HT940624Q0060.pdf
PDF 657 KB Posted
- Attached to
- CCTV SYSTEM INSTALL Federal contract opportunity
- Solicitation number
- HT940624Q0060
- Issued by
- Defense Health Agency
About this file
This document is a Request for Quotation (RFQ) for the procurement, installation, and programming of a Closed-Circuit Television (CCTV) system at the Naval Medical Center in Portsmouth, Virginia. The contractor shall provide all equipment, services, and training required to deliver a turnkey CCTV solution that integrates with the government's existing system.
The key details are:
- This is a small business set-aside solicitation, with responses due by 10:00 AM EST on May 28, 2024.
- The contractor must provide a technical capabilities statement, past performance references, and pricing information to be considered for award.
- Evaluation factors are technical approach, key personnel, delivery schedule, past performance, and price, with technical being the most important.
- The government will award a Firm-Fixed-Price contract for all requirements - no partial awards will be considered.
- The contractor shall remove and dispose of the existing CCTV equipment and provide training to the government's staff upon completion of the installation.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
HT940624Q0060 21-May-2024
b. TELEPHONE NUMBER
(757)953-5740
8. OFFER DUE DATE/LOCAL TIME
10:00 AM 28 May 2024
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
HT94069. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
KIMBERLY BUNN
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
0012102481
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED OR X
SMALL BUSINESSX
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
DHA CONTRACTING OFFICE TIDEWATER HT9406
7700 ARLINGTON BLVD
FALLS CHURCH VA 22042
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE HT0242 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
DFAS INDIANAPOLIS (GFEBS) 21001
DFAS INDIANAPOLIS (GFEBS) 21001
8899 E. 56 TH STREET
INDIANAPOLIS IN 46249-3120
INDIANAPOLIS IN 46249-3120
TEL: FAX:
FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$19,000,000
NAICS:
811412
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF35
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
HT940624Q0060
Section A - Solicitation/Contract Form
POINTS OF CONTACT
VENDOR TO COMPLETE THE FOLLOWING:
COMPANY NAME: ______________________
CAGE: ___________________
DUNS: ___________________
Vendor POC: ____________________
Phone: ____________________
Fax: ____________________
Vendor email: _________________________________
Defense Health Agency Contracting Activity (DHACA) POC: Kimberly Bunn
Phone: 757-953-5740
Email: kimberly.p.bunn.civ@health.mil
Product/Services for: Naval Medical Center Portsmouth VA
620 John Paul Jones Circle
Portsmouth VA 23708-2297
Phone: 757-953-1494
Vendor to reference RFQ Number: HT940624Q0060 on all inquiries.
PAYMENT INFORMATION
Payment in Arrears (Check One): Monthly Quarterly Semi-Annually Annually
*Please ensure that quoted price matches the choice above and is evenly divisible depending on the selection
PROMPT PAYMENT
For Prompt Payment Act Purposes, this contract is:
Subject to the 7-calender day constructive acceptance period.
Note: Vendor will be required to provide billing electronically via the WAWF Electronic Invoicing Method. For additional information, a review of the following web sites may be required: websites: https://wawf.eb.mil or http://wawftraining
Email: usn.detrick.nmrlc-detftdmd.list.nmlc-wawf@health.mill
DISCOUNTS
The vendor's initial response to this RFQ should reflect the Vendors' best price including all allowable discounts that are available to the Federal Government. Please identify all discounts that are being offered as part of the vendor's quote submission. The government does not intend to go out for a best and final offer.
EMAIL QUOTES/PROPOSALS TO: kimberly.p.bunn.civ@health.mil
DO NOT forward via U.S. Mail service. It is the Contractor’s responsibility to confirm receipt of quote/proposal.
https://wawf.eb.mil/ http://wawftraining/ mailto:usn.detrick.navmedlogcomftdmd.list.nmlc-wawf@mail.mil mailto:usn.detrick.navmedlogcomftdmd.list.nmlc-wawf@mail.mil kimberly.p.bunn.civ@health.mil%20
Section B - Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 1 Each
CCTV SYSTEM
FFP
CCTV SYSTEM
ER and Back ER Cameras
FOB: Destination
PURCHASE REQUEST NUMBER: 0012102481
J074
NET AMT
Section C - Descriptions and Specifications
PERFORMANCE WORK STATEMENT
PERFORMANCE WORK STATEMENT (PWS)
FOR CLOSED-CIRCUIT TELEVISION (CCTV) INSTALLATION AT NAVAL
MEDICAL CENTER PORTSMOUTH (NMCP)
PART 1
SCOPE OF WORK- ER and Back ER Cameras
This contract is for the procurement, installation, and programming of Closed-circuit television
(CCTV) equipment. The contract also includes the removal and disposal of existing CCTV equipment for NMCP Emergency Department (ED) and to provide training on all install equipment to NMCP ED/Telecommunication staff members as identified by the government.
The contractor shall provide fully operational CCTV equipment that meets the government requirements which must interface with existing government provided equipment. The contractor shall provide a plan for a system design to include any changes, recommendations, and wiring with the new installation. All components or equipment installed must be new and fully operational prior to government testing and acceptance. Government will only accept new equipment that meet the above specifications and meet manufacturer requirements.
1 GENERAL: This is a non-personal services contract to provide CCTV equipment installation. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.
1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, other items, and non-personal services necessary to perform a turn-key CCTV installation as defined in this
PWS except for those items specified as government furnished property and services. The contractor shall provide training to all staff members as identify by the government. The contractor shall perform to the standards in this contract.
1.2 Background: The procurement, installation, and digital programming of CCTV equipment, along with the removal and disposal of current CCTV equipment.
1.3 Objectives:
a. Removal of current CCTV equipment
b. Installation of new CCTV equipment
c. Programming if applicable of all digital components
d. Provide training to all identified NMCP ED/Telecommunication staff members.
1.4 Scope: The installation and programming of CCTV digital systems. The removal of existing CCTV equipment. The contractor shall accomplish the installation of new CCTV equipment and all programming as require for all digital component or systems to provide a turn-key product. Also provide training upon completion of installation to identified NMCP
ED/Telecommunication staff members.
1.5 Period of Performance: Not applicable for the PWS.
GENERAL INFORMATION
1.6 Quality Control: The contractor shall develop and maintain an effective QCP to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services.
The contractor’s quality control program is how the contractor assures that the work performance complies with the contract requirements of the contract. After acceptance of the QAP the contractor shall receive the KO’s acceptance in writing of any proposed change to the QC system.
1.7 Recognized Holidays: Contractor is not required to perform services on holidays.
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Memorial Day Thanksgiving Day
Independence Day Christmas Day
1.8 Hours of Operation: The contractor is responsible for conducting business, between the hours of 0730 a.m. to 4:30 p.m. Monday thru Friday except Federal holidays or when the
Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The Contractor must always maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.
1.9 Place of Performance: The work to be performed under this contract will be performed at
NMCP ED.
1.10 Type of Contract: The government will award a FFP Contract.
1.11 PHYSICAL Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
1.12 Key Control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the KO.
1.12.01 In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks;
however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.
1.12.02 The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than
Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.
1.12.03Lock Combinations: Not applicable. The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons.
The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s QCP
1.13 Special Qualifications: The contractor is responsible for ensuring that employees are Cisco and AMX certified for digital programming.
1.14Identification of Contractor Employees: All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
1.15Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the KO. All materials supplied to the
Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
PART 2
DEFINITIONS & ACRONYMS
2 DEFINITIONS AND ACRONYMS:
2.1 DEFINITIONS:
2.1.01 CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.
2.1.02 CONTRACTING OFFICER (KO). A person with authority to enter, administer, and/or terminate contracts, and make related determinations and findings on behalf of the government. This is the only individual who can legally bind the government.
2.1.03 CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S.
Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations.
This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.04 DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.
2.1.05 DELIVERABLE. Anything that can be physically delivered but may include non-manufactured things such as meeting minutes or reports.
2.1.06 KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key
Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.07 PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.1.08 QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
2.1.09 QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
2.1.10 QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of a product or service meet contract requirements.
2.1.11 SUBCONTRACTOR. One that enters a contract with a prime contractor. The
Government does not have privity of contract with the subcontractor.
2.1.12 WORKDAY. The number of hours per day the Contractor provides services in accordance with the contract.
2.1.13 WORK WEEK. Monday through Friday, unless specified otherwise.
2.2 ACRONYMS:
ACOR Alternate Contracting Officer's Representative
CFR Code of Federal Regulations
CONUS Continental United States (excludes Alaska and Hawaii)
COR Contracting Officer Representative
COTS Commercial-Off-the-Shelf
DD250 Department of Defense Form 250 (Receiving Report)
DFARS Defense Federal Acquisition Regulation Supplement
DOD Department of Defense
FAR Federal Acquisition Regulation
HIPAA Health Insurance Portability and Accountability Act of 1996
KO Contracting Officer
OCI Organizational Conflict of Interest
OCONUS Outside Continental United States (includes Alaska and Hawaii)
ODC Other Direct Costs
POC Point of Contact
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Program
TE Technical Exhibit
PART 3
CONTRACTOR FURNISHED ITEMS AND SPECIFIC TASKS
The contractor with reprogram 5 each CDM1250 control stations for LTR system located in building 1 and 2 and provide frequency and talk group associated to each.
3 CONTRACTOR RESPONSIBILITIES AND SPECIFIC TASKS:
3.1 Basic Services. The contractor shall provide services for Installation of multimedia equipment.
3.2 The Contractor shall all supplies, equipment and services that will be needed for this installation.
3.3 Task Heading.
Section E - Inspection and Acceptance
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government
CLAUSES INCORPORATED BY REFERENCE
52.246-4 Inspection Of Services--Fixed Price AUG 1996
52.246-16 Responsibility For Supplies APR 1984
Section F - Deliveries or Performance
DOCK HOURS
Naval Medical Center Portsmouth (NMCP) Receiving Dock Hours of Operation:
NMCP Receiving Dock is open Monday through Friday 0700 to 1600 (7:00 a.m. to 4:00 p.m.), excluding federal holidays. Receiving personnel may be reached at 757-953-5770.
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 POP 01-JUN-2024 TO
30-MAY-2025
N/A DFAS INDIANAPOLIS (GFEBS) 21001
DFAS INDIANAPOLIS (GFEBS) 21001
8899 E. 56 TH STREET
INDIANAPOLIS IN 46249-3120
INDIANAPOLIS IN 46249-3120
FOB: Destination
HT0242
52.211-17 Delivery of Excess Quantities SEP 1989
52.247-34 F.O.B. Destination NOV 1991
Section G - Contract Administration Data
CLAUSES INCORPORATED BY FULL TEXT
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (JAN 2023)
(a) Definitions. As used in this clause—
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area
WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of
Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-
7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall—
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training
Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data
Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items—
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting
Officer.
https://www.sam.gov/
(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the
Contracting Officer.
(Contracting Officer: Insert either “Invoice 2in1” or the applicable invoice and receiving report document type(s) for fixed price line items for services.)
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial financing, submit a commercial financing request.
(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table*
Field Name in WAWF Data to be entered in WAWF
Pay Official DoDAAC ____
Issue By DoDAAC ____
Admin DoDAAC** ____
Inspect By DoDAAC ____
Ship To Code ____
Ship From Code ____
Mark For Code ____
Service Approver (DoDAAC) ____
Service Acceptor (DoDAAC) ____
Accept at Other DoDAAC ____
LPO DoDAAC ____
DCAA Auditor DoDAAC ____
Other DoDAAC(s) ____
(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert
“See Schedule” or “Not applicable.”)
(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the
DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)
(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition
Regulation 52.216-7, Allowable Cost and Payment, as applicable.
(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.
(g) WAWF point of contact.
(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s
WAWF point of contact.
(Contracting Officer: Insert applicable information or “Not applicable.”)
(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.
(End of clause)
Section H - Special Contract Requirements
PRIVACY
BUSINESS ASSOCIATE AGREEMENT
Privacy, Access, Use, and Disclosure of Protected Health Information
1. Introduction. In accordance with 45 C.F.R. §§ 164.502(e)(2) and 164.504(e), and DoDM 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health
Care Programs,” March 13, 2019, this document serves as a Business Associate Agreement (BAA) between the signatory Parties for purposes of the HIPAA and the “HITECH Act” amendments thereof, as implemented by the
HIPAA Rules and DoD HIPAA issuances (both defined below). The Parties are (1) a DoD Military Health System
(MHS) component command such as a Navy Medicine Medical Treatment Facility (MTF) (Naval Medical center or
Naval hospital), or special mission command (research, public health, other), acting as a HIPAA covered entity, and
(2) another Federal or Government organization, civilian academic institution, or other civilian entity, acting as a
HIPAA Business Associate (BA). The HIPAA Rules require BAAs between covered entities and BAs.
Implementing this BAA requirement, the applicable DoD HIPAA issuances (DoDM 6025.18) provides that requirements applicable to BAs must be incorporated (or incorporated by reference) into the contract or agreement between the Parties.
2. Definitions:
a. Terms. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules (DoDM6025.18-): Data aggregation, designated record set, disclosure, health care operations, individual, minimum necessary, notice of privacy practices, protected health information (PHI), required by law, secretary, security incident, subcontractor, unsecured PHI, and use.
b. Breach. means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other Personally Identifiable Information (PII) (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of “Breach” in DoD Privacy Act issuances as defined herein.
c. BA. shall generally have the same meaning as the term “BA” in the DoD HIPAA issuances, and in reference to this BAA, shall mean the entity (another Government organization, civilian academic institution, or other civilian organization), entering into agreement with a Navy Medicine MTF or special mission command.
d. Agreement. means this BAA together with the documents or other arrangements under which the
BA signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.
e. Covered Entity. shall generally have the same meaning as the term “covered entity” in the DoD
HIPAA issuances, and in reference to this BAA, shall mean a Navy Medicine MTF or special mission command under the Bureau of Medicine and Surgery.
f. DHA Privacy Office. means the Defense Health Agency (DHA) Privacy and Civil Liberties
Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the
National Capital Region Medical Directorate.
g. DoD HIPAA Issuances. means the DoD issuances implementing the HIPAA Rules in the DoD
MHS. These issuances are DoDM 6025.18 Implementation of the HIPAA Privacy Rule in DoD Health Care
Programs,” March 13, 2019; DoD Instruction 6025.18, Privacy of Individually Identifiable Health Information in
DoD Health Care Programs of December 2009, and DoD Instruction 8580.02, Security of Individually Identifiable
Health Information in DoD Health Care Programs of August 2015.
h. DoD Privacy Act Issuances. means the DoD issuances implementing the Privacy Act, which are
DoD Directive 5400.11, DoD Privacy Program of 29 October 2014, and DoD 5400.11-R, Department of Defense
Privacy Program of 8 May 2007.
i. HIPAA Rules. means, collectively, the HIPAA privacy, security, breach and enforcement rules, issued by the United States (US) Department of Health and Human Services (HHS) and codified at 45 C.F.R. §§ 160 and 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and 45 C.F.R. § 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules which implemented the “HITECH Act” provisions of Publication
L. 111-5. See 78 Federal Regulation 5566-5702 of 25 January 2013 (with corrections at 78 Federal Regulation
32464 of 7 June 2013. Additional HIPAA rules regarding electronic transactions and code sets (45 C.F.R. § 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
j. HHS Breach. means a breach that satisfies the HIPAA Breach Rule definition of “Breach” in 45
C.F.R. § 164.402.
k. Service-Level Privacy Office. means one or more offices within the military services (Army, Navy, or
Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance.
3. Obligations and Activities of BA:
a. The BA shall not access, use, or disclose PHI other than as permitted or required by this
Agreement, the controlling Memorandum of Understanding (MOU) or training affiliation agreement, or as required by law.
b. The BA shall use appropriate safeguards and comply with the DoD HIPAA Rules with respect to electronic PHI to prevent use or disclosure of PHI other than as provided for by this Agreement, the controlling
MOU, or law.
c. The BA shall report to the covered entity any Breach of which it becomes aware and shall proceed with breach response steps required by paragraph 7 (Breach Response) of this BAA. With respect to electronic PHI, the BA shall also respond to any security incident of which it becomes aware in accordance with any information assurance provisions of the Understanding. If at any point the BA becomes aware that a security incident involves a breach, the BA shall immediately initiate breach response as required by paragraph 7 (Breach Response) of this
BAA.
d. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, as applicable, the BA shall ensure that any entities that create, receive, maintain, or transmit PHI on behalf of the BA agree to the same restrictions, conditions, and requirements that apply to the BA with respect to such PHI.
e. The BA shall make available PHI in a designated record set, to the covered entity or, as directed by the covered entity, to an Individual, as necessary to satisfy the covered entity obligations under 45 C.F.R. § 164.524.
f. The BA shall make any amendment(s) to PHI in a designated record set as directed or agreed to by the covered entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy covered entity’s obligations under 45 C.F.R. § 164.526.
g. The BA shall maintain and make available the information required to provide an accounting of disclosures to the covered entity or an individual as necessary to satisfy the covered entity’s obligations under 45
C.F.R. § 164.528.
h. To the extent the BA is to carry out one or more of the covered entity’s obligation(s) under the
HIPAA privacy rule, the BA shall comply with the requirements of HIPAA privacy rule that apply to the covered entity in the performance of such obligation(s).
i. The BA shall make its internal practices, books, and records available to the Secretary and the covered entity for purposes of audit and in determining compliance with the HIPAA Rules.
4. Permitted Uses and Disclosures by BA:
a. The BA may only use or disclose PHI as necessary to perform the services set forth in the
Understanding or as required by law. The BA is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 C.F.R. § 164.514(a) through (c), nor is it permitted to use or disclose de-identified PHI except as provided by the Understanding or directed by the covered entity.
b. The BA agrees to use, disclose, and request PHI only in accordance with the HIPAA privacy rule
“minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA issuances.
c. The BA shall not use or disclose PHI in a manner that would violate the DoD HIPAA issuances or
HIPAA privacy rules if done by the covered entity, except uses and disclosures for the BA’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs:
(1) Except as otherwise limited in the understanding, the BA may use PHI for the proper management and administration of the BA or to carry out the legal responsibilities of the BA. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(2) Except as otherwise limited in the Understanding, the BA may disclose PHI for the proper management and administration of the BA or to carry out the legal responsibilities of the BA, provided that disclosures are required by law, or the BA obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the BA of any instances of which it is aware in which the confidentiality of the information has been breached.
(3) Except as otherwise limited in the Understanding, the BA may use PHI to provide Data Aggregation services relating to the covered entity’s health care operations.
5. Provisions for Covered Entity to Inform BA of Privacy Practices and Restrictions:
a. The covered entity shall provide the BA with the notice of privacy practices that the covered entity produces in accordance with 45 C.F.R.§ 164.520 and the corresponding provision of the DoD HIPAA issuances
(DoDM 6025.18).
b. The covered entity shall notify the BA of any changes in, or revocation of, the permission by an
Individual to use or disclose his or her PHI, to the extent that such changes affect the BA’s use or disclosure of PHI.
c. The covered entity shall notify the BA of any restriction on the use or disclosure of PHI that the covered entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such changes may affect the BA’s use or disclosure of PHI.
6. Permissible Requests by Covered Entity. The covered entity shall not request the BA to use or disclose
PHI in any manner that would not be permissible under the HIPAA privacy rule or any applicable Government regulations (including without limitation, DoD HIPAA issuances) if done by the covered entity, except for providing
Data Aggregation services to the covered entity and for management and administrative activities of the BA as otherwise permitted by this BAA.
7. Breach Response:
a. General. Breach Response is designed to satisfy the DoD Privacy Act issuances and the HIPAA
Breach Rule as implemented by the DoD HIPAA issuances. In general, the BA shall report the breach to the covered entity, assess the breach incident, notify affected individuals, and take mitigating actions, as applicable.
Because DoD defines “Breach” to include possible (suspected) as well as actual (confirmed) breaches, the BA shall implement these breach response requirements immediately upon the BA’s discovery of a possible breach. The following provisions set forth the BA’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches (defined below). In the event of a breach of PII or PHI held by the BA, the BA shall follow the breach response requirements set forth under paragraphs 7, 8, and 9 of this BAA, which are designed to satisfy both the Privacy Act and HIPAA, as applicable.
(1) If a breach involves PII without PHI, then the BA shall comply with DoD Privacy Act issuance breach response requirements only.
(2) If a breach involves PHI (a subset of PII), then the BA shall comply with both Privacy Act and HIPAA breach response requirements.
(3) If a breach involves PHI, it may or may not constitute an HHS Breach. If a breach is not an HHS
Breach, then the BA has no HIPAA breach response obligations. In such cases, the BA must still comply with breach response requirements under the DoD Privacy Act issuances.
b. HHS Breach. If the DHA Privacy Office determines that a breach is an HHS Breach, then the BA shall comply with both the HIPAA Breach Rule and DoD Privacy Act issuances, as directed by the DHA Privacy
Office, regardless of where the breach occurs.
c. Non-HHS Breach. If the DHA Privacy Office determines that the breach does not constitute an
HHS Breach, then the BA shall comply with DoD Privacy Act issuances, as directed by the applicable Service-Level
Privacy Office.
d. Service-Level Privacy Office Point of Contact (POC). Brian Martin, who may be reached at
Comm: 904-542-3559, DSN: 312-942-3559, or via E-mail: brian.k.martin4.civ@mail.mil, or usn.ncr.bumedfchava.list.bumed-pii-rpt@mail.mil.
BRIAN K. MARTIN
CODE M31 PRIVACY OFFICE
BUMED DETACHMENT JACKSONVILLE
H2005 KNIGHT LANE
PO BOX 140
NAVAL AIR STATION JACKSONVILLE FL 32212
8. Breach Reporting Provisions:
a. The BA shall report the breach within 1 business day of discovery to the US Computer Emergency
Readiness Team (US-CERT) and within 24 hours of discovery to the
DHA Privacy Office and the other Parties set forth below. The BA is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer, or other agent of the BA.
b. The BA shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report. Before submission to US-CERT, the BA shall save a copy of the on-line report. After submission, the BA shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the 1 hour deadline for submission, the BA shall submit the US-CERT report by the deadline. The
BA shall e-mail updated information as it is obtained, following the instructions at: http://www.us-cert.gov/pgp/email.html. The BA shall provide a copy of the initial or updated US-CERT report to the DHA Privacy
Office and the applicable Service-Level Privacy Office, if requested by either.
BA questions about US-CERT reporting shall be directed to the DHA or Service-Level Privacy Office, not the US-
CERT office.
c. The BA report due within 24 hours shall be submitted by completing the New Breach Reporting
Form DD 2959 at the Breach Response page on the DHA Privacy Office web site and emailing that form to, as applicable, the DHA Privacy Office, the Service-Level Privacy Office, the Contracting Officer (CO) and
Contracting Officer’s Representative (COR) (if the Understanding is not a contract, delete these references to the
CO and COR), and the BA’s DoD POC unless the POC specifies another addressee for breach reporting.
Encryption is not required, because Breach Report Forms should not contain PII or PHI. The email address for notices to the DHA Privacy Office is provided at the Privacy Office web site breach response page. If electronic mail is not available, telephone notification is also acceptable, but all notifications and reports delivered telephonically must be confirmed by email as soon as technically feasible.
d. If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The BA shall inform the DHA
Privacy Office as soon as possible if it believes that “single event” breach response is appropriate; the DHA Privacy
Office will determine how the BA shall proceed and, if appropriate, consolidate separately reported breaches for purposes of BA report updates, beneficiary notification, and mitigation.
e. When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the BA shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the BA shall report include, but are not limited to:
(1) Confirmation on the exact data elements involved.
(2) Root cause of the incident.
(3) Any mitigation actions to include, sanctions, training, incident containment, follow-up, etc. The BA shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the DHA Privacy Office to make timely final determinations on any subsequent notifications or reports. The BA shall provide updates to the same Parties as required for the initial Breach
Reporting Form. The BA is responsible for reporting all information needed by the DHA Privacy Office to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the
Defense Privacy and Civil Liberties Office as required by DoD Privacy Act issuances.
f. In the event the BA is uncertain on how to apply the above requirements, the BA shall consult with the DHA privacy office or service-level privacy office when determinations on applying the above requirements are needed.
9. Breach - Individual Notification Provisions:
a. Determine if Notification is Required. If the DHA Privacy Office determines that individual notification is required, the BA shall provide written notification to individuals affected by the breach as soon as possible, but no later than 60 working days after the breach is discovered and the identities of the individuals ascertained. The 60-day period begins when the BA is able to determine the identities (including addresses) of the individuals whose records were impacted.
b. Draft Proposed Notification. The BA’s proposed notification to be issued to the affected individuals shall be submitted to the Parties to which reports are submitted under paragraph 7 (breach response) for their review and for approval by the DHA Privacy Office. Upon request, the BA shall provide the DHA Privacy
Office with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the BA shall provide the text of the letter for each group. PII shall not be included with the text of the letter(s) provided. Copies of further correspondence with affected individuals need not be provided unless requested by the Privacy Office. The BA’s notification to the individuals, at a minimum, shall include the following:
(1) Identify PII Lost. The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated
SSNs, and Dates of Birth are involved, it is critical to advise the individual that these data elements potentially have been breached.
(2) Inform. The affected individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
(3) Protective Actions. The affected individual(s) must be informed of what protective actions the BA is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline:
Toll Free: 1-877-ID-THEFT (438-4338), TTY: 1-866-653-4261.
(4) Credit Monitoring. The individual(s) must also be informed of any mitigating support services (e.g., 1 year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the BA may offer affected individuals, the process to follow to obtain those services, the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information.
(5) Labeling. BAs shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents (e.g., “Data Breach Information Enclosed”) and that the envelope is marked with the identity of the BA or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, email address, and postal address.
c. Notification within 60 Days. If the BA determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 60-day period after discovering the breach, the BA shall so indicate in the initial or updated Breach Report Form. Within the 10-day period, the BA shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 60 days after identities and addresses are ascertained. The BA shall consult with the DHA Privacy Office, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The BA shall issue a generalized media notice(s) to that population in accordance with Privacy Office approval.
d. Costs. The BA shall, at no cost to the government, bear any costs associated with a breach of PII or PHI that the BA has caused or is otherwise responsible for addressing.
e. Security Incident versus Breach. Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII or PHI. In the event of a security incident not involving a PII or PHI breach, the BA shall follow applicable DoD Information Assurance requirements under its Understanding. If at any point the BA finds that a cyber security incident involves a PII or PHI breach (suspected or confirmed), the BA shall immediately initiate the breach response procedures set forth herein. The BA shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.
10. Termination:
a. Termination. Noncompliance by the BA (or any of its staff, agents, or subcontractors) with any requirements in this BAA may subject the BA to termination under any applicable default or other termination provision of the Understanding.
b. Effect of Termination.
(1) If the Understanding has records management requirements, the BA shall handle such records in accordance with the records management requirements. If the Understanding does not have records management requirements, the records should be handled in accordance with subparagraphs (2) and (3) below. If the
Understanding has provisions for transfer of records and PII or PHI to a successor BA or if DHA gives directions for such transfer, the BA shall handle such records and information in accordance with such Understanding provisions or DHA direction.
(2) If the Understanding does not have records management requirements, except as provided in the following paragraph (3), upon termination of the Understanding, for any reason, the BA shall return or destroy all PHI received from the covered entity, or created or received by the BA on behalf of the covered entity that the BA still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the
BA. The BA shall retain no copies of the PHI.
(3) If the Understanding does not have records management provisions and the BA determines that returning or destroying the PHI is infeasible, the BA shall provide to the covered entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the covered entity and the BA that return or destruction of PHI is infeasible, the BA shall extend the protections of the Understanding to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the BA maintains such PHI.
11. Miscellaneous:
a. Survival. The obligations of BA under the “Effect of Termination” provision of this BAA shall survive the termination of the Understanding.
b. Interpretation. Any ambiguity in the Understanding shall be resolved in favor of a meaning that permits the covered entity and the BA to comply with HIPAA and the DoD HIPAA Rules.
(End of Text)
BASE ACCESS (NMCP)
Commander, Navy Installations Command (CNIC), has established the Navy Commercial Access Control System
(NCACS), a standardized process for granting unescorted access privileges to vendors, contractors, suppliers and service providers not otherwise entitled to the issuance of a Common Access Card (CAC) who seek access to and can provide justification to enter Navy installations and facilities. Vendors visiting Naval Medical Center
Portsmouth (NMCP) may obtain daily passes directly from Naval Station Norfolk (NSN) Pass and ID office, located at NSN (Bldg CD-9), 9040 Hampton Blvd, Norfolk, Virginia, 23505, by submitting identification credentials for verification and undergoing a criminal screening/ background check. Alternatively, if the vendor so chooses, it may voluntarily elect to obtain long-term credentials through enrollment, registration, background vetting, screening, issuance of credentials, and electronic validation of credentials at its own cost through one of the designated independent contractor NCACS service providers. Credentials will be issued every five years and access privileges will be reviewed / renewed on an annual basis. The costs incurred to obtain Navy installation access of any kind are not reimbursable, and the price(s) paid for obtaining long-term NCACS credentials will not be approved as a direct cost of this contract.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .