Recreation Facilities

4) Military dining facilities

5) Class VI (alcoholic beverages, including rationed items)

6) Legal assistance (on a ‘space available’ basis)

7) Military Banking facilities

8) Military postal services

9) Officer and NCO Club memberships

10) Mortuary services

11) Privately Owned Vehicle (POV) authorization

12) Petroleum, Oils, and Lubricants (POL) purchases

13) Transient billets on space available basis

14) Army Continuing Education Courses

(15) Credit union facilities

(16) Dependent Schools, on space available, tuition paying basis

(17) Medical/Dental on a reimbursable basis. Dental on emergency basis only

(18) Pet and firearm registration and control

(19) NATO SOFA stamp (subject to approval of Host nation Customs Authority)

(20) Customs exemptions

4.8 EMERGENCY HEALTHCARE FOR CONTRACTOR PERSONNEL. The MTF will provide emergency health care for injuries or life threatening medical emergencies occurring while on duty under the provisions of Air Force Instruction (AFI) 41-114. (See 5.1–Applicable Forms and Publications). In emergencies, transportation in U.S. Government ambulances may be furnished by the U.S. Government on a reimbursable basis.

The Contractor shall reimburse the U.S. Government for such services as billed by the MTF.

4.9 OVERSEAS REQUIREMENTS. The Contractor is responsible for ensuring all country clearances, passports, visas, and accreditations required by the Host Nation are obtained prior to employment of individuals under this contract. Documentation requirements are subject to change as SOFAs change. In the event a proposed

Contractor employee is denied Host Nation approval, accreditation, and/or permission, the prospective awardee shall submit like documentation for another nominee. The Contractor will be responsible for obtaining the appropriate country specific requirements, and will coordinate this with the CO or COR. The Contractor shall provide written notification to the CO and the COR within 24 hours of becoming aware of accredited Contract personnel no longer performing duties requiring accreditation/clearances/permissions. The Contractor shall recognize that Host Nation authorities may conduct on-site inspections at any time in the Contractor personnel’s work area for the purpose of verifying the status of positions and Contractor personnel and appropriate visas or permissions. The Contractor shall assume all costs related to submission of required documentation. At the time of preparation of this contract, applicable information and forms for placement of Contractor personnel in Germany may be accessed at the DOCPER and U.S. Department of State websites. (See 5.1–Applicable Forms and Publications)

4.10 CONTRACTOR PERSONNEL HEALTH REQUIREMENTS. Contractor personnel and dependents shall be up to date on immunizations required or recommended by the U.S. Department of Health and Human Services for travel to the Host Nation. (See 5.1–Applicable Forms and Publications) The U.S. Government will not reimburse the Contractor for this expense. Contractor personnel providing services under this contract shall receive a pre-employment physical examination prior to commencement of work and annually thereafter. Certification shall be provided to the COR that Contractor personnel have completed medical evaluation required no later than seven (7) business days prior to commencement of work . This certification shall state the date on which the examination was completed, the doctor’s name that performed the examination, and a statement concerning the physical health of the individual. The certification shall also contain the following statement: “(name of contractor employee) is suffering from no contagious diseases to include but not limited to Tuberculosis and Hepatitis.” Per Occupational Safety Health

Administration (OSHA) requirements, all Contractor personnel who will have occupational exposure to blood or body fluids, or other potentially infectious materials, shall receive Hepatitis B vaccine, sign a voluntary declination, or have documented proof of immunity to Hepatitis B infection. (See 5.1–Applicable Forms and Publications) Personnel who sign declinations may change their minds at anytime and receive the Hepatitis B vaccine without penalty. It is the

Contractor’s responsibility to report all information necessary to assure hospital records can be maintained correctly, and therefore comply with the OSHA and Center for Disease Control (CDC) health records requirement. (See 5.1–

Applicable Forms and Publications)

4.11 ABUSE OF PRIVILEGES. The U.S. Government retains the right to withdraw privileges as a result of

Contractor or Contractor personnel’s abuse of privileges at no additional cost to the U.S. Government. The Contractor shall ensure that, upon termination or transfer of any Contractor personnel who is granted privileges identified above, action is taken simultaneously with termination of employment to ensure that said Contractor personnel ceases to have access to the above privileges. The Contractor shall ensure that identification passes or other documents pertinent to and/or peculiar to the contract or privileges hereunder are turned over to the issuing office upon termination or transfer of any Contractor personnel. The Contractor shall require a written receipt of such return and shall immediately forward a copy to the CO.

4.12 ADMINISTRATIVE CHECKS AND REQUIREMENTS.

4.12.1 NATIONAL AGENCY CHECK WITH INQUIRIES (NACI). Since personnel under this contract will have access to critical government information and/or process information requiring protection under the Privacy Act of 1974, these positions are considered Public Trust Positions. Compliance with DoD Directive

5200.2-R, AFI 31-501and Homeland Security Presidential Directive 12 (HSPD-12) is mandatory for these positions.

(See 5.1–Applicable Forms and Publications) A back-ground investigation consisting of a National Agency Check with Inquiries (NACI) is required for all personnel under this contract. The Contractor shall fully adhere with the provisions of referenced publications by having each of their employees who are performing under this contract initiate and complete a NACI. Background investigation requests for employee will be submitted through the

Personnel Security Office, Ramstein AB, Germany. Member will be fingerprinted and required to complete the appropriate forms (Standard Form 85P, Questionnaire for Public Trust Positions and OF 306, Declaration for

Federal Employment). (See 5.1–Applicable Forms and Publications). The contractor shall advise employee that a favorable suitability determination is required as a condition of employment under this specific contract. The employee shall apply for the NACI prior to start of performance. The government is solely responsible for the cost associated with the initiation, application and completion of the background investigation with exceptions for expenses incurred for Police Checks for “local hire” personnel.

4.12.2 CRIMINAL HISTORY BACKGROUND CHECK (CHBC). CHBC are required for Contractor personnel involved in the delivery of healthcare to children under the age of 18 on a frequent and regular basis, as stated in Department of Defense Instruction (DoDI) 1402.5, Enclosure 5. (See 5.1–Applicable Forms and

Publications) The Contractor shall ensure that the personnel follow local MTF policy to provide fingerprints on a properly completed Standard Form 87, Fingerprint Card for Federal Employees. (See 5.1–Applicable Forms and

Publications). The procedures for completing the required CHBC are outlined in the DoDI 1402.5.

4.12.3 PENDING COMPLETION OF NACI AND CHCB. The Contractor personnel may provide contract services prior to completion of background investigation. The Contractor understands that the MTF Commander may allow the Contractor personnel to temporarily occupy sensitive positions pending NACI. The Contractor personnel will be immediately removed from the position if at any time the NACI receives unfavorable adjudication, or if other unfavorable information that would affect the NACI becomes known. Pending completion of CHBC the Air Force

Surgeon General requires close clinical supervision and full compliance with existing DoD Directives, Instructions, and other guidance on quality assurance, risk management, licensure, personnel orientation and certification verification. The MTF Commander will determine what constitutes “close clinical supervision” for individuals whose

NACIs/CHCB are pending, either supervised practice ensuring protection of patients under the age of 18 or line-of-sight supervision (i.e., chaperoned by an individual whose background investigation has been successfully completed) at all times when caring for these patients.

4.13 COMMON ACCESS CARD. Common Access Card (CAC) is a DOD-mandated program affecting military, DOD civilians and eligible Contractors. The Contractor shall comply with the requirements of this program. Visit the website for more information: http://www.cac.mil/.

4.14 HOURS OF OPERATION. The healthcare services are to be performed at the 86 th MDG, Ramstein Air

Force Base, Germany. The 86 th

MDGs normal business hours are 0700-1630 hours Monday through Friday, excluding

U.S. Federal holidays, contractor personnel shall be physically present during the normal business hours

4.14.1 HOLIDAYS. The following is a list of legal federal holidays. Any federal holiday falling on a Saturday will be observed on the preceding Friday, holidays falling on a Sunday will be observed the following Monday.

U.S. Holidays:

January 1 New Year’s Day rd

Monday in January Martin Luther King, Jr. Day rd

Monday in February Washington’s Birthday

Last Monday in May Memorial Day

July 4 Independence Day st Monday in September Labor Day nd

Monday in October Columbus Day

November 11 Veterans Day th

Thursday in November Thanksgiving Day

December 25 Christmas Day

4.14.2 USAFE FAMILY DAYS. For the base period and each option period(s) of this contract, the clinic will be closed on scheduled Family Days and the Contractor will not be able to provide services, and will not be compensated for these days. Therefore, the Contractor shall advise their personnel accordingly and treat these situations as determined appropriate. USAFE Family days are scheduled by the USAFE Commander and are subject to change.

4.15 CONTRACTOR ORIENTATION AND NEW PERSONNEL REQUIREMENTS.

http://www.cac.mil/

4.15.1 GENERAL TRAINING. The Contractor shall be responsible for ensuring personnel comply with health information privacy and security policies and procedures. The Government will provide training on Government provided forms and equipment, Air Force directives, general MTF policies and procedures. Contractor personnel shall participate in continuing education programs to update and/or maintain skills and knowledge to meet annual requirements.

4.15.2 ORIENTATION TRAINING. The Contractor shall ensure that all Contractor personnel participate in the Government provided MTF orientation program for newly assigned personnel within 30 days of performance start.

Orientation training will be conducted during normal hours of operation, and will be scheduled by the COR.

Orientation shall include training on regulations specific to the professional specialty, and hospital and Air Force policy and procedures, instructions on automation processing, quality assurance policies, and other information systems as they apply to the position.

4.15.3 GOVERNMENT PROVIDED TRAINING.

Alcohol and Drug Abuse Prevention and Treatment Program

Annual Block Training

Armed Forces Health Longitudinal Technology Application (AHLTA)

Basic Life Support (BLS) IAW AFI 41-101 – current/continual certification (See 5.1–Applicable Forms and

Publications)

Composite Healthcare Computer System (CHCS)

Cultural Diversity

Infection Control

Health Insurance Portability and Accountability Act (HIPAA) – initial and annual certification training.

(See 5.1–Applicable Forms and Publications)

Military Health Care Computer Systems/Procedures

New Personnel Orientation

On-the-job-training (work center/patient safety, waste disposal, fire prevention etc.)

Personnel Reliability Program

PEBLO Computer Based Training

Total Force Awareness Training – DoD Information Assurance Awareness

Total Force Awareness Training – Information Protection Training

Defense Medical Human Resources System – Internet (DMHRSi) Training

4.15.4. COMPUTER TRAINING. Contractor personnel who have any interaction with the MTF computer systems must receive training for the applicable system(s). The COR will coordinate the necessary computer training.

The training will be on-site and during normal hours of operation. This training will be at no cost to the Contractor.

Access to patient data systems is an “Automated Data Processing Sensitive” position requiring compliance with AFI

31-501. The Contractor shall comply with agency personal identity verification procedures that implement Homeland

Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and

Federal Information Processing Standards Publication (FIPS PUB) Number 201. (See 5.1–Applicable Forms and

Publications).

4.16 COMMANDER’S TOBACCO USE GUIDANCE. The Air Force recognizes equal work breaks

(when these breaks are permitted) for tobacco users and non-tobacco users. The MTF will have a smoke free medical campus with only one authorized smoking area for buildings 2114, 2121 and 2182.

Tobacco use is prohibited in government vehicles, inside buildings and within 50 feet of building‘s direct service entryway. The spitting of such non-smoking tobacco products into cups, cans, or any type of container within the above-restricted areas is prohibited.

4.17 U.S. GOVERNMENT-SHARED PROPERTY, INFORMATION AND SERVICES:

4.17.1. Government property under this contract will be furnished to Contractor employees at no cost and shall be used only in performance of services under this contract.

4.17.2. The Government will provide the Contractor access to Air Force directives, MTF policies and procedures at or prior to start of contract performance date.

4.17.3. Facilities: During the hours of operation under this contract, the Contractor employees shall have the use of office space available.

4.17.4. Equipment and Supplies: Available equipment and office supplies for the performance of services under this contract, such as desk, chair, lighting, computer, printer, FAX machine, phone, copier, paper, folders, file cabinets, etc.

4.17.5. Electronic Documentation: As available at the local MTF, a standardized electronic documentation system or electronic medical record will be provided, such as, but not limited to CHCS and AHLTA.

4.17.6. Forms/Work Files: Unless noted otherwise, all required Air Force and Department of Defense directives, forms and other work files applicable to the MTF MM Program/Services will be furnished by the Government and will be retained by the Government.

4.18. CONFORMANCE WITH ENVIRONMENTAL MANAGEMENT SYSTEMS. The Contractor shall perform work under this contract consistent with the relevant environmental policy and objectives identified in the installation environmental management system (EMS) applicable for your contract. The Contractor shall perform work in a manner that conserves water, energy and other resources to the maximum extent feasible and ensure minimum production of waste as possible, giving preference to recycling and reutilization opportunities.

Furthermore, the Contractor shall give preference to less toxic materials whenever available and still reliable for their work. In the event an environmental nonconformance or noncompliance of host nation and USAF environmental laws and regulations associated with the contracted services is identified, the contractor shall take corrective and/or preventative actions. In the case of a noncompliance, the Contractor shall respond and take corrective action immediately. In the case of a nonconformance, the Contractor shall respond and take corrective action based on the time schedule established by the EMS Coordinator. In addition, the Contractor shall ensure that their employees are aware of the environmental management system on base and how these requirements affect their work performed under this contract. All on-site contractor personnel shall receive the installation EMS awareness level information.

4.19. CONFORMANCE WITH ENVIRONMENTAL REQUIREMENTS. The contractor shall perform all work in accordance with applicable German and US Air Force environmental laws, regulations and operating standards, including but not limited to the Final Governing Standards (FGS) for Germany. The contractor shall be immediately capable of understanding and addressing environmental laws and regulations as they pertain to work performed under this contract.

The FGS for Germany and other important environmental laws & requirements are applicable for all contractors working on base.

4.20. CONTRACTOR MANPOWER REPORTING. The contractor shall report ALL contractor labor hours

(including subcontractor labor hours) required for performance of services provided under this contract. The contractor is required to completely fill in all required data fields at http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported any time during the FY, all data shall be reported no later than

31 October* of each calendar year. Contractors may direct questions to the CMRA help desk.

Reporting Period: Contractors are required to input data by 31 October of each year.

Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the contractor name and contract number associated with the data.

User Manuals: Data for Air Force service requirements must be input at the Air Force CMRA link. User manuals for government personnel and contractors are available at the Air Force CMRA link at http://www.ecmra.mil.

5.0. APPENDICES.

5.1. APPLICABLE FORMS AND PUBLICATIONS. Supplements or amendments to listed publications and/or forms from any organizational level may be issued during the life of this contract. Should any publication or form revision cause a change in the contractor’s processes, procedures and/or standards of operation, the contractor shall advise the CO of such changes in writing within 30 days of receipt of the publication or form revisions.

REFERENCE LONG TITLE

AFI 31-501 Personnel Security Program Management

AFI 33-322 Records Management Program

Disability Counseling

Guide

Disability Counseling Guide

DOCPER DoD Contractor Personnel Office

DoDD 5200.2-R DoD Personnel Security Program

DoDI 1402.5 Criminal History Background Checks on Individuals In Child Care Services

FIPS PUB 201 Federal Information Processing Standards Publication 201

HIPAA Health Insurance Portability and Accountability Act

HSPD 12 Homeland Security Presidential Directive 12

OF 306 Declaration for Federal Employment

OMB M-05-24 Office of Management and Budget M-05-24

Standard Form 85P Questionnaire for Public Trust Positions

Standard Form 87 Fingerprint Card for Federal Employees state.gov U.S. Department of State

Vaccination/Immunization U.S. Department of Health and Human Services

Hepatitis B - OSHA Occupational Safety Health Administration

Health Records Occupation Safety Health Administration http://www.ecmra.mil/ http://www.ecmra.mil/

5.2. HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) OF 1996

Business Associate Agreement

This Business Associate Agreement (this "Agreement") is entered into this ___ day of ________, _____

(the “Effective Date”) between 86th Medical Group ("Covered Entity") and [NAME OF BUSINESS

ASSOCIATE], a ("Business Associate").

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the

HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health

System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.

Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph

C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated

Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy

Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD

HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS

ASSOCIATE].

Agreement means this BAA together with the documents and/or other arrangements under which the

Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA

Issuances, and in reference to this BAA, shall mean 86th Medical Group.

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office

Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region

Medical Directorate (NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military

Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD

8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD

5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR

164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part

164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D

(Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June

7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air

Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this

Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this

Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic

PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business

Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding

DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered

Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA

Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under

DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity.

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA

Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA

Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the

Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the

Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data

Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and

Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD

HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of

PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the

Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of

PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business

Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations

(including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing

Data Aggregation services to the Covered Entity and for management and administrative activities of the

Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business

Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and

HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS

Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of

PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered

Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US Computer

Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number.

Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business

Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer

(if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form

2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business

Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the

Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .