ATTACHMENT_2_PWS_VTC.pdf

PDF 257 KB Posted

Attached to
Video Teleconference Maintenance Support Federal contract opportunity
Solicitation number
FA8052-16-R-0016
Issued by
Department of the Air Force Materiel Command Installation and Mission Support Center Installation Contracting Agency

About this file

ATTACHMENT 2 PWS VTC

View the file

Other files for this federal contract opportunity

Other files attached to Video Teleconference Maintenance Support, newest first.
File Type Posted
22_Jun_2016_VTC_QUESTIONS_ _ANSWERS_RFP_0007.pdf PDF
20_Jun_2016_VTC_QUESTIONS__ANSWERS_RFP_0007a.pdf PDF
13_Jun_2016_VTC_QUESTIONS_ _ANSWERS_RFP_0007.pdf PDF
Attachment__9_WD_15.pdf PDF
ATTACHMENT_4__VTC.pdf PDF
31_May_2016_VTC_QUESTIONS_ _ANSWERS_RFP_0016.doc DOC document
RFP_FA8052-16-R-0007_________VTC_Combined_Synopsis_Cover.pdf PDF
ATTACHMENT_5_VTC.pdf PDF
ATTACHMENT_4__VTC.pdf PDF
ATTACHMENT_6_VTC.pdf PDF
ATTACHMENT_7_VTC.pdf PDF
RFP_FA8052-16-R-0016_________VTC_Combined_Synopsis_Cover.pdf PDF
ATTACHMENT_8_VTC.pdf PDF
ATTACHMENT_1_SCHEDULE_B_VTC.pdf PDF
ATTACHMENT_3_QASP_VTC.pdf PDF
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AIR FORCE MEDICAL SUPPORT AGENCY (AFMSA)

PERFORMANCE WORK STATEMENT (PWS)

FOR

VIDEO TELECONFERENCE (VTC) MAINTENANCE SUPPORT

CONUS/OCONUS

24 FEB 2016

TABLE OF CONTENTS

Page

1.0 DESCRIPTION OF SERVICES

1.1 Background 3

1.2 Scope 3

1.3 Acronyms 3

2.0 SUMMARY OF REQUIREMENTS

2.1 Description of Duties 4

2.2 General Contractor Personnel Requirements 5

2.3 Services Summary 6

2.4 Government Furnished Support 7

2.5 Security Requirements 7

2.6 Travel 7

2.7 Deliverables 7

2.8 Data Reporting Requirements 8

3.0 QUALITY ASSURANCE 8

4.0 NON PERSONAL SERVICES 8

5.0 HOURS OF OPERATION 8

6.0 APPENDICES

6.1 APPENDIX A Business Association Agreement 10

6.2 APPENDIX B HQ USAF/SG Organizational Conflict of Interest (OCI) 19

6.3 APPENDIX C HQ USAF/SG Non-Disclosure Agreement 23

6.4 APPENDIX D Customer Complaint Record 25

6.5 APPENDIX E VTC Installations 80 Sites 29

6.6 APPENDIX F VTC Installations 4 Site – Option Year 1 39

1.0 DESCRIPTION OF SERVICES

1.1 Background: The Air Force Medical Support Agency (AFMSA)/Surgeon General’s Medical Support Agency (SG3) Office requires maintenance and sustainment support for 80 deployed Polycom HDX 7000 Series Video Teleconferencing (VTCs) Units throughout the Air Force Medical Service (AFMS) in support of the Wounded Warrior Tele-Mental Health Program. These VTC units support AFMSA's diverse behavioral health mission across multiple organizations. VTC maintenance support is required to ensure maximum availability to meet our behavioral health enterprise-wide mission requirements.

1.2 Scope: A non-personal services maintenance support contract is required to ensure hardware and software support for the AFMSA VTC Continental U.S. (CONUS) and Outside Continental U.S. (OCONUS) installations as identified in “Appendix E” entitled “VTC Installation Sites” are able to connect to the Defense Information’s Services Agency (DISA) Global Video Services (GVS) Network and Defense Health Agency (DHA) Movi-Jabber network on a routine or as needed basis. As such, a Federally Certified Polycom Platinum Provider referred to as the contractor, shall provide Premier Service 4870-00408-106 VTC maintenance support – for 80 each HDX 7000 Series units. Any new VTC units which are procured to support AFMSAs Tele-Mental Health Program will be incorporated into this Maintenance and Sustainment Contract by a contract modification.

1.3 Acronyms:

ACRONYMS

ACRONYM DEFINITIONS

AFMS Air Force Medical Service AFMOA Air Force Medical Operations Agency APL Approved Products List BAA Business Associate Agreement CFR Code of Federal Regulations CO Contracting Officer COMSEC Communications Security CONUS Continental United States COR Contracting Officer Representative DHA Defense Health Agency DISA Defense Information Services Agency GVS Global Video Services EST Eastern Standard Time JITC Joint Interoperability Test Command HIPAA Health Insurance Portability and Accountability Act IAW In Accordance With IT Information Technology MTF Medical Treatment Facility NLT No Later Than

OCONUS Outside Continental United States PII Personally Identifiable Information POC Point Of Contact PWS Performance Work Statement QC Quality Control SG3 Surgeon General’s Medical Support Agency Office TSO Telehealth Support Office VTC Video Teleconference

2.0 SUMMARY OF REQUIREMENTS:

2.1 Description of Duties: The contractor shall support all AFMSA/SG3 VTC units currently located in the Mental Health Clinics of our Medical Treatment Facilities (MTFs) as identified in “Appendix E” entitled “VTC Installation Sites." The Contractor shall provide access to help desk support during duty hours (0700 – 1700) Eastern Standard Time (EST) for telephone troubleshooting, diagnosis, advance parts replacement, next business day parts delivery (all freight charges to/from shall be included), access to online support tools, and access to manufacturer software updates/upgrades, when available. If the problem cannot be resolved over the phone, a technician shall be deployed to the applicable location to resolve the emergency or work-stoppage situations. The Contractor shall coordinate with Contracting Officer Representative (COR) to arrange the on-site reporting timeframe.

2.1.1 DoD approved software updates shall be provided by the Contractor on an as needed basis and In Accordance With (IAW) the Joint Interoperability Test Command/Approved Product List (JTIC/APL). The Contractor shall be responsible for preventive maintenance inspections and quality assurance checks. The Contractor shall coordinate with the Telehealth Support Office (TSO) to accomplish these actions at a minimum of twice a year or whenever software and other support updates are deemed to be necessary.

2.1.2 The Contractor shall coordinate with the TSO and VTC Site for installing and uninstalling all equipment needing repairs. The Contractor shall report and document all maintenance, diagnostics, and problem solving results directly to the Government and its representative within five (5) business days after each on-site visit. The report shall include what the problem was and the corrective action taken to resolve the problem.

2.1.3 The Contractor shall establish and maintain a database for all corrective maintenance actions pertaining to the AFMSA VTC facilities. The database shall consist of all maintenance records, and repair information. The Contractor shall provide COR a report of activity no later than (NLT) five (5) business days after repair completion.

2.1.4 The AFMSA VTC equipment supported is listed in “Appendix E” entitled “VTC Installation Sites.”

2.2 GENERAL CONTRACTOR PERSONNEL REQUIREMENTS: The Contractor shall provide personnel that meet the following requirements:

2.2.1 Work performed under the contract is unclassified. In the event the contractor comes into contact with Personally Identifiable Information (PII), the Contractor shall handle and protect all data as directed and implemented by the AFMSA enterprise and its implementation of the Business Associate Agreement (BAA) (Appendix A).

2.2.2 Physical Security: The Contractor shall be accountable for control of Government property. The Contractor is also responsible for the protection of any contractor-owned equipment or supplies brought onto the installation. Furthermore, the Contractor shall not remove any Government property/equipment from the installation without the permission of the Government.

2.2.3 Installation Entry: The Contractor shall comply with established security procedures for entering the installation and its facilities to include any special security procedures that may be established for entry to Restricted Areas or mission essential or vulnerable areas.

2.2.4 Denial of Entry: Government reserves the right to terminate entry of any contractor employee upon disclosure of information that indicates the individual’s continued entry to the installation is not in the best interest of the national security. Additionally, violation of or deviation from established security procedures by contractor employees may result in confiscation of identification media and denial of future entry to the installation.

2.2.5 The Contractor shall provide a primary Point of Contact (POC) for taskings, who shall be responsible for the overall performance of the work. The POC shall have full authority to act for the Contractor on all matters relating to the daily operation of this contract. The Contractor shall designate this individual, in writing, to the Contracting Officer and the COR before the contract start date. An alternate may be designated, but the Contractor shall identify those times when the alternate shall be the primary POC. The Government has no preference to on-site or off-site Program Manager POC.

2.2.6 Conduct of Contractor Personnel:

2.2.6.1 Shall be required to observe all base and facility parking, safety and traffic regulations that apply to all facility employees.

2.2.6.2 Evidence of workplace impairment due to substance abuse (alcohol, illegal drugs, or prescription drugs) will not be tolerated and is grounds for removal from the facility.

2.2.6.3 There shall be no loud, profane or abusive language used on the job.

2.2.6.4 Respect for the welfare of patients and visitors will be mandatory at all times.

2.2.6.5 Contract personnel shall wear neat, clean, casual business attire and present a neat and well-groomed appearance.

2.2.7 Section 508 Compliance: The industry partner shall support the government in its compliance with Section 508 throughout the development and implementation of the work to be performed. Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S. Code.

794d), and implemented by 36 Code of Federal Regulations (CFR) 1194, requires that when

Federal agencies develop, procure, maintain, or use electronic Information Technology (IT), federal employees with disabilities have access to and use of information and data that is comparable to the access and use by federal employees who do not have disabilities, unless an undue burden would be imposed on the agency. Section 508 also requires that individuals with disabilities, who are members of the public seeking information or services from a Federal agency, have access to and use of information and data that is comparable to that provided to the public who are not individuals with disabilities, unless an undue burden would be imposed on the agency. For additional Section 508 information, the industry partner should review the following websites listed below:

http://www.section508.gov http://www.access-board.gov/508.htm http://www.w3.org/WAI/Resources

2.2.8 Data Rights: All products (software, coding, documentation, reports, or any other item developed under this contract) resulting from this contract shall be the property of the Government with unlimited rights, except as pursuant to 15 U.S.C. § 3710a©(7)(A) & (B), the Freedom of Information Act, 5 U.S.C. § 552, et seq.

2.2.9 Customer Feedback Form: The COR is the primary POC for collection of all customer feedbacks. Appendix D, Customer Complaint Record, to this PWS can be used by the customer for positive and/or negative feedback on contractor performance. Appendix D contains 4 copies of the same form with the receiving POC labeled on the bottom right corner of each copy for required submission.

2.3 SERVICES SUMMARY: The Government will periodically evaluate the Contractor’s performance by appointing a representative(s) to monitor performance to ensure services are received. The Government representative will evaluate the Contractor’s performance through inspection of deliverables and receipt of all complaints from customers. The Government may inspect each task as completed or increase the number of quality control (QC) inspections if deemed appropriate because of repeated failures discovered during QC inspections or because of repeated customer complaints. Likewise, the Government may decrease the number of QC inspections if performance dictates. The COR shall make final determination of the validity of customer complaints. Below is a matrix table listing a summary of performance objectives and performance thresholds required by the Government in contractor performance.

Table 1 – SERVICES SUMMARY

Services Summary Performance Objectives

PWS

Paragraph

Performance Threshold Method of Surveillance

Conduct Preventive Maintenance Inspection and Quality Assurance Check

2.1.1 At a minimum twice a

year or whenever software and other supports updates are deemed to be necessary.

100% Inspection/Customer Feedback (Valid Complaint) http://www.section508.gov/ http://www.access-board.gov/508.htm http://www.w3.org/WAI/Resources

Report and document all maintenance, diagnostics, and problem solving results

2.1.2 Submit within five (5)

business days after each on-site visit

Periodic Inspection/Customer Feedback (Valid Complaint)

Corrective Maintenance Data Base

2.1.3 NLT five (5) business

days after repair completion

Periodic Inspection/Customer Feedback (Valid Complaint)

2.4 GOVERNMENT FURNISHED SUPPORT: There shall be no office space, telephones, reproduction equipment, hardware/software, and equipment or materials provided by the Government in support of this requirement. The facilities provided to the contractor for on-site repairs shall be limited to the conference room area where the VTC equipment is located.

2.5 SECURITY REQUIREMENTS: N/A

2.6 TRAVEL:

2.6.1. Travel may be required during the performance period of this task order at the request of the Government within both CONUS and OCONUS and the scope of the contract. Dates and destinations are not available at this time. The contractor shall coordinate travel requirements with the COR, no less than 14 business days prior to travel date and receive Government authorization from the office they support for all travel. The contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence at the best value for the Government and in accordance with the Joint Travel Regulation https://defensetravel.dod.mil/Docs/perdiem/JTR.pdf per FAR 31.205-46, Travel Costs.

Travel to and from work shall be considered a cost of doing business and shall not be reimbursable.

2.6.1.1 All travel costs shall be reimbursed on actual costs only and receipts shall be submitted with invoices. The travel costs shall not be burdened with fee, profit, or overhead. In addition, reimbursement will not exceed the travel listed on contract line item number (CLIN) dollar amount on the contract.

2.6.1.2 Trip Reports shall be submitted to the COR five (5) business days after trip completion. Trip Report format shall include at a minimum the following: dates of travel, destination, purpose, individuals’ contacted, brief synopsis, issues & challenges, recommendations, and a signature.

2.7 DELIVERABLES: Any papers, recommendations, etc. that the contractor submits are drafts, not final copies. The Government reserves the right to make changes prior to delivery of the final product. Deliverables and due dates are identified in the Deliverables table below.

Government personnel will have five (5) work days to review deliverables and provide written acceptance/rejection. The final product is due within five (5) working days after government recommended changes are incorporated. Deliverables are to be transmitted with a cover letter, on the prime contractor’s letterhead, describing the contents, to the COR and the contracting officer, and to any other destination(s) as required per the COR’s request. The contractor shall provide hard copy deliverables as required per the COR’s request. All deliverables shall be produced using recommended software tools/versions as approved by the COR.

2.7.1 Schedule of Deliverables:

Deliverable PWS Paragraph Delivery Date Maintenance Activity Report 2.1.2 NLT five (5) business days after each on-site visit.

Corrective Maintenance Database 2.1.3 NLT five (5) business days after repair completion Travel Trip Report 2.6.1.2 NLT five (5) business days after trip completion

2.7.2 Criteria for Acceptance. All deliverables shall be submitted in a draft format mutually agreed upon by the contractor and the COR.

2.8 DATA REPORTING REQUIREMENTS: N/A

3.0 QUALITY ASSURANCE: Work and documentation produced by the contract personnel will be reviewed monthly by the COR. Only the COR may accept or reject deliverables provided by the Contractor.

3.1 Customer Complaint Record (see Appendix D): The COR is the primary point of contact for collection of all customer feedbacks. The Customer Complaint Record can be used by the contractor, Government and/or Government customer for positive feedback on contractor performance and/or negative feedback on issues affecting the performance of this contract. The Government representative shall make final determination of the validity of customer complaints(s).

4.0 NON PERSONAL SERVICES: The Government shall neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the contractor’s responsibility to notify the Contracting Officer immediately. These services shall not be used to perform work of a policy/decision making or management nature, i.e., inherently Governmental functions. All decisions relative to programs supported by the contractor shall be the sole responsibility of the Government.

5.0 HOURS OF OPERATION: Normal duty hours are 7:00 AM to 4:30 PM, local time, Monday through Friday (excluding Federal Holidays), unless mutually agreed upon by Government and the contractor. As the rule, duty hours are dictated by the local MTF commander, as some locations may follow a 40-hour, 4-day work schedule, and these will take precedence. Due to mission need or due to unforeseen acts of nature or emergency, the CO/COR and contactor may agree to different duty hours/works days/duty locations.

5.1 Scheduled Federal Holidays: Government facilities are closed on New Year’s Day, Dr.

Martin Luther King, Jr. Birthday, Presidents Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.

5.2 Place of Performance: AFMSA/SG3 Office oversees (80) deployed VTC units currently located in the Mental Health Clinics of our CONUS/OCONUS MTFs. See “Appendix E – Base Year” VTC Installation Sites.

6.0 APPENDICES

6.1 APPENDIX A Business Association Agreement

6.2 APPENDIX B HQ USAF/SG Organizational Conflict of Interest (OCI)

6.3 APPENDIX C HQ USAF/SG Non-Disclosure Agreement

6.4 APPENDIX D Customer Complaint Record

6.5 APPENDIX E VTC Installations 80 Sites

6.6 APPENDIX F VTC Installations 4 Site – Option Year 1

APPENDIX A

Business Associate Agreement

[USE FOR STANDALONE BAA ONLY] This Business Associate Agreement (this "Agreement") is entered into this ___ day of ________, _____ (the “Effective Date”) between [NAME OF MHS COVERED ENTITY] ("Covered Entity") and [NAME OF BUSINESS ASSOCIATE], a [type of business entity] ("Business Associate").

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates.

Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF BUSINESS

ASSOCIATE].

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF COMPONENT].

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD

5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY

THIS SECTION IF THE PURPOSE OF THE AGREEMENT/CONTRACT IS FOR THE

BA TO DEIDENTIFY PHI FOR THE CE].

(b) The -Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of

PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number.

Although only limited information about the breach may be available as of on hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD Form 2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII. for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity. Upon request, the Business Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

(B) The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.

(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.

(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and

(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address

(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information. The [REMOVE CO REFERENCES FOR STAND-ALONE AGMT] Contracting Officer, in consultation with the Covered Entity will determine the appropriate level of support services.

(iii) Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Important information – do not destroy,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, e-mail address, and postal address.

(iv) If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10-day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10-day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the Covered Entity, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with the Covered Entity approval.

(d) Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Bus

(b) Effect of Termination.

(1) If this Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If this Agreement does not have records management requirements, the records should be handled in accordance with paragraphs VI. (2) and (3) below. If this Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if the Covered Entity gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or the Covered Entity’s direction.

(2) If this Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of this Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.

(3) If this Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.

VII. Notices. Any notices to be given hereunder will be made in the most expedient manner, via e-mail, facsimile, U.S. Mail, or express courier to such party’s address given below.

If to the Business Associate: If to the Covered Entity:

Attn: Attn:

Title: Title: MTF HIPAA Privacy Officer Company: Unit:

Address: Address:

Phone: Phone:

Fax: Fax:

E-mail: E-mail:

With a copy to:

Name: Name:

Company: Title: Contracting Officer Address: Address:

Phone: Phone:

Fax: Fax:

Email: Email:

Each party named above may change its address and that of its representative for notice by the giving of notice thereof in the manner provided in this subsection.

VIII. Miscellaneous

(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of this Agreement.

(b) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA

[USE FOR STANDALONE BAA ONLY] (c) Counterparts; Facsimiles. This Agreement may be executed in any number of counterparts, each of which shall be deemed an original. The parties acknowledge and agree that faxed and/or electronically affixed signatures shall act as original signatures that bind each faxing, or electronically affixing, signatory to the terms and provisions of this Agreement.

Delivery of an executed counterpart of this Agreement by facsimile or electronic mail shall be equally effective as delivery of a manually executed counterpart.

[USE FOR STANDALONE BAA ONLY (d) Entire Agreement; Amendment. This Agreement embodies the entire understanding between the parties pertaining to the subject matter contained in it;

supersedes any and all prior negotiations, correspondence, understandings, or agreements of the parties with respect to its subject matter; and may be waived, altered, amended, modified, revised or repealed, in whole or in part, only on the written consent of the parties to this Agreement.

[USE FOR STANDALONE BAA ONLY] IN WITNESS WHEREOF, the parties have executed this Agreement as of the Effective Date.

[USE FOR STANDALONE BAA ONLY]

BUSINESS ASSOCIATE: COVERED ENTITY:

Signature: Signature:

Print name: Print name:

Title: Title:

Date: Date:

APPENDIX B

HQ AF/SG ORGANIZATIONAL CONFLICT OF INTEREST

The purpose of this clause is to accomplish the following three objectives: (1) to inform prospective Offerors that Air Force Surgeon General (AF/SG) presumes that award of this contract or task order may give rise to real or apparent Organizational Conflict of Interest (OCI) with respect to other requirements or contracts within the Air Force Medical Service (AFMS); (2) to assist current contractors and prospective Offerors in developing their own business strategies regarding participation in AFMS requirements and in identifying and, where possible, avoiding or mitigating against OCIs; and (3) to ensure that all current contractors and prospective Offerors are afforded the maximum practicable opportunity to compete for all AFMS requirements consistent with the restrictions required under FAR Subpart 9.5, Government Accountability Office or Court of Federal Claims decisions, and sound business practices.

The contractor and all of its agents (including officers, managers, employees, consultants, and subcontractors) will fully comply with the Special Terms and Conditions OCI required for efforts in support of Air Force Medical Support Agency (AFMSA) activities. Contractor will ensure that all confidential and sensitive information will be fully protected. Such information will include, but not be limited to, all source selection sensitive information, government plans or strategies, and all proprietary information of other companies during contract performance. The disclosure of information shall not constitute a grant of any species of right, title, interest, or property in or to said information.

The contractor understands and appreciates the absolute need to prevent conflicting roles that could or may bias its support to the AFMS office and its AF-wide responsibilities. To ensure that any support provided by the contractor, its personnel, or its agents, is free of any bias in judgment or objectivity and to preclude the contractor, its personnel, or its agents, from any unfair competitive advantage in current or future acquisitions, the contractor will implement the following:

• Organizational Isolation

• Company Wide Policy Implementation

• Non-Disclosure Agreements

Contractor participation in a requirement or contract with AFMS programs may give rise to an unfair competitive advantage in other AFMS procurement actions because of access to advance acquisition planning, source selection sensitive or proprietary information. Furthermore, contractor participation in one area may give rise to a real or apparent loss of contractor impartiality and objectivity where its advisory or planning assistance in one area potentially affects its present or future participation in another area.

For purposes of identifying, avoiding and/or mitigating against OCIs, AFMS will examine all its requirements and acquisitions for potential OCI or ethical problems, regardless of the cognizant contracting activity (e.g., AFMC, VA, GSA, other agency Multiple Award Schedules, etc.) or the type of contract vehicle used (e.g., FSS order, Multiple Award ID/IQ Contracts, BPAs, FAR Part 15 competitively awards, etc.).

An Offeror/contractor wishing to submit an offer for this procurement, or any Offeror/contractor which provides or previously has provided support to AFMS, must include the following as part of its offer:

• Perform a comparative analysis of the potential new work against all current and previous work performed in support of AFMS. The comparative analysis must be included in the proposal for the new work, and must include a statement certifying whether the contractor believes that its performance of the proposed new work would create a real or apparent OCI. If the contractor believes that no real or perceived OCI will result from an award of the proposed work, no additional action by the contractor is required.

• If the Offeror/contractor believes that a real or apparent OCI may exist as a result of an award, the contractor shall also submit an OCI Avoidance or Mitigation Plan with its proposal.

Inclusion of the comparative analysis and OCI Avoidance or Mitigation Plan will not be counted against any offer page limitations otherwise stated in the solicitation.

The Contracting Officer (and when applicable the appropriate program office, acquisition manager, and legal counsel) will review the comparative analysis and, if provided, the Avoidance or Mitigation Plan, in accordance with the requirements of FAR Subpart 9.5 (Organizational Conflict of Interest) to make an independent determination of whether award to that Offeror would be consistent with those requirements. If it is unilaterally determined by the Contracting Officer that no OCI would arise or that the OCI Avoidance or Mitigation Plan adequately protects the interests of the government in the event of award to that Offeror, the Offeror will be determined, for purposes of this clause, to be eligible for award.

If the Offeror/contractor knows of no OCI in accepting work under this contract, it shall certify its OCI status and submit the certification at the end of this clause with its proposal and any later award, if awarded the contract.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .