FA568219Q7034-APT._CLERK.docx
DOCX document 203 KB Posted
- Attached to
- Appointment Line Clerk Service Federal contract opportunity
- Solicitation number
- FA568219Q7034
About this file
COMBINED SYNOPSIS-APPOINTMENT CLERK
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
31st Contracting Squadron Aviano AB, Italy Combined Synopsis Solicitation for Appointment Line Clerk Service
11 Sept 2019
The issuing agency’s address is as follows:
31st Contracting Squadron/PKB Via Pordenone 89/b, Bldg. 600, Area E Aviano Air Base 33081 Aviano (PN) Italy
SUBJECT: Combined Synopsis/Solicitation for Appointment Line Clerk Service.
GENERAL INFORMATION
SOLICITATION #: FA568219Q7034
SOLICITATION DATE: 11 Sept 2019 QUOTES DUE: Wednesday, 18 Sept 2019 @ 1600 Central European Time (CET)
Coordinator – Reference (FA568219Q7034) [ X ] Request for Quotation (RFQ) [ ] Request for Proposal (RFP) [ ] Invitation for Bid (IFB)
This solicitation and the incorporated provision and clauses are those in effect through Federal Acquisition Circular (FAC) 2019-06 Effective 10 September 2019; Defense DPN 201900628 Effective 28 June 2019 and AFAC 2018-0525 Effective 25 May 2018
Due to the overseas location of this solicitation, no small business set-aside will be used.
North American Industry Classification Code (NAICS): 561110
Offerors must be registered and active in System for Award Management (SAM) (see https://www.sam.gov) to be eligible for award.
The following information will be provided by offerors/suppliers:
NAME OF ORGANIZATION: _______________________________________________________
CAGE CODE: ________________________
DUNS NUMBER: _____________________
SAM REGISTRATION EXPIRATION DATE: ________________
QUOTATION SCHEDULE:
| CLIN # |
| Item Description |
| Unit of issue |
| Quantity |
| Unit Price |
| Total |
| 0001 |
| Appointment Line Clerk Service |
Contractor is responsible to provide all services outlined in the PWS
PoP: 27 Sept 2019 – 28 Sept 2020
| HOURS |
| 1920 |
| EU/$ |
| EU/$ |
| 1001 |
| Appointment Line Clerk Service |
Contractor is responsible to provide all services outlined in the PWS
PoP: 27 Sept 2020 – 28 Sept 2021
| HOURS |
| 1920 |
| EU/$ |
| EU/$ |
| 2001 |
| Appointment Line Clerk Service |
Contractor is responsible to provide all services outlined in the PWS
PoP: 27 Sept 2021 – 28 Sept 2022
| HOURS |
| 1920 |
| EU/$ |
| EU/$ |
Appointment Line Clerk Service
PoP: 27 Sept 2022 – 28 Sept 2023
| HOURS |
| 1920 |
| EU/$ |
| EU/$ |
| 4001 |
| Appointment Line Clerk Service |
PoP: 27 Sept 2023 – 28 Sept 2024
| HOURS |
| 1920 |
| EU/$ |
| EU/$ |
The FY19 budget rate of 0.8582 will be used for conversion and evaluation of price quotations.
PERFORMANCE WORK STATEMENT
MEDICAL APPOINTMENT CLERK
1. DESCRIPTION OF SERVICES.
1.1. OVERVIEW OF SERVICES. This contract is a services contract. The contractor shall furnish administrative services in support of the 31st Medical Group’s Medical Appointing Section. Performance shall be according to the requirements contained in the this Performance Work Statement (PWS), and professional standards of the Joint Commission (TJC), Unit Effectiveness Inspection (UEI) and Health Insurance Portability & Accountability Act (HIPAA).
1.2. BACKGROUND INFORMATION. The contractor shall accomplish all service tasks to meet the completeness of the requirements and quality as required by the 31st Medical Support Squadron, Medical Appointment Section, Aviano AB, Italy.
1.3. LOGISTICAL SUPPORT: The principal place of performance for this requirement will be Aviano AB, Italy. The Government does not intend to provide any logistical support (to include but not limited to the following: relocation cost, cost of living allowance, housing allowance, Department of Defense Education Activity (DODEA) school access, vehicle registration in the military vehicle registration system, fuel coupons or any other rationed items, access to Commissary or Base/Post Exchange, medical care, military postal system use, supporting work qualification documents) to any bidders. All offerors outside of the local area shall be responsible for all incurred relocation costs and will not be reimbursed.
2. SERVICE SUMMARY.
2.1. Overview. This Services Summary (SS) is a summary of the minimum performance objectives and performance thresholds required by the government from the contractor while performing the service (s) as described in this PWS .
The Government reserves the right to inspect all services specified in the contract, and determine whether the performance objectives and goals are met.
2.2. The absence of any contract requirement from the SS shall not detract from its enforceability nor limit the rights or remedies of the Government under any other provision or clause of the contract including FAR clause 52.212-4, Contract Terms and Conditions- Commercial Items, paragraphs (a) and (m).
2.3. Surveillance methods may include customer complaints and periodic inspection performed by the Mission Owner.
2.4. Method of surveillance can change after contract award by modifying the PWS and will be based on, but not limited to Contractor performance – based on results from FRED reports submitted to the Mission Owner on a monthly bases.
2.5. PERFORMANCE EVALUATION. Performance of the service will be evaluated to determine whether it meets the performance threshold. Re-performance is the preferred method of correcting any unacceptable performance.
2.6. SERVICE SUMMARY (SS) PERFORMANCE OBJECTIVES
Item Paragraph Performance Objective Threshold Surveillance Remedy for Threshold Violations
| Item |
| Paragraph |
| Performance Objective |
| Threshold |
| Surveillance |
| Remedy for Threshold Violations |
| 1. |
| 5.3. |
| Meet or Exceed the AFMS Standard for Service Level which is the percentage of calls answered within 90 seconds. |
| 90% or higher |
| Reported monthly to AFMSA/SG3S using UCCX (Cisco) reports. |
| Improve efficiency to meet threshold requirements by the next reported month. |
| 2. |
| 5.3. |
| Meet or Exceed the AFMS Standard for % of abandoned calls. |
| 8% or lower |
| Reported monthly to AFMSA/SG3S using UCCX (Cisco) reports. |
| Improve efficiency to meet threshold requirements by the next reported month. |
| 3. |
| 5.3. |
| Meet or Exceed the AFMS Standard for average call talk time. |
| 180 seconds or less |
| Reported monthly to AFMSA/SG3S using UCCX (Cisco) reports. |
| Improve efficiency to meet threshold requirements by the next reported month. |
3. GENERAL REQUIREMENTS.
3.1. While serving within the 31st Medical Group (MDG) the contractor shall follow general MDG requirements.
3.2. The Contractor shall comply with Executive Order 12731, October 17, 1990, (55 Fed. Reg. 42547), "Principles of Ethical Conduct for Government Officers and Employees", and shall also comply with Department of Defense (DOD) and Department of the Air Force regulations implementing this Executive Order.2.1.3. The Secretary of the Air Force has determined that the illegal possession or use of drugs and paraphernalia in a military setting contributes directly to military drug abuse and undermines Command efforts to eliminate drug abuse among military personnel. The policy of the Department of the Air Force is to deter and detect drug offenses on military installations. If there is probable cause to believe that a Contractor has been engaged in use, possession, or trafficking of drugs, the Contractor may be detained for a limited period of time until he or she can be removed from the installation or turned over to local law enforcement personnel having jurisdiction. Implicit with the acceptance of the contract is the agreement by the Contractor to comply with all Federal and State laws as well as regulations issued by the Commanding Officer of the military installation concerning illegal drugs and paraphernalia.
3.3. Adhere to infection control procedures including use of personal protective equipment, disposal of waste, and aseptic technique.
3.4. Participate in training and continuing education programs for new procedures, techniques, and equipment.
3.5. Ensure a safe work environment and employee safe work habits.
3.6. Establish and maintain appropriate, professional, interpersonal relationships with co-workers, families, peers, and other team members.
4. SPECIFIC REQUIREMENTS.
4.1 Schedule medical appointments and determine patient eligibility for services from phone calls, secured messaging or other methods used for appointment requests. Support PCM by name processing for appointment and appropriate access to care timeframes during allocation of standard appointment types.
4.2 Maintain appointment schedules using Composite Health Care Systems (CHCS), AHLTA, OR MHS GENESIS.
4.3 Validate eligibility through appropriate booking through Defense Eligibility Report System (DEERS). May be required to register patients not already in computer system, such as newborns.
4.4. Maintain accurate and up-to-date patient schedules and logs. Utilizes CHCS/AHLTAMHS GENESIS system tools (detail codes, freezing slots, and TRICARE on-line usage) to facilitate maintenance of appointment slots, rescheduling options or cancellation processing.
4.5. Validate basic CHCS/MHS GENESIS patient demographic information prior to booking appointment for patients and make required updates.
4.6. Call patients or respond to secure messaging requests as needed to schedule, reschedule, and/or cancel appointments. Assist clinic with enrolling patients in the secure messaging system. Promote consult/referral specialty medical care within the MTF or at the civilian facilities. Provide patient with specific visit instruction.
4.7. Pull records and files documentation as needed. Confirm medical records are available for upcoming appointments on provider schedules.
4.8. May assist in preparation of patient notices (telephonically or form letter formats) for appointment reminders, no shows, or reschedule/cancellations.
4.9. Receive and electronically deliver telephone messages (t-cons) to PCMs and/or clinical nurses by using CHCS/OR AHLTA/MHS GENESIS.
4.10 If in the lead clerk position, attendance to the clinic Access to Care Meeting mandatory for central booking representation.
4.11 May assist with other applicable minor administrative duties as needed.
5. EDUCATION AND TRAINING REQUIREMENTS: Contracted employee shall meet the following minimum qualifications:
5.1. Knowledge of clerical and administrative office functions.
5.2. Contractor personnel shall be able to read, write, speak, and understand English at high level equal to a B2 (“Independent User; Vantage level” of the Common European framework of reference for languages).
5.3. Personnel shall strive to achieve the Air Force Medical Service (AFMS) Standard in the following quality of service metrics which are reported monthly to the AFMSA/SG3S office. Unmet standards in any category will require more efficient handling of calls by the next month’s reporting period.
a. Service Level: AFMS standard is 90% of calls answered within 90 seconds
b. Percentage of Abandoned: AFMS standard is 8% or lower
c. Average Call Talk Time: AFMS standard is 180 seconds or less
5.4. In-service training for all contractor employees is to be provided and documented by government personnel throughout the period of the contract. The contractor shall maintain a copy of its certifiable continuing education program and provide a copy to the government prior to the start of the contract.
5.5. Personnel shall attend the 31st Medical Group Command Mandatory In-services (CMI) orientation. CMI orientation is held monthly. CMI topics are, but not limited to the following:
a. Hospital Accreditation Standards (HAS) by TJC
b. Infection Control Policies MDGI 44-105
c. Smoking Policy
d. Regulated Medical Waste Management MDGI 41-209
e. Disposal of waste
f. Facility Safety MDGI 91-2002
g. Aviano Base Fire Regulation MDGI 32-2001
5.6 A fully qualified typist (computer keyboard) with a minimum of 50 WPM is required.
5.7. Standard office equipment, such as personal computers, copiers, fax machines, and telephone systems.
5.8 General medical ethics, telephone etiquette, and excellent communication and customer service skills.
5.9 Education. High school diploma or General Educational Development (GED) equivalency. Medical terminology desired.
5.10 Work Environment/Physical Requirements. The work is mainly sedentary, but may require walking, bending, standing, and/or carrying of light items such as files, manuals, and medical records.
6. GOVERNMENT PROVIDED ITEMS. The Government will provide the following equipment, supplies, and services listed below:
6.1. EQUIPMENT/OFFICE FURNITURE. The contractor shall have joint use of all available equipment for performing services required by this contract.
6.2. COMPUTER EQUIPMENT. The MTF will provide computer equipment required to schedule, check in, document, order ancillary services, and maintain appropriate electronic medical information that support the hard copy medical record. The MTF will provide required training for these systems. The contractor will be required to use the computer systems that are standard for the support of health care delivery at the MTF.
6.3. UTILITIES. For the purpose of this contract, the government will furnish all required utilities (such as water, telephone, electricity, etc.) at no cost to the contractor. Long distance and Defense Switched Network (DSN) telephone services will be provided for official use only. The contractor shall participate in government energy conservation programs.
6.4. All financial, statistical, personnel, and technical data which is furnished, produced or otherwise available to the Contractor during the performance of the contract are considered confidential business information and shall not be used for purposes other than performance of work under the contract. Such data shall not be released by the Contractor without prior written consent of the Commander. Any presentation of any statistical or analytical materials, or any reports based on information obtained from studies covered by the contract, will be subject to review and approval by the Contracting Officer Representative before publication or dissemination.
6.5. HOUSEKEEPING. Housekeeping services will be provided by the MTF.
7. GENERAL INFORMATION
7.1. GENERAL DEFINITIONS. The following terms shall have the meaning set forth in accordance with the terms of this PWS.
7.2. COMMANDER. MTF Commander, Squadron Commander, Flight Commander or other activity head, or a designated representative, e.g., Contracting Officer's Representative (COR) or Department Head, of the activity.
7.3. CONTRACTOR. The Contractor is an independent contractor and responsible for its own liability.
7.4. MEDICAL TREATMENT FACILITY (MTF). Air Force hospitals or clinics, including all activities providing outpatient and/or in-patient healthcare services for authorized personnel.
7.5. AHLTA Armed Forces Health Longitudinal Technology Application.
7.6. CHCS Composite Health Care System.
7.7. DEERS Defense Enrollment Eligibility Reporting System.
7.8 TOL Tricare Online.
7.9. MHS GENESIS Military Health System Genesis.
8. HEALTH REQUIREMENTS
8.1. In accordance with AFI 48-105, all contractor shall follow the methods for controlling and preventing disease as described in the American Public Health Association publication, Control of Communicable Diseases Manual, and the Centers for Disease Control and Prevention (CDC) publication, Morbidity and Mortality Weekly Report (MMWR), and its supplements. Where applicable, the most recent guidelines from these publications are utilized as the standard.
8.2. Before start of work, contractor shall provide proof of immunization from the following diseases according to CDC guidelines: Hepatitis B, measles, mumps, rubella, varicella, and influenza. The contractor shall also provide proof of a negative TB skin test within 12 months (if positive, proof of negative chest Xray within 12 months) prior to start of work. After start of work, the Government will provide post blood borne exposure protocols according to applicable AFIs.
8.3. In those areas where there is a higher risk of transmission of tuberculosis, contractor will be tested as frequently as directed by the MTF policy. This test will be provided by the MTF.
8.4 Immunization information will be tracked in DoD computer systems for all contractor.
8.5. Medical Tests. No medical tests or procedures required by the contract may be performed at the MTF (with the exception of Tuberculosis testing after start of work). Expenses for all required tests and/or procedures (e.g., respirator fit testing where required) shall be borne by the contractor at no addition al expense to the Government.
8.6. Contractor must be immunized annually with the influenza vaccine. This vaccine will be provided by the Government, if available as determined by the MTF. Although this vaccine may be provided by the Government, it may be obtained at other facilities with the cost being borne by the contractor or the Contractor. Unless vaccinated by the Government, the contractor shall be required to show proof of the vaccination.
8.7. PREGNANT EMPLOYEES. Contractor should report their pregnancy to the Contracting Officer Representative. The MTF Employee Health Office will provide information concerning any work hazards in her work area inherent to gestational females. The Government is to notify the pregnant contractor of any work hazards.
It will be the Government and contractor’s joint decision whether she continues work in the environment.
8.8. APPEARANCE. The contracted worker shall present a professional, conservative, and neat appearance. The contracted worker shall report for duty in a professional manner, in appropriate attire befitting a health care setting, and having complied with socially acceptable standards of personal hygiene expected of healthcare workers.
9.0 HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) OF 1996: All individuals performing services at an Air Force MTF are required to complete initial and annual refresher HIPAA Privacy and Security Rule training as provided by the MTF for its personnel and will be held accountable for complying with health information privacy and security policies and procedures. Reference Section H for detailed HIPAA DoD Business Associate clause.
10.0 WORK SCHEDULES. CONTRACTOR HOURS OF OPERATION AND LOCATION
10.1. The primary duty location for this service contract is the 31 MDG campus, which is located between Area One and Area F. Duty hours required for this contract is 40 hours per week. The Facility Management normal duty hours are from 0700-1630 (Monday through Friday, excluding Italian holidays) which is when the majority of the workload is generated.
10.2. Planned absences must be coordinated with the Mission Owner at least two weeks in advance. If an absence is expected to exceed five days, the contractor must arrange for a trained replacement. The contractor is responsible for compensating the trained replacement. This payment includes but is not limited to compensation for time and injuries. In instances of unplanned absences in excess of five days, the contractor must provide a trained replacement.
10.3. Federal holidays are provided in addition to paid time off. The contracted worker may be required to provide services on down days or the following Federal holidays (or the actual day set aside for observation):
New Year's DayMartin Luther King Jr.'s Birthday President's Day Memorial Day Independence Day Labor Day Columbus Day Veterans Day Thanksgiving Day Christmas Day if mission requires and active duty personnel are present
11. AUTOMATED DATA PROCESSING III SECURITY REQUIREMENTS
11.1. Since the contractor under this contract have access to and/or process information requiring protection under the Privacy Act of 1974, these positions are considered "ADP III" positions. Compliance with DoD Directive 8500.1, DoD Directive 5200.2, AFI 31-501 and AFI 33-202 is mandatory for ADP Ill positions. Therefore, a National Agency Check with Inquiries (NACI) is required for each contractor under this contract. The Contractor shall fully adhere with the provisions of referenced publications by having each of their employees who are performing under this contract make an appointment (through the 31 MDG POC) with the appropriate security organization at the installation where service is provided. Each contractor will require a Common Access Card (CAC) to access the government network. In order to obtain a CAC each individual will be fingerprinted and required to complete the appropriate forms, usually a Standard Form 86, Standardized Investigative Request Form. The contractor shall advise their employees that a positive report is needed as a condition of employment under this contract. The Contractor shall apply for the NACI prior to the start of performance for each contractor.
11.2. The contractor understands that, while the MTF commander may allow contractor to temporarily occupy noncritical sensitive positions pending NACI, contract will be terminated if at any time the NACI receives unfavorable adjudication, or if other unfavorable information becomes known.
11.3. Privacy System Notices. The medical information systems identified in Appendix B are identified for the purposes of privacy system notices. These systems may be accessed by contractor during performance of task orders.
12. TAX NOTIFICATION
12.1. Before submitting an offer in response to the solicitation, all prospective offerors are encouraged to investigate the potential tax consequences should they elect to perform on the resulting contract (including by using subcontractors, in lieu of individuals carried by their payrolls). Under this solicitation, or resulting contract the Air Force does not dictate whether the successful offeror (and/or its employees/subcontractors) would be classified as an "independent Contractor" or an "employee” for tax purposes. This determination shall be made solely by the offeror. If subsequent to award the successful offeror's determination is challenged, this shall be a matter to be resolved between the offeror and the governing tax body (e.g. Ministero delle Finanze, Agenzia delle Entrate, Internal Revenue Service, etc.). The Air Force will not consider favorably any request for the equitable adjustment to the contract upon the successful offeror’s receipt of an adverse action. Additionally, it is the Contractor’s responsibility to be aware of applicable federal, state, and local laws concerning taxes and wage compensation to individual workers.
13. CRIMINAL HISTORY BACKGROUND CHECK
13.1. The contract will ensure criminal background check on the contracted worker. The Contractor is responsible for ensuring the completed SF 86 (Security Clearance Application) is contained in the background check paperwork submitted for non-privileged contractor prior to providing services at the MTF. The contractor shall ensure that the contracted worker follows local MTF policy to provide fingerprints on a properly completed SF87 (FBI U S Department of Justice Fingerprint Card).
13.2. The name and address of the MTF security section representative shall be included in the request as the recipient of the results in accordance with MTF procedures. If neither position exists, the MTF Commander shall be designated to receive a copy of the results.
13.3. Contracted technician has the right to obtain a copy of the background check report. Contracted worker may challenge the accuracy and completeness of the information in the report by contacting the individual identified in the previous paragraph.
13.4. If the technician has previously received a background check, proof of the check shall be provided or a new one obtained. A new investigation is required if a break in service to the Department of Defense results in a time lapse of more than 2 years. Re-verification shall be accomplished every 5 years.
13.5. Payment of fees incurred in the conduct of any criminal history background check is the responsibility of the Government.
14. BUSINESS ASSOCIATE AGREEMENT
This BAA can serve as a separate standalone agreement or may be used for new or existing contracts between the MTF and the business associate. If this BAA is used as a separate standalone agreement and as part of an underlying Contract, there are several identified references to Contracting Officers (COs) throughout the BAA that need to be removed. This BAA is NOT to be used in contracts for access to MHS-wide data or components of DHA. Contact the DHA Procurement Directorate at Contract PolicyDivision@dha.mil. For applicable contract language and guidance.
INTRODUCTION
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.
Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books and records available to the Secretary for purposes of determining compliance with HIPPA Rules.
II. Permitted Uses and Disclosures by Business Associates
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY THIS SECTION IF THE PURPOSE OF THE AGREEMENT/CONTRACT IS FOR THE BA TO DEIDENTIFY PHI FOR THE CE].
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Resources by covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us- cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number.
Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us- cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions
(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:
(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.
(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and
(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address.
(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.
(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.
(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.
(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber security incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forth here. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.
VI. Termination
(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the underlying Contract [FOR STANDALONE INSERT, REPLACE WITH “this Agreement”].
(b) Effect of Termination.
(1) If this Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If this Agreement does not have records management requirements, the records should be handled in accordance with paragraphs VI.(2) and (3) below. If this Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if the Covered Entity gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or the Covered Entity’s direction.
(2) If this Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of this Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.
(3) If this Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.
15. CONTRACTOR MANPOWER REPORTING.
15.1. The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract. The contractor is required to completely fill in all required data fields at http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September. While inputs may be reported any time during the FY, all data shall be reported no later than 31 October of each calendar year.
Contractors may direct questions to the CMRA help desk.
Reporting Period: Contractors are required to input data by 31 October of each year.
Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.