Award_HT0011-13-F-0054_Haemonetics.pdf

PDF 313 KB Posted

Attached to
Defense Blood Standard System (DBSS) Federal contract opportunity
Solicitation number
HT0011-13-R-0048
Issued by
Defense Health Agency

About this file

Award Defense Blood Standard System (DBSS)

View the file

Other files for this federal contract opportunity

Other files attached to Defense Blood Standard System (DBSS), newest first.
File Type Posted
DBSS_JA_Other_Than_Full__Openv1_Signed.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TRICARE MANAGEMENT ACTIVITY

7700 ARLINGTON BLVD

FALLS CHURCH VA 22042

UNDER DPAS (15 CFR 700)

11. DELIVERY FOR FOB

RFQ

SEE SCHEDULE

14. METHOD OF SOLICITATION

IFB RFP

CODE

SEE ADDENDUM

BLOCK IS MARKED

DESTINATION UNLESS

12. DISCOUNT TERMS

Net 30 Days

HQ0649

(No Collect Calls)

13b. RATING

13a. THIS CONTRACT IS A RATED ORDER

X

CODE

SEE ITEM 9

HT0011-13-R-0048

b. TELEPHONE NUMBER

703-681-5906

8. OFFER DUE DATE/LOCAL TIME

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV 3/2005)

Prescribed by GSA

FAR (48 CFR) 53.212

(TYPE OR PRINT)

30-Sep-2013

(SIGNATURE OF CONTRACTING OFFICER) 31c. DATE SIGNED

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

22. UNIT 23. UNIT PRICE 24. AMOUNT21. QUANTITY

5D INFORMATION MANAGEMENT, INC

SEAN MCGUIRE

400 WOOD RD

BRAINTREE MA 02184-2412

CODE 10. THIS ACQUISITION IS

UNRESTRICTED

FAX: NAICS:

TEL:

CODE 18a. PAYMENT WILL BE MADE BYOFFEROR

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

4BS08

TEL. 613-256-2179

HT0011

SIZE STD:

9. ISSUED BY

FACILITY

CODE

17a.CONTRACTOR/

DFAS IN VP DAI TMA

8899 EAST 56TH STREET

INDIANAPOLIS IN 46249-1505

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

15. DELIVER TO CODE 16. ADMINISTERED BY

SEE SCHEDULE

GS35F0543T 30-Sep-2013 HT0011-13-F-0054

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

SHEILA MIRRIELEES

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

REF:

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

19. ITEM NO. 20. SCHEDULE OF SUPPLIES/ SERVICES

SEE SCHEDULE

TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS

SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS

SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED HEREIN.

SB

HUBZONE SB

SET ASIDE: % FOR

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

HT000335220

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

Robert LeBlanc / Contract Officer

TEL: EMAIL: Robert.LeBlanc@tma.osd.mil

See Schedule $2,184,010.00

1 COPIES

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS: SEE SCHEDULE

.OFFER DATED 24-Sep-2013 YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN 29. AWARD OF CONTRACT: REFERENCE

X

8(A)

SVC-DISABLED VET-OWNED SB

EMERGING SB

X

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

SEE SCHEDULE

19. ITEM NO. 20. SCHEDULE OF SUPPLIES/ SERVICES 21. QUANTITY 22. UNIT 24. AMOUNT

PAGE 2 OF

23. UNIT PRICE

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV 3/2005) BACK

Prescribed by GSA

FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

HT0011-13-F-0054

Section B - Supplies or Services and Prices

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 1 Lot $2,100,260.00 $2,100,260.00 Labor

FFP

Provide operation, maintenance and life-cycle sustainment of the Defense Blood Standard System (DBSS) at 67 operational sites ‘which includes peacetime sites, training sites, testing sites and hospital ships.

FOB: Destination

PURCHASE REQUEST NUMBER: HT000335220

NET AMT $2,100,260.00

000101 $0.00 Funding for CLIN 0001

FFP

NET AMT $0.00

ACRN AD

CIN: HT0003317552190001

$1,600,206.37

000102 $0.00 Funding for CLIN 0001

ACRN AC

CIN: HT00033175522000102

$496,626.52

000103 $0.00 Funding for CLIN 0001

ACRN AB

CIN: HT000332736719000103

$3,427.11

0002 Lot $34,000.00 Travel

COST

Contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR). All travel requires Government approval/authorization and notification to the COR. NTE $34,000

ESTIMATED COST $34,000.00

000201 $0.00 Funding for CLIN 0002

ACRN AA

CIN: HT000332736720000201

$33,691.50

000202 $0.00 Funding for CLIN 0002

CIN: HT000332736719000202

$308.50

0003 Lot $49,750.00

ODC

COST

NTE $49,750

ESTIMATED COST $49,750.00

000301 $0.00 Funding for CLIN 0003

CIN: HT000332736719000301

$49,750.00

1001 1 Lot $2,953,930.00 $2,953,930.00 OPTION Labor

FFP

Provide operation, maintenance and life-cycle sustainment of the Defense Blood Standard System (DBSS) at 67 operational sites ‘which includes peacetime sites, training sites, testing sites and hospital ships.

NET AMT $2,953,930.00

1002 Lot $42,000.00 OPTION Travel

COST

Contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR). All travel requires Government approval/authorization and notification to the COR.

ESTIMATED COST $42,000.00

1003 Lot $85,600.00

OPTION ODC

COST

ESTIMATED COST $85,600.00

2001 1 Lot $2,966,252.00 $2,966,252.00 OPTION Labor

FFP

Provide operation, maintenance and life-cycle sustainment of the Defense Blood Standard System (DBSS) at 67 operational sites ‘which includes peacetime sites, training sites, testing sites and hospital ships.

NET AMT $2,966,252.00

2002 Lot $42,000.00 OPTION Travel

COST

Contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR). All travel requires Government approval/authorization and notification to the COR.

2003 Lot $249,880.00

OPTION ODC

COST

ESTIMATED COST $249,880.00

3001 1 Lot $2,686,186.00 $2,686,186.00 OPTION Labor

FFP

Provide operation, maintenance and life-cycle sustainment of the Defense Blood Standard System (DBSS) at 67 operational sites ‘which includes peacetime sites, training sites, testing sites and hospital ships.

NET AMT $2,686,186.00

3002 Lot $42,000.00 OPTION Travel

COST

Contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR). All travel requires Government approval/authorization and notification to the COR.

3003 Lot $89,880.00

OPTION ODC

COST

ESTIMATED COST $89,880.00

4001 1 Lot $1,014,772.80 $1,014,772.80 OPTION Transition Out

FFP

Detailed Outgoing Transition Plan that includes a comprehensive listing of activities of all the tasks involved with a transition-out as well as a timeline on when those tasks would best be conducted for the benefit of the Government.

NET AMT $1,014,772.80

4002 1 Lot $100,000.00 $100,000.00 OPTION ODCs - Transition Out

NET AMT $100,000.00

Section C - Descriptions and Specifications

PWS

PERFORMANCE WORK STATEMENT (PWS)

DEFENSE BLOOD STANDARD SYSTEM (DBSS) V3.04WIN2K LIFE CYCLE SUSTAINMENT

Part 1

General Information

1. GENERAL: This PWS identifies services that are strictly non-personal in nature, and that are non-severable in nature.

1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Life Cycle Maintenance and Sustainment for the Defense Blood Standard System (DBSS) as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.

1.2 Background: The DBSS v3.04 WIN2K is a Blood Establishment Computer Software (BECS) that is required by law to be developed and sustained under the Code of Federal Regulations (CFR), Title 21, Series 800 to 899.

The FDA requires compliance to current Good Manufacturing Practices (cGMP) by qualified medical device suppliers to meet industry standards of care. cGMPs provide guidance for system reliability, availability, and maintainability (RAM) that assure proper design, monitoring, and control of manufacturing processes and facilities.

The current fielded version of DBSS v3.04WIN2K must provide safe and effective blood components and is subject to potential product recalls when root cause analysis discovers unacceptable risk to patients. The DBSS is a Department of Defense (DoD) mission critical system supporting the Military Health Services (MHS) blood management operations in the following areas:

Armed Services Whole Blood Processing Laboratory (ASWBPL) Blood Donor Centers (BDCs) Mobile Collection Support Military Medical Treatment Facility (MTF) Blood Banks Expeditionary Blood Transshipment Centers EBTCs

The DBSS v3.04WIN2K provides procedures for collecting, manufacturing, testing, processing, freezing, storing, shipping, and distributing blood components and substitutes. The DBSS v3.04WIN2K supports the tracking of blood components and substitutes, as well as, the tracking of blood donors and recipients (look-back) for infectious disease (e.g. Human Immunodeficiency Virus (HIV) and Hepatitis), and provides a deferral list of donors prohibited from donating blood. The DBSS v3.04WIN2K is operated by the Military Departments at Blood Transfusion facilities on military installations both in the Continental United States (CONUS) and Outside the Continental United States (OCONUS).

This award will affect the entire DoD blood supply, worldwide. It contributes directly to deployment readiness, prevention, and surveillance, which are all goals of the MHS.

1.3 Objectives: The objective of this Performance Work Statement (PWS) is to secure services in order to support the operation, maintenance and life-cycle sustainment of the Defense Blood Standard System (DBSS) at 67 operation sites which includes peacetime sites, training sites, testing sites and hospital ships. The Contractor shall utilize the CFR, Title 21, Series 800 to 899, to ensure that the DBSS v3.04WIN2K is safe and effective for its intended use. This shall ensure that the DBSS v3.04WIN2K is maintained and manufactured as a FDA regulated medical device, so that it manages safe, pure, and potent blood products for its 9.7 million MHS beneficiaries.

1.3.1 Preparation for shut down, turn-in and storage of the Defense Blood Standard System (DBSS):

It is the government’s intension over the life cycle of this contract (See Section 1.5) to sunset (shut down) the Defense Blood Standard System (DBSS) at the current 62 operational sites. DOD intends to replace the current DBSS with a new DOD Enterprise Blood Management System (EBMS) which consists of a Blood Donor Management System (BDMS) and a Blood Bank/Transfusion Services System (BB/TS). As BDMS and BB/TS systems become operational at individual sites (not an objective of this contract) DBSS will be shut down and removed from that individual site (See Section 5.4 for specific tasks).

In compliance with current DoD direction, the Contractor shall coordinate actively and responsively with the Government and other Government designated participating contractors to coordinate DBSS sites sunsetting dates with the Enterprise Blood Management System (EBMS) deployment schedule.

1.4 Scope: This Performance Work Statement (PWS) provides for maintenance services in support of the Defense Blood Standard System (DBSS) v3.04 WIN2K, a Food and Drug Administration (FDA) regulated Class II medical device. This PWS includes requirements for 24 x 7 customer support, system maintenance and quality assurance.

In addition, this PWS provides for software maintenance to ensure DBSS performs as intended in the production of safe, pure, and potent blood products, as well as the procurement and implementation of incidental hardware and software to restore the system to the required operational effectiveness of the “cleared” device. This PWS includes the maintenance and support of DBSS which is currently issued a Denial Authority to Operate (DATO). This PWS shall also provide for the personnel, materials, facilities, travel, training, and other related support services required to perform these tasks. This PWS includes services necessary for the Contractor to manage its own staff, resources, products, and schedules in performing work, but specifically excludes any services to support the MHS in planning or managing MHS programs or offices.

1.5 Period of Performance: The period of performance shall be for one (1) 4-month Base Period, three (3) 6-month Option Periods and one (1) 2-month Transition Out Period. The Period of Performance reads as follows:

Base Period – September 1, 2013 through December 31, 2013 (4-Months) Option Period 1 – January 1, 2014 through June 30, 2014 (6-Months) Option Period 2 – July 1, 2014 through December 31, 2014 (6-Months) Option Period 3 – January 1, 2015 through June 30, 2015 (6-Months) Transition Out – July 1, 2015 through August 31, 2015 (2-Months)

1.6 General Information

1.6.1 Hours of Operation: The contractor is responsible for providing maintenance support 24 x 7 with the same functional and technical support regardless of the DBSS site’s time zone. For other than firm fixed price contracts, the contractor will not be reimbursed when the government facility is closed. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed.

1.6.2 Place of Performance: The work to be performed under this contract will be performed at the contractor facility, to be determined, and at various Department of Defense (DoD) Military Health Services (MHS) blood management facilities including but not limited to the following:

Armed Services Whole Blood Processing Laboratory (ASWBPL) Blood Donor Centers (BDCs) Mobile Collection Support Military Medical Treatment Facility (MTF) Blood Banks

1.6.3 Type of Contract: The Government intends to award a Firm Fixed Price Contract.

1.6.4 Security Requirements:

1.6.4.1 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use.

1.6.4.2 Non-Disclosure / Non-Use Agreement

The Contractor shall ensure that the Non-Disclosure/ Non-Use Statement (Appendix A) (Deliverable 1) is signed by all staff (including all prime contractor employees, subcontractor employees and consultants) assigned to or performing on this Task Order before performing any work and at a minimum lasting for the duration of the contract awarded as a result of this procurement. The Non-Disclosure / Non-Use statement shall be cosigned by a corporate official (Contractor Task Manager or higher). The Contractor shall also ensure that all staff (as described above) understand and adhere to the terms of the Non-Disclosure / Non-Use statement, protecting procurement sensitive information of the Government and the proprietary information of others. Assignment of staff who has not executed this statement or failure to adhere to this statement by the contractor or its subs and consultants shall in and of itself constitute a basis for default on the part of the Contractor.

1.6.4.3 Information Assurance

General Security Requirements - The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of Government data. As a minimum, this shall include provisions for personnel security, electronic security and physical security as listed in the sections that follow:

1.6.4.3.1 Personnel Security.

The Contractor shall comply with DoD Directive 8500.1, "Information Assurance (IA);" DoD Instruction 8500.2, "Information Assurance (IA) Implementation;" DoD Directive 5400.11, "DoD Privacy Program;" DoD 6025.18-R, "DoD Health Information Privacy Regulation;" and DoD 5200.2-R, "Personnel Security Program Requirements."

Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:

Follow the TMA Privacy Office guidelines for submittal of Automated Data Processor/Information Technology (ADP/IT) security clearances and ensure all Contractor personnel are designated as ADP/IT-I, ADP/IT-II, or ADP/IT-III where their duties meet the criteria of the position sensitivity designations.

Contact the TMA Privacy Office for guidance on the appropriate ADP/IT levels for personnel on the contract. The TMA Privacy Office procedures for personnel security are listed on the following website:

http://www.tricare.osd.mil/tmaprivacy/personnel-security.cfm.

Initiate, maintain, and document personnel security investigations appropriate to the individual's responsibilities and required access to MHS Sensitive Information (SI).

Immediately report to the TMA Privacy Office and deny access to any automated information system (AIS), network, or MHS SI information if a Contractor employee filling a sensitive position receives an unfavorable adjudication, if information that would result in an unfavorable adjudication becomes available, or if directed to do so by the appropriate Government representative for security reasons.

Ensure that all Contractor personnel, to include sub-contractors and consultants, receive information assurance (IA) training before being granted access to DoD AISs/networks, and/or MHS SI information.

1.6.4.3.2 Electronic Security.

Contractor Information Systems (IS)/networks that are involved in the operation of systems in support of the DoD MHS shall operate in accordance with controlling laws, regulations, and DoD policy.

Contractors designing, developing or operating DoD ISs shall comply with the requirements of the DoD Information Assurance (IA) program as promulgated in DoDIA 8500.2IA Implementation, 6 February 2003.

Certification & Accreditation (C&A) requirements as promulgated in DoDI 8510.01 apply to all DoD and Contractor's IS/networks that receive process, display, and store or transmit DoD information. The Contractor shall comply with the C&A process for safeguarding SI. Certification is the determination of the appropriate level of protection required for IS/networks. Certification also includes a comprehensive evaluation of the technical and non-technical security features and countermeasures required for each system/network.

Accreditation is the formal approval by the Government to operate the Contractor's IS/networks in a particular security mode using a prescribed set of safeguards at an acceptable level of risk. In addition, accreditation allows IS/networks to operate within the given operational environment with stated interconnections; and with appropriate level of protection for the specified period.

The Contractor shall comply with C&A requirements, as specified by the Government that meet appropriate DoD Information Assurance requirements. The C&A requirements shall be met before the Contractor's system is authorized to access DoD data or interconnect with any DoD IS/network that receives, processes, stores, displays or transmits DoD data. The Contractor shall make its IS/networks available for testing, and initiate the C&A testing in advance of accessing DoD data or interconnecting with DoD IS/networks. The Contractor shall ensure the proper Contractor support staff is available to participate in all phases of the C&A process. This includes, but is not limited to:

Attending and supporting C&A meetings with the Government Supporting/conducting the vulnerability mitigation process Supporting the C&A Team during system security testing Contractors must confirm that their IS/networks are locked down prior to initiating testing.

Confirmation of system lock down shall be agreed upon during the definition of the C&A boundary and be signed and documented as part of the System Security Authorization Agreement (SSAA) Locking down the system means that there shall be no changes made to the configuration of the system

(within the C&A boundary) during the C&A process

Any re-configuration or change in the system during the C&A testing process will require a re-baselining of the system and documentation of system changes.

Vulnerabilities that have been identified by the Government as "must-fix" issues during C&A process must be mitigated according to the timeline identified by the Government Representative. C&A checklists are provided for complying DoD C&A requirements. Reference material and C&A tools may be obtained at:

http://iase.disa.mil/ditscap.

A request for a waiver to the C&A requirements may be submitted for temporary testing and other usual circumstances. A waiver request must be submitted, in writing, to the Designated Accrediting Authority (DAA).

The request must include mitigation strategies that ensure adequate protection measures and security controls are in place (for example: air gapping a testing network).

Information Assurance Vulnerability Management (IAVM). The Contractor shall implement an information assurance vulnerability management program. The DoD IAVM program provides electronic security protections against known threats and vulnerabilities. The IAVM program requires the registration of DoD IS assets in the DoD Vulnerability Management System (VMS), which allows for the timely dissemination of critical vulnerability information. It also assists in the documentation and tracking of compliance, providing increased electronic security to MHS systems. As part of the program, the Contractor shall provide a primary and secondary point of contact in the VMS and to the MHS Information Assurance Vulnerability Alert (IAVA) Monitor. The point of contact shall provide, upon receipt of a vulnerability message, an acknowledgment of receipt via the VMS. The contactor shall thoroughly test all mitigations for the vulnerability, and upon applying the mitigation to the system, report compliance in the VMS. Receipt and compliance messages to the Government shall occur within the stipulated time window, as stated in the vulnerability message or in the VMS.

The Contractor shall ensure DoD IS assets that are under development are registered in the VMS and have all applicable electronic patches installed for the system (1) when the system is delivered to the Government, or (2) if the DoD IS assets are used to store or process Government data prior to delivery (such as when being used in testing and development).

Guidance regarding the requirement for IAVM is contained in the DoD Information Assurance Vulnerability Alert (IAVA) December 30, 1999 memorandum and Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01 (Appendix A to Enclosure B) provides additional reference information. Implementation is addressed in the Defense

Information Systems Agency (DISA) IAVA Process Handbook, Version 2.1, June 11, 2002. An asset is any device on any DoD-owned, controlled or contracted IS or network, to include (but not limited to) workstations, servers, routing devices (routers, switches, firewalls), networked peripherals (e.g., network printers, portable electronic devices) and controlled interfaces (e.g., guards). A device is considered a node on a network if it has its own network identification (internet protocol (IP) and/or media access control address). The Defense Information System Agency’s (DISA) VMS web enabled application is used to disseminate Information Assurance Vulnerability Alerts (IAVA) Information Assurance Vulnerability Bulletins (IA VBs), and Information Assurance Technical Advisories down to the System Administrator (SA) and applicable personnel throughout the chain of command.

The Contractor shall maintain any development environments in accordance with TMA Information Assurance IA best practices and operational requirements. During product development for the Government, the Contractor shall ensure that all IA mitigation strategies have been applied to the development environment prior to any Government data being loaded onto any assets or software for testing or delivery.

IA mitigation strategies include security updates, service packs, and changes to operating procedures as physical and cyber vulnerabilities are detected. Operating system, routers, servers, development platforms and the application being delivered to the Government shall be in compliance with all known applicable Department of Defense Computer Emergency Response Team (DoD-CERT) Alert, Bulletin, and Technical Advisory Notices published during the past 36 months.

Disposing of Electronic Media. Contractors shall follow the DoD standards, procedures, and use approved products to dispose of unclassified hard drives and other electronic media, as appropriate, in accordance with DoD Memorandum "Disposition of Unclassified Computer Hard Drives," June 4, 2001. Contractors are required to also follow DoD guidance on sanitization of other internal and external media components in DODI 8500.2 "Information Assurance (IA) Implementation," 6 Feb 2003 and DoD 5220.22-M "Industrial Security Program Operating Manual (NISPOM)," (Chapter 8).

Ports, Protocols, and Services. Contractors shall follow all current DoD and Defense Information Systems Agency (DISA) standards and requirements for acceptable Ports, Protocols, and Services. Any requests for exception to using the current DISA Ports, Protocols, and Services standards requires an request for exception sent through the Program Manager to the DAA.

Public Key Infrastructure and Encryption. Contractors shall follow the DoD standards, policies, and procedures related to the use of Public Key Infrastructure (PKI) certificates and biometrics for positive authentication. Where interoperable PKI is required for the exchange of unclassified information between DoD and its Contractors, industry partners shall obtain all necessary certificates. Contractors must turn over to the Government all encryption keys for deployed systems, backdoor algorithms, and procedures for their use in remote support. Contractors must provide a written report detailing all of the above, prior to task order expiration, regardless of modifications or extensions.

1.6.4.3.3 Information Systems (IS)/Networks Physical Security

The Contractor shall employ physical security safeguards for IS/Networks involved in processing or storage of Government Data to prevent the unauthorized access, disclosure, modification, destruction, use, etc., and to otherwise protect the confidentiality and ensure use conforms with DoD regulations. In addition, the Contractor will support a Physical Security Audit performed by the Government of the Contractor's internal information management infrastructure. The MHS Physical Security Audit Matrix is available at:

http://www.tricare.osd.mil/tmis_new/Policy/PSA_Matrix_%20012304%200930%20clean%20version.xls.

The Contractor shall correct any deficiencies identified by the Government of the Contractor's physical security posture. The Contractor shall be required to follow all requirements in the MHS Information Assurance Policy. New MHS policies will be posted to the following website: http://www.tricare.osd.mil/tmis_new/IA.htm.

1.6.4.4 Enterprise Architecture

Refer to section 5.2.1.12

1.6.4.5 Protection of Information

1.6.4.5.1 Dissemination of Information/Publishing

There shall be no dissemination or publication, except within and between the Contractor and any sub- Contractors or specified Integrated Product/Process Team (IPT) members who have a need to know, of information developed under this order or contained in the reports to be furnished pursuant to this order without prior written approval of the TMA TM or the Contracting Officer. TMA approval for publication will require provisions which protect the intellectual property and patent rights of both TMA and the Contractor.

1.6.4.5.2 Contractor Employees

Contractor Identification The Contractor shall ensure that Contractor personnel identify themselves as Contractors when attending meetings, answering Government telephones, providing any type of written correspondence, or working in situations where their actions could be construed as official Government acts.

Attendance at Meetings Contractor personnel may be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their Contractor status known during introductions.

Use of Military Rank by Contractor Personnel Contractor personnel, while performing in a Contractor capacity, are prohibited from using their retired or reserve component military rank or title in all written or verbal communications associated with the contract under which they provide services.

1.6.4.5.3 Personally Identifiable Information (PII) and Protected Health Information (PHI) The TMA Privacy Office website at http://www.tricare.mil/tmaprivacy/contract.cfm contains guidance regarding Protected Health Information (PHI) and Personally Identifiable Information PII).

The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of Government data, and to comply with data breach reporting and response requirements, in accordance with DFAR Subpart 224.1 (Protection of Individual Privacy) that incorporates the following DoD regulations by reference: DoDD 5400.11, Department of Defense Privacy Program, and DoD 5400.11-R, Department of Defense Privacy Program.

Health Insurance Portability and Accountability Act (HIPAA) The Contractor shall comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (P.L.

104-191) requirements, as well as the Department of Defense (DoD) 6025.18-R, "DoD Health Information Privacy Regulation," January, 2003. This includes the Standards for Electronic Transactions, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards. The Contractor shall also comply with all Applicable HIPAA-related rules and regulations as they are published and as Government requirements are defined (including identifiers for providers, employers, health plans, and individuals, and standards for claims Appendix transactions). Any rules and regulations that are published and/or requirements that are defined after the award date of this contract, that require expenditure of additional Contractor resources for compliance may be considered "changes" and will be subject to the changes clause under the contract.

Breach Reporting The Contractor shall adhere to the reporting and response requirements set forth in the Office of the Secretary of Defense (OSD) Memorandum 1504-07, “Safeguarding Against and Responding to the Breach of Personally Identifiable Information,” September 21, 2007; DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007, and applicable TMA Privacy Office guidance available at: http://www.tricare.mil/tmaprivacy/breach.cfm.

Systems of Record

In order to meet the requirements of 5 U.S.C. 552a, the Privacy Act of 1974, Contractors shall assist the TMA Privacy Office in completing a Privacy Act System of Records Notice for collections of records where information in identifiable form is retrieved. The Contractor will also comply with the requirements in Office of Management and Budget (OMB) Circular A-130, in the DoD Directive 5400.11, “DoD Privacy Program,” May 8, 2007, and in the DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007. The contactor shall work with the government point of contact to identify Privacy Act System of Records that are maintained or operated for TMA.

Completed System of Records Notice formats for the applicable systems should be sent to the TRICARE Management Activity (TMA) Privacy Office at sormail@tma.osd.mil.

Privacy Impact Assessment The Contractor shall provide for the completion of a Privacy Impact Assessment (PIA) for any applicable systems that collect, maintain, use or disseminate personally identifiable information (PII) or protected health information (PHI) about members of the public, Federal personnel, Contractors, or in some cases foreign nationals.

Contractors are responsible for the completion of the Privacy Impact Assessment Determination Checklist. This Checklist provides basic information to the TMA Privacy Office and ensures that the appropriate decision concerning PIA requirements is made. The Checklist can be downloaded from http://www.tricare.mil/tmaprivacy/downloads/PIADC.121008.pdf.

Contractors are responsible for the employment of practices that satisfy the requirements and regulations of the E- Government Act of 2002, (PubL. 107-347); DoD 5400.16-R, “DoD Privacy Impact Assessment (PIA) Guidance,” February 12, 2009; Office of Management and Budget Memorandum M-03-22, “OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002,” September 26, 2003, and current DoD PIA Guidance Memorandum at http://www.tricare.mil/TMAPrivacy/Info-Papers-PIAs.cfm. When completing a PIA, the Contractor is responsible for using the DoD-approved PIA Template, DoD Standard Form DD 2930, available at http://www.dtic.mil/whs/directives/infomgt/forms/eforms/dd2930.pdf.

PIAs will be sent to the TRICARE Management Activity (TMA) Privacy Office at piamail@tma.osd.mil

Data Use Agreement (DUA) A Data Use Agreement (DUA) is currently used to request Military Health System (MHS) data that is owned and/or managed by HA/TMA. The DUA ensures that applicable privacy and security requirements are followed in the use and/or disclosure of the data. To begin the DUA request process, contact duamail@tma.osd.mil. After receiving approval on a DUA, anyone needing access to information system applications or data sources managed by the Defense Health Services Systems (DHSS) will need to contact the DHSS Program Office at eidsaccess@tma.osd.mil to obtain information on access requirements. DUAs are active for one year, after which the Contractor must submit a renewal request or provide a Certificate of Data Destruction (CDD) to the TMA Privacy Office.

1.6.4.5.4 Business Associates

In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy Regulation” the Contractor meets the definition of Business Associate. Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Contractor agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause, and DoD 6025.18-R and DoD 8580.02-R, as amended. Additional requirements will be addressed when implemented.

(a) Definitions. As used in this clause generally refer to the Code of Federal Regulations (CFR) definition unless a more specific provision exists in DoD 6025.18-R.

Individual has the same meaning as the term “individual'' in 45 CFR 164.501 and 164.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).

Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.

Protected Health Information has the same meaning as the term “protected health information'' in 45 CFR 164.501, limited to the information created or received by the Contractor from or on behalf of The Government.

Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.

Required by Law has the same meaning as the term “required by law'' in 45 CFR 164.501 and 164.103.

Secretary means the Secretary of the Department of Health and Human Services or his/her designee.

Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part 164, subpart C.

Terms used, but not otherwise defined, in this Clause shall have the same meaning as those terms in 45 CFR 160.103, 164.501 and 164.304.

(b) The Contractor shall not use or further disclose PHI other than as permitted or required by the Contract or as Required by Law.

(c) The Contractor shall use appropriate safeguards to prevent use or disclosure of the PHI other than as provided for by this Award.

(d) The Contractor shall use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Award.

(e) The Contractor shall, at their own expense, take action to mitigate, to the extent practicable, any harmful effect that is known to the Contractor of a use or disclosure of Protected Health Information by the Contractor in violation of the requirements of this Clause. These mitigation actions will include as a minimum those listed in the TMA Breach Notification Standard Operating Procedure (SOP), which is available at:

http://www.tricare.mil/tmaprivacy/breach.cfm

(f) The Contractor shall report to the Government any security incident involving protected health information of which it becomes aware.

(g) The Contractor shall report to the Government any use or disclosure of the PHI not provided for by this Award of which the Contractor becomes aware.

(h) The Contractor shall ensure that any agent, including a sub-Contractor, to whom it provides PHI received from, or created or received by the Contractor on behalf of the Government, agrees to the same restrictions and conditions that apply through this Contract to the Contractor with respect to such information.

(i) The Contractor shall ensure that any agent, including a sub-Contractor, to whom it provides electronic Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.

(j) The Contractor shall provide access, at the request of the Government, and in the time and manner designated by the Government to PHI in a Designated Record Set, to the Government or, as directed by the Government, to an individual in order to meet the requirements under 45 CFR 164.524.

(k) The Contractor shall make any amendment(s) to PHI in a Designated Record Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government or an Individual, and in the time and manner designated by the Government.

(l) The Contractor shall make internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by the Contractor on behalf of, the Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner designated by the Government or the Secretary, for purposes of the Secretary determining the Government’s compliance with the Privacy Rule.

(m) The Contractor shall document such disclosures of PHI and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR 164.528.

(n) The Contractor shall provide to the Government or an Individual, in time and manner designated by the Government, information collected in accordance with this Clause of the Contract, to permit the Government to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR 164.528.

General Use and Disclosure Provisions Except as otherwise limited in this Clause, the Contractor may use or disclose PHI on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of PHI would not violate the Privacy Rule, the Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the Government.

Specific Use and Disclosure Provisions

(a) Except as otherwise limited in this Clause, the Contractor may use Protected Health Information for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor.

(b) Except as otherwise limited in this Clause, the Contractor may disclose Protected Health Information for the proper management and administration of the Contractor, provided that disclosures are required by law, or the Contractor obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Contractor of any instances of which it is aware in which the confidentiality of the information has been breached.

(c) Except as otherwise limited in this Clause, the Contractor may use PHI to provide Data Aggregation services to the Government as permitted by 45 CFR 164.504(e)(2)(i)(B).

(d) Contractor may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).

Obligations of the Government Provisions for the Government to Inform the Contractor of Privacy Practices and Restrictions

(a) Upon request the Government shall provide the Contractor with the notice of privacy practices that the Government produces in accordance with 45 CFR 164.520, as well as any changes to such notice.

(b) The Government shall provide the Contractor with any changes in, or revocation of, permission by Individual to use or disclose PHI, if such changes affect the Contractor's permitted or required uses and disclosures.

(c) The Government shall notify the Contractor of any restriction to the use or disclosure of PHI that the Government has agreed to in accordance with 45 CFR 164.522.

Permissible Requests by the Government The Government shall not request the Contractor to use or disclose Protected Health Information (PHI) in any manner that would not be permissible under the Privacy Rule if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this clause.

Termination

(a) Termination. A breach by the Contractor of this clause, may subject the Contractor to termination under any applicable default or termination provision of this Contract.

(b) Effect of Termination.

(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below

(2) If this PWS does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Contractor shall return or destroy all Protected Health Information received from the Government, or created or received by the Contractor on behalf of the Government.

This provision shall apply to Protected Health Information that is in the possession of sub-Contractors or agents of the Contractor. The Contractor shall retain no copies of the PHI.

(3) If this contract does not have records management provisions and the Contractor determines that returning or destroying the Protected Health Information is infeasible, the Contractor shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Contractor that return or destruction of PHI is infeasible, the Contractor shall extend the protections of this Contract to such PHI and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such PHI.

Miscellaneous

(a) Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule means the section as in effect or as amended, and for which compliance is required.

(b) Survival. The respective rights and obligations of Business Associate under the “Effect of Termination'' provision of this Clause shall survive the termination of this Contract.

(c) Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the Government to comply with DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule

1.6.4.5.5 Public Key Infrastructure Authentication and Encryption.

Contractors shall follow the DoD standards, policies, and procedures related to the use of Public Key Infrastructure (PKI) certificates and biometrics for positive authentication including authentication to DoD private web servers or applications. Where interoperable PKI is required for the exchange of unclassified information, including the encryption of e-mail containing sensitive information, between DoD and its vendors and Contractors, industry partners shall obtain all necessary certificates if they are not eligible for a DoD Common Access Card. (refer to http://iase.disa.mil/pki/eca/ and http://www.cac.mil/).

1.6.4.6 Access Requirements

1.6.4.6.1 Contractor access to HA/TMA Network/DoD Systems

The TMA Personnel Security Office website at http://tricare.mil/tma/aboutTMA/oa/psd/adpit.aspx contains guidance regarding Contractor access to the HA/TMA Network/DoD Systems.

The Contractor shall contact the COR after being awarded a contract if access to a DoD system is required. The Contractor is responsible for submitting the SF85P and FD 258 for their respective Contractor employees if the Contractor employees are required to gain access to a DoD system for performance of this contract. As such, Contractor personnel shall undergo appropriate background investigation (Trustworthiness Determination for Public Trust positions/ADP-IT) or have a security clearance and Information Assurance training if deemed necessary. The Contractor should be prepared for this process to take at least two (2) weeks.

Prior to the submission of the SF85P for new Contractor employees, the Contractor's Facility Security Officer (FSO) shall submit the contract number, contract start date, contract end date, personnel names, and the ADP position designations, to the designated COTRs for verification and approval with a list of personnel being submitted for an ADP/IT Trustworthiness Determination. The Contractor’s FSO shall submit all appropriate forms as provided by the COTRs to request a background investigation to the Office of Personnel Management (OPM) and obtain receipt confirmation as a prerequisite for Contractor personnel to access DoD systems. The Standard Form 85P is available at: http://www.tricare.osd.mil/tmapivacy/sf85p.pdf.

The Contracting company shall ensure all Contractor personnel are designated as ADP/IT-I, ADP/IT-II where their duties meet the criteria of the position sensitivity designations.

The Contractor must notify the COR and COTRs when the security officer has submitted the SF85P user form to OPM for new employees. Upon termination of a Contractor employee from the contract, the Contractor’s FSO must notify the COR and COTRs and OPM of the action, including the termination date. In both cases, the COR or the COTR must notify the Deputy Director, TMA Privacy Office at Pamela.Schmidt@tma.osd.mil. All emails should be sent using CAC encryption.

Non-U.S. Citizens - Only United States citizens shall be granted a personnel security clearance, assigned to sensitive duties, or granted access to classified information unless approved by an authority. Exceptions to these requirements shall be permitted only for compelling national security reasons. (DoD 5200.2-R. C2.1.1, AP6.6.1) Non-U.S. citizens are not being adjudicated by any government agency for a trustworthiness determination at this time. Non-U.S. Citizens are not allowed access to any DoD systems/networks.

The Contractor shall ensure that data which contains PHI is continuously protected from unauthorized access, use, modification, or disclosure. The Contractor shall comply with all previously stated requirements for HIPAA, Personnel Security, Electronic Security, and Physical Security.

Termination of access - Upon termination of a Contractor employee the Contractor Point of Contact shall forward a request to have the employee deleted from DoD system access to the COR and COTRs.

1.6.4.6.2 Contractor Access to Classified Information

The Contractor will require access to classified data to perform this task. See DD Form 254 attached.

1.6.4.7 Development

All telecommunications network designs shall make maximum use of existing telecommunications infrastructure.

All MHS system modifications and new development shall comply with the latest version of the DoD Joint Technical Architecture and any other applicable DoD and MHS technical standards and policies. The goal of the MHS architectural framework is to use the Defense Information Infrastructure Common Operating Environment (DII COE) to support the MHS, as required. The MHS will emphasize both software reuse and interoperability and incorporate the DII COE standards as applicable. All new systems development and new development in deployed migration systems will use DoD data standards in accordance with PDASD – HA policy memo, “Use of DoD Standards in MHS Migration Systems,” of 11 March 1996.

1.6.4.8 Section 508 Requirement

The Contractor shall comply with Section…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .