DAS Revised PWS_08122024.docx

DOCX document 182 KB Posted

Attached to
In-Building Cellular Distributed Antenna System (DAS) Federal contract opportunity
Solicitation number
HT001424R0025
Issued by
Defense Health Agency

About this file

This document is a Performance Work Statement (PWS) for the operation and maintenance of the in-building cellular distributed antenna system (DAS) at the Walter Reed National Military Medical Center (WRNMMC) and Dalecarlia locations.

The key objectives of the PWS include providing 24/7 remote monitoring and on-call support, performing preventative and emergency maintenance, coordinating with cellular carriers, obtaining and maintaining the DHA Risk Management Framework (RMF) standalone authorization to operate, and training WRNMMC staff on the DAS platform. The contractor will be responsible for all design, planning, execution, implementation, installation, configuration, and testing of the DAS solution. The period of performance is five years from October 21, 2024 to October 20, 2029, with option years. The government will provide the existing DAS equipment, facilities, and utilities, while the contractor will furnish all other necessary items and services. The contractor must have industry certifications such as RCDD and BCSI, and adhere to DHA cybersecurity requirements.

View the file

Other files for this federal contract opportunity

Other files attached to In-Building Cellular Distributed Antenna System (DAS), newest first.
File Type Posted
2nd round Q and A_HT0014-24-R-0025.pdf PDF
Update PWS_HT0014-24-R-0025.pdf PDF
Special Notice Due Date Extension.pdf PDF
Special Notice 2nd round Question 08262024.pdf PDF
Special Notice - Site Visit.pdf PDF
WRNMMC Vendor Parking Request Form_DAS.pdf PDF
Q and A FOR DAS RFP HT001424R0025_ 08122024.docx DOCX document
DAS PWS Oand M v29 07252024.docx DOCX document
DAS Instructions to Offerors 07302024.docx DOCX document
HT0014-24-R-0025 RFP.pdf PDF
RFP HT001424R0025 - PPQ template.docx DOCX document
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense Defense Health Agency – Performance Work Statement – Operation & Maintenance of the WRNMMC In-Building Cellular Distributed Antenna System (DAS)

Walter Reed National Military Medical Center (WRNMMC) Directorate for Administration (DFA) Information Technology Department (ITD)

Solicitation Number:

Version:

Date:

PART 1

1.0 GENERAL INFORMATION

1.1 This is a non-personal services contract to provide Operation and Maintenance of an existing system. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.2 Description of services/introduction:

The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Operation & Maintenance of the WRNMMC In-Building Cellular Distributed Antenna System (DAS) at Bethesda and Dalecarlia Annex - Fremont Building, 6000 MacArthur Blvd, Betheda, Maryland 20816. as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this performance work statement.

Walter Reed National Military Medical Center (WRNMMC) requires services in the form of skilled technical engineers to provide both operational and maintenance support for the In-Building Cellular DAS at the Bethesda and Dalecarlia locations. Inherent in providing these services, the Contractor shall supply the management and operational resources necessary for efficient and effective administration, operation, maintenance and control of all duties to be performed pursuant to this Performance Work Statement (PWS).

Said duties shall include, but not be limited to, the maintenance and support of the Defense Health Agency (DHA) Risk Management Framework (RMF) accreditation Standalone Authorization to Operate (ATO) for the WRNMMC In-Building Cellular DAS at Bethesda and Dalecarlia.

The Contractor shall ensure adequate resources are dedicated to satisfy the requirements of all work assignments.

1.3 Background:

MISSION:

The mission of the Walter Reed National Military Medical Center is to maximize operational readiness and keep the uniformed services fit to fight, deliver quality primary and tertiary care in a customer focused environment, provide distinguished undergraduate and graduate medical education, professional education and research, develop and export innovations in healthcare services and informatics, and serve as the President’s Hospital. Walter Reed National Military Medical Center is recognized as the finest establishment in the world for the teaching and practice of military medicine and a center of excellence for ambulatory care, critical care, and women’s health.

VISION:

Walter Reed National Military Medical Center is America's academic health center and the global leader for military medical readiness, providing extraordinary care to those we are privileged to serve.

The DAS system, currently in sustainment, uses a fiber optic cable and coaxial cable-based DAS, which is fed by repeaters and base transceiver stations for 700/850/900/1700/1800/1900 and 2100 MHz cellular bands systems.

The incoming RF ‘donor’ signals for AT&T, Sprint, and Verizon (“carriers”) are received via coaxial cable connecting the base stations, located in the basement of Building 19 room B339 and outside of B339, to the head-end sub-racks, continuing through single mode composite fiber, connecting to Fiber Remote Units (FRUs) in the Telco closets, and ½ in. coaxial cables terminating with ceiling mounted indoor antennas.

The carrier T-Mobile (also a “carrier”) signal originates from a building 19 roof top donor antenna, through a repeater in Building 19 communications room 6102 and terminating in B339. The T-Mobile amplifier then provides RF signal via coaxial cable to the head-end sub-racks.

The head-end equipment comprises a sub rack located within Building 19 room B339. The head-end Master Units connect via single mode fiber strands to the (133) FRUs. One FRU is serving one to five antennas, depending on the specific cable installation. Each FRU power fed with a 48 VDC adapter.

The coaxial cable from the donor RF signal to the head-end equipment is as follows:

· Verizon = Originate from outside of Building 19 room B339

· AT&T = Originate from inside of Building 19 room B339

· T-Mobile/Sprint = Originate from inside of Building 19 room B339

The Covered Equipment chart provided in this PWS lists the specialized hardware, including specifications, that make up the In-Building Cellular DAS.

1.4 Objectives:

The Contractor shall be responsible to implement, configure, and support the entire In-Building Cellular DAS Solution to provide all the requirements as described in this PWS, to include providing and maintaining all hardware, software, and licenses necessary for every requirement in this PWS. Contractor proposals in response to this PWS shall describe any risks associated with the solicitation, including perceived problems with the requirements as described in the PWS as well as any risks associated with implementation of the offeror’s technical approach; describe any techniques and actions to mitigate such risks; and explain whether the techniques and actions identified for risk mitigation have been used previously by the Contractor with success. The Contractor shall provide any other information the Contractor considers relevant to the solicitation.

Contractor Solution proposed for In-Building Cellular DAS shall include the following top priority Objectives/Functions/Features for both WRNMMC and Dalecarlia locations:

1.4.1 Baseline Survey

1.4.2 Coordination with carriers

1.4.3 Assessment and Design

1.4.4 Implementation and Deployment

1.4.5 Documentation and Training

· Contractor shall provide documentation of all DAS System components as defined in this PWS and attachments.

· Documentation of all Solution components shall be provided as a record of what the Contractor intends to perform as a record and as a means to obtain the necessary government approvals.

· Training and enablement of the larger, cross-functional WRNMMC team on the In-Building Cellular DAS platform is critical to the long-term sustainment of the Solution with WRNMMC staff. The Contractor shall include classroom (Contractor-provided local facility and onsite at WRNNMC) and web-based training as part of the Solution.

· Development of a training calendar with personnel assignments shall be completed within the initial 30 days.

· Training shall include personnel from all applicable teams; patch management, imaging, inventory, etc.

1.4.6 Maintenance and Sustainment

· Perform all tasks and maintenance necessary to achieve and maintain In-Building Cellular DAS availability, functionality, security, and reliability targets. Leverage the built-in reporting tools and generate various reports to provide a consistent methodology on which to measure performance, compliance, configuration item status, history, ownership, cost and lifecycle.

1.4.7 Obtaining, Maintaining, and Supporting the DHA RMF Standalone Authorization to Operate (ATO)

· All Solution components not on the DOD JITC approved products list shall be specifically identified.

· All cryptographic modules of the Solution shall be FIPS 140-2 compliant.

· User and Administrator access to all Solution components shall be PKI compliant (see DoD Instruction 8520.2).

· Achieve Standalone RMF ATO compliance in accordance with Attachment 27 - DHA Stand Alone Authorization

1.5 Scope:

The scope of services for management and operation of the In-Building Cellular DAS includes all design, planning, execution, implementation, installing, configuring, and testing for all components of the In-Building Cellular DAS. The selected Contractor shall be responsible for the design of each phase of the project and shall require approval from WRNMMC stakeholders before implementing and before moving onto the next stage. The scope of work includes all necessary DHA Risk Management Framework (RMF) Standalone Authorization accreditation, service, administration, maintenance and support; provision of service and maintenance support including technical service and system maintenance; provision and maintenance of all necessary licensing and continuing system software revitalization; and continual full operational maintenance and sustainment of the Command’s In-Building Cellular DAS Services. The selected Contractor shall ensure it has adequate resources to accomplish the objectives and tasks of this PWS within the time allowed. Specific Tasks, Deliverables and Milestones are listed in the Work Requirements, Specific Tasks, Schedule/Milestones, and Deliverables Table sections of this PWS.

The In-Building Cellular DAS is a component of readiness, distance learning, telehealth and administrative activities at WRNMMC. The In-Building Cellular DAS serves to enhance communication and facilitate collaboration. Contractor shall implement a comprehensive information technology Solution for In-Building Cellular DAS encompassing the requirements and specifications delineated in this PWS.

WRNMMC requires the services detailed in this PWS in support of the equipment listed at the locations listed below in order to maximize cellular and radio frequency pager service coverage at WRNMMC while ensuring WRNMMC adherence to industry standards and best practice for wireless and RF technology, Telecommunications Industry Association (TIA) standards 568-C (Structured Cabling) and 1179 (Healthcare Facility Telecommunications Infrastructure).

See PART 5. SPECIFIC TASKS and other areas of this PWS for detailed descriptions of equipment and services.

1.6 Period of Performance (PoP):

In-Building Cellular DAS project duration is five years beginning October 21, 2024 and ending October 20th, 2029. All work shall be scheduled within this timeframe.

Base Period: Beginning October 21, 2024 and ending October 20th, 2025.

Option Year 1: Beginning October 21, 2025 and ending October 20th, 2026.

Option Year 2: Beginning October 21, 2026 and ending October 20th, 2027.

Option Year 3: Beginning October 21, 2027 and ending October 20th, 2028.

Option Year 4: Beginning October 21, 2028 and ending October 20th, 2029.

1.6.1 Transition: Transition-in/transition-out period

To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the phase in/ phase out periods. During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date.

1.6.1.1 Transition-in period.

Full performance start date is, November 21, 2024 Transition-in performance is defined as provision of seamless support of the system. During the transition-in period, the contractor shall prepare to meet all contract requirements and ensure incoming personnel are functionally trained and qualified on the full performance start. Any remaining incoming personnel shall be trained and qualified before beginning support of the system. If the incoming contractor partner is the incumbent prime contractor or has a partnership with the incumbent prime contractor which allows the continuation of the existing staff and support contracts, the contractor’s proposal shall not include a cost for the Transition-in Period. Full Performance is defined as meeting all contract requirements and performance targets, with all staff on-boarded, having obtained all necessary security clearance and CAC. Cybersecurity requirements must be fully adhered throughout the performance period. Specific requirements are included in great detail at various places in the PWS, including 1.11.7, 1.12, 6.4, 6.5, etc.

1.6.1.1.1 The contractor shall comply with transition-in requirements of the DHA, as listed in paragraph 1.11.1, for contractors needing to be issued Common Access Card (CAC) identification, including Department of Defense (DoD)- and DHA-directed training and forms submission, prior to network access.

1.6.1.2 Transition-out period. The transition-out plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract.

1.6.1.2.1 The contractor shall comply with transition-out requirements of the DHA for contractors who have been issued a CAC or who generate “records”, as defined by DoD (records manual), including DoD- directed disposition of records, and others displayed on the In/Out (I/O) Processing Portal.

1.7 Administrative specifications

1.7.1 Place of performance:

The work shall be performed at WRNMMC and Dalecarlia. The technical engineers are required to come onsite at the facility as necessary to attain all objectives of this PWS. Additionally, all project reviews for acceptance shall be held at WRNMMC, or virtually at the option of the COR.

Telework in general is not approved for this project. Telework may be an option for some Contractor personnel while performing certain tasks, when coordinated in advance and approved by the Contract Office Representative (COR).

1.7.2 Recognized Federal holidays: The Contractor is not required to perform work on Federal Holidays, except as needed for 24 hour on-call Incident Response.

New Year’s DayLabor Day
Martin Luther King Jr.’s BirthdayColumbus Day
President’s DayVeteran’s Day
Memorial DayThanksgiving Day
Juneteenth Day of ObservanceChristmas Day

Independence Day

1.7.3 Hours of operation:

· The Contractor shall provide 24/7/365 pro-active remote monitoring.

· The Contractor shall provide 24/7/365, on-call support and on-call-on-site support to resolve troubles identified as a result of proactive remote monitoring, or as the result of a trouble call placed by WRNMMC ITD. Response times shall be in accordance with the priority level defined in the Service Level Agreement section of this PWS.

· On-site calls are not limited to the normal day hours at WRNMMC (0700-1900), but are required 24/7/365 days per year.

· Routine, planned on-site maintenance should be scheduled for WRNMMC business hours, 0700 to 1900, Monday through Friday, excluding Federal Holidays.

· On-site night, Holiday and weekend support may be required for planned service interruptions, to minimize system downtime during peak hours and to resolve service issues.

· On-site night and weekend support shall be pre-scheduled when possible, but shall be supported on an on-call basis.

· The Contractor must maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS at all times except when the Government facility is closed. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce is essential.

1.7.3.1 Time Log Requirement: Reserved

1.7.4 Emergency Services: On occasion, services may be required to support an activation or exercise of contingency plans outside othe normal duty hours.

1.7.5 Conduct: Contractor personnel shall adhere to standards of conduct as established by the DHA Director.

1.7.6 Shipping:

All shipping charges are the responsibility of the Contractor. Shipping of materials needs to work in conjunction with the expectation of service as listed above.

1.7.7 Warranty:

The Contractor shall provide a full and unlimited warranty for the period of performance of the PWS for all Contractor-provided hardware, software, materials, and workmanship. The warranty shall include emergency off-site technical assistance for remote diagnostics and troubleshooting as required. The Contractor shall track and resolve the problem(s) in accordance with standard commercial practices and the terms of this PWS.

1.7.8 Points Of Contact:

Contracting Officer Ms. Erica S. Oh Defense Health Agency Contracting Activity (DHACA) Northeastern Market-Contracting Division (NEM-CD) Falls Church, VA 22042 Office: 703-275-6338 / Cell: 726-203-0075 Email: erica.s.oh.civ@health.mil

WRNMMC Program Manager and Contract Officer’s Representative (COR):

Stephen Ngeke Department of Information Technology Walter Reed National Military Medical Center 4655 Taylor Road, Bldg 27 Bethesda, MD 20889-5639 Mobile: 301-547-1454 Office: 301-319-4615 Email: Stephen.ngeke.civ@health.mil

1.7.9. Program Management:

Contractor shall provide general Program Management services consisting of all activities associated with the overall administration of this task including but not limited to:

1. Government coordination, reports, invoicing, subcontracts, support, and logistics management.

2. Reserved

3. Any material delivered to WRNMMC and not received onsite by Contractor Program Manager shall be addressed to:

Walter Reed National Military Medical Center – Bethesda

Information Technology Department
8901 Wisconsin Avenue
Bethesda, MD 20889
ATTN: Stephen Ngeke

4655 Taylor Rd Bldg 27, Room 1132, 1st Floor 301-547-1454

4. Contractor Program Manager shall oversee the installation and act as a liaison between WRNMMC and Contractor; and shall communicate directly with the WRNMMC COR and address any issues that may arise.

5. Contractor Program Manager is required to attend recurring meetings with the WRNMMC COR to discuss the project's progression and allow for additional inquiries.

6. Contractor Program Manager shall prepare an agenda for the meeting including at a minimum the 3-week look-ahead of activities, progress reports, pending actions for both Government and Contractor.

7. Contractor Program Manager shall provide monthly status reports and a following month target plan. This shall be submitted with each month's pay request.

8. Contractor Program Manager shall gather and make available all information and documentation required for any WRNMMC access, outage, infection control or other authorization request necessary for implementation of the Solution.

9. Customer is responsible for approval project management and task management related to the Contractor Staff. Contractor shall provide access to an escalation point of contact (the “Delivery Manager”) who shall review and track tasks as well as work with the Contractor Staff and internal Contractor Staff resources to assist with goal progression and issue resolution and document the escalation plan in CDRL A008- Final Escalation Plan.

10. Contractor shall follow Customer’s change control processes. Contractor Staff is responsible for obtaining all necessary approvals for system changes, including exceptions to change control processes.

11. Spontaneous knowledge transfer activities provided by Contractor Staff outside of a scheduled class, in the course of daily work, are not formal training and no courseware shall be required.

12. Contractor shall provide notice for all planned absences of its permanent onsite staff (if applicable) and shall schedule planned absences so as not to impact time-critical projects.

1.7.10 Organizational Conflict of Interest

Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.

1.8 Contractor travel:

No travel or per diem is anticipated under this contract.

1.9 Other Direct Costs (ODC): No ODC is anticipated under this contract.

1.10 Quality

1.10.1 Quality Control (QC): The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure nonrecurrence of defective services. The contractor’s quality control program is the means by which the work complies with stated requirements. Contactor shall deliver QCP to WRNMMC within 30 days of Award Date. After acceptance of the Quality Control Plan (QCP) the contractor shall receive the contracting officer’s (CO) acceptance in writing of any proposed change to his QC system. See Technical Exhibit 1 - Contract Data Requirements List (CDRL) A001.

1.10.2 Quality assurance: The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). Please see Performance Requirements Summary section for details and service targets.

1.10.3 Acceptance Criteria

All project acceptances of deliverables shall reside with WRNMMC. The project team shall ensure the completeness of each phase of the project and that the scope of work has been met. Once a project phase is completed, The Contractor shall provide their report/presentation for review and approval.

Once all project tasks have been completed, the project task shall enter the handoff/closure phase. The acceptance of this documentation by WRNMMC will acknowledge acceptance of all project deliverables and that the Contractor has met all assigned tasks (documentation and project deliverables are deemed accepted if WRNMMC does not affirmatively accept or reject the documentation within thirty (30) days following its submission by Contractor).

Acceptance of the implemented Solution shall be in writing and signed by a designated representative of the Leadership of the Information Technology Department at WRNMMC (CORE). As part of said Acceptance, Contractor shall provide:

· documentation detailing the As-Built Solution topology,

· documentation of all necessary post-installation approvals and quality control for cabling and structural modifications approvals,

· a copy of the manufacturer's warranty for all installed parts,

· a copy of Contractor’s warranty for all parts and workmanship,

· an inventory of any spare parts,

· a copy of all code developed by Contractor and installed as part of this Solution,

· a copy of all software installed by Contractor as part of this Solution,

· a post installation network analysis report detailing the results of Solution testing,

· a post installation cable record including test results for any new copper or fiber runs (in accordance with the Walter Reed Bethesda Information Technology Department Telecommunications Branch Structured Cable Plant Standards incorporated herein), and

· a network diagram and spreadsheet detailing all physical connections (including identification of drop, switch and port) in use by the implemented Solution.

1.11 Contractor personnel

1.11.1 CAC requirements: For all contractors who will work in Government facilities, the Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the PWS. A CAC is the standard identification for eligible DoD contractor personnel.

1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).

1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms per the following DHA instructions:

1.11.2.1 The DHA’s Onboarding Checklist for Contractor Employees is located at the DHA Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx

1.11.2.2 The DHA’s Contractor training instructions embedded at Part 7 Section 7.1.2.

1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at: https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure (PKI)-restricted, printed versions available).

1.11.2.4 The DHA’s new employee handbook at Part 7 Section 7.1.4.

1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.

1.11.4 Key control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.

1.11.4.1 In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the CO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

1.11.4.2 The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the CO.

1.11.5 Lock combinations: The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s QCP.

1.11.6 Contractor Employees Who Require Access to Government Information Technology: All contractor employees requiring access to government information technology shall successfully complete the current DoD approved Cyber Awareness Challenge training prior to being granted access, and annually thereafter. This training takes approximately 30 – 60 minutes to complete and requires the student to pass a test at the conclusion. The official DoD certificate of completion shall be presented to the COR. DoD Cyber Awareness Challenge shall be taken utilizing the Defense Health Agency (DHA) Learning Management System , Joint Knowledge Online (JKO): http://jko.jten.mil/mhs.

1.11.7 Contractor Employees Performing Cybersecurity / Cyberspace Functions shall comply with the requirements listed below:

1.11.7.1 Training:

All contractor and associated subcontractor employees working Cybersecurity (Information Assurance (IA))/Cyberspace functions shall comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01, and DoD 8570.01-M. For all contractor employees, the baseline certification as stipulated in DoD 8570.01-M shall be completed prior to the beginning of their contract support services.

1.11.7.2 Certification:

Per DoDD 8140.01, Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7001, contractor employees supporting Cybersecurity (Information Assurance)/Cyberspace functions shall be appropriately certified upon contract/task order award. For all contractor employees, the baseline certification as stipulated in DoD 8570.01-M shall be completed prior to the beginning of their contract support services. Please see the embedded DoD 8570.01-M Directive Guidelines and Position Descriptions: N/A

1.11.7.3 Government training:

The Contractor shall ensure that all Contractor employees attend or successfully complete all mandatory Government training. The training typically encompasses matters of security and safety, and is provided during billable time at no cost to the Contractor. Continuous training/education shall be required for all Contractor resources providing the incidental maintenance support for the this PWS as technology and standards are constantly changing. The Contractor staff members supporting this PWS shall complete the Department of Defense, Department of Navy and Health Insurance Portability and Accountability Act (HIPAA) training annually. The contractor shall be required to complete applicable DoD Cybersecurity training.

1.11.7.4 Privileged User Requirements:

All contractor employees with privileged user status shall comply with the requirements of DHA-Administrative Instruction.

1.11.8 Department of Defense Information Network Approved Products List (DODIN APL):

The Contractor shall propose equipment and software in response to this request that have been added to the DODIN APL. The Department of Defense Information Network Approved Products List (DODIN APL) is established in accordance with the UC Requirements (UCR 2013) document and mandated by the DOD Instruction (DODI) 8100.04. Its purpose is to maintain a single consolidated list of products that have completed Interoperability (IO) and Cybersecurity certification. Use of the DODIN APL allows DOD Components to purchase and operate systems over all DOD network infrastructures. The DODIN APL is the only listing of equipment by DOD to be fielded in DOD networks. DOD components are required to fulfill their system needs by only purchasing DODIN APL listed products, providing one of the listed products meets their needs. The Department of Defense Information Network Approved Products List (DODIN APL) is established in accordance with the UC Requirements (UCR 2013) document and mandated by the DOD Instruction (DODI) 8100.04. Its purpose is to maintain a single consolidated list of products that have completed Interoperability (IO) and Cybersecurity certification. Use of the DODIN APL allows DOD Components to purchase and operate systems over all DOD network infrastructures. The DODIN APL is the only listing of equipment by DOD to be fielded in DOD networks. DOD components are required to fulfill their system needs by only purchasing DODIN APL listed products, providing one of the listed products meets the requirements. If no listed product meets the needs of this PWS/PWS request, the contractor may propose a product for testing that does meet the requirements.

1.11.9 Background Investigation Requirements And Security Approval Process For Contractors Assigned To National Security Positions Or Performing Sensitive Duties Security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Recognizing contractor employees under this contract as Non- Critical Sensitive [ADP/IT-II] when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and Protected Health Information (PHI), provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions. At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The NACLC consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:

SF-86 Questionnaire for National Security Positions (or equivalent OPM investigative product) Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission) Original Signed Release Statements Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than 10 years) throughout the contract performance period. The Contractor's Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required. Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the Command's Security Manager upon arrival to the command and shall out• process prior to their departure at the completion of the individual's performance under the contract. Employees requiring IT access shall also check-in and check-out with the Command's Information Assurance Manager. Completion and approval of a System Authorization Access Request (SAAR-N) form is required for all individuals accessing Information Technology resources. The SAAR-N shall be forwarded to the Command's Security Manager at least 30 days prior to the individual's start date. Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date. The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Information Assurance (IA) training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the Command Security Manager. The Command's Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (OPM). Suitability/security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The Command's Security Manager will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DON Central Adjudication Facility (CAF) for a determination. If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a Visit Authorization Request (VAR) via the Joint Personnel Adjudication System (JPAS) or a hard copy VAR directly from the contractor's Security Representative. Although the contractor shall take JPAS "Owning" role over the contractor employee, the Command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The contractor shall include the IT Position Category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee's performance under the contract.

1.11.10 Background Investigation Requirements And Security Approval Process For Contractors Assigned To Or Performing Non-Sensitive Duties Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc.) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:

· Must be either a US citizen or a US permanent resident with a minimum of 3 years legal residency in the United States (as required by The Deputy Secretary of Defense DTM 08-006 or its subsequent DoD instruction) and

· Must have a favorably completed National Agency Check with Written Inquiries (NACI) including a FBI fingerprint check prior to installation access.

To be considered for a favorable trustworthiness determination, the Contractor's Security Representative must submit for all employees each of the following:

· SF-85 Questionnaire for Non-Sensitive Positions

· Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)

· Original Signed Release Statements The contractor shall ensure each individual employee has a current favorably completed National Agency Check with Written Inquiries (NACI) or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM. Failure to provide the required documentation at least 30 days prior to the individual's start date may result in delaying the individual's start date.

* Consult with your Command Security Manager and Information Assurance Manager for local policy when IT-III (non-sensitive) access is required for non-US citizens outside the United States.

1.11.11 DBIDS Pass and Walter Reed Bethesda Base Access:

Any permanent Contractor staff working at WRNMMC shall be required to obtain and maintain a DoD Contract Client Common Access Card (CAC) (see section 1.11 Contractor personnel). However, any Contractor staff requiring repeated access to WRNMMC (installers, project managers, etc.) that do not require a CAC shall obtain and maintain a Defense Biometric Identification System (DBIDS) or similar access pass at Contractor expense in order to facilitate access and to eliminate the need for the government to escort Contractor staff and to repeatedly add said staff to the base access list. The WRNMMC COR will provide the necessary Government sponsorship.

1.12 Key personnel (Contractor): There are no key personnel defined for this contract as the Contractor shall propose their way to meet the Professional Services according to their approach, which may include dedicated full time people or it may include shared roles across multiple personnel who perform the tasks as necessary, or it may be a combination of each.

1.13 Data rights:

The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.

1.14 Reporting

1.14.1 Contractor Manpower Reporting (CMR): RESERVED

1.14.2 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA Contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The Contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the Contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.

1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor Contractor's performance and notifies both the CO and Contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.

1.14.4 Post award conference/periodic progress meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor shall apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.

1.15 Contractor Identification

1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel. Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.

1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their contractor status known during introductions.

1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.

1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)

1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation, HIPAA Training, and the security awareness training. The Contractor shall be prepared for this process as it could take two (2) or more weeks. The Facilities Security Officer/Security POC shall submit a Standard Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.

1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.

1.17. Personnel Security

1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program,” December 19, 2005 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs”, DoDI 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM 5200.02 “Procedures for the DoD Personnel Security Program (PSP),” dated April 3, 2017. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:

1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 681-6777.

1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).

1.17.1.3 DHA Personnel Security Office will deny any access to any automated information system (AIS), network, or CUI if a contractor receives an unfavorable adjudication, or if information that would result in an unfavorable adjudication becomes available.

PART 2

2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE PUBLICATIONS

2.1 Definitions:

2.1.1 Category D: Information Technology and Telecommunications Services (called D-Services)

2.1.2 Category R: Support (Professional/Administrative/Managements) Services (called R-Services)

2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the contracting officer to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.

2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The Government may either prepare the quality assurance surveillance plan or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.

2.1.7 Contractor.

A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.8 Defective Service.

A service output that does not meet the standard of performance associated with the Performance Work Statement.

2.1.9 Deliverable.

Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

2.1.10 Physical Security.

Actions that prevent the loss or damage of Government property.

2.1.11 Quality Assurance.

The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.

2.1.12 Quality Control.

All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

2.1.13 Subcontractor.

One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.

2.1.14 Work Day.

The number of hours per day the Contractor provides services in accordance with the contract.

2.1.15 Work Week.

Monday through Friday, unless specified otherwise.

2.1.16 Carrier

A telecommunications radio frequency signal service provider. For this PWS, Verizon, AT&T, Sprint and T-Mobile are considered carriers.

2.1.17 Covered Equipment

Equipment comprising the DAS. Please see Section 3 for additional detail.

2.1.18 Solution elements

Any DAS-specific equipment, components, or services.

2.2 Acronyms:

AOAuthorizing Official

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .