About this file

PWS- 9 JANUARY 2018

View the file

Other files for this federal contract opportunity

Other files attached to Quality of Care Delivery and Program Development Psychologist, newest first.
File Type Posted
Continuation_of_QA.pdf PDF
Q&A_QoC.pdf PDF
5._CDRL_-_A001_Meeting_Agenda.pdf PDF
8._CDRL_-_A004_Trip_Report.pdf PDF
6._CDRL_-_A002_Meeting_Minutes.pdf PDF
RFQ_Letter_QoC.pdf PDF
9._CDRL_-_A005_Technical_Report.pdf PDF
7._CDRL_-_A003_Monthly_Status_Financial_Report.pdf PDF
3._Pricing_Schedule.pdf PDF
4._Clause_and_Provisions_.pdf PDF
2.__Instructions_to_Offerors.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation/Contract Number: TBD

January 9, 2018

Performance Work Statement (PWS) for

Air Force Medical Operations Agency

(AFMOA)

Quality of Care Delivery and Program

Development Psychologist Contract Number TBD

9 Jan 2018

TABLE OF CONTENTS

Page

1.0 DESCRIPTION OF SERVICES 3

1.1 Background 3

1.2 Scope 3

2.0 GENERAL INFORMATION 3

2.1 Contractor Identification 3

2.2 Contractor Training 3

2.3 Contractor/Government Communication 4

2.4 Place of Performance 4

2.5 Travel Requirements 4

2.6 Mission/Emergency Essential 5

2.7 Duty Hours 5

2.8 Federal Holidays 5

2.9 General Requirements 5

2.10 Conduct of Contractor Personnel 5

3.0 CONTRACT REQUIREMENTS 6

3.1 The Psychologist 6

3.2 Security Requirements 7

3.3 Contractor Manpower Reporting Requirements Application 8

3.4 Post-Award Meeting 8

4.0 PERFORMANCE OBJECTIVE 9

4.1 Services Summary 9

4.2 Initial Contract Performance Review 9

4.3 Services Summary Surveillance 9

5.0 GOVERNMENT FURNISHED PROPERTY 9

6.0 DELIVERABLES 10

7.0 APPENDICES 11

7.1 APPENDIX A Acronym and Definition List 12

7.2 APPENDIX B Business Associate Agreement (BAA) 13

7.3 APPENDIX C Headquarters United States Air Force (HQ USAF)/SG

Non-Disclosure Agreement 23

1.0 DESCRIPTION OF SERVICES:

1.1 BACKGROUND: The mission of the Air Force Medical Operations Agency (AFMOA)

Mental Health Division Support (SGHW) is to ensure the Mental Health (MH) needs of Air Force beneficiaries are met and that Military Treatment Facility (MTF) has the resources needed to accomplish that mission. In order to become a High Reliability Organization, AFMOA/SGHW must standardize clinical tools and training for 76 MTFs. AFMOA/SGHW must also evaluate the effectiveness of implementing standardized protocols. In order to meet the unprecedented demand for standardizing and program evaluation, AFMOA/SGHW requires a contract psychologist whose duties include developing standardized resources and providing evaluation and quality checks of clinical care provided across MH clinics in the Air Force Medical Services (AFMS).

1.2 SCOPE: This is an advisory and assistance services (A&AS), performance based non-personal service contract. The Contractor shall perform duties at AFMOA/SGHW in support of the MH mission for the AFMS. Obtaining lessons learned for patient safety and quality of care domains and standardizing best practices for the field are top priorities of the AFMS. The period of performance shall be a base plus four (4) option years starting 31 Jan 18 – 30 Jan 23.

2.0 GENERAL INFORMATION:

2.1 Contractor Identification: All Contractor/Subcontractor personnel will identify themselves as Government Contractor personnel during all forms of communications such as business meetings, telephone conversations, electronic mail, attendance sheets, coordination documentations, reports, and the signature blocks utilized in all correspondence. If a contract requires Government workspace, the Contractor/Subcontractor personnel shall wear a picture identification badge and identify their workspace area with their name and company affiliation.

2.2 Contractor Training: When directed by the Contracting Officer Representative (COR) or

Contracting Officer (CO), contract employees shall attend all such Government provided annual training in a paid status as part of normal services required and billed under the contract. The

COR may require training other than the web-based training required below:

2.2.1 Health Insurance Portability and Accountability Act (HIPAA) and Privacy Act

Training: Contractor employee is required to complete annual HIPAA and Privacy Act training.

HIPAA and Privacy Act training is available through computer-based modules which must be facilitated by the Contractor.

2.2.2 Department of Defense (DoD) Cyber Awareness Challenge: The Contractor employee is required to complete annual DoD Cyber Awareness Challenge training. DoD Cyber Awareness

Challenge training is available through computer-based modules which must be facilitated by the

Contractor.

2.2.3 Environmental Management Systems (EMS) General Awareness Training: The

Contractor employee is required to complete the EMS General Awareness Training computer based module. This is a one-time training requirement.

2.2.4 Security Administration: The Contractor employee is required to complete the Security

Administration training computer based module which must be facilitated by the Contractor. This is a one-time training requirement.

2.2.5 Operations Security (OPSEC) Awareness Training: The Contractor employee is required to complete the latest OPSEC Awareness Training. This is a one-time training requirement.

2.3 Contractor/Government Communication: The Contractor employee shall designate a

Focal Point to be the single point of contact (POC) for all Contractor and Government correspondence. The Focal Point shall provide a clear and consistent written and verbal response to the Government within 12 business hours of Government initiated communication (e.g., return phone calls, emails or other communication).

2.3.1 The Contractor’s Focal Point shall meet with the Government team at least quarterly, and additional meetings may be requested by the Government or the Contractor as necessary. The CO, Contractor Focal Point, Contract Officer Representative (COR) and/or other designated representative will provide monthly performance feedback to the Contractor. The Contractor shall provide an agenda and minutes in accordance with (IAW) Contract Data Requirements List

(CDRL) A001 and A002.

2.4 Place of Performance: The primary place of performance is Bldg. 1, JBSA Lackland, 3515

S. General McMullen, San Antonio, Texas 78226, or an alternate work location pending approval from the COR (SGHW) at AFMOA.

2.5 Travel Requirements: Travel may be required during the performance period of this contract at the request of the Government and within the Continental United States (CONUS).

Maximum permissible travel for each contract period will be detailed in priced Exhibits and will be incorporated into the contract by bilateral modification as near as practicable to the beginning of each contract period and based on the table below. Particular travel requirements for each contract period may vary from the estimated annual travel requirements table. The Contractor shall utilize the following procedures.

2.5.1 The COR will notify the Contractor no later than 14 days in advance of any scheduled travel requirements. Notification will include specific travel dates, in-scope work tasks to be accomplished, and the specific Contractor personnel required to travel.

2.5.2 The Contractor shall send an email to the COR with a written travel itinerary meeting

Government parameters along with a written request to proceed no later than 10 calendar days prior to the travel start date.

2.5.3 The Government COR will grant or deny authorization to proceed no later than seven (7) calendar days prior to the travel start date. If the COR denies authorization to proceed, Contractor personnel shall not travel and the travel event concerned shall not be invoiced and will not be paid for under the contract. Only those travel events which are authorized in advance by the COR and fulfilled by the Contractor are billable under this contract.

2.5.4 Travel Reports shall be submitted to the COR within 10 business days after each trip completion. Travel report format shall include at a minimum the following: dates of travel, destination, purpose, individuals’ contacted, brief synopsis, issues & challenges, recommendations, and the traveler’s signature. The Contractor shall provide the Travel Itinerary

IAW CDRL A004.

2.5.5

Trip Purpose

Travel Location

From/To

Number of Trip

Days

Number of

Travelers

Annual AF Suicide

Prevention Meeting San Antonio/Washington DC 5 1

Annual DoD Suicide

Prevention Meeting San Antonio/Washington DC 5 1

2.6 Mission/Emergency Essential: None of the services listed in this PWS are mission/emergency essential.

2.7 Duty Hours: Normal duty hours are between 7:30 am to 4:30 pm, Monday through Friday

(excluding Federal Holidays) and Family/Down Days.

2.8 Federal Holidays: Federal offices are closed on New Year’s Day, Dr. Martin Luther King, Jr.’s Birthday, Presidents Day, Memorial Day, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, and Christmas Day.

2.8.1 Family Days: The Family/Down Days are non-duty days. The Contractor shall not provide services during Family/Down Days. Upon Government notification, the COR will immediately notify the Contractor of the non-planned closure. The Calendar Year 2018

Family/Down Days are: 16 Feb 18, 25 May 18, 31 Aug 18, 23 Nov 18, 24 Dec 18, and 31 Dec 18.

2.9 General Requirements:

2.9.1 Ability to communicate in English clearly, both written and orally.

2.9.2 Self-directed and possesses leadership, organizational, communication and interpersonal skills; with the ability to work independently with no supervision.

2.9.3 Must demonstrate the ability to motivate and mentor others through use of training and coaching skills and the ability to communicate information on programs and activities, both orally and in writing, to diverse audiences.

2.9.4 Contractor personnel shall be knowledgeable with standard software programs such as the

Microsoft Office 2010 Professional Suite.

2.9.5 Have working knowledge of latest versions of office automation software and recognize potential enhancements or limitations of new software utilized within their area of expertise/tasking

2.9.6 Complete all tasks and subtasks by the suspense issued at the time the task is received.

2.9.7 Have working knowledge of Government regulations, policies, procedures, and limitations within their scope of responsibilities.

2.9.8 Coordinate with the management levels, as required by DoD policies or procedures.

2.9.9 Assist the Government in a smooth transition of services when a change of personnel is necessary, whether due to Contractor personnel’s notice of discontinuance of service or by

Government cancellation of the contract. The transition service will entail providing familiarization, on-the-job training, and appropriate documentation required by the replacement personnel. Provide this transition service to the replacement personnel, whether that person belongs to the current Contractor, another Contractor or is a Government employee.

2.10 Conduct of Contractor Personnel: The CO may require the Contractor to remove

Contractor personnel working under this contract from the job site. Removal from the job site or dismissal from the premises shall not relieve the Contractor of the contract requirements.

2.10.1 Contractor personnel shall be required to observe Government facility parking, safety and traffic regulations that apply to all facility employees.

2.10.2 Alcoholic beverages on the job are prohibited.

2.10.3 There shall be no loud, profane or abusive language used on the job.

2.10.4 Contractor personnel shall present a neat well-groomed appearance. Neat, clean, casual business attire clothing shall be worn.

3.0 CONTRACT REQUIREMENTS: The Contractor shall provide a psychologist not otherwise furnished by the Government to perform independently the following technical services associated with the scope and desired capabilities defined in the below section during the period of performance.

3.1 The Psychologist Shall:

3.1.1 Assist the MH Division as the primary POC for record reviews for administrative separations (Average of 5 per month) as well as suicide attempts and completions.

3.1.2 Conduct a needs assessment each year with the MH Division to identify program develop needs, strategic planning requirements, and continuous processing improvement needs. This report will be delivered 10 business days prior to meeting/presentation. The Contractor shall provide the

Technical Report IAW CDRL A005.

3.1.3 Ensure all Air Force policies are followed for the mental health related care of the patient and report any deficiencies in care. Track those requirements that are not being regularly met as well as develop and implement a countermeasure program.

3.1.4 Provide subject matter expertise in all Air Force (AF) suicide risk guidance and administrative separations including aspects of relevant Department of Defense Instruction (DoDI)s, AF Guide and Air Force Instructions (AFI)s such as AFI 90-905 and 44-172.

3.1.5 Track findings, identify trends, recommend process improvements and identify best practices to the field in the area of quality and evidence based practice.

3.1.6 Creates reports and present briefings to the AFMOA leadership and MTFs across the

AFMS on lessons learned from these suicide reviews.

3.1.7 Create a standard of care review (delivered electronically to the SGHW) following each suicide notification and use this information to create standardized templates, checklists, resources, guidance, and training for the AFMS on suicide risk assessment, management and treatment based on existing DoD and AF policies and clinical practice guidelines policies.

3.1.8 Represent AFMOA MH as the primary POC for reviewing medical records when the

AFMOA/Commander is requested to endorse an administrative separation recommendation for a mental health condition. This requires a package of information be put together and routed through

SGHW and AFMOA/CC for signatures. The MH Division estimates five (5) packages are completed each month or 60 annually. When policy requirements for administrative separation are not met, the Contractor personnel will disclose those deficiencies to the MTF requesting

AFMOA/CC endorsement.

3.1.9 Attend MH Division conferences and meetings and create meeting minutes IAW CDRL

A002, no later than 10 business days after the meeting/presentation.

3.1.10 Create and maintains on Knowledge Exchange (KX) the standardized templates, checklists, resources, guidance, and training for the AFMS on recommendations for Administrative

Separation, Suicide Risk Assessment and Treatment.

3.1.11 Participate in and serve as the POC for other MH research projects, quality improvement initiatives, and other MH Division taskings at the discretion of the COR. This may include but is not limited to: developing resources and training for evidence-based treatment, participating in research projects, organizing and/or creating briefs for webinars, planning conferences, collecting and analyzing data for program evaluation efforts, and responding to mental health questions from the AFMS.

3.1.12 Specific Qualification / Experience Requirements:

3.1.12.1 Doctorate of Philosophy or Doctorate of Psychology degree in clinical or counseling psychology from an American Psychological Associationaccredited psychology program.

3.1.12.2 Completion of an American Psychological Association accredited internship/residency in clinical psychology.

3.1.12.3 License (current) to practice psychology in any one of the 50 United States, the District of Columbia, and territory of the United States to include Puerto Rico, Guam, and the United

States Virgin Islands.

3.1.12.4 Three (3) years’ experience in the last six (6) years providing clinical care in a DoD (AF clinic experience preferred) MH Clinic.

3.1.12.5 The Contractor employee should have documented knowledge of suicide risk assessment, management, treatment research, and policies dealing with suicide risk. In addition, the Contractor employee should have clinical experience within the past 12 months including direct hands-on experience working with patients at risk for suicide.

3.1.12.6 Three (3) years’ experience mentoring, teaching or training other professionals.

3.1.12.7 12 months of direct hands-on experience within the last 24 months with computer operations, basic word processing, data entry, and use of an automated medical record system.

3.2 Security Requirements:

3.2.1 Security Clearance Requirements: The Contractor employee shall have an active or within 30 calendar days of hire date a favorable Tier (T1) prior to performing work on this contract. The Government assumes costs and conducts investigations for confidential facility security clearances. The Contractor shall request personnel security clearances, at the company’s expense. Due to costs involved with security investigations, requests for personnel security clearances shall be kept to the minimum amount of employees required to perform contract requirements.

3.2.2 List of Contractor Personnel: The Contractor shall maintain a current listing of

Contractor personnel. The list shall include Contractor personnel’s name, social security number, and level of security clearance. The list shall be validated and signed by the company’s Facility

Security Officer and provided to the CO and Information Security Program Manager (ISPM) at each performance site 30 calendar days prior to the service start date. Updated listings shall be provided when Contractor personnel’s status or information changes. A Visit Request for all

Contractor personnel with security clearances is required to be sent through the Joint Personnel

Adjudication System (JPAS), and must be updated at least annually. The Contractor shall notify the ISPM at each operating location 30 calendar days before on-base performance of the service.

The notification shall include:

3.2.2.1 Name, address, and telephone number of the company’s key management personnel.

3.2.2.2 The contract number and contracting agency.

3.2.2.3 The highest level of classified information to which employees require access.

3.2.2.4 The location(s) of service performance and future performance, if known.

3.2.2.5 The date performance of service begins.

3.2.2.6 All changes to information previously provided under this paragraph.

3.2.3 Local Area Network: All Contractor employees requiring access to the Government unclassified computer network shall have a valid T1 verified through JPAS. No Contractor employee will be provided access to unclassified computer network or its inherent capabilities

(i.e., internet access, electronic mail, file and print services,) without a valid T1. The Contractor shall be aware of and abide by all Government regulations concerning the authorized use of the

Government’s computer network including the restriction against using the network to recruit

Government personnel or to advertise job openings

3.2.4 Disclosure of Information: In the performance of this contract, the Contractor may have access to data and information proprietary to a Government agency or to another Government

Contractor, or of such nature that its dissemination or use, other than as specified in this contract, would be illegal or otherwise adverse to the interests of the Government or others. The Contractor and its personnel shall not divulge or release data or information developed or obtained under performance of this contract, except to authorize Government personnel or upon written approval of the CO. The Contractor and its Contractor personnel shall not use, disclose, or reproduce proprietary information bearing a restrictive legend, other than as specified in the contract

3.2.5 Non-Disclosure Agreement (NDA): All Contractor employees shall sign the non-disclosure statement provided at Appendix C prior to beginning of contract performance. The

Contractor must then provide a copy of the signed/dated NDA to the COR prior to beginning work

3.3 Contractor Manpower Reporting Requirements Application (CMRA): The Contractor shall report ALL Contractor labor hours (including subcontracted labor hours) required for performance of services provided under this contract for the Air Force and Army via a secure data collection site. The Contractor is required to completely fill in all required data fields at http://www.ecmra.mil. Reporting inputs will be for the labor executed during the period of performance for each Government fiscal year (FY), which runs 1 October through 30 September.

While inputs may be reported at any time during the FY, all data shall be reported no later than 31

October of each calendar year. Contractors may direct questions to the CMRA help desk.

3.3.1 Uses and Safeguarding of Information: Information from the secure web site is considered to be proprietary in nature when the contract number and Contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor name and contract number associated with the data.

3.3.2 User Manuals. Data for Air Force service requirements must be input at the Air Force

Contract Manpower Reporting Application (CMRA) link. However, user manuals for

Government personnel and Contractors are available at the Army CMRA link http://www.ecmra.mil.

3.4 Post-Award Meeting: The Government will host a post-award meeting with the

Contractor within 10 business days after contract award. The CO shall contact the Program

Manager (PM)/Contracting Officer Representative (COR) and the Contractor to schedule this meeting. Telecon/teleconference is permissible for the post-award meeting. The purpose of the post-award meeting is to introduce the Contractor to the Government representatives (PM/COR) that the Contractor will support; provide the Contractor the opportunity to explain in more detail their proposal’s technical approach; and entertain questions from either party. Takeaways from the meeting should be an exchange of contact information; a timeline of when direct support will start, if not yet started; and an understanding by all parties of all the requirements to be performed by the

Contractor and the support the Government will provide the Contractor to perform the requirements, safely and efficiently.

http://www.ecmra.mil/ http://www.ecmra.mil/

4.0 PERFORMANCE OBJECTIVES:

4.1 Services Summary (SS): The Contractor services requirements are summarized into performance objectives that relate directly to mission essential items. The performance threshold briefly describes the minimum acceptable levels of service for each requirement. These thresholds are critical to mission success.

4.2 Initial Contract Performance Review: The initial evaluation of Contractor performance is a joint determination by the multi-functional team that the Contractor has successfully started performance, completed transition, is fully operational, and is within the estimated cost, schedule, and performance parameters of the contract. The initial evaluation will be conducted by the

Government within 30 business days after the Contractor assumes full performance responsibilities.

4.3 Services Summary Surveillance:

PERFOMANCE OBJECTIVE

PWS

Para

PERFORMANCE THRESHOLD

Achieve knowledge/expertise in the

AF Guide for Suicide Risk

Assessment, Management and

Treatment, AFI 90-905, and 44-172

3.1.4

Able to work independently within three

(3) months of start date with no more than two (2) review errors during medical record reviews post AFMS suicide attempt/completions

Achieve knowledge/expertise in

DoD and AF administrative separation recommendation policies.

3.1.8

Able to work independently within three

(3) months of start date with no more than two (2) review errors during administrative separation case reviews

Create and maintain on KX the standardized templates, checklist, resources, guidance, and training for the AFMS on Administrative

Separations, Suicide Risk

Assessment and Treatment

3.1.10 Completed by deadlines designated by the

COR.

Participate in MH research projects for developing resources and training for evidence-based treatment and collecting and analyzing data for program evaluation efforts

3.1.11

No more than two (2) substantiated negative customer complaints during 6-month period.

5.0 GOVERNMENT FURNISHED PROPERTY (GFP):

5.1 No GFP is being provided to the Contractor in support of this contract. The Government will provide the Contractor with the facilities, equipment, and information necessary to perform the tasks stipulated in this contract. Equipment includes computers (unclassified), desks, chairs, access to printers, unclassified networks, copy machines, telephones (secure, DSN, commercial access capabilities), basic office supplies, and Government vehicles, if necessary and available.

These items are incidental to the place of performance and remain accountable to the Government.

In addition, the Government shall require each individual Contractor employee to sign hand receipts for all Information Technology Equipment (ITE) that they exclusively use (i.e., all equipment on their desks). This includes laptops for travel or out-of-office use. Contractor employees are not required to sign for multiple users ITE such as network equipment, network printers, and servers. Information includes all reference material or documentation required to perform job duties. All facilities, equipment, and information used by the Contractor will remain the property of the Government and the Contractor shall return all facilities, equipment, and information to the COR or other designated representative upon the request of the Government or at the end of the contract period of performance.

6.0 DELIVERABLES: The Contractor shall submit all deliverables as specified in this PWS and

Section J – List of Documents, Exhibits and Other Attachments.

6.1 Monthly Status/Financial Report: The Contractor employee shall prepare and submit a monthly status/financial report concurrently to the primary/alternate CORs. The Contractor shall include the contract number and reporting period identifying all tasks performed, status, issues, and anticipated actions consistent with the PWS each month. With concurrence of the

Government, the Contractor may combine the financial and monthly status report; however, the report must be submitted no later than 10 calendar days after the end of the previous month. The

Contractor shall provide the Monthly Status Financial Report IAW CDRL A003.

6.1.1 Monthly Status Report. The status report shall be used to review and evaluate the overall progress along with any existing or potential problem areas. The Contractor shall provide the

Monthly Status Financial Report IAW CDRL A003.

6.1.1.1 The Contractor shall include a brief task description, to include labor category, task and hours associated with each labor category; a narrative review of tasks accomplished during the reporting period and/or significant events, status of major and minor milestones and project/program deliverables in the monthly status report. The Contractor shall address problem areas encountered and remedial actions taken or recommendations for solutions. Potential problems should be addressed at the time of occurrence to the COR but should also be included in the monthly status report. The Contractor shall provide the Monthly Status Financial Report IAW CDRL A003.

6.1.1.2 The monthly status report shall include a summary of technical milestones. The report shall include the key technical milestones met or actions accomplished. Also include expected key technical milestones or actions in the next reporting period, any problem areas and other relative information impacting their attainment. The Contractor shall provide the Monthly Status Financial Report IAW

CDRL A003.

6.1.1.3 Address staffing issues that affect the successful completion of all requirements.

6.1.1.4 Provide recommendations and/or actions the Contractor expects to take to overcome any delays due to technical, regulatory or staffing issues.

6.1.1.5 Provide a description of anticipated activities for the next reporting period, such as a description of any travel or unique services to be provided and other relative information as necessary.

6.1.1.6 Address all vacancies to coincide with invoicing.

6.1.2 Financial Report. Financial information to be provided shall include:

6.1.2.1 A brief narrative of financial transactions during the reporting period.

6.1.2.2 The financial report shall be used to document expenditure of funds and shall be consistent with the monthly status report, para. 6.1.1.1.

6.1.2.3 The Contractor shall submit invoices monthly. Each invoice should have only one billing period covered except in the case of travel that was not charged on a previous invoice. The Contractor shall provide the Monthly Status Financial Report IAW CDRL A003.

6.1.2.4 The Contractor shall separate charges in line with the contract line items for all invoices submitted.

6.2 Provide informal reports by e-mail as requested by the COR.

7.0 APPENDICES:

Appendix A

ACRONYM DEFINITIONS

AF Air Force

AFI Air Force Instructions

AFMS Air Force Medical Service

AFMOA Air Force Medical Operations Agency

A&AS Advisory and Assistance Services

BAA Business Association Agreement

CMRA Contractor Manpower Requirement Reporting Application

CO Contracting Officer

CONUS Continental United States

COR Contracting Officer Representative

DoD Department of Defense

DoDI Department of Defense Instruction EMS Environmental Management Systems

FAR Federal Acquisition Regulation

FY Fiscal Year

GFP Government Furnished Property

HIPAA Health Insurance Portability and Accountability Act of 1996

HQ USAF/SG Headquarters United States Air Force Surgeon General

ITE Information Technology Equipment

JPAS Joint Personnel Adjudication System

KX Knowledge Exchange

MHS Military Health System

MH Mental Health

MTF Military Treatment Facility

NDA Non-Disclosure Agreement

OPSEC Operations Security

PM Program Manager

POC Point of Contact

PWS Performance Work Statement

SS Service Summary

T1 Tier 1

Appendix B

BUSINESS ASSOCIATE AGREEMENT

This BAA can serve as a separate standalone agreement or may be used for new or existing contracts between the MTF and the business associate.

Business Associate Agreement

[USE FOR STANDALONE BAA ONLY] This Business Associate Agreement (this

"Agreement") is entered into this ___ day of ________, _____ (the “Effective Date”) between

[NAME OF MHS COVERED ENTITY] ("Covered Entity") and [NAME OF BUSINESS

ASSOCIATE], a [type of business entity] ("Business Associate").

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD

6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health

Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below).

The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD Contractor, acting as a HIPAA business associate. The HIPAA Rules require

BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this

BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other Personally Identifiable Information (PII) (which may include, but is not limited to

PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy

Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the

DoD HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF

BUSINESS ASSOCIATE].

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD

HIPAA Issuances, and in reference to this BAA, shall mean [INSERT NAME OF MTF

COMPONENT].

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office

Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital

Region Medical Directorate (NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD

Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18

(2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are

DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR

164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part

160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and/or HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose Personal Health Information (PHI) other than as permitted or required by this Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA

Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the

Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, and corresponding DoD HIPAA Issuances, as applicable, the Business Associate shall ensure that any

Subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered

Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered

Entity obligations under 45 CFR 164.524 and corresponding DoD HIPAA Issuances.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526, and corresponding DoD

HIPAA Issuances.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the

Covered Entity’s obligations under 45 CFR 164.528 and corresponding DoD HIPAA Issuances.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the

Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in this Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by this Agreement or directed by the Covered Entity [MODIFY THIS SECTION IF THE PURPOSE OF THE

AGREEMENT/CONTRACT IS FOR THE BA TO DEIDENTIFY PHI FOR THE CE].

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the

HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD

HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in this Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in this Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the

Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in this Agreement, the Business Associate may use PHI to provide

Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and

Restrictions

(a) The Covered Entity shall notify the Business Associate of any limitation(s) in the notice of privacy practices of the Covered Entity under 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR

164.522 and the corresponding DoD HIPAA Issuances, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

(1) In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall report the breach to the Covered Entity in accordance with Section VII, assess the breach incident, take mitigation actions as applicable, and notify affected individuals, as directed by the

Covered Entity.

(2) The Business Associate shall coordinate all investigation actions with the Covered Entity, and at a minimum, follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business

Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

(3) The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

(b) Government Reporting Provisions

(1) If the Covered Entity determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the

Covered Entity, regardless of where the breach occurs. If the Covered Entity determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD

Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office.

(2) This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business

Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(3) The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

(i) The Business Associate shall report the breach within one hour of discovery to the US

Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the

Covered Entity, and to other parties as deemed appropriate by the Covered Entity. The Business

Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.

(ii) The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-

CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the Installation Privacy Act Officer, MTF HIPAA Privacy Officer, and the Contracting Officer (if applicable), if requested. Business

Associate questions about US-CERT reporting shall be directed to the Installation Privacy Act

Officer or MTF HIPAA Privacy Officer, not the US-CERT office.

(iii) The Business Associate shall comply with the Breach Timeline and Notification Flow Chart processes attached to this Agreement, to include the timelines established for completing the DD

Form 2959 and the HIPAA Privacy Incident Report.

(4) If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business

Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business

Associate report updates, beneficiary notification, and mitigation.

(i) When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, and follow-up. The Business Associate shall submit these report updates within three (3) business days after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil

Liberties Office as required by DoD Privacy Act Issuances.

(ii) In the event the Business Associate is uncertain on how to apply the above requirements, the

Business Associate shall consult with the Covered Entity and Contracting Officer (if applicable) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

(i) If the Covered Entity determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

(ii) The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph VII for their review, and for approval by the [REMOVE CO REFERENCES FOR STAND-ALONE AGMT]

Contracting Officer, in consultation with the Covered Entity. Upon request, the Business

Associate shall provide the Contracting officer and Covered Entity with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group (PII shall not be included with the text of the letter(s) provided). Copies of further correspondence with affected individuals need not be provided unless requested by the

Contracting Office or Covered Entity. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

(A) The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated

SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

(B) The individual(s) must be informed of the facts and circumstances surrounding the breach.

The description should be sufficiently detailed so the individual clearly understands how the breach occurred.

(C) The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.

(D) A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and

(E) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Web site, or postal address

(F) The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.