HT0011-14-R-0021-OHI_RFP.pdf

PDF 501 KB Posted

Attached to
Other Health Insurance Federal contract opportunity
Solicitation number
HT0011-14-R-0021
Issued by
Defense Health Agency

About this file

OHI request for proposal is attached.

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

HT0011-14-R-0021 22-May-2014

b. TELEPHONE NUMBER 8. OFFER DUE DATE/LOCAL TIME

12:00 AM 30 Jun 2014

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

HT00119. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

0 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED OR X

SMALL BUSINESSX

WOMEN-OWNED SMALL

BUSINESS (WOSB)

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

DEFENSE HEALTH AGENCY

7700 ARLINGTON BLVD

FALLS CHURCH VA 22042

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE HT0003 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

DEFENSE HEALTH AGENCY

VICKIE LAPERLE

DHHQ BUILDING

7700 ARLINGTON BLVD, SUITE 5101

FALLS CHURCH VA 22042-5101

TEL: 703-681-0062 FAX:

FAX:

TEL: 703-681-1143 SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

ECONOMICALLY DISADVANTAGED

WOMEN-OWNED SMALL BUSINESS

(EDWOSB)

SIZE STANDARD:

14.0

NAICS:

541611

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF119

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

Section SF 1449 - CONTINUATION SHEET

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 2 Months Transition In/Incoming Transition

FFP

60 Days Incoming transition Period. Defense Manpower Data Center (DMDC) Setup Maintenance.

FOB: Destination

NET AMT

0002 100 Thousand Identification of New OHI Discoveries

FFP

0-100K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

0003 49 Thousand Identification of New OHI Discoveries

FFP

101-150K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

0004 49 Thousand Identification of New OHI Discoveries

FFP

150-200K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

0005 99 Thousand Identification of New OHI Discoveries

FFP

201-300K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

0006 99 Thousand Identification of New OHI Discoveries

FFP

301-400K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

0007 35 Thousand validation of Existing OHI

FFP

0-35K (Estimated Workload Data). Technical Exhibit 4 of PWS.

0008 34 Thousand validation of Existing OHI

FFP

36-70K (Estimated Workload Data). Technical Exhibit 4 of PWS.

0009 35 Thousand validation of Existing OHI

FFP

71-106K (Estimated Workload Data). Technical Exhibit 4 of PWS.

0010 35 Thousand validation of Existing OHI

FFP

107-142K (Estimated Workload Data). Technical Exhibit 4 of PWS.

0011 35 Thousand validation of Existing OHI

FFP

143-178K (Estimated Workload Data). Technical Exhibit 4 of PWS.

0012 12 Months Prefessional Services

FFP

Program Manager (1880 hours)

0013 12 Months

ODC

FFP

ODC accordance with PWS.

0014 12 Months Travel

COST

Travel

ESTIMATED COST

1002 100 Thousand OPTION Identification of New OHI Discoveries

FFP

0-100K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

1003 49 Thousand OPTION Identification of New OHI Discoveries

FFP

101-150K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

1004 49 Thousand OPTION Identification of New OHI Discoveries

FFP

150-200K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

1005 99 Thousand OPTION Identification of New OHI Discoveries

FFP

201-300K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

1006 99 Thousand OPTION Identification of New OHI Discoveries

FFP

301-400K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

1007 52 Thousand OPTION validation of Existing OHI

FFP

0-52K (Estimated Workload Data). Technical Exhibit 4 of PWS.

1008 52 Thousand OPTION validation of Existing OHI

FFP

53-105K (Estimated Workload Data). Technical Exhibit 4 of PWS.

1009 52 Thousand OPTION validation of Existing OHI

FFP

106-158K (Estimated Workload Data). Technical Exhibit 4 of PWS.

1010 52 Thousand OPTION validation of Existing OHI

FFP

159-211K (Estimated Workload Data). Technical Exhibit 4 of PWS.

1011 52 Thousand OPTION validation of Existing OHI

FFP

212-264K (Estimated Workload Data). Technical Exhibit 4 of PWS.

1012 12 Months OPTION Prefessional Services

FFP

1013 12 Months

OPTION ODC

FFP

1014 12 Months OPTION Travel

COST

2002 20 Thousand OPTION Identification of New OHI Discoveries

FFP

0-20K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

2003 20 Thousand OPTION Identification of New OHI Discoveries

FFP

21-41K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

2004 20 Thousand OPTION Identification of New OHI Discoveries

FFP

42-62K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

2005 20 Thousand OPTION Identification of New OHI Discoveries

FFP

63-83K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

2006 20 Thousand OPTION Identification of New OHI Discoveries

FFP

84-104K Discoveries(Estimated Workload Data). Technical Exhibit 4 of PWS.

2007 38 Thousand OPTION validation of Existing OHI

FFP

0-38K (Estimated Workload Data). Technical Exhibit 4 of PWS.

2008 38 Thousand OPTION validation of Existing OHI

FFP

39-77K (Estimated Workload Data). Technical Exhibit 4 of PWS.

2009 38 Thousand OPTION validation of Existing OHI

FFP

78-116K (Estimated Workload Data). Technical Exhibit 4 of PWS.

2010 38 Thousand OPTION validation of Existing OHI

FFP

117-155K (Estimated Workload Data). Technical Exhibit 4 of PWS.

2011 38 Thousand OPTION validation of Existing OHI

FFP

156-194K (Estimated Workload Data). Technical Exhibit 4 of PWS.

2012 12 Months OPTION Prefessional Services

FFP

2013 12 Months

OPTION ODC

FFP

2014 12 Months OPTION Travel

COST

3002 20 Thousand OPTION Identification of New OHI Discoveries

FFP

3003 20 Thousand OPTION Identification of New OHI Discoveries

FFP

3004 20 Thousand OPTION Identification of New OHI Discoveries

FFP

3005 20 Thousand OPTION Identification of New OHI Discoveries

FFP

3006 20 Thousand OPTION Identification of New OHI Discoveries

FFP

3007 38 Thousand OPTION validation of Existing OHI

FFP

3008 38 Thousand OPTION validation of Existing OHI

FFP

39 -77K (Estimated Workload Data). Technical Exhibit 4 of PWS.

3009 38 Thousand OPTION validation of Existing OHI

FFP

3010 38 Thousand OPTION validation of Existing OHI

FFP

3011 38 Thousand OPTION validation of Existing OHI

FFP

3012 12 Months OPTION Prefessional Services

FFP

3013 12 Months

OPTION ODC

FFP

3014 12 Months OPTION Travel

COST

4002 20 Thousand OPTION Identification of New OHI Discoveries

FFP

4003 20 Thousand OPTION Identification of New OHI Discoveries

FFP

4004 20 Thousand OPTION Identification of New OHI Discoveries

FFP

4005 20 Thousand OPTION Identification of New OHI Discoveries

FFP

4006 20 Thousand OPTION Identification of New OHI Discoveries

FFP

4007 38 Thousand OPTION validation of Existing OHI

FFP

4008 38 Thousand OPTION validation of Existing OHI

FFP

39-77K (Estimated Workload Data). Technical Exhibit 4 of PWS.

4009 38 Thousand OPTION validation of Existing OHI

FFP

4010 38 Thousand OPTION validation of Existing OHI

FFP

4011 38 Thousand OPTION validation of Existing OHI

FFP

4012 12 Months OPTION Prefessional Services

FFP

4013 12 Months

OPTION ODC

FFP

4014 12 Months OPTION Travel

COST

4015 2 Months OPTION TransitionOut

FFP

60 Days Transition out

INSPECTION AND ACCEPTANCE TERMS

Supplies/services will be inspected/accepted at:

CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY

0001 Destination Government Destination Government 0002 Destination Government Destination Government 0003 Destination Government Destination Government 0004 Destination Government Destination Government 0005 Destination Government Destination Government 0006 Destination Government Destination Government 0007 Destination Government Destination Government 0008 Destination Government Destination Government 0009 Destination Government Destination Government 0010 Destination Government Destination Government 0011 Destination Government Destination Government 0012 Destination Government Destination Government 0013 Destination Government Destination Government 0014 Destination Government Destination Government 1002 Destination Government Destination Government 1003 Destination Government Destination Government 1004 Destination Government Destination Government 1005 Destination Government Destination Government 1006 Destination Government Destination Government 1007 Destination Government Destination Government 1008 Destination Government Destination Government 1009 Destination Government Destination Government 1010 Destination Government Destination Government 1011 Destination Government Destination Government 1012 Destination Government Destination Government 1013 Destination Government Destination Government 1014 Destination Government Destination Government 2002 Destination Government Destination Government 2003 Destination Government Destination Government 2004 Destination Government Destination Government 2005 Destination Government Destination Government 2006 Destination Government Destination Government 2007 Destination Government Destination Government 2008 Destination Government Destination Government 2009 Destination Government Destination Government 2010 Destination Government Destination Government 2011 Destination Government Destination Government 2012 Destination Government Destination Government 2013 Destination Government Destination Government 2014 Destination Government Destination Government 3002 Destination Government Destination Government 3003 Destination Government Destination Government 3004 Destination Government Destination Government 3005 Destination Government Destination Government 3006 Destination Government Destination Government 3007 Destination Government Destination Government 3008 Destination Government Destination Government 3009 Destination Government Destination Government 3010 Destination Government Destination Government

3011 Destination Government Destination Government 3012 Destination Government Destination Government 3013 Destination Government Destination Government 3014 Destination Government Destination Government 4002 Destination Government Destination Government 4003 Destination Government Destination Government 4004 Destination Government Destination Government 4005 Destination Government Destination Government 4006 Destination Government Destination Government 4007 Destination Government Destination Government 4008 Destination Government Destination Government 4009 Destination Government Destination Government 4010 Destination Government Destination Government 4011 Destination Government Destination Government 4012 Destination Government Destination Government 4013 Destination Government Destination Government 4014 Destination Government Destination Government 4015 Destination Government Destination Government

DELIVERY INFORMATION

CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS UIC

0001 POP 01-AUG-2014 TO

30-SEP-2014

N/A DEFENSE HEALTH AGENCY

VICKIE LAPERLE

DHHQ BUILDING

7700 ARLINGTON BLVD, SUITE 5101

FALLS CHURCH VA 22042-5101

703-681-0062

HT0003

0002 POP 01-AUG-2014 TO

31-JUL-2015

N/A (SAME AS PREVIOUS LOCATION)

0003 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0004 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0005 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0006 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0007 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0008 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0009 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0010 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0011 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0012 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0013 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

0014 POP 01-AUG-2014 TO

N/A (SAME AS PREVIOUS LOCATION)

1002 POP 01-AUG-2015 TO

31-JUL-2016

N/A (SAME AS PREVIOUS LOCATION)

1003 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1004 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1005 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1006 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1007 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1008 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1009 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1010 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1011 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1012 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1013 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

1014 POP 01-AUG-2015 TO

N/A (SAME AS PREVIOUS LOCATION)

2002 POP 01-AUG-2016 TO

31-JUL-2017

N/A (SAME AS PREVIOUS LOCATION)

2003 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2004 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2005 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2006 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2007 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2008 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2009 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2010 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2011 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2012 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2013 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

2014 POP 01-AUG-2016 TO

N/A (SAME AS PREVIOUS LOCATION)

3002 POP 01-AUG-2017 TO

31-JUL-2018

N/A (SAME AS PREVIOUS LOCATION)

3003 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3004 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3005 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3006 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3007 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3008 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3009 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3010 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3011 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3012 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3013 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

3014 POP 01-AUG-2017 TO

N/A (SAME AS PREVIOUS LOCATION)

4002 POP 01-AUG-2018 TO

31-MAY-2019

N/A (SAME AS PREVIOUS LOCATION)

4003 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4004 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4005 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4006 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4007 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4008 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4009 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4010 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4011 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4012 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4013 POP 01-AUG-2018 TO

31-JUL-2019

N/A (SAME AS PREVIOUS LOCATION)

4014 POP 01-AUG-2018 TO

N/A (SAME AS PREVIOUS LOCATION)

4015 POP 01-JUN-2019 TO

N/A (SAME AS PREVIOUS LOCATION)

CLAUSES INCORPORATED BY REFERENCE

52.203-3 Gratuities APR 1984 52.204-9 Personal Identity Verification of Contractor Personnel JAN 2011 52.204-10 Reporting Executive Compensation and First-Tier

Subcontract Awards

JUL 2013

52.209-7 Information Regarding Responsibility Matters JUL 2013 52.212-4 Contract Terms and Conditions--Commercial Items MAY 2014 52.217-5 Evaluation Of Options JUL 1990 52.222-37 Employment Reports on Veterans SEP 2010 52.223-18 Encouraging Contractor Policies To Ban Text Messaging

While Driving

AUG 2011

252.201-7000 Contracting Officer's Representative DEC 1991 252.203-7002 Requirement to Inform Employees of Whistleblower Rights SEP 2013 252.203-7005 Representation Relating to Compensation of Former DoD

Officials

NOV 2011

252.205-7000 Provision Of Information To Cooperative Agreement Holders DEC 1991 252.209-7001 Disclosure of Ownership or Control by the Government of a

Terrorist Country

JAN 2009

252.232-7003 Electronic Submission of Payment Requests and Receiving Reports

JUN 2012

PERFORMANCE WORK STATEMENT

HT0011-14-R-0021

PERFORMANCE WORK STATEMENT

IDENTIFICATION AND

VALIDATION OF OTHER HEALTH INSURANCE (OHI)

PERFORMANCE WORK STATEMENT (PWS)

Part 1

General Information

1. GENERAL: This is a non‐personal services contract to provide other health insurance (OHI) identification and validation support services. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, other items, and non‐personal services necessary to perform other health insurance identification and validation support services as defined in this Performance Work Statement except for those items specified as government furnished property and services. The contractor shall perform to the standards in this contract.

1.2 Background: The Department of Defense (DoD) uses commercial other health insurance (OHI) information in two ways. First, it ensures TRICARE is a secondary payer to any applicable third party insurance. Additionally, military treatment facilities (MTFs) operated by the Uniformed Services bill to and collect from commercial insurance companies for medical treatment provided to non‐active duty service member beneficiaries.

1.3 Objective: Obtain valid and timely commercial health insurance policy information regarding non‐active duty service member beneficiaries.

1.4 Scope: The Defense Health Agency (DHA) is looking to establish a service contract for health insurance identification and validation support for the DoD. The Contractor shall identify and validate billable other health insurance for non‐active duty service member beneficiaries that have no commercial health insurance information on file as well as validate and update existing OHI information stored in the OHI repository in the Defense Enrollment Eligibility Reporting System (DEERS) database.

The Government will provide the Contractor access to the data from DEERS in the form of an extract file to accomplish this task. The Contractor shall be responsible for maintaining the security of the data once received from the Government. Once the data is collected, the Contractor shall utilize the identified patient’s information to query various insurance databases and gather all relevant information regarding OHI for active duty family members, retirees, and retiree family members. The Contractor must comply with all the Health Insurance Portability and Accountability Act (HIPAA) standards enacted on 21 August 1996 as well as any pertinent DoD directives and subsequent legislation (ARRA/HITECH) related to privacy and security of patient information.

The Contractor must be able to search commercial health insurance carriers to include but not limited to Blue Cross/Blue Shield, Aetna, Mailhandlers, United, and OHI providers as well as pharmacy benefit managers/providers. The Contractor shall utilize their own existing OHI search engine(s) to identify OHI on the patients identified by the contractor. The Government shall only be billed for newly identified OHI information found on patients identified by the contractor. Only OHI data that was not previously identified by the Government will be considered as “new OHI discovery.”

1.5 Period of Performance: The period of performance shall be for one (1) Base Year of 12 months and four (4) 12‐month option years. The Period of Performance reads as follows:

Base Year: Date of Award – Date of Award + 12 Months (Including 60 days Incoming Transition) Option Year I – 12 Months Option Year II – 12 Months Option Year III –12 Months Option Year IV – 12 Months (Including 60 days Outgoing Transition)

1.6 Prior Experience: The contractor shall provide evidence (contract number, facility location, and dates of service) and demonstrate prior experience in utilizing extracted OHI data with contracts of this type and scope for U.S. Government/DoD medical facilities and/or commercial medical facilities or providers. This information shall include, but not limited to, the number of records evaluated/OHI identified, the type of OHI identified (major medical and/or pharmacy), the quality of the data provided, the percent of OHI information validated with commercial insurers and/or employers, types of formats used and provided back to the medical facility, and the type and number of clients serviced.

1.6 General Information

1.6.1 Quality Control: The contractor shall develop and maintain an effective quality control (QC) program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify retrospective billing opportunities from OHI files and initiate recovery. The Contractor shall compile a before and after report of findings and statistics of cost avoidance. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract. A Quality Control Plan (Deliverable #1) will be delivered with the Contractor’s proposal, within 5 days after contract award to the Contracting Officer (CO) and Contracting Officer

Representative (COR), and within 5 working days when changes are made thereafter to the CO and COR. After acceptance of the quality control plan the Contractor shall receive the CO’s acceptance in writing of any proposed change to his QC system.

1.6.2 Quality Assurance: The government shall evaluate the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.6.3 Contractor Availability: Key contractor personnel are expected to be available between the hours of 8:00 a.m. to 4:00 p.m., Eastern time Monday through Friday except Federal holidays.

1.6.4 Place of Performance: The work to be performed under this contract will be performed at the Contractor’s facility.

1.6.5 Type of Contract: The government will award a firm fixed price contract single task order using Government‐Wide Acquisition Contract (GWAC).

1.6.6 Security Requirements: Contractor personnel performing work under this contract must apply for ADP/IT II clearance at time of contract award, and must maintain this level of security for the life of the contract. See Attachment 7/Technical Exhibit 7 for ADP/IT II procedures and requirements

1.6.7 Physical Security: The Contractor shall be responsible for safeguarding all government information provided for contractor use.

1.6.8 Non‐Disclosure / Non‐Use Agreement:

The Contractor shall ensure that the Non‐Disclosure Statement (Deliverable 2 at Attachment 6) is signed by all staff performing work on this contract prior to performing any work under this contract. The Non‐Disclosure / Non‐Use statement shall be cosigned by a responsible corporate official. The Contractor shall also ensure that all staff understand and adhere to the terms of the non‐disclosure statement, protect any procurement sensitive information of the Government and any proprietary information of other contractors. Assignment of staff who have not executed this statement or failure to adhere to this statement shall constitute default on the part of the Contractor.

1.6.9 General Security Requirements:

The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of

Government data. As a minimum, this shall include provisions for personnel security, electronic security and physical security as listed in the sections that follow:

1.6.9.1 System Security

The Contractor shall implement and maintain information security in its project, enterprise, or company‐wide unclassified information technology system(s) in accordance with the requirements set forth in DoD Instruction 8582.0 I, Security of Unclassified DoD Information on Non‐DoD Information Systems, June 6, 2012. The Contractor shall, at a minimum, comply with the security controls specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800‐53, Revision 3, dated August 2009, Privacy Act Program Requirements (DoD 5400, 11‐R), the Personnel Security Program (DoD 5200.2‐R) and OMB M‐06‐16, Protection of Sensitive Agency Information. In addition, the Contractor shall comply with DoD Minimum security requirements as outlined in the TRICARE Systems Manual, Chapter 1, Section

1.1 (except for paragraphs 3.4 and 3.5 through 3.5.1.7). Government validation of the Checklist and Certification for Minimum Level of Enhanced Safeguarding for Unclassified DoD Information (Deliverable #3 as shown in Attachment 8) is required prior to accessing DoD data or inter‐connectivity with the Government systems and testing. If a control is not implemented, the Contractor shall prepare a written determination (Deliverable 4 as shown in Attachment 9) that explains how either the required security control is not applicable or how an alternative control or protective measure is used to achieve equivalent protection in accordance with the Contract Deliverable Requirements List (CDRL) (Attachment 9). For inspection purposes, at the Government's direction the Contractor will provide a NIST certification briefing at a designated Government location, presenting an overview of its certification efforts.

1.6.9.2 The NIST requirements apply to the Contractor, subcontractors, and business partners, as specified in 1.6.9.1 that perform functions such as program/business management, where the program/business management function requires the use of DoD/TRICARE data, beneficiary enrollment eligibility, verification, etc.

1.6.9.3 Personally Identifiable Information (PII), Protected Health Information, and Federal Information Requirements

1.6.9.3.1 General Requirements Overview ‐ Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Privacy and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and DoD issuances. In general, the Contractor shall comply with the specific requirements set forth in this section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.

This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.

For purposes of this Section, the following definitions apply.

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11‐R (2007)

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C‐D (Enforcement), as amended by the 2013 modifications to those Rules, 78 FR 5566‐ 5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18‐R (2003), DoDI 6025.18 (2009), and DoD 8580.02‐R (2007).

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of a breach in 45

CFR 164.402.

1.6.9.3.2 Records Management

When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 USC Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DOD AI‐15), “OSD Records and Information Management Program” (2013).

1.6.9.3.3 Freedom of Information Act (FOIA)

The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:

The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042‐5101 (or email requests addressed to FOIARequests@tma.osd.mil), and that the request shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible.

In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference the Freedom of Information Act shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between DHA contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.

1.6.9.3.4 Systems of Records

In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy and Civil Liberties Office, and as required by the DoD Privacy Act Issuances.

Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99‐05, Attachment B, and OMB Circular A‐130. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.

1.6.9.3.5 Privacy Impact Assessment (PIA)

The Contractor shall provide for the completion of a PIA for any applicable systems that collect, maintain, use or disseminate PII or PHI about members of the public, federal personnel, contractors, or in some cases foreign nationals. The Contractor shall establish practices that satisfy the requirements of DoDI 5400.16, “DoD Privacy Impact Assessment (PIA) Guidance,” February 12, 2009.

To begin the PIA process, the Contractor shall use the DoD‐approved PIA Template, DD Form 2930. The Contractor shall use the DHA PIA Guide to complete the DD Form 2930. The Contractor should send completed DD Form 2930s to the DHA Privacy Office for review and approval, with a copy to the CO (Deliverable 5 at Attachment 10), no later than 5 calendar days after contract award.

1.6.9.3.6 Data Sharing Agreement (DSA)

The Contractor shall consult with the DHA Privacy Office to determine if the Contractor must obtain a Data Sharing Agreement (DSA) or Data Use Agreement (DUA), when MHS data that is managed by DHA will be accessed, used, disclosed or stored, to perform the requirements of this Contract. The Contractor shall comply with requests for additional documentation by the DHA Privacy Board when requesting PHI for research. In addition, the Contractor shall submit any research requests for MHS data that include PHI to the DHA Privacy Board in order to be reviewed for HIPAA compliance.

The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and the DoD HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.

To begin the data sharing request process, the Contractor shall submit a Data Sharing Agreement Application (DSAA) (Deliverable 6 at Attachment 11) to the DHA Privacy Office as required. If the application is approved, the requestor shall enter into one of the following agreements, depending on the data involved:

� DSA for De‐Identified Data � DSA for PHI � DSA for PII Without PHI � Data Use Agreement for Limited Data Set.

DSAs are active for one year, or until the end of the current option year, whichever comes first.

If the DSA will not be renewed, the Contractor shall provide a Certificate of Data Disposition (CDD) to the DHA Privacy Office.

1.6.9.3.7 Privacy Act and HIPAA Training

The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, the Alcohol, Drug Abuse and Mental Health Administration (ADAMHA) Reorganization Act, 42 USC 290dd‐2, and the ADAMHA implementing regulations, 42 CFR Part 2.

The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter (Deliverable 7).

1.6.9.3.8 HIPAA Business Associate Provisions

1.6.9.3.8.1 Business Associate – General Provisions

The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. This paragraph serves as the required BAA. As a Business Associate, the Contractor shall comply with the HIPAA Rules and the DoD HIPAA Issuances applicable to a business associate performing under this Contract.

1.6.9.3.8.1.1 Catch‐All Definition: The following terms used, but not otherwise defined in paragraph 1.6.9.4.8, shall have the same meaning as those terms have in the DoD HIPAA Issuances: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information (Unsecured PHI), and Use.

1.6.9.3.8.1.2 The Contractor shall not use, sell, or further disclose PHI other than as permitted or required by the Contract or as required by law.

1.6.9.3.8.1.3 The Contractor shall use appropriate safeguards, and comply with the HIPAA Security Rule with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Contract

1.6.9.3.8.1.4 The Contractor shall report to DHA any breach of which it becomes aware, and shall proceed with breach response steps as required by Paragraph 1.6.9.3.9. With respect to electronic PHI, the Contractor shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of this Contract. If at any point the Contractor becomes aware that a security incident involves a breach, the contractor shall immediately initiate breach response as required by paragraph 1.6 9.3.9.

1.6.9.3.8.1.5 In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), the Contractor shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Contractor agree to the same restrictions, conditions, and requirements that apply to the Contractor with respect to such PHI.

1.6.9.3.8.1.6 With respect to individual rights of access to PHI, the Contractor shall make available PHI in a designated record set to the individual or the individual’s designee as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding 45 CFR 164.524. If the Contractor intends to deny the individual’s request, the Contractor shall forward it (within seven working days of receipt) to the CO. The CO shall make a determination within 20 calendar days (50 calendar days for justified delays) of the request. The CO shall notify the individual, with a copy to the Contractor, of any approved or denied access determinations and the reason for any denial. The individual may appeal the denial determination to the DHA Privacy Office.

1.6.9.3.8.1.7 The Contractor shall make any amendment(s) to PHI in a designated record set as directed or agreed to by DHA, or take other measures as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding 45 CFR 164.526.

1.6.9.3.8.1.8 The contractor shall maintain and make available to the Government the information required to provide an accounting of disclosures to the MHS or to the individual as necessary to satisfy DHA’s obligations under the DoD HIPAA Issuances and the corresponding

45 CFR 164.528.

1.6.9.3.8.1.9 To the extent the Contractor is to carry out one or more of DHA’s obligation(s) under the HIPAA Rules, the Contractor shall comply with the requirements of the HIPAA Rules.

1.6.9.3.8.1.10 The Contractor shall make its internal practices, books, and records available to the HHS Secretary for purposes of determining compliance with the HIPAA Rules.

1.6.9.3.8.2 Permitted Uses and Disclosures

1.6.9.3.8.2.1 General Use and Disclosure Provisions

The Contractor may only use or disclose PHI as necessary to perform the services set forth in this Contract or as required by law. The Business Associate is not permitted to de‐identify PHI under DoD HIPAA Issuances or the corresponding 45 CFR 164.514(a)‐(c), nor is it permitted to use or disclose de‐identified PHI, except as provided by the Contract or directed by DHA. The Contractor agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances. The Contractor shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the covered entity, except uses and disclosures for the Contractor’s own management and administration and legal responsibilities or for data aggregation services as set forth in paragraphs 1.6.9.4.8.2.2.1 – 1.6.9.4.2.2.3.

1.6.9.3.8.2.2 Specific Use and Disclosure Provisions

1.6.9.3.8.2.2.1 Except as otherwise limited in this Section, the Contractor may use PHI for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

1.6.9.3.8.2.2.2 Except as otherwise limited in this Section, the Contractor may disclose PHI for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor, provided that disclosures are required by law, or the Contractor obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Contractor of any instances of which it is aware in which the confidentiality of the information has been breached.

1.6.9.3.8.2.2.3 Except as otherwise limited in this Section, the Contractor may use PHI to provide Data Aggregation services relating to DHA’s health care operations.

1.6.9.3.8.3 Contractor Compliance with DHA Notices and Restrictions

1.6.9.3.8.3.1 Upon request, DHA will provide the Contractor with the notice of privacy practices that DHA produces in accordance with the DoD HIPAA Issuances and the corresponding 45 CFR 164.520.

1.6.9.3.8.3.2 Upon notification by DHA of any changes in, or revocation of, permission by an Individual to use or disclose his or her PHI, the Contractor shall comply to the extent that such changes may affect the Contractor’s use or disclosure of PHI.

1.6.9.3.8.3.3 Upon notification by DHA, the Contractor shall comply with any restriction on the use or disclosure of PHI that the Government has agreed to or is required to abide by under the DoD HIPAA Issuances or the corresponding 45 CFR 164.522 , to the extent that such restriction may affect Contractor’s use or disclosure of PHI.

1.6.9.3.8.4 Permissible Requests by DHA

The Government will not request the Contractor to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this Contract.

1.6.9.3.8.5 Termination

1.6.9.3.8.5.1 Effect of Noncompliance

Noncompliance by the Contractor (or any of its staff, agents, or subcontractors) with any requirement in these HIPAA Business Associate Provisions may subject the Contractor to termination under any applicable default or other termination provision of this Contract.

1.6.9.3.8.5.2 Effect of Termination.

1.6.9.3.8.5.2.1 If this Contract has records management requirements, the Contractor shall handle such records in accordance with the records management requirements. If this Contract does not have records management requirements, the Contractor shall handle such records in accordance with paragraphs 1.6.9.4.8.5.2.2 and 1.6.9.4.8.2.3 below. If this Contract has provisions for transfer of records and PII/PHI to a successor contractor, or if DHA gives directions for such transfer, the Contractor shall handle such records and information in accordance with such Contract provisions or DHA direction.

1.6.9.3.8.5.2.2 If this contract does not have records management requirements, except as provided in paragraph 1.6.9.4.8.5.2.3 below, upon termination of the Contract, for any reason, the Contractor shall return or destroy all PHI received from the Government, or created or received by the Contractor on behalf of the Government that the Contractor still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Contractor. The Contractor shall retain no copies of the PHI.

1.6.9.3.8.5.2.3 If this Contract does not have records management provisions and the Contractor determines that returning or destroying the PHI is infeasible, the Contractor shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Contractor that return or destruction of PHI is infeasible, the Contractor shall extend the protections of the Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such PHI.

1.6.9.3.8.6 Miscellaneous

1.6.9.3.8.6.1 Survival. The obligations of the Contractor under the “Effect of Termination” provision of paragraph 1.6.9.3.8.5.2 shall survive the termination of this Contract.

1.6.9.3.8.6.2 Interpretation. Any ambiguity in this Contract shall be interpreted in a manner to permit compliance with the HIPAA Rules and the DoD HIPAA Issuances.

1.6.9.3.9. Breach Response

In the event of a breach of PII/PHI by the Contractor, the Contractor shall follow the breach response requirements set forth in this paragraph, which are designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves only PII, then the Contractor shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Contractor shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Contractor has no HIPAA breach response obligations. In such cases, the Contractor must still comply with breach response requirements under the DoD Privacy Act Issuances.

If the DHA Privacy Office determines that a breach is an HHS Breach, then the Contractor shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the Privacy Office, regardless of whether the breach occurs at DHA or at one of the Service components. If the Privacy Office determines that the breach does not constitute an HHS Breach, then the Contractor shall comply with DoD Privacy Act Issuances, as directed by the Privacy Office.

The following provisions of this paragraph set forth the Contractor’s Privacy Act and HIPAA breach response requirements for DHA breaches, including but not limited to HHS breaches.

For other breaches not involving the DHA Privacy Office (i.e., Privacy Act‐only breaches occurring at a Service‐level component), the Contractor shall follow the directions of the Service‐Level Privacy Office.

The Contractor shall comply with all breach response requirements set forth in this paragraph.

In general, for breach response, the Contractor shall report the breach to the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .