HT940624Q0017 .pdf
PDF 470 KB Posted
- Attached to
- NMCP - Laboratory Document Management Control System Federal contract opportunity
- Solicitation number
- HT940624Q0017
- Issued by
- Defense Health Agency
About this file
This is a solicitation for a quality management software system. Naval Medical Readiness Training Command Portsmouth Laboratory requires a document control system to maintain Standard Operating Procedures in accordance with accreditation requirements. The system must support up to 500 users and offer continuing education credits. Products and services include document control, software reliability with zero downtime, and compatibility with DoD networks. The base period of performance is one year with four optional one-year extensions. The solicitation was issued on February 7, 2024 with an offer due date of February 28, 2024. Award will be made based on lowest price and capability to meet requirements. The Defense Health Agency is the contracting agency.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HT940624Q0017-0002 Solicitation PWS Update.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
HT940624Q0017 07-Feb-2024
b. TELEPHONE NUMBER
757-953-7570
8. OFFER DUE DATE/LOCAL TIME
12:00 AM 28 Feb 2024
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
HT94069. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
LINDSAY GRAY
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
0011990108-0001
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED ORX
SMALL BUSINESS
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
DHA CONTRACTING OFFICE TIDEWATER HT9406
7700 ARLINGTON BLVD
FALLS CHURCH VA 22042
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE HT0242 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
NAV MED CNT PORTSMOUTH VA - MM
KRISTEN COTE
ATTN SUPPLY OFFICER BLDG 250
54 LEWIS MINOR STREET
PORTSMOUTH VA 23708-2297
TEL: FAX:
FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$24,000,000
NAICS:
611710
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF23
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
HT940624Q0017
Section SF 1449 - CONTINUATION SHEET
SOLICITATION/CONTRACT FORM
VENDOR TO COMPLETE THE FOLLOWING:
CAGE: _____________________
UEI: _____________________
Vendor POC: _____________________
Vendor Phone: ____________________
Vendor E-mail: ____________________
Notes to Vendor:
-At a minimum, the SF1449 must be completed to be considered for this opportunity. Additional reqirement in order to be considered for the opportunity; submit a brochure, spec sheet, or past performance information. Please respond to blocks 17a and 30a-c on page 1 and the vendor information on page 3, as well as provide your price(s) on the
Contract Line Item Number(s) (CLINs). Cursive font signatures will not be accepted.
-Offeror will provide all license agreements, End User License Agreements (EULA), Terms of Service (TOS), Federal Payment Plans, Extended Payment Plans, and other similar instruments or agreements, required to be signed, or agreed to, by the Government that the offeror or any of its suppliers or subcontractors (at any level) require. The Government may review to ensure terms and conditions are consistent with Federal law and otherwise satisfy the Government’s needs. Among terms and conditions that are not acceptable, which makes an offer ineligible for award, include: those such as Government indemnification of any party; choice of law or forum for disputes; mandatory arbitration; any language that would or might require the Government to renew or extend performance or usage of any item, product, or service; or any other feature that unduly puts a burden or restriction on the Government.
-Vendor to reference request for quotes number (RFQ#) HT940624Q0017 on all inquiries.
NOTE TO VENDOR:
Because the Government’s automated procurement system does not provide for the contractor’s electronic signature, a fully executed copy of this bilateral award, signed by both parties, will be retained in the Government’s official contract file.
-For competitive service buys, type: Award will be made on the basis of the lowest evaluated price and the capability to meet the requirement detailed in the Performance Work Statement.
PROMPT PAYMENT
For Prompt Payment Act purposes, this contract is subject to the 7 calendar day constructive acceptance period.
Billing / Payment in arrears
For all questions, POC:
Ms. Lindsay A. Gray Contract Specialist E: Lindsay.a.gray.civ@health.mil mailto:Lindsay.a.gray.civ@health.mil
PERFORMANCE WORK STATEMENT
1.0 GENERAL INFORMATION
NMRTC Portsmouth Laboratory requires a quality management software for clinical laboratory to retain positive document control of all forms and Standard Operating Procedurs in accordance with accrediting agency (College of American Pathologist) requirements.
1.1 This is a non-personal services contract to provide quality management software for the clinical laboratory.
1.1.1 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to provide a quality management software as defined in this
Performance Work Statement (PWS).
1.1.2 Background: NMRTC Portsmouth’s Laboratory currently uses this software as provided by current vendor. Market research was performed to compare top competitors to current vendor.
1.1.3 Scope: Services to be provided include document control, reliable software with zero downtime, allows up to 150 users, and has proper authorizations to perform on government networks.
1.1.4 Period of Performance (PoP): 09 Jun 2024- 08 Jun 2025 (Base Year + 4 option years).
1.2 Administrative specifications
1.2.1 Place of performance: The work shall be performed at NMRTC Portsmouth Laboratory-
Building 2, 1st floor
1.2.2 Recognized Federal holidays: Software must perform and offer technical support on all holidays
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Memorial Day Thanksgiving Day
Juneteenth Day Christmas Day
Independence Day
1.2.3 Hours of operation: The contractor is responsible for conducting business Monday thru
Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.2.4 Emergency Services: Software is expected to perform 24/7 to ensure continuous, safe patient care to patients at NMRTC Portsmouth
1.3 Contractor Identification
1.3.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the Governemnt understands that the person is contractor support personnel.
2.0 SPECIFIC TASKS
2.1 Document Control- Vendor must provide positive document control of all Laboratory
Standard Operating Procedures in accordance with accrediting agency requirements. All procedures, forms, and appendixes will be locked and controlled by Laboratory’s Quality
Assurance team as well as supervisors/technical leads as stated in Medical Director’s delegation letter. Software must provide security against all entities outside Laboratory from having access or ability to alter any documents being controlled.
2.2 150 Users Minimum- Software must be able to support atleast 150 users without any system glitches or delays to daily operations. Vendor must ensure that any glitches due to high user volume are resolved immediately and take measures to alleviate.
2.3 Proper Government Network Authorizations- Software must have pre-approval to operate seamlessly on government networks. All features and applications must be compatible with DoD network. Vendor must ensure that their permissions to operate on these networks are maintained without any lapses to services.
3.0 Qualifications/Considerations
3.1 Special Qualifications/Considerations: Proper authorizations to operate at optimal level on government networks.
Software and/or hardware must be an approved product by the Defense Health Agency (DHA), and authorized to be used on the DHA network.
4.0 Points of Contact
4.1 Points of Contact: LTJG Ramanvir Sidhu 757-953-1737. John Kmieciak 757-953-7918.
PRIVACY & SECURITY OF PHI
Personally Identifiable Information, Protected Health Information, and Federal
Information Requirements (Revised 10/27/2020)
1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information
(PHI) and Federal Information Laws
This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of
Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the
Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The
Contractor shall also comply with requirements relating to records management as described herein.
This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.
For purposes of this Section, the following definitions apply.
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDI 5400.11, DoD Privacy and Civil Liberties Programs, January 29, 2019 and DoDI 5400.11- R, Department of Defense Privacy
Program, May 14, 2007
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S.
Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E
(Enforcement), as amended. Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part
162) are not addressed in this Section and are not included in the term HIPAA Rules.
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health
System (MHS). These issuances are DoDM 6025.18, “Implementation of the Health Insurance Portability and
Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, DoDI 6025.18, Health
Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs, March 13, 2019, and DoDI 8580.02, Security of Individually Identifiable Health Information in DoD Health Care
Programs, August. 12, 2015.
Defense Health Agency (DHA) Privacy Office is the DHA Privacy and Civil Liberties Office. The DHA Privacy
Office Chief is the HIPAA Privacy and Security Officer for DHA.
2. Records Management
When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter
XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction
No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records
Management requirements outlined in the current TRICARE Operations Manual (TOM).
3. Freedom of Information Act (FOIA)
The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:
The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request preferably sent via the National FOIA Portal at: www.FOIA.gov. However, requesters may also submit requests via email at http://www.dtic.mil/whs/directives http://www.foia.gov/
DHA.FOIA@mail.mil; or via postal delivery addressed to the DHA Freedom of Information Service Center, 7700
Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101. All FOIA requests shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Contract and/or Modification numbers must be included in all FOIA requests seeking DHA procurement records. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible and respond to DHA within ten working days.
In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of
DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of
Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the
Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.
4. Systems of Records
In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier.
Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil Liberties, and Transparency
Division, and as required by the DoD Privacy Act Issuances.
Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, OMB Circular A-130, and Privacy Act of 1974 requirements applicable to contractors operating systems of records on behalf of federal agencies. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.
5. Privacy Impact Assessment (PIA)
If DHA data is stored on a Contractor owned system, a PIA is required from the Contractor.
6. Data Sharing Agreement (DSA)
6.1 (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de-identified data)
The Contractor shall consult with the DHA Privacy Office to determine if the Contractor must obtain a DSA or Data
Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.
The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and DoD HIPAA Issuances. Likewise, the
Contractor shall comply with the DoD Privacy Act Issuances.
mailto:DHA.FOIA@mail.mil
Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor must gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA Privacy Board requests for additional documentation.
To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the DHA Privacy
Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data involved:
• DSA for De-Identified Data
• DSA for PHI
• DSA for PII Without PHI
• DUA for Limited Data Set
DSAs executed for contract support will expire after 1 year or at the end of the contract option 2 year, whichever comes first. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the
Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.
6.2 (Applies if contract requirements may include human subject research)
This Contract incorporates by reference the Protection of Human Subject Research clause in the Defense Federal
Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235-7004. A separate DFARS provision, 48 CFR
235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR 219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a contractor participates in a study or demonstration project or other activity that involves human subject research, then the contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If contractor activity appears to involve human subject research, then the contractor shall consult the DHA Privacy Office, which may contact the Research Regulatory Oversight Office in the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)).
7. Privacy Act and HIPAA Training
The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this
Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of substance use disorder patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a
Covered Entity, or Business Associate.
The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the
Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.
8. HIPAA Business Associate Provisions
8.1 Business Associate – General Provisions
The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the
Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. The contractor shall use the DoD BAA, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD Components”, located at, https://www.health.mil/Military-Health-Topics/Privacy-and-
CivilLiberties/Privacy-Contract-Language/HIPAA-Compliant-Business-Associate-Agreement-for- the-MHS. b.i.
and (3)b.ii
9. Breach Response
[This paragraph 9 is inoperative, and all references herein to “paragraph 9” shall be deemed to refer to the TOM breach responses provisions, if the contract incorporates the TOM by reference
9.1 Definitions Related to Breach response
9.1.2 Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The foregoing definition is based on the definition of breach in DoDM 6025.18. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral
PII/PHI).
9.1.3 A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the contractor does not initially know whether or not the PII/PHI was encrypted, then the incident must initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the contractor. In determining whether unauthorized access should be suspected, the contractor shall consider at least the following factors:
• How the event was discovered;
• Did the information stay within the covered entity’s control;
• Was the information actually accessed/viewed; and
• Ability to ensure containment (e.g., recovered, destroyed, or deleted).
9.1.4 A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the contractor knows that the PII/PHI is unencrypted, then the contractor should classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the contractor knows this even without knowing whether or not unauthorized access to the
PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the contractor should re-classify the incident as a non-breach incident.
9.1.5 A HHS breach is an incident that satisfies the definition of breach in Section 164.402 of the HIPAA Breach
Rule. The text of the HHS definition states:
Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.
HHS breach excludes:
Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the
HIPAA Privacy Rule.
Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy Rule.
A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.
Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
The unauthorized person who used the PHI or to whom the disclosure was made;
Whether the PHI was actually acquired or viewed; and
The extent to which the risk to the PHI has been mitigated.
9.1.6 A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI. A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.
9.2 General
9.2.1 The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.
9.2.2 Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the
Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation
(which includes individual notification), eradication, recovery, and follow-up.
9.2.3 The contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The contractor should consult with the DHA Privacy Office where guidance is needed, such as when the contractor is uncertain whether a discovered breach is the contractor’s responsibility (e.g., if the contractor discovers a breach not caused by the contractor), or how the contractor is to classify an incident (breach
vs. non-breach, confirmed vs. possible, cyber vs. non-cyber). Under no circumstances will a contractor delay reporting a confirmed or possible breach to the DHA Privacy Office beyond the 24-hour deadline.. In conjunction with its initial investigation, the contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.
9.2.4 In the event of a cybersecurity incident not involving a PII/PHI breach, the contractor shall follow applicable
DoD cybersecurity and NIST requirements, which include United StatesComputer Emergency Readiness Team (US-
CERT) reporting (see paragraph 9.3). If at any point a contractor finds that a cybersecurity incident involves a
PII/PHI breach (possible or confirmed), the contractor shall immediately initiate the reporting procedures set forth below. The contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.
9.2.5 Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the contractor immediately after discovery. The time of that report to the contractor shall trigger the contractor’s DHA Privacy Office reporting deadline (24 hours) under paragraph 9.3.2. If a cybersecurity incident is involved, the contractor’s deadline for US-CERT reporting (1 hour) runs from the time the incident is confirmed. The contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the contractor to complete the breach response requirements herein. Alternatively, the contractor and subcontractor may agree that the subcontractor shall report directly to US-CERT and the DHA Privacy Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the contractor of the incident and the subsequent response actions.
9.2.6 Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the outcome. Investigations identifying unauthorized disclosures must be logged for HIPAA and Privacy Act disclosure accounting purposes, whether or not individual notification is required under the HIPAA Breach Rule.
9.2.7 Contractors, when acting as HIPAA-covered entities, and not as business associates, are not subject to the breach response requirements herein. However, such contractors are subject to both the HIPAA Breach Rule
(applicable to them in their capacity as covered entities) and DoD cybersecurity requirements (applicable to them in their capacity as DoD contractors).
9.3 Reporting Provisions
9.3.1 Immediately upon discovery of a possible or confirmed breach or cybersecurity incident, the contractor shall initiate an investigation. If the incident involves electronic PII/PHI, and if the investigation finds a confirmed breach or cybersecurity incident, the contractor shall report it, within 1 hour of confirmation, to the US-CERT Incident
Reporting System at https://forms.uscert.gov/report/, as required by the Department of Homeland Security (DHS).
Note: DHS no longer requires US-CERT reporting of non-cyber breaches or unconfirmed electronic breaches.
However, DHS permits US-CERT reporting of unconfirmed cyber-related incidents on a voluntary basis. Thus, if a contractor is uncertain whether a possible cyber-related incident should be treated as confirmed and thus reportable, the contractor may voluntarily report the incident.
Before submission to US-CERT, the contractor shall save a copy of the on-line report. After submitting the report, the contractor shall record the US-CERT incident reporting number, which shall be included in the initial report to the DHA Privacy Office as described in paragraph 9.3.2.
Note: Regardless of whether or not an incident is confirmed as a breach, the contractor must also investigate whether or not the incident impacts data integrity or availability of PII/PHI. If such impact is confirmed, then the incident is reportable to US-CERT as a cybersecurity incident. For guidance on investigating the impact on data integrity and availability, refer to DoD cybersecurity and NIST guidance.
The contractor shall provide any updates to the initial US-CERT report by email to soc@uscert.gov, with the
Reporting Number in the subject line. The contractor shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office if requested. Contractor questions about US-CERT reporting shall be directed to the
DHA Privacy Office, not the US- CERT office.
9.3.2 In addition to US-CERT reporting, the contractor shall report to the DHA Privacy Office by submitting the form specified below within 24 hours of discovery of a breach (possible or confirmed), unless the breach falls within a category that the Privacy Office has determined to be not reportable. This 24-hour period runs from the time of discovery, unlike the 1 hour USCERT reporting period, which runs from the time a cybersecurity incident is confirmed. Thus, depending on the time period needed to confirm, the report to the DHA Privacy Office may be due either before or after the US-CERT report.
The breach report form required within the 24-hour deadline shall be sent by e-mail to:
DHA.PrivacyOfficer@mail.mil. The contractor shall also e-mail the report to the CO, the COR and its usual point of contact at the applicable Program Office. Encryption is not required, because reports and notices shall not contain
PII/PHI. If electronic mail is not available, telephone notification is also acceptable (at 703-275-6363), but all notifications and reports delivered telephonically must be confirmed in writing as soon as technically feasible.
mailto:DHA.PrivacyOfficer@mail.mil
Contractors shall prepare the breach reports required within the 24-hour deadline by completing the Breach
Reporting Department of Defense Form DD 2959 (Breach of PII Report), available at https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf. For non-cyber incidents without a US-
CERT number, the contractor shall assign an internal tracking number and include that number in Box 1.e of the DD
Form 2959. The contractor shall coordinate with the DHA Privacy Office for subsequent action, such as beneficiary notification, and mitigation. The contractor must promptly update the DD Form 2959 as new information becomes available.
When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Contractor shall submit a revised form or forms promptly after the new information becomes available, stating the updated status and previous report date(s) and showing any revisions or additions in red text. The Contractor shall provide updates to the same parties as required for the initial Breach
Report Form.
9.4 Individual Notification Provisions
9.4.1 If the DHA Privacy Office determines that individual notification is required, the Contractor shall provide written notification to beneficiaries affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities and addresses of the beneficiaries are ascertained. The 10 day period begins when the Contractor is able to determine the identities (including addresses) of the beneficiaries whose records were impacted. If notification cannot be accomplished within 10 working days, the contractor shall notify the DHA Privacy Office.
9.4.2 The Contractor’s proposed notification to be issued to the affected beneficiaries shall be 2 submitted to the
DHA Privacy Office for approval. The notification to beneficiaries shall include, at a minimum, the following:
• Specific data elements,
• Basic facts and circumstances,
• Recommended precautions the beneficiary can take,
• Federal Trade Commission (FTC) identity theft hotline information, and
• Any mitigation support services offered, such as credit monitoring.
Contractors shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Contractor and/or subcontractor organization that suffered the breach.
If media notice is required, the contractor will submit a proposed notice and suggested media outlets for the DHA
Privacy Office review and approval (which will include coordination with the DHA Communications Division).
9.5 In the event the Contractor is uncertain on how to apply the above requirements, the Contractor shall consult with the CO, who will consult with the Privacy Office as appropriate when determinations on applying the above requirements are needed.
The Contractor shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the
Contractor has caused or is otherwise responsible for addressing.
https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 1 Job MediaLab Corporate System Account
FFP
See List of Deliverables
See Performance Work Statement for full description
FOB: Destination
PURCHASE REQUEST NUMBER: 0011990108-0001
DA10
NET AMT
1001 1 Job OPTION MediaLab Corporate System Account
2002 1 Job OPTION MediaLab Corporate System Account
3001 1 Job OPTION MediaLab Corporate System Account
4001 1 Job OPTION MediaLab Corporate System Account
5001 1 Job OPTION MediaLab Corporate System Account
See List of Deliverables (Six-month extension POP:09 JUN 2029-08 DEC 2029)
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government
1001 Destination Government Destination Government
2002 Destination Government Destination Government
3001 Destination Government Destination Government
4001 Destination Government Destination Government
5001 Destination Government Destination Government
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 POP 09-JUN-2024 TO
08-JUN-2025
N/A NAV MED CNT PORTSMOUTH VA - MM
KRISTEN COTE
ATTN SUPPLY OFFICER BLDG 250
54 LEWIS MINOR STREET
PORTSMOUTH VA 23708-2297
HT0242
1001 POP 09-JUN-2025 TO
08-JUN-2026
N/A (SAME AS PREVIOUS LOCATION)
2002 POP 09-JUN-2026 TO
08-JUN-2027
N/A (SAME AS PREVIOUS LOCATION)
3001 POP 09-JUN-2027 TO
08-JUN-2028
N/A (SAME AS PREVIOUS LOCATION)
4001 POP 09-JUN-2028 TO
08-JUN-2029
N/A (SAME AS PREVIOUS LOCATION)
5001 POP 09-JUN-2029 TO
08-DEC-2029
N/A (SAME AS PREVIOUS LOCATION)
CLAUSES INCORPORATED BY REFERENCE
52.201-1 Acquisition 360: Voluntary Survey SEP 2023
52.203-7 Anti-Kickback Procedures JUN 2020
52.203-11 Certification And Disclosure Regarding Payments To
Influence Certain Federal Transactions
SEP 2007
52.203-12 Limitation On Payments To Influence Certain Federal
Transactions
JUN 2020
52.203-18 Prohibition on Contracting With Entities That Require Certain
Internal Confidentiality Agreements or Statements--
Representation
JAN 2017
52.203-19 Prohibition on Requiring Certain Internal Confidentiality
Agreements or Statements
JAN 2017
52.204-3 Taxpayer Identification OCT 1998
52.204-7 System for Award Management OCT 2018
52.204-8 Annual Representations and Certifications MAR 2023
52.204-10 Reporting Executive Compensation and First-Tier
Subcontract Awards
JUN 2020
52.204-13 System for Award Management Maintenance OCT 2018
52.204-16 Commercial and Government Entity Code Reporting AUG 2020
52.204-17 Ownership or Control of Offeror AUG 2020
52.204-18 Commercial and Government Entity Code Maintenance AUG 2020
52.204-19 Incorporation by Reference of Representations and
Certifications.
DEC 2014
52.204-20 Predecessor of Offeror AUG 2020
52.204-22 Alternative Line Item Proposal JAN 2017
52.204-23 Prohibition on Contracting for Hardware, Software, and
Services Developed or Provided by Kaspersky Lab Covered
Entities
DEC 2023
52.204-24 Representation Regarding Certain Telecommunications and
Video Surveillance Services or Equipment
NOV 2021
52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment
NOV 2021
52.204-26 Covered Telecommunications Equipment or Services--
Representation.
OCT 2020
52.204-27 Prohibition on a ByteDance Covered Application JUN 2023
52.204-28 Federal Acquisition Supply Chain Security Act Orders--
Federal Supply Schedules, Governmentwide Acquisition
Contracts, and Multi-Agency Contracts.
DEC 2023
52.204-29 Federal Acquisition Supply Chain Security Act Orders--
Representation and Disclosures.
DEC 2023
52.204-30 Federal Acquisition Supply Chain Security Act Orders--
Prohibition.
DEC 2023
52.209-2 Prohibition on Contracting with Inverted Domestic
Corporations--Representation
NOV 2015
52.209-10 Prohibition on Contracting With Inverted Domestic
Corporations
NOV 2015
52.209-11 Representation by Corporations Regarding Delinquent Tax
Liability or a Felony Conviction under any Federal Law
FEB 2016
52.211-2 Availability of Defense Specifications, Standards, and Data
Item Descriptions in the Acquisition Streamlining and
Standardization Information System (ASSIST) Website
SEP 2023
52.212-4 Contract Terms and Conditions--Commercial Products and
Commercial Services
NOV 2023
52.212-5 Contract Terms and Conditions Required to Implement
Statutes or Executive Orders--Commercial Products and
Commercial Services
DEC 2023
52.214-34 Submission Of Offers In The English Language APR 1991
52.214-35 Submission Of Offers In U.S. Currency APR 1991
52.217-5 Evaluation Of Options JUL 1990
52.219-1 Alt I (Dev) Small Business Program Representations (DEVIATION
2024-O0002) Alternate I
JAN 2024
52.219-4 Notice of Price Evaluation Preference for HUBZone Small
Business Concerns
OCT 2022
52.219-28 (Dev) Post-Award Small Business Program Rerepresentation
(DEVIATION 2024-O0002)
JAN 2024
52.219-31 Notice of Small Business Reserve MAR 2020
52.219-32 Orders Issued Directly Under Small Business Reserves MAR 2020
52.219-33 Nonmanufacturer Rule SEP 2021
52.222-3 Convict Labor JUN 2003
52.222-4 Contract Work Hours and Safety Standards - Overtime
Compensation
MAY 2018
52.222-18 Certification Regarding Knowledge of Child Labor for Listed
End Products
FEB 2021
52.222-22 Previous Contracts And Compliance Reports FEB 1999
52.222-25 Affirmative Action Compliance APR 1984
52.222-26 Equal Opportunity SEP 2016
52.222-50 Combating Trafficking in Persons NOV 2021
52.222-54 Employment Eligibility Verification MAY 2022
52.223-1 Biobased Product Certification MAY 2012
52.223-2 Affirmative Procurement of Biobased Products Under Service and Construction Contracts
SEP 2013
52.223-18 Encouraging Contractor Policies To Ban Text Messaging
While Driving
JUN 2020
52.223-22 Public Disclosure of Greenhouse Gas Emissions and
Reduction Goals -- Representation.
DEC 2016
52.225-1 Buy American--Supplies OCT 2022
52.225-13 Restrictions on Certain Foreign Purchases FEB 2021
52.225-18 Place of Manufacture AUG 2018
52.225-20 Prohibition on Conducting Restricted Business Operations in
Sudan--Certification
AUG 2009
52.225-25 Prohibition on Contracting with Entities Engaging in Certain
Activities or Transactions Relating to Iran-- Representation and Certifications.
JUN 2020
52.226-1 Utilization Of Indian Organizations And Indian-Owned
Economic Enterprises
JUN 2000
52.232-23 Alt I Assignment of Claims (May 2014) - Alternate I APR 1984
52.232-28 Invitation to Propose Performance-Based Payments MAR 2000
52.232-33 Payment by Electronic Funds Transfer--System for Award
Management
OCT 2018
52.232-39 Unenforceability of Unauthorized Obligations JUN 2013
52.232-40 Providing Accelerated Payments to Small Business
Subcontractors
MAR 2023
52.233-4 Applicable Law for Breach of Contract Claim OCT 2004
52.237-2 Protection Of Government Buildings, Equipment, And
Vegetation
APR 1984
52.237-3 Continuity Of Services JAN 1991
52.242-15 Stop-Work Order AUG 1989
52.244-6 Subcontracts for Commercial Products and Commercial
Services
DEC 2023
52.249-4 Termination For Convenience Of The Government (Services)
(Short Form)
APR 1984
52.252-1 Solicitation Provisions Incorporated By Reference FEB 1998
52.252-5 Authorized Deviations In Provisions NOV 2020
52.252-6 Authorized Deviations In Clauses NOV 2020
252.203-7000 Requirements Relating to Compensation of Former DoD
Officials
SEP 2011
252.203-7002 Requirement to Inform Employees of Whistleblower Rights DEC 2022
252.204-7003 Control Of Government Personnel Work Product APR 1992
252.204-7007 Alternate A, Annual Representations and Certifications NOV 2023
252.204-7012 Safeguarding Covered Defense Information and Cyber
Incident Reporting
JAN 2023
252.204-7015 Notice of Authorized Disclosure of Information for Litigation
Support
JAN 2023
252.204-7016 Covered Defense Telecommunications Equipment or Services
-- Representation
DEC 2019
252.204-7017 Prohibition on the Acquisition of Covered Defense
Telecommunications Equipment or Services -- Representation
MAY 2021
252.204-7018 Prohibition on the Acquisition of Covered Defense
Telecommunications Equipment or Services
JAN 2023
252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements NOV 2023
252.204-7020 NIST SP 800-171 DoD Assessment Requirements NOV 2023
252.204-7022 Expediting Contract Closeout MAY 2021
252.204-7024 Notice on the Use of the Supplier Performance Risk System MAR 2023
252.209-7004 Subcontracting With Firms That Are Owned or Controlled By
The Government of a Country that is a State Sponsor of
Terrorism
MAY 2019
252.215-7014 Exception from Certified Cost or Pricing Data Requirements for Foreign Military Sales Indirect Offsets.
DEC 2022
252.215-7015 Program Should-Cost Review NOV 2019
252.215-7998 (Dev) Pilot Program to Accelerate Contracting and Pricing
Processes. (DEVIATION 2023-O0004)
JAN 2023
252.223-7997 (Dev) Prohibition on Procurement of Certain Items Containing
Perfluorooctane Sulfonate or Perfluorooctanoic Acid -
Representation (DEVIATION 2022-O0010)
SEP 2022
252.223-7998 (Dev) Prohibition on Procurement of Certain Items Containing
Perfluorooctane Sulfonate or Perfluorooctanoic Acid
(DEVIATION 2022-O0010)
SEP 2022
252.225-7001 Buy American And Balance Of Payments Program--Basic JAN 2023
252.225-7002 Qualifying Country Sources As Subcontractors MAR 2022
252.225-7048 Export-Controlled Items JUN 2013
252.225-7050 Disclosure of Ownership or Control by the Government of a
Country that is a State Sponsor of Terrorism
DEC 2022
252.225-7053 Representation Regarding Prohibition on Use of Certain
Energy Sourced from Inside the Russian Federation
AUG 2021
252.225-7054 Prohibition on Use of Certain Energy Sourced from Inside the
Russian Federation
JAN 2023
252.225-7055 Representation Regarding Business Operations with the
Maduro Regime
MAY 2022
252.225-7056 Prohibition Regarding Business Operations with the Maduro
Regime
JAN 2023
252.225-7059 Prohibition on Certain Procurements from the Xinjiang
Uyghur Autonomous Region - Representation
JUN 2023
252.225-7060 Prohibition on Certain Procurements from the Xinjiang
Uyghur Autonomous Region
JUN 2023
252.225-7061 Restriction on the Acquisition of Personal Protective
Equipment and Certain Other Items from Non-Allied Foreign
Nations
JAN 2023
252.225-7972 (Dev) Prohibition on the Procurement of Foreign-Made Unmanned
Aircraft Systems (DEVIATION 2020-O0015)
MAY 2020
252.225-7973 (Dev) Prohibition on the Procurement of Foreign-Made Unmanned
Aircraft Systems - Representation (DEVIATION 2020-
O0015)
MAY 2020
252.232-7003 Electronic Submission of Payment Requests and Receiving
Reports
DEC 2018
252.232-7010 Levies on Contract Payments DEC 2006
252.232-7015 Performance-Based Payments--Representation DEC 2022
252.232-7016 Notice of Progress Payments or Performance-Based Payments APR 2020
252.233-7001 Choice of Law (Overseas) JUN 1997
252.237-7010 Prohibition on Interrogation of Detainees by Contractor
Personnel
JAN 2023
252.239-7001 Information Assurance Contractor Training and Certification JAN 2008
252.243-7001 Pricing Of Contract Modifications DEC 1991
252.244-7000 Subcontracts for Commercial Products or Commercial
Services
NOV 2023
252.246-7008 Sources of Electronic Parts JAN 2023
252.247-7023 Transportation of Supplies by Sea JAN 2023
CLAUSES INCORPORATED BY FULL TEXT
52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the
Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the
Contractor within 3 months.
(End of clause)
52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
(a) The Government may extend the term of this contract by written notice to the Contractor within 7 months provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 5 days before the contract expires.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .