Attachment 1 PAAS PWS (Revised 07 DEC 21).docx
DOCX document 72 KB Posted
- Attached to
- Program Administrative and Assistant Support (PAAS) Federal contract opportunity
- Solicitation number
- FA8003-22-Q-0004
About this file
This document is a performance work statement (PWS) for a firm fixed price commercial non-personal services contract to provide Program Administrative and Assistant Support (PAAS) to the Air Force Medical Readiness Agency (AFMRA). The contract requires a Medical Manning Assistance Program Administrative Assistant to be located at HQ AFPC, Randolph AFB, TX, and a Dental Administrative Assistant to be located at AFMRA, Falls Church, VA. The positions will perform a range of non-personal administrative support services in accordance with the PWS, including assistance with medical staffing programs, records management, correspondence, travel arrangements, task tracking, document preparation, and meeting support. The 771 Enterprise Sourcing Squadron Contracting Officer at Wright-Patterson AFB intends to award the contract with a period of performance from December 2021. The PWS appendices include acronym definitions, a business associate agreement, and non-disclosure agreement.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PAAS Solicitation FA800322Q0004 QAs (thru 07 DEC 21).docx | DOCX document | |
| Solicitation Amendment FA800322Q00040001 SF 30.pdf | ||
| Solicitation FA800322Q0004 (Revised 07 DEC 21).pdf | ||
| PAAS Solicitation FA800322Q0004 QAs (thru 01 DEC 21).pdf | ||
| Solicitation - FA800322Q0004.pdf | ||
| Attachment 2 - CDRL A004 Quality Control Plan.pdf | ||
| Attachment 2 - CDRL A001 Meeting Agenda.pdf | ||
| Attachment 2 - CDRL A003 Monthly Status Financial Report.pdf | ||
| Attachment 1 - PAAS Performance Work Statement (PWS) 01 NOV 21.pdf | ||
| Attachment 2 - CDRL A002 Meeting Minutes.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
for
Air Force Medical Readiness Agency (AFMRA) Program Administrative and Assistant Support (PAAS)
Contract Number: TBD 07 December 2021
Solicitation # FA800322Q0004 Amendment 1
TABLE OF CONTENTS
Section Page Number
1. Description of Services
| Background | 3 |
| Scope | 3 |
| General Information | 3 |
| Contractor Identification | 3 |
| Contractor Training | 3 |
| Contractor/Government Communication | 4 |
| Place of Performance | 4 |
| Travel Requirements | 4 |
| Mission/Emergency Essential | 4 |
| Duty Hours | 4 |
| Federal Holidays | 4 |
| Conduct of Contractor Personnel | 4 |
| Contract Requirements | 5 |
| Medical Support Services | 5 |
| Security Requirements` | 7 |
| Service Contract Reporting | 9 |
| Quality Control Plan | 9 |
| Post-Award and Initial Contract Performance Meeting | 9 |
| Performance Objectives | 9 |
| Services Summary | 9 |
| Government Furnished Property | 12 |
| Deliverables | 12 |
| Appendices | 13 |
| 7.1 Appendix A – Acronym and Definition List | 14 |
| Appendix B – Business Association Agreement (BAA) | 15 |
| Appendix C – HQ USAF/SG Non-Disclosure Agreement | 23 |
| Exhibits | 26 |
| Exhibit A – Contract Data Requirements List (CDRL) | 27 |
Page
PERFORMANCE WORK STATEMENT (PWS)
Program Administrative and Assistant Support (PAAS)
1. DESCRIPTION OF SERVICES
1.1. Background. AF/SG 3/4's mission is to provide dental readiness support to Dental Treatment Facilities via AFMRA/SG3D and support the Air Force Medical Service (AFMS) in assignability of providers via Air Force Personnel Center (AFPC) by ensuring programmed manning shortfalls do not occur at Medical Treatment Facilities (MTFs). AF/SG 3/4 strives to optimize the health and wellness of their populations through appropriate, effective and efficient healthcare practices and service delivery. AF/SG 3/4' provides military readiness support through management of various programs directly and/or indirectly engaged in providing healthcare to all service members and their dependents. The AFMS through AFMRA is coordinating with all USAF Major Commands and DoD MTFs to continue and improve established healthcare programs and initiatives.
1.2. Scope. This contract supports the AF/SG 3/4’s mission through the Program Administrative and Assistant Support (PAAS) requirement by providing a Medical Manning Assistance Program Administrative Assistant and a Dental Administrative Assistant to perform a full range of non-personal services in support of AFMS programs. The Government will neither supervise Contractor employee nor control the method by which the Contractor employee performs the required tasks. Under no circumstance shall the Government assign tasks to, or prepare work schedules for Contractor employee. It shall be the responsibility of the Contractor to manage its personnel and to guard against any actions that are personal services, or give the perception of personal services. If the Contractor employee feels any actions constitute, or are perceived to constitute personal services, notify the Contracting Officer (CO) immediately. These services shall not be used to perform work of a policy/decision making or management nature, i.e. inherently governmental functions. All decisions relative to programs supported by the Contractor employee shall be the sole responsibility of the Government.
2. GENERAL INFORMATION
2.1. Contractor Identification. All Contractor personnel will identify themselves as Government Contractor personnel during all forms of communications such as business meetings, telephone conversations, electronic mail, attendance sheets, coordination documentations, reports, and the signature blocks utilized in all correspondence. This contract requires a Government workspace, and the Contractor personnel shall wear a picture identification badge and identify their workspace area with their name and company affiliation.
2.2. Contractor Training. Contract employees shall attend all such Government provided training in a paid status as part of normal services required and billed under the contract.
2.2.1. HIPAA and Privacy Act Training (Annual Training)
2.2.2. DoD IAA Cyber Awareness Challenge (Annual Training)
2.2.3. Information Assurance (Annual Training)
2.2.4. Operation OPSEC Awareness Training (Annual Training)
2.2.5. Defense Travel System (DTS) Training (One-Time Training) Solicitation
Number
Contract
Number
TBD
Insert
Date, Mod
Page
2.2.6. Task Management Tool (TMT) Training (One-Time Training)
2.3. Contractor/Government Communication. The Contractor shall designate a Focal Point to be the single point of contact for all Contractor and Government correspondence. The Focal Point shall provide clear and consistent written and verbal response to Government within 12 business hours of Government initiated communication (e.g., return phone calls, emails or other communication). The point of contact shall have full authority to act for the Contractor on all matters relating to the daily operation of this contract. The Contractor shall designate this individual, in writing, to the CO/ Contracting Officer Representative (COR) before the contract start date. An alternate may be designated, but the Contractor shall identify those times when the alternate shall be the primary point of contact.
2.3.1. The Contractor’s Focal Point shall meet with the Government team at least quarterly, and additional meetings may be requested by the Government or the Contractor as necessary. The Contractor shall provide an agenda and minutes IAW Contract Data Requirements List (CDRL) A001 and A002.
2.4. Place of Performance: The work to be performed under this contract will be performed at Government facilities located at HQ AFMRA, Falls Church, Virginia and HQ AFPC, Randolph AFB, Texas.
2.4.1. The Medical Manning Assistance Program Administrative Assistant is located at HQ AFPC, Randolph AFB, Texas.
2.4.2. The Dental Administrative Assistant is located at HQ AFMRA Falls Church, Virginia.
2.4.3. Situational telework may be directed by the CO when base conditions deem necessary. Government computers will be provided to ensure network reliability for continued work performance. The Contractor is responsible for proper use of provided equipment. The Contractor is required to coordinate with the COR so that necessary monitoring of work products can be accomplished.
2.5. Travel Requirements: No Travel Authorized.
2.6. Mission/Emergency Essential. None of the services listed in this Performance Work Statement (PWS) are mission/emergency essential.
2.7. Duty Hours: Normal duty hours are 7:30 am to 4:30 pm, Monday through Friday (excluding Federal Holidays).
2.8. Federal Holidays: Federal offices are closed on New Year’s Day, Martin Luther King Day, Presidents’ Day, Memorial Day, Juneteenth, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day, and any other day designated by Federal Statute, Executive Order, and/or Presidential Proclamation.
2.9. Conduct of Contractor Personnel. The CO may require the Contractor to remove from the job site Contractor personnel working under this contract. Removal from the job site or dismissal from the premises shall not relieve the Contractor of the contract requirements. Contractor must have the ability to fill vacant positions in a timely manner with qualified personnel.
3. CONTRACT REQUIREMENTS
3.1 Medical Support Services.
3.1.1 Medical Manning Assistance Program Administrative Assistant. The duties of the Medical Manning Assistance Program Administrative Assistant position shall include:
3.1.1.1 Provides assistance with administering the SG temporary duty (TDY) Manning Assistance Program in accordance with AF assignment policy oversight depicted in DoDI 1315.18, Procedures for Military Personnel Assignments; AFI 36-2110, Assignments; and Air Force senior leadership guidance.
3.1.1.2 While maintaining records in the area of responsibility for the DoD, the contractor shall comply with all records management oversight necessary to ensure all Air Force record-keeping requirements, electronic and paper, are met IAW the following:
3.1.1.2.1 AFI 33-322, Records Management Program
3.1.1.2.2 AFI 33-364, Records Disposition--Procedures and Responsibilities
3.1.1.2.3 AF Electronic Records Solution Guide
3.1.1.2.4 AFMAN 33-363, Management of Records
3.1.1.2.5 AF Records Information Management System Records Disposition Schedule (AFRIMS RDS). This applies to contractors performing records management support and where contractors perform duties/services/functions in place of U.S. Government employees.
3.1.1.2.6 AFI 33-322, Records Management Program, paragraph 10. In accordance with Title 18, U.S.C., Section 2071, the contractor shall not conceal, remove, mutilate, obliterate or destroy records without proper authority. Air Force Instructions, guides and publications can be accessed at http://www.e-publishing.af.mil.
3.1.1.3 Additionally the contractor will assist with Line manning assistance requests to maintain the integrity and continuity of the AF Manning Assistance program as needed.
3.1.1.4 Manning assistance processing includes the following:
3.1.1.4.1 Receive manning assistance request from requesting organization.
3.1.1.4.2 Quality check request to ensure it meets criteria in AFI 36-2110, Assignments.
3.1.1.4.3 Coordinate request with SG functional (assignment officer or Noncommissioned Officer (NCO) for validation.
3.1.1.4.4 Task and suspense supporting base.
3.1.1.4.5 Validate and redirect (with prior AFPC functional manager coordination) any reclaims.
3.1.1.4.6 Notify, by message, tasked individual with courtesy copy to squadron and group commanders and others as required.
3.1.1.4.7 Monitor and maintain manning assistance files.
3.1.1.5 A review of the last three years of data indicate that SG TDY manning assistance requests vary between 350 to 500 per year and each request may have more than one position and requested type of member. Coordination with multiple assignment functional for each request is possible.
3.1.1.6 The contractor will also provide assistance for other medical assignment procedural services to include reviewing and processing time on station waivers; review/coordinate on duty Air Force Specialty Code change requests; review, validate and update (where appropriate) overseas tour data, review/coordinate on retirement exception to policy requests and other assignment procedural processes as deemed appropriate by the branch chief.
3.1.1.7 Qualifications. Contractor personnel shall be able to demonstrate their expertise through a combination of education and/or experience.
3.1.1.7.1 Minimum of 2 years’ experience within the last five (5) years working DoD and Air Force policies and procedures related to Assignment programs.
3.1.1.7.2 Minimum of 2 years’ experience within the last five (5) years working with and using the Military Personnel Data System (MilPDS) and Microsoft Office applications.
3.1.1.7.3 Minimum of 2 years’ experience within the last five years preparing, monitoring, controlling, and processing written and electronic communications from creation to final disposition.
3.1.1.7.4 Contract personnel shall read, understand, speak, and write English to include necessary medical terms.
3.1.1.7.5 Contract personnel shall be proficient in Microsoft Office software, able to use various programs, such as Teams, Word, Excel, Access, PowerPoint, and Project to generate various products.
3.1.2 Dental Administrative Assistant. The duties of the Dental Administrative Assistants shall include:
3.1.2.1 Prepares a wide variety of recurring and nonrecurring correspondence, reports, forms and other documents, to include staff summary sheets.
3.1.2.2 Builds, reviews, tracks, and finalizes correspondence tracking of documents to include Officer Performance Reports (OPRs), Promotion Recommendation Form (PRF), Enlisted Performance Reports (EPRs), decorations, and feedbacks prepared by others in handwritten or electronic drafts through electronic management system (MYPERS).
3.1.2.3 Reviews, processes, and tracks incoming and outgoing correspondence, materials, publications, regulations, and directives.
3.1.2.4 Receives telephone calls, greets visitors, and ascertains the nature of the calls or visits. Maintains Dental Directorate’s calendar, reviews AFMRA shared calendar & update Comm Cell, coordinates meeting arrangements, print out agenda/PowerPoint prior to meetings, schedules meetings and/or conferences.
3.1.2.5 Processes travel arrangements in DTS. Prepares travel packet to include: Travel orders, Itinerary, Airlines tickets (MyTrip & more) lodging, rental car information, receipt envelope and additional requested documents.
3.1.2.6 Performs work-flow manager duties for Dental Directorate. Manages tracking of tasks and suspense’s in TMT; creates additional tasks, and ensures timely replies and closure of tasks.
3.1.2.7 Performs other administrative and clerical work in support of the office/organization that includes generating documents in Microsoft Office software such as Teams, Publisher, Word, Excel, Access, One Note, PowerPoint and Project; consistent use of correct grammar, spelling, punctuation and capitalization.
3.1.2.8 Reserves conference rooms for multiple areas; arranges for teleconference/Video Teleconference (VTC) numbers and assists with establishing connections utilizing various conferencing platforms.
3.1.2.9 Receives, sorts, distributes, ships, and tracks all incoming/outgoing mail for duty section.
3.1.2.10 Maintains shared drive files and electronic office file plans.
3.1.2.11 Coordinates weekly staff and additional meetings upon request to takes notes and prepare minutes.
3.1.2.12 Maintains office supply inventories.
3.1.2.13 Qualifications. Contractor personnel shall be able to demonstrate their expertise through a combination of education and experience.
3.1.2.13.1 Must have strong ability to interact with diverse clientele, senior level managers such as high level military and civilian medical, health care and technical personnel.
3.1.2.13.2 High school diploma or GED equivalent
3.1.2.13.3 Must be able to operate in wide latitude of independent action and is consulted as an expert in the field.
3.1.2.13.4 Must be a fully qualified typist.
3.1.2.13.5 Must be able to correct grammar, spelling, punctuation, capitalization, and format to prepare and edit written correspondence and reports IAW Tongue and Quill.
3.1.2.13.6 Minimum of one year experience within the last three years, working with the DTS is preferred but not mandatory. Training will be provided for contractors’ without experience.
3.1.2.13.7 Minimum of one year experience within the last three years, working with TMT is preferred but not mandatory. Training will be provided for contractors’ without experience.
3.1.2.13.8 Minimum of one year experience in reviewing and editing military forms and documents such as Officer Performance Reports (OPR), Enlisted Performance Reports (EPR), Promotion Recommendation Form (PRF), Staff Summary Sheets (SSS), electronic Staff Summary Sheets (eSSS) Decorations, and Memorandums For Record.
3.1.2.13.9 Minimum of one year experience with establishing and maintaining office file plans. 3.1.2.13.10 Contract personnel shall read, understand, speak, and write English to include necessary medical terms.
3.1.2.13.11 Contract personnel shall be proficient in Microsoft Office software, able to use various programs, such as Teams, Publisher, Word, Excel, Access, One Note, PowerPoint, and Project to generate various products and schedule/organize various video conferencing platforms.
3.1.3. Personnel Staffing. The contractor shall accomplish, at a minimum, the following personnel staffing performance management outcomes:
3.1.3.1. Ensure positions are filled 100% and all personnel are present for duty at the start of POP.
3.1.3.2. Ensure continuation of services during personnel absences due to sickness, leave, or termination from employment such that impact to the mission is minimal and position vacancies do not exceed 10 days. The Contractor shall maintain an overall filled rate of 95%.
3.1.3.3. The substitute/replacement of personnel shall begin work no later than 10 calendar days after notification or immediately after departure of the incumbent personnel, whichever is earlier.
3.1.3.4. The contractor shall promptly notify the CO and COR within 5 calendar days of any projected vacancies exceeding 10 calendar days.
3.2. Security Requirements
3.2.1. Security Clearance Requirements: The Contractor personnel shall have a Tier 1 National Agency Check and Inquiries, investigative clearance/background investigation prior to performing work on this contract. The Contractor shall request personnel security clearances, at the company’s expense. The contractor shall provide documentation received from the appropriate Government agency as to the verification of contract personnel’s Tier 1 certification. Due to costs involved with security investigations, requests for personnel security clearances shall be kept to the minimum required to perform contract requirements.
3.2.2. List of Contractor Personnel: The Contractor shall maintain a current listing of Contractor personnel. The list shall include Contractor personnel’s name, social security number, and level of security clearance. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the CO and Information Security Program Manager (ISPM) at each performance site 30 calendar days prior to the service start date.
Updated listings shall be provided when Contractor personnel’s status or information changes. A Visit Request for all Contractor personnel with security clearances is required to be sent through the Joint Personnel Adjudication System (JPAS), and must be updated at least annually. The Contractor shall notify the ISPM at each operating location 30 calendar days before on-base performance of the service. The notification shall include:
3.2.2.1. Name, address, and telephone number of the company key management representatives.
3.2.2.2. The contract number and contracting agency.
3.2.2.3. The highest level of classified information to which employees require access.
3.2.2.4. The location(s) of service performance and future performance, if known.
3.2.2.5. The date service performance begins.
3.2.2.6. Any change to information previously provided under this paragraph.
3.2.3. Local Area Network (LAN). All Contractor employees requiring access to the Government unclassified computer network shall have a valid Tier 1 investigation verified through JPAS. No Contractor employee will be provided access to unclassified computer network or its inherent capabilities (i.e., internet access, electronic mail, file and print services) without a valid Tier 1 investigation. The Contractor shall be aware of and abide by all Government regulations concerning the authorized use of the Government’s computer network including the restriction against using the network to recruit Government personnel or advertise job openings.
3.2.4. Disclosure of Information. In the performance of this contract, the Contractor may have access to data and information proprietary to a Government agency or to another Government Contractor, or of such nature that its dissemination or use, other than as specified in this contract, would be illegal or otherwise adverse to the interests of the Government or others. The Contractor and its personnel shall not divulge or release data or information developed or obtained under performance of this contract, except to authorized Government personnel or upon written approval of the CO. The Contractor and its Contractor personnel shall not use, disclose, or reproduce proprietary information bearing a restrictive legend, other than as specified in the contract. Contractor personnel shall not release any personnel or medical/patient information to include patient/person-level content with personal health information.
3.2.5. Non-Disclosure Agreement (NDA). All Contractor employees shall sign the non- disclosure statement provided at Appendix C prior to beginning of contract performance. The Contractor must then provide a copy of the signed/dated NDA to the CO and COR prior to beginning work.
3.3. Service Contract Reporting (SCR). The Contractor shall report Government Fiscal Year (GFY) manpower data under this non-personal services contract in the SCR section of the System for Award Management (SAM) located at: https://sam.gov. The Contractor must be registered in SAM and the user responsible for reporting must have an individual SAM user account with the Service Contract Inventory (SCI) Reporter user role to access reporting functionality. The Contractor manages all of these roles in SAM, and the Entity Administrator user roles are able to assign the SCI Reporter role to other users in their organization. To fulfill the service contract reporting requirements for this contract, the SCI Reporter shall enter the total dollar amount invoiced for services performed under this contract and the number of direct labor hours expended under this contract for each recently completed GFY, from 01 OCT 20XX to 30 SEP 20XX, during the entire period of performance no later than 30 days after its completion. SCR Guidebook is located at: https://dodprocurementtoolbox.com/cms/sites/default/files/resources/2020- 10/SCR%20Guidebook%2021%20October%202020.pdf.
3.3.1. Uses and Safeguarding of Information. Information from the secure web site is considered to be proprietary in nature when the contract number and contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor name and contract number associated with the data.
3.4. Quality Control Plan (QCP) (CDRL A004): The Contractor shall submit a finalized QCP after award and prior to the period of performance, and the QCP will need to be maintained/updated after contract award. Any update to the QCP must be reviewed by the COR. Establish and maintain a complete QCP to ensure the requirements of this PWS are provided as specified.
3.5. Post-Award and Initial Contract Performance Meeting. The Government will host a post-award meeting with the Contractor within ten (10) business days after contract award. The CO will contact the PM/COR and the Contractor to schedule this meeting. Teleconference is permissible for the post-award meeting. The purpose of the post-award meeting is to introduce the Contractor to the Government representatives (PM/COR), discuss avoiding the appearance of personal services, and go over the contract. Takeaways from the meeting should be an exchange of contact information; a timeline of when direct support will start, if not yet started; and an understanding by all parties of all the requirements to be performed by the Contractor and the support the Government will provide the Contractor to perform the requirements, safely and efficiently.
4. Performance Objectives
4.1. Services Summary (SS): The Contractor services requirements are summarized into performance objectives that relate directly to the mission. The performance threshold briefly describes the minimum acceptable levels of service for each requirement. These thresholds are critical to mission success.
Table 1 PWS SS
4.1.1 Services Summary for Medical Manning Assistance Program Administrative
| Performance Objectives |
| PWS |
Paragraph Performance Threshold
| Provide assistance with administration of the TDY Manning Assistance Program. |
| 3.1.1.1 |
| No more than three substantiated reported complaints during a six (6) month period. |
| Monitor and maintain records in the area of responsibility in accordance with applicable Air Force Instructions. |
| 3.1.1.2 |
| No more than three substantiated errors during a six (6) month period. |
| Provide Assistance with Line Manning Assistance Requests. |
| 3.1.1.3 |
| No more than three substantiated errors during a six (6) month period. |
4.1.2 Services Summary for Dental Administrative Assistant
| Performance Objectives |
| PWS |
Paragraph Performance Threshold/ Standard
| Prepare recurring and nonrecurring correspondence, reports, forms and other documents, to include staff summary sheets. |
| 3.1.2.1 |
| No more than three substantiated reported complaints during a six (6) month period. |
| Review, track, and finalize correspondence/documents prepared by others in handwritten or electronic drafts to include OPRs, PRF, EPRs, decorations, and feedbacks. |
| 3.1.2.2 |
| No more than three substantiated errors during a six (6) month period. |
Maintain Dental Directorate’s calendar, coordinates meeting arrangements, and schedules meetings and/or conferences.
| 3.1.2.4 |
| No more than three substantiated errors during a six (6) month period. |
| Processes travel arrangements in DTS. Prepares travel packet to include: Travel orders, Itinerary, Airlines tickets (MyTrip & more) lodging, rental car information, receipt envelope and additional requested documents. |
| 3.1.2.5 |
| No more than three substantiated errors during a six (6) month period. |
Manage tracking of tasks and suspense’s in TMT; creates additional taskers, ensures timely replies and closure of taskers.
| 3.1.2.6 |
| No more than three substantiated errors during a six (6) month period. |
| Generates documents in Microsoft Office software, uses various programs, such as Teams, Publisher, Word, Excel, Access, One Note, PowerPoint, and Project to generate various work products; consistent use of correct grammar, spelling, punctuation and capitalization. |
| 3.1.2.7 |
| No more than three substantiated errors during a six (6) month period. |
Reserves conference rooms for multiple areas; arranges for teleconference/VTC numbers and assists with establishing connections utilizing various conferencing platforms.
| 3.1.2.8 |
| No more than three substantiated errors during a six (6) month period. |
5. GOVERNMENT FURNISHED PROPERTY (GFP)
5.1. No GFP will be provided to the Contractor. The Government will provide the Contractor with the facilities, equipment, and information necessary to perform the tasks stipulated in this contract. Facilities include office space in unclassified work areas. Equipment includes computers ( unclassified), desks, chairs, access to printers, unclassified networks, copy machines, destruction equipment, telephones (DSN, commercial access capabilities), basic office supplies, and Government vehicles, if necessary and available. These items are incidental to the place of performance and remain accountable to the Government. In addition, the Government shall require each individual Contractor employee to sign hand receipts for all Information Technology Equipment (ITE) that they exclusively use (i.e., all equipment on their desks). This includes laptops for travel or out-of-office use. Contractor employees are not required to sign for multiple users ITE such as network equipment, network printers, and servers. Information includes all reference material or documentation required to perform. All facilities, equipment, and information used by the Contractor will remain the property of the Government and the Contractor shall return all facilities, equipment, and information to the COR or other designated representative upon the request of the Government or at the end of the contract period of performance.
6.0 DELIVERABLES
6.1 The Contractor shall submit all deliverables as specified in this PWS and contract Exhibit A, Contract Data Requirements List (CDRL).
6.1.1 All deliverables must be submitted electronically to the COR(s).
6.1.2 The CO may approve extensions to the delivery timeline based on magnitude and complexity of the document topic.
6.1.3 Provide informal reports by e-mail to the COR.
6.2 Monthly Status/Financial Report: The Contractor shall prepare and submit a monthly status/financial report identifying all tasks performed, status, issues, and anticipated actions consistent with the PWS each month. The Contractor shall provide the Monthly/Financial Report IAW CDRL A003.
7.0 APPENDICES
7.1 APPENDIX A Acronym and Definition List
7.2 APPENDIX B Business Associate Agreement (BAA)
7.3 APPENDIX C Non-Disclosure Agreement
Appendix A ACRONYMS
ACRONYMS AND DEFINITIONS
| ACRONYM |
| DEFINITIONS |
| AF |
| Air Force |
| AFI |
| Air Force Instruction |
| AFMRA |
| Air Force Medical Operations Agency |
| AFMAN |
| Air Force Manual |
| AFMS |
| Air Force Medical Service |
| AFPC |
| Air Force Personnel Center |
| AFRIMS |
| Air Force Records Information Management System |
| CDRL |
| Contractor Data Requirements Lists |
| CFR |
| Code of Federal Regulations |
| CO |
| Contracting Officer |
| COR |
| Contracting Officer Representative |
| DoD |
| Department of Defense |
| DoDD |
| Department of Defense Directive |
| DTS |
| Defense Travel System |
| EPR |
| Enlisted Performance Report |
| FAR |
| Federal Acquisition Regulation |
| HIPAA |
| Health Insurance Portability and Accountability Act of 1996 |
| HQ USAF/SG |
| Headquarters United States Air Force Surgeon General |
| MHS |
| Military Health System |
| MILPDS |
| Military Personnel Data System |
| MTF |
| Medical Treatment Facility |
| MYPERS |
| My Personnel Services |
| NCO |
| Non Commissioned Officer |
| NDA |
| Non-Disclosure Agreement |
| OPR |
| Officer Performance Report |
| PA |
| Privacy Act |
| PM |
| Program Manager |
| POC |
| Point of Contact |
| PRF |
| Promotion Recommendation Form |
| PWS |
| Performance Work Statement |
| QCP |
| Quality Control Plan |
| RDS |
| Records Disposition Schedule |
| SAV |
| Staff Assistant Visit |
| SI |
| Sensitive Information |
| TDY |
| Temporary Duty |
| VTC |
| Video Tele Conference |
| USAF |
| United States Air Force |
APPENDIX B
BUSINESS ASSOCIATE AGREEMENT
This BAA can serve as a separate standalone agreement or may be used for new or existing contracts between the MTF and the business associate.
Business Associate Agreement
[USE FOR STANDALONE BAA ONLY] This Business Associate Agreement (this "Agreement") is entered into this day of , (the “Effective Date”) between [NAME OF MHS COVERED ENTITY] ("Covered Entity") and [NAME OF BUSINESS ASSOCIATE], a [type of business entity] ("Business Associate").
Introduction
In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.
(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other Personally Identifiable Information (PII) (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.
Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS ASSOCIATE].
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].
DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).
HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566- 5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.
I. Obligations and Activities of Business Associate
(a) The Business Associate shall not use or disclose Personal Health Information (PHI) other than as permitted or required by this Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.
(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.
(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.
(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.
(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.
(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and
(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY THIS SECTION IF THE PURPOSE OF THE AGREEMENT/CONTRACT IS FOR THE BA TO DEIDENTIFY PHI FOR THE CE].
(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.
(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.
(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
(b) Government Reporting Provisions
(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.
(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable.
Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us- cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.
(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.
(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions
(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:
(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so the individual clearly understands how the breach occurred.
(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID- THEFT (438-4338); TTY: 1-866-653-4261.
(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and
(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll- free telephone number, an e-mail address, Web site, or postal address
(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll- free, e-mail address and postal address) for obtaining more information.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .