HT940624Q0017 .pdf

PDF 470 KB Posted

Attached to
NMCP - Laboratory Document Management Control System Federal contract opportunity
Solicitation number
HT940624Q0017
Issued by
Defense Health Agency

About this file

This is a solicitation for a quality management software system. Naval Medical Readiness Training Command Portsmouth Laboratory requires a document control system to maintain Standard Operating Procedures in accordance with accreditation requirements. The system must support up to 500 users and offer continuing education credits. Products and services include document control, software reliability with zero downtime, and compatibility with DoD networks. The base period of performance is one year with four optional one-year extensions. The solicitation was issued on February 7, 2024 with an offer due date of February 28, 2024. Award will be made based on lowest price and capability to meet requirements. The Defense Health Agency is the contracting agency.

View the file

Other files for this federal contract opportunity

Other files attached to NMCP - Laboratory Document Management Control System, newest first.
File Type Posted
HT940624Q0017-0002 Solicitation PWS Update.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

HT940624Q0017 07-Feb-2024

b. TELEPHONE NUMBER

757-953-7570

8. OFFER DUE DATE/LOCAL TIME

12:00 AM 28 Feb 2024

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

HT94069. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

LINDSAY GRAY

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

0011990108-0001

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED ORX

SMALL BUSINESS

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

DHA CONTRACTING OFFICE TIDEWATER HT9406

7700 ARLINGTON BLVD

FALLS CHURCH VA 22042

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE HT0242 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

NAV MED CNT PORTSMOUTH VA - MM

KRISTEN COTE

ATTN SUPPLY OFFICER BLDG 250

54 LEWIS MINOR STREET

PORTSMOUTH VA 23708-2297

TEL: FAX:

FAX:

TEL: SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

$24,000,000

NAICS:

611710

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF23

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

HT940624Q0017

Section SF 1449 - CONTINUATION SHEET

SOLICITATION/CONTRACT FORM

VENDOR TO COMPLETE THE FOLLOWING:

CAGE: _____________________

UEI: _____________________

Vendor POC: _____________________

Vendor Phone: ____________________

Vendor E-mail: ____________________

Notes to Vendor:

-At a minimum, the SF1449 must be completed to be considered for this opportunity. Additional reqirement in order to be considered for the opportunity; submit a brochure, spec sheet, or past performance information. Please respond to blocks 17a and 30a-c on page 1 and the vendor information on page 3, as well as provide your price(s) on the

Contract Line Item Number(s) (CLINs). Cursive font signatures will not be accepted.

-Offeror will provide all license agreements, End User License Agreements (EULA), Terms of Service (TOS), Federal Payment Plans, Extended Payment Plans, and other similar instruments or agreements, required to be signed, or agreed to, by the Government that the offeror or any of its suppliers or subcontractors (at any level) require. The Government may review to ensure terms and conditions are consistent with Federal law and otherwise satisfy the Government’s needs. Among terms and conditions that are not acceptable, which makes an offer ineligible for award, include: those such as Government indemnification of any party; choice of law or forum for disputes; mandatory arbitration; any language that would or might require the Government to renew or extend performance or usage of any item, product, or service; or any other feature that unduly puts a burden or restriction on the Government.

-Vendor to reference request for quotes number (RFQ#) HT940624Q0017 on all inquiries.

NOTE TO VENDOR:

Because the Government’s automated procurement system does not provide for the contractor’s electronic signature, a fully executed copy of this bilateral award, signed by both parties, will be retained in the Government’s official contract file.

-For competitive service buys, type: Award will be made on the basis of the lowest evaluated price and the capability to meet the requirement detailed in the Performance Work Statement.

PROMPT PAYMENT

For Prompt Payment Act purposes, this contract is subject to the 7 calendar day constructive acceptance period.

Billing / Payment in arrears

For all questions, POC:

Ms. Lindsay A. Gray Contract Specialist E: Lindsay.a.gray.civ@health.mil mailto:Lindsay.a.gray.civ@health.mil

PERFORMANCE WORK STATEMENT

1.0 GENERAL INFORMATION

NMRTC Portsmouth Laboratory requires a quality management software for clinical laboratory to retain positive document control of all forms and Standard Operating Procedurs in accordance with accrediting agency (College of American Pathologist) requirements.

1.1 This is a non-personal services contract to provide quality management software for the clinical laboratory.

1.1.1 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to provide a quality management software as defined in this

Performance Work Statement (PWS).

1.1.2 Background: NMRTC Portsmouth’s Laboratory currently uses this software as provided by current vendor. Market research was performed to compare top competitors to current vendor.

1.1.3 Scope: Services to be provided include document control, reliable software with zero downtime, allows up to 150 users, and has proper authorizations to perform on government networks.

1.1.4 Period of Performance (PoP): 09 Jun 2024- 08 Jun 2025 (Base Year + 4 option years).

1.2 Administrative specifications

1.2.1 Place of performance: The work shall be performed at NMRTC Portsmouth Laboratory-

Building 2, 1st floor

1.2.2 Recognized Federal holidays: Software must perform and offer technical support on all holidays

New Year’s Day Labor Day

Martin Luther King Jr.’s Birthday Columbus Day

President’s Day Veteran’s Day

Memorial Day Thanksgiving Day

Juneteenth Day Christmas Day

Independence Day

1.2.3 Hours of operation: The contractor is responsible for conducting business Monday thru

Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.

1.2.4 Emergency Services: Software is expected to perform 24/7 to ensure continuous, safe patient care to patients at NMRTC Portsmouth

1.3 Contractor Identification

1.3.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the Governemnt understands that the person is contractor support personnel.

2.0 SPECIFIC TASKS

2.1 Document Control- Vendor must provide positive document control of all Laboratory

Standard Operating Procedures in accordance with accrediting agency requirements. All procedures, forms, and appendixes will be locked and controlled by Laboratory’s Quality

Assurance team as well as supervisors/technical leads as stated in Medical Director’s delegation letter. Software must provide security against all entities outside Laboratory from having access or ability to alter any documents being controlled.

2.2 150 Users Minimum- Software must be able to support atleast 150 users without any system glitches or delays to daily operations. Vendor must ensure that any glitches due to high user volume are resolved immediately and take measures to alleviate.

2.3 Proper Government Network Authorizations- Software must have pre-approval to operate seamlessly on government networks. All features and applications must be compatible with DoD network. Vendor must ensure that their permissions to operate on these networks are maintained without any lapses to services.

3.0 Qualifications/Considerations

3.1 Special Qualifications/Considerations: Proper authorizations to operate at optimal level on government networks.

Software and/or hardware must be an approved product by the Defense Health Agency (DHA), and authorized to be used on the DHA network.

4.0 Points of Contact

4.1 Points of Contact: LTJG Ramanvir Sidhu 757-953-1737. John Kmieciak 757-953-7918.

PRIVACY & SECURITY OF PHI

Personally Identifiable Information, Protected Health Information, and Federal

Information Requirements (Revised 10/27/2020)

1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information

(PHI) and Federal Information Laws

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of

Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the

Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The

Contractor shall also comply with requirements relating to records management as described herein.

This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.

For purposes of this Section, the following definitions apply.

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDI 5400.11, DoD Privacy and Civil Liberties Programs, January 29, 2019 and DoDI 5400.11- R, Department of Defense Privacy

Program, May 14, 2007

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S.

Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E

(Enforcement), as amended. Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part

162) are not addressed in this Section and are not included in the term HIPAA Rules.

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health

System (MHS). These issuances are DoDM 6025.18, “Implementation of the Health Insurance Portability and

Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, DoDI 6025.18, Health

Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs, March 13, 2019, and DoDI 8580.02, Security of Individually Identifiable Health Information in DoD Health Care

Programs, August. 12, 2015.

Defense Health Agency (DHA) Privacy Office is the DHA Privacy and Civil Liberties Office. The DHA Privacy

Office Chief is the HIPAA Privacy and Security Officer for DHA.

2. Records Management

When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter

XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction

No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records

Management requirements outlined in the current TRICARE Operations Manual (TOM).

3. Freedom of Information Act (FOIA)

The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:

The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request preferably sent via the National FOIA Portal at: www.FOIA.gov. However, requesters may also submit requests via email at http://www.dtic.mil/whs/directives http://www.foia.gov/

DHA.FOIA@mail.mil; or via postal delivery addressed to the DHA Freedom of Information Service Center, 7700

Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101. All FOIA requests shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Contract and/or Modification numbers must be included in all FOIA requests seeking DHA procurement records. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible and respond to DHA within ten working days.

In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of

DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of

Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the

Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.

4. Systems of Records

In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier.

Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil Liberties, and Transparency

Division, and as required by the DoD Privacy Act Issuances.

Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, OMB Circular A-130, and Privacy Act of 1974 requirements applicable to contractors operating systems of records on behalf of federal agencies. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.

5. Privacy Impact Assessment (PIA)

If DHA data is stored on a Contractor owned system, a PIA is required from the Contractor.

6. Data Sharing Agreement (DSA)

6.1 (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de-identified data)

The Contractor shall consult with the DHA Privacy Office to determine if the Contractor must obtain a DSA or Data

Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.

The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and DoD HIPAA Issuances. Likewise, the

Contractor shall comply with the DoD Privacy Act Issuances.

mailto:DHA.FOIA@mail.mil

Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor must gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA Privacy Board requests for additional documentation.

To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the DHA Privacy

Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data involved:

• DSA for De-Identified Data

• DSA for PHI

• DSA for PII Without PHI

• DUA for Limited Data Set

DSAs executed for contract support will expire after 1 year or at the end of the contract option 2 year, whichever comes first. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the

Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.

6.2 (Applies if contract requirements may include human subject research)

This Contract incorporates by reference the Protection of Human Subject Research clause in the Defense Federal

Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235-7004. A separate DFARS provision, 48 CFR

235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR 219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a contractor participates in a study or demonstration project or other activity that involves human subject research, then the contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If contractor activity appears to involve human subject research, then the contractor shall consult the DHA Privacy Office, which may contact the Research Regulatory Oversight Office in the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)).

7. Privacy Act and HIPAA Training

The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this

Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of substance use disorder patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a

Covered Entity, or Business Associate.

The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the

Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.

8. HIPAA Business Associate Provisions

8.1 Business Associate – General Provisions

The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the

Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. The contractor shall use the DoD BAA, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD Components”, located at, https://www.health.mil/Military-Health-Topics/Privacy-and-

CivilLiberties/Privacy-Contract-Language/HIPAA-Compliant-Business-Associate-Agreement-for- the-MHS. b.i.

and (3)b.ii

9. Breach Response

[This paragraph 9 is inoperative, and all references herein to “paragraph 9” shall be deemed to refer to the TOM breach responses provisions, if the contract incorporates the TOM by reference

9.1 Definitions Related to Breach response

9.1.2 Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The foregoing definition is based on the definition of breach in DoDM 6025.18. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral

PII/PHI).

9.1.3 A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the contractor does not initially know whether or not the PII/PHI was encrypted, then the incident must initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the contractor. In determining whether unauthorized access should be suspected, the contractor shall consider at least the following factors:

• How the event was discovered;

• Did the information stay within the covered entity’s control;

• Was the information actually accessed/viewed; and

• Ability to ensure containment (e.g., recovered, destroyed, or deleted).

9.1.4 A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the contractor knows that the PII/PHI is unencrypted, then the contractor should classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the contractor knows this even without knowing whether or not unauthorized access to the

PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the contractor should re-classify the incident as a non-breach incident.

9.1.5 A HHS breach is an incident that satisfies the definition of breach in Section 164.402 of the HIPAA Breach

Rule. The text of the HHS definition states:

Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.

HHS breach excludes:

Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the

HIPAA Privacy Rule.

Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy Rule.

A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.

Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;

The unauthorized person who used the PHI or to whom the disclosure was made;

Whether the PHI was actually acquired or viewed; and

The extent to which the risk to the PHI has been mitigated.

9.1.6 A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI. A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.

9.2 General

9.2.1 The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.

9.2.2 Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the

Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation

(which includes individual notification), eradication, recovery, and follow-up.

9.2.3 The contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The contractor should consult with the DHA Privacy Office where guidance is needed, such as when the contractor is uncertain whether a discovered breach is the contractor’s responsibility (e.g., if the contractor discovers a breach not caused by the contractor), or how the contractor is to classify an incident (breach

vs. non-breach, confirmed vs. possible, cyber vs. non-cyber). Under no circumstances will a contractor delay reporting a confirmed or possible breach to the DHA Privacy Office beyond the 24-hour deadline.. In conjunction with its initial investigation, the contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.

9.2.4 In the event of a cybersecurity incident not involving a PII/PHI breach, the contractor shall follow applicable

DoD cybersecurity and NIST requirements, which include United StatesComputer Emergency Readiness Team (US-

CERT) reporting (see paragraph 9.3). If at any point a contractor finds that a cybersecurity incident involves a

PII/PHI breach (possible or confirmed), the contractor shall immediately initiate the reporting procedures set forth below. The contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.

9.2.5 Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the contractor immediately after discovery. The time of that report to the contractor shall trigger the contractor’s DHA Privacy Office reporting deadline (24 hours) under paragraph 9.3.2. If a cybersecurity incident is involved, the contractor’s deadline for US-CERT reporting (1 hour) runs from the time the incident is confirmed. The contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the contractor to complete the breach response requirements herein. Alternatively, the contractor and subcontractor may agree that the subcontractor shall report directly to US-CERT and the DHA Privacy Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the contractor of the incident and the subsequent response actions.

9.2.6 Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the outcome. Investigations identifying unauthorized disclosures must be logged for HIPAA and Privacy Act disclosure accounting purposes, whether or not individual notification is required under the HIPAA Breach Rule.

9.2.7 Contractors, when acting as HIPAA-covered entities, and not as business associates, are not subject to the breach response requirements herein. However, such contractors are subject to both the HIPAA Breach Rule

(applicable to them in their capacity as covered entities) and DoD cybersecurity requirements (applicable to them in their capacity as DoD contractors).

9.3 Reporting Provisions

9.3.1 Immediately upon discovery of a possible or confirmed breach or cybersecurity incident, the contractor shall initiate an investigation. If the incident involves electronic PII/PHI, and if the investigation finds a confirmed breach or cybersecurity incident, the contractor shall report it, within 1 hour of confirmation, to the US-CERT Incident

Reporting System at https://forms.uscert.gov/report/, as required by the Department of Homeland Security (DHS).

Note: DHS no longer requires US-CERT reporting of non-cyber breaches or unconfirmed electronic breaches.

However, DHS permits US-CERT reporting of unconfirmed cyber-related incidents on a voluntary basis. Thus, if a contractor is uncertain whether a possible cyber-related incident should be treated as confirmed and thus reportable, the contractor may voluntarily report the incident.

Before submission to US-CERT, the contractor shall save a copy of the on-line report. After submitting the report, the contractor shall record the US-CERT incident reporting number, which shall be included in the initial report to the DHA Privacy Office as described in paragraph 9.3.2.

Note: Regardless of whether or not an incident is confirmed as a breach, the contractor must also investigate whether or not the incident impacts data integrity or availability of PII/PHI. If such impact is confirmed, then the incident is reportable to US-CERT as a cybersecurity incident. For guidance on investigating the impact on data integrity and availability, refer to DoD cybersecurity and NIST guidance.

The contractor shall provide any updates to the initial US-CERT report by email to soc@uscert.gov, with the

Reporting Number in the subject line. The contractor shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office if requested. Contractor questions about US-CERT reporting shall be directed to the

DHA Privacy Office, not the US- CERT office.

9.3.2 In addition to US-CERT reporting, the contractor shall report to the DHA Privacy Office by submitting the form specified below within 24 hours of discovery of a breach (possible or confirmed), unless the breach falls within a category that the Privacy Office has determined to be not reportable. This 24-hour period runs from the time of discovery, unlike the 1 hour USCERT reporting period, which runs from the time a cybersecurity incident is confirmed. Thus, depending on the time period needed to confirm, the report to the DHA Privacy Office may be due either before or after the US-CERT report.

The breach report form required within the 24-hour deadline shall be sent by e-mail to:

DHA.PrivacyOfficer@mail.mil. The contractor shall also e-mail the report to the CO, the COR and its usual point of contact at the applicable Program Office. Encryption is not required, because reports and notices shall not contain

PII/PHI. If electronic mail is not available, telephone notification is also acceptable (at 703-275-6363), but all notifications and reports delivered telephonically must be confirmed in writing as soon as technically feasible.

mailto:DHA.PrivacyOfficer@mail.mil

Contractors shall prepare the breach reports required within the 24-hour deadline by completing the Breach

Reporting Department of Defense Form DD 2959 (Breach of PII Report), available at https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf. For non-cyber incidents without a US-

CERT number, the contractor shall assign an internal tracking number and include that number in Box 1.e of the DD

Form 2959. The contractor shall coordinate with the DHA Privacy Office for subsequent action, such as beneficiary notification, and mitigation. The contractor must promptly update the DD Form 2959 as new information becomes available.

When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Contractor shall submit a revised form or forms promptly after the new information becomes available, stating the updated status and previous report date(s) and showing any revisions or additions in red text. The Contractor shall provide updates to the same parties as required for the initial Breach

Report Form.

9.4 Individual Notification Provisions

9.4.1 If the DHA Privacy Office determines that individual notification is required, the Contractor shall provide written notification to beneficiaries affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities and addresses of the beneficiaries are ascertained. The 10 day period begins when the Contractor is able to determine the identities (including addresses) of the beneficiaries whose records were impacted. If notification cannot be accomplished within 10 working days, the contractor shall notify the DHA Privacy Office.

9.4.2 The Contractor’s proposed notification to be issued to the affected beneficiaries shall be 2 submitted to the

DHA Privacy Office for approval. The notification to beneficiaries shall include, at a minimum, the following:

• Specific data elements,

• Basic facts and circumstances,

• Recommended precautions the beneficiary can take,

• Federal Trade Commission (FTC) identity theft hotline information, and

• Any mitigation support services offered, such as credit monitoring.

Contractors shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Contractor and/or subcontractor organization that suffered the breach.

If media notice is required, the contractor will submit a proposed notice and suggested media outlets for the DHA

Privacy Office review and approval (which will include coordination with the DHA Communications Division).

9.5 In the event the Contractor is uncertain on how to apply the above requirements, the Contractor shall consult with the CO, who will consult with the Privacy Office as appropriate when determinations on applying the above requirements are needed.

The Contractor shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the

Contractor has caused or is otherwise responsible for addressing.

https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 1 Job MediaLab Corporate System Account

FFP

See List of Deliverables

See Performance Work Statement for full description

FOB: Destination

PURCHASE REQUEST NUMBER: 0011990108-0001

DA10

NET AMT

1001 1 Job OPTION MediaLab Corporate System Account

2002 1 Job OPTION MediaLab Corporate System Account

3001 1 Job OPTION MediaLab Corporate System Account

4001 1 Job OPTION MediaLab Corporate System Account

5001 1 Job OPTION MediaLab Corporate System Account

See List of Deliverables (Six-month extension POP:09 JUN 2029-08 DEC 2029)

INSPECTION AND ACCEPTANCE TERMS

Supplies/services will be inspected/accepted at:

CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY

0001 Destination Government Destination Government

1001 Destination Government Destination Government

2002 Destination Government Destination Government

3001 Destination Government Destination Government

4001 Destination Government Destination Government

5001 Destination Government Destination Government

DELIVERY INFORMATION

CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /

CAGE

0001 POP 09-JUN-2024 TO

08-JUN-2025

N/A NAV MED CNT PORTSMOUTH VA - MM

KRISTEN COTE

ATTN SUPPLY OFFICER BLDG 250

54 LEWIS MINOR STREET

PORTSMOUTH VA 23708-2297

HT0242

1001 POP 09-JUN-2025 TO

08-JUN-2026

N/A (SAME AS PREVIOUS LOCATION)

2002 POP 09-JUN-2026 TO

08-JUN-2027

N/A (SAME AS PREVIOUS LOCATION)

3001 POP 09-JUN-2027 TO

08-JUN-2028

N/A (SAME AS PREVIOUS LOCATION)

4001 POP 09-JUN-2028 TO

08-JUN-2029

N/A (SAME AS PREVIOUS LOCATION)

5001 POP 09-JUN-2029 TO

08-DEC-2029

N/A (SAME AS PREVIOUS LOCATION)

CLAUSES INCORPORATED BY REFERENCE

52.201-1 Acquisition 360: Voluntary Survey SEP 2023

52.203-7 Anti-Kickback Procedures JUN 2020

52.203-11 Certification And Disclosure Regarding Payments To

Influence Certain Federal Transactions

SEP 2007

52.203-12 Limitation On Payments To Influence Certain Federal

Transactions

JUN 2020

52.203-18 Prohibition on Contracting With Entities That Require Certain

Internal Confidentiality Agreements or Statements--

Representation

JAN 2017

52.203-19 Prohibition on Requiring Certain Internal Confidentiality

Agreements or Statements

JAN 2017

52.204-3 Taxpayer Identification OCT 1998

52.204-7 System for Award Management OCT 2018

52.204-8 Annual Representations and Certifications MAR 2023

52.204-10 Reporting Executive Compensation and First-Tier

Subcontract Awards

JUN 2020

52.204-13 System for Award Management Maintenance OCT 2018

52.204-16 Commercial and Government Entity Code Reporting AUG 2020

52.204-17 Ownership or Control of Offeror AUG 2020

52.204-18 Commercial and Government Entity Code Maintenance AUG 2020

52.204-19 Incorporation by Reference of Representations and

Certifications.

DEC 2014

52.204-20 Predecessor of Offeror AUG 2020

52.204-22 Alternative Line Item Proposal JAN 2017

52.204-23 Prohibition on Contracting for Hardware, Software, and

Services Developed or Provided by Kaspersky Lab Covered

Entities

DEC 2023

52.204-24 Representation Regarding Certain Telecommunications and

Video Surveillance Services or Equipment

NOV 2021

52.204-25 Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment

NOV 2021

52.204-26 Covered Telecommunications Equipment or Services--

Representation.

OCT 2020

52.204-27 Prohibition on a ByteDance Covered Application JUN 2023

52.204-28 Federal Acquisition Supply Chain Security Act Orders--

Federal Supply Schedules, Governmentwide Acquisition

Contracts, and Multi-Agency Contracts.

DEC 2023

52.204-29 Federal Acquisition Supply Chain Security Act Orders--

Representation and Disclosures.

DEC 2023

52.204-30 Federal Acquisition Supply Chain Security Act Orders--

Prohibition.

DEC 2023

52.209-2 Prohibition on Contracting with Inverted Domestic

Corporations--Representation

NOV 2015

52.209-10 Prohibition on Contracting With Inverted Domestic

Corporations

NOV 2015

52.209-11 Representation by Corporations Regarding Delinquent Tax

Liability or a Felony Conviction under any Federal Law

FEB 2016

52.211-2 Availability of Defense Specifications, Standards, and Data

Item Descriptions in the Acquisition Streamlining and

Standardization Information System (ASSIST) Website

SEP 2023

52.212-4 Contract Terms and Conditions--Commercial Products and

Commercial Services

NOV 2023

52.212-5 Contract Terms and Conditions Required to Implement

Statutes or Executive Orders--Commercial Products and

Commercial Services

DEC 2023

52.214-34 Submission Of Offers In The English Language APR 1991

52.214-35 Submission Of Offers In U.S. Currency APR 1991

52.217-5 Evaluation Of Options JUL 1990

52.219-1 Alt I (Dev) Small Business Program Representations (DEVIATION

2024-O0002) Alternate I

JAN 2024

52.219-4 Notice of Price Evaluation Preference for HUBZone Small

Business Concerns

OCT 2022

52.219-28 (Dev) Post-Award Small Business Program Rerepresentation

(DEVIATION 2024-O0002)

JAN 2024

52.219-31 Notice of Small Business Reserve MAR 2020

52.219-32 Orders Issued Directly Under Small Business Reserves MAR 2020

52.219-33 Nonmanufacturer Rule SEP 2021

52.222-3 Convict Labor JUN 2003

52.222-4 Contract Work Hours and Safety Standards - Overtime

Compensation

MAY 2018

52.222-18 Certification Regarding Knowledge of Child Labor for Listed

End Products

FEB 2021

52.222-22 Previous Contracts And Compliance Reports FEB 1999

52.222-25 Affirmative Action Compliance APR 1984

52.222-26 Equal Opportunity SEP 2016

52.222-50 Combating Trafficking in Persons NOV 2021

52.222-54 Employment Eligibility Verification MAY 2022

52.223-1 Biobased Product Certification MAY 2012

52.223-2 Affirmative Procurement of Biobased Products Under Service and Construction Contracts

SEP 2013

52.223-18 Encouraging Contractor Policies To Ban Text Messaging

While Driving

JUN 2020

52.223-22 Public Disclosure of Greenhouse Gas Emissions and

Reduction Goals -- Representation.

DEC 2016

52.225-1 Buy American--Supplies OCT 2022

52.225-13 Restrictions on Certain Foreign Purchases FEB 2021

52.225-18 Place of Manufacture AUG 2018

52.225-20 Prohibition on Conducting Restricted Business Operations in

Sudan--Certification

AUG 2009

52.225-25 Prohibition on Contracting with Entities Engaging in Certain

Activities or Transactions Relating to Iran-- Representation and Certifications.

JUN 2020

52.226-1 Utilization Of Indian Organizations And Indian-Owned

Economic Enterprises

JUN 2000

52.232-23 Alt I Assignment of Claims (May 2014) - Alternate I APR 1984

52.232-28 Invitation to Propose Performance-Based Payments MAR 2000

52.232-33 Payment by Electronic Funds Transfer--System for Award

Management

OCT 2018

52.232-39 Unenforceability of Unauthorized Obligations JUN 2013

52.232-40 Providing Accelerated Payments to Small Business

Subcontractors

MAR 2023

52.233-4 Applicable Law for Breach of Contract Claim OCT 2004

52.237-2 Protection Of Government Buildings, Equipment, And

Vegetation

APR 1984

52.237-3 Continuity Of Services JAN 1991

52.242-15 Stop-Work Order AUG 1989

52.244-6 Subcontracts for Commercial Products and Commercial

Services

DEC 2023

52.249-4 Termination For Convenience Of The Government (Services)

(Short Form)

APR 1984

52.252-1 Solicitation Provisions Incorporated By Reference FEB 1998

52.252-5 Authorized Deviations In Provisions NOV 2020

52.252-6 Authorized Deviations In Clauses NOV 2020

252.203-7000 Requirements Relating to Compensation of Former DoD

Officials

SEP 2011

252.203-7002 Requirement to Inform Employees of Whistleblower Rights DEC 2022

252.204-7003 Control Of Government Personnel Work Product APR 1992

252.204-7007 Alternate A, Annual Representations and Certifications NOV 2023

252.204-7012 Safeguarding Covered Defense Information and Cyber

Incident Reporting

JAN 2023

252.204-7015 Notice of Authorized Disclosure of Information for Litigation

Support

JAN 2023

252.204-7016 Covered Defense Telecommunications Equipment or Services

-- Representation

DEC 2019

252.204-7017 Prohibition on the Acquisition of Covered Defense

Telecommunications Equipment or Services -- Representation

MAY 2021

252.204-7018 Prohibition on the Acquisition of Covered Defense

Telecommunications Equipment or Services

JAN 2023

252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements NOV 2023

252.204-7020 NIST SP 800-171 DoD Assessment Requirements NOV 2023

252.204-7022 Expediting Contract Closeout MAY 2021

252.204-7024 Notice on the Use of the Supplier Performance Risk System MAR 2023

252.209-7004 Subcontracting With Firms That Are Owned or Controlled By

The Government of a Country that is a State Sponsor of

Terrorism

MAY 2019

252.215-7014 Exception from Certified Cost or Pricing Data Requirements for Foreign Military Sales Indirect Offsets.

DEC 2022

252.215-7015 Program Should-Cost Review NOV 2019

252.215-7998 (Dev) Pilot Program to Accelerate Contracting and Pricing

Processes. (DEVIATION 2023-O0004)

JAN 2023

252.223-7997 (Dev) Prohibition on Procurement of Certain Items Containing

Perfluorooctane Sulfonate or Perfluorooctanoic Acid -

Representation (DEVIATION 2022-O0010)

SEP 2022

252.223-7998 (Dev) Prohibition on Procurement of Certain Items Containing

Perfluorooctane Sulfonate or Perfluorooctanoic Acid

(DEVIATION 2022-O0010)

SEP 2022

252.225-7001 Buy American And Balance Of Payments Program--Basic JAN 2023

252.225-7002 Qualifying Country Sources As Subcontractors MAR 2022

252.225-7048 Export-Controlled Items JUN 2013

252.225-7050 Disclosure of Ownership or Control by the Government of a

Country that is a State Sponsor of Terrorism

DEC 2022

252.225-7053 Representation Regarding Prohibition on Use of Certain

Energy Sourced from Inside the Russian Federation

AUG 2021

252.225-7054 Prohibition on Use of Certain Energy Sourced from Inside the

Russian Federation

JAN 2023

252.225-7055 Representation Regarding Business Operations with the

Maduro Regime

MAY 2022

252.225-7056 Prohibition Regarding Business Operations with the Maduro

Regime

JAN 2023

252.225-7059 Prohibition on Certain Procurements from the Xinjiang

Uyghur Autonomous Region - Representation

JUN 2023

252.225-7060 Prohibition on Certain Procurements from the Xinjiang

Uyghur Autonomous Region

JUN 2023

252.225-7061 Restriction on the Acquisition of Personal Protective

Equipment and Certain Other Items from Non-Allied Foreign

Nations

JAN 2023

252.225-7972 (Dev) Prohibition on the Procurement of Foreign-Made Unmanned

Aircraft Systems (DEVIATION 2020-O0015)

MAY 2020

252.225-7973 (Dev) Prohibition on the Procurement of Foreign-Made Unmanned

Aircraft Systems - Representation (DEVIATION 2020-

O0015)

MAY 2020

252.232-7003 Electronic Submission of Payment Requests and Receiving

Reports

DEC 2018

252.232-7010 Levies on Contract Payments DEC 2006

252.232-7015 Performance-Based Payments--Representation DEC 2022

252.232-7016 Notice of Progress Payments or Performance-Based Payments APR 2020

252.233-7001 Choice of Law (Overseas) JUN 1997

252.237-7010 Prohibition on Interrogation of Detainees by Contractor

Personnel

JAN 2023

252.239-7001 Information Assurance Contractor Training and Certification JAN 2008

252.243-7001 Pricing Of Contract Modifications DEC 1991

252.244-7000 Subcontracts for Commercial Products or Commercial

Services

NOV 2023

252.246-7008 Sources of Electronic Parts JAN 2023

252.247-7023 Transportation of Supplies by Sea JAN 2023

CLAUSES INCORPORATED BY FULL TEXT

52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)

The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the

Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the

Contractor within 3 months.

(End of clause)

52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 7 months provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 5 days before the contract expires.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .