J.1 - SMPIA SOW.docx

DOCX document 246 KB Posted

Attached to
State Medicaid Program Integrity Audits Federal contract opportunity
Solicitation number
75FCMC24RJ002
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

This document is a Statement of Work (SOW) for the State Medicaid Program Integrity (PI) Audits contract. The purpose of this contract is to assist the Centers for Medicare & Medicaid Services (CMS) with reviewing state Medicaid and Children's Health Insurance Program (CHIP) program integrity and beneficiary eligibility functions. The contractor will perform program integrity and beneficiary eligibility audits, identify findings and observations, and develop analyses and reports for CMS and the states. The SOW outlines the administrative, program integrity audit, and beneficiary eligibility audit requirements, as well as transition-in and transition-out activities. Key tasks include developing audit protocols, conducting virtual and on-site audits, reviewing eligibility determinations, providing draft and final audit reports, and transitioning work to a new contractor if needed. The related federal contract opportunity is a solicitation from CMS for the State Medicaid Program Integrity Audits contract.

View the file

Other files for this federal contract opportunity

Other files attached to State Medicaid Program Integrity Audits, newest first.
File Type Posted
75FCMC24RJ002_Amendment 0001.pdf PDF
E.1 - SMPIA Questions Submission - Response.xlsx XLSX spreadsheet
E.3 - Scenario 2 - Review Guide Module.docx DOCX document
E.4 - Scenario 2 - Response Template.docx DOCX document
E.11 - CMS 508 PDF Checklist.xlsx XLSX spreadsheet
E.6 - Responsibility Questionnaire.docx DOCX document
E.8 - Consent to Subcontract.docx DOCX document
75FCMC24RJ002.pdf PDF
E.12 - CMS 508 Webapps Checklist.xlsx XLSX spreadsheet
J.2 - CFM Report.xlsx XLSX spreadsheet
E.15 - CMS 508 PowerPoint Checklist.xlsx XLSX spreadsheet
E.9 - Business Proposal Template.xlsx XLSX spreadsheet
E.13 - CMS 508 Word Checklist.xlsx XLSX spreadsheet
E.14 - CMS 508 Excel Checklist.xlsx XLSX spreadsheet
E.1 - SMPIA Questions Submission Template.xlsx XLSX spreadsheet
E.10 - 508 Checklist Instructions.docx DOCX document
E.2 - Scenario 1 - Compliance Plan.docx DOCX document
J.3 - Conflict of Interest Template.docx DOCX document
E.5 - Past Performance Questionnaire.docx DOCX document
E.7 - Prime Proposal Checklist.docx DOCX document
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

State Medicaid Program Integrity (PI) Audits Statement of Work (SOW)

INFORMATION NOT RELEASABLE TO THE PUBLIC UNLESS AUTHORIZED BY LAW: This information has not been publicly disclosed and may be privileged and confidential. It is for internal government use only and must not be disseminated, distributed, or copied to persons not authorized to receive the information. Unauthorized disclosure may result in prosecution to the full extent of the law. If you are not the intended recipient, or have received this message in error, please delete it without reading or otherwise using it and notify the sender that you received this communication in error.

I. SCOPE

A. Purpose of contract

The purpose of this contract to assist CMS with its review of state Medicaid Fee-for-Service (FFS) and managed care services areas; and Children’s Health Insurance Program (CHIP) program integrity oversight functions, including compliance with Medicaid program integrity (PI) regulations and beneficiary eligibility requirements. As part of this work, the Contractor shall 1) perform program integrity and beneficiary eligibility audits and requisite follow-up, including the development of audit protocols and other materials to gather relevant information for the audits; 2) identify findings (areas of non-compliance with federal and state rules and laws) and observations (opportunities for programmatic improvements); 3) develop analyses useful to both CMS and the states, including generating reports summarizing the audit findings and the identification of policy gaps or vulnerabilities that may lead to fraud, waste and abuse in Medicaid and CHIP.

B. Background

Medicaid and CHIP are joint federal and state programs that provide health coverage to over 88 million Americans as of September 2023.[footnoteRef:1] Medicaid is the single largest source of health coverage in the United States. All states, the District of Columbia, and the U.S. territories have Medicaid programs designed to provide health coverage for low-income people. Although the Federal government establishes certain parameters for all states to follow, each state administers their Medicaid program differently, resulting in variations in Medicaid coverage across the country. [1: https://www.medicaid.gov/medicaid/program-information/medicaid-and-chip-enrollment-data/report-highlights/index.html ]

Federal law requires states to cover certain groups of individuals under the state’s Medicaid program. Low-income families, qualified pregnant women and children, and individuals receiving Supplemental Security Income (SSI) are examples of individuals who are eligible under mandatory eligibility groups. States have additional options for coverage and may choose to cover other groups, such as individuals receiving home and community-based services and children in foster care who are not otherwise eligible. CHIP provides health coverage to uninsured children. States can use their federal CHIP funds to finance coverage for children whose family incomes are too high to qualify for Medicaid. States may opt to use CHIP funds to expand Medicaid for children, cover children through a separate CHIP program, or combine the two approaches.

The Deficit Reduction Act of 2005 (DRA) created the Medicaid Integrity Program (MIP) under Section 1936 of the Social Security Act and provided CMS with more resources for CMS to fight Medicaid fraud, waste, and abuse. State Medicaid agencies and CMS share mutual obligations and accountability for the integrity of the Medicaid program and for the development, application, and improvement of program safeguards necessary to ensure proper and appropriate use of both federal and state dollars. States provide the first line of defense against fraud, waste, and abuse in their Medicaid programs as they enroll beneficiaries, screen and enroll providers, establish payment policies, contract with managed care entities, process claims, and pay for services furnished to Medicaid beneficiaries. CMS provides states with guidance on federal Medicaid policies, education and technical assistance, program assessment and feedback, and federal resources for strengthening their program integrity capacities.

The CMS Fiscal Year 2018 - 2023 Comprehensive Medicaid Program Integrity Plan (CMIP) describes CMS’ Medicaid program integrity strategy that aims to improve MPI through greater transparency and accountability, strengthened data, and innovative and robust analytic tools. Key components of this strategy are identifying vulnerabilities and program integrity related risks in the states’ operations and help the states improve their program integrity efforts, as well as conducting audits of Medicaid and CHIP beneficiary eligibility determinations.

To achieve these objectives, the CMS Center for Program Integrity (CPI) performs audits of the states’ Medicaid PI procedures and processes to determine if the states’ program integrity policies and procedures satisfy the requirements of federal and state law and guidance. CMS uses the data collected from the reviews to identify areas of noncompliance (findings), opportunities for improvement (observations), and promising practices. CMS develops recommendations based on these findings and the audited state is required to develop plans to address identified issues. CMS shares the audit reports with the audited states and with other internal and external stakeholders, as appropriate, for educational purposes.

CPI also conducts in-depth reviews of Medicaid and CHIP eligibility determinations made by states by examining individual cases, selected from samples, for compliance with federal and state rules and regulations during an established audit period. Through these audits, CMS identifies findings and related recommendations that will help states make proper eligibility determinations in the future. CMS also provides states with feedback and promising practices that may be used to enhance program integrity within the Medicaid and CHIP beneficiary eligibility determination process.

C. Definitions

· Program Integrity Audits: Audits conducted to determine the extent of program integrity compliance with the Medicaid FFS and managed care services areas program requirements by the states. Traditionally, Program Integrity Audits have focused on high-risk areas such as managed care, Affordable Care Act provisions, personal care services and non-emergency medical transportation.

· Eligibility Audits: Audits conducted to confirm if state eligibility determinations were appropriate for the Medicaid and CHIP populations and if Federal match was assessed correctly.

· Finding: Findings represent areas of non-compliance with federal and/or state Medicaid statutory, regulatory, sub-regulatory, or contractual requirements.

· Observation: Observations represent operational or policy suggestions that may be useful to the state in the oversight of its Medicaid FFS program, Medicaid managed care program, and/or CHIP.

· Recommendation: Recommendations are based on findings that will enable the state to come into compliance with federal and/or state Medicaid and/or CHIP requirements related to program integrity or beneficiary eligibility.

D. Assumptions/Constraints

The Contractor shall assume the following. Note that all assumptions in this section are subject to change based on Agency direction and priorities:

1. The Contractor is not required to be located in the same geographical area as the states and territories that will be under review.

2. Audits will generally be conducted virtually, although there may be limited instances in which the contractor will be expected to perform an onsite audit.

3. Extensive preparation prior to the review is required, including research into state status of relevant program integrity issues, document collection, data analysis and regulation/guidance reviews, and preparation of interview questions.

4. During the review, interviews, document sampling, and walkthroughs will be conducted by the Contractor, as required.

5. The Contractor will submit documentation using BOX.

6. No access to CMS systems or databases will be required.

7. All documents shall be drafted using the Microsoft platform and Adobe.

The Contractor shall be constrained by the following:

1. The contractor shall complete privacy training annually.

2. Contractor shall comply with federal information technology and accessibility policies.

3. All documents developed to support the activities and deliverables of this contract, are the property of CMS.

4. The Contractor shall deliver all documents to CMS during the contract, upon expiration of the contract, or upon termination of this contract.

5. The Contractor shall provide the Government with interim and final files, and file documentation upon request by the COR.

6. The Contractor shall not design, implement, or maintain any customized or proprietary documents or utilities without prior approval in writing from the COR.

II. REQUIREMENTS

The Contractor shall perform all tasks and deliverables detailed in this SOW. The Contractor shall perform multiple tasks simultaneously while meeting deliverable timelines, including assisting with multiple review activities concurrently. The Contractor shall have more than one team to staff concurrent audit activities. The Contractor shall furnish all the necessary services, qualified personnel, material, equipment, and facilities not otherwise provided by the Government needed to perform the work described in this SOW.

General Requirements

Key Personnel

The Contractor shall provide appropriate personnel who shall be designated as “key” personnel. Key personnel are those individuals that play a critical role in the management and decision making of the contract, and/or have a specific skill set/expertise necessary for successful contract performance. All key personnel positions require Contracting Officer (CO) approval before the personnel are assigned to or removed from this contract. All proposed substitutions must be submitted, in writing, to the CO at least 30 days prior to the proposed substitution or as soon as reasonably known. Each request shall provide a detailed explanation of the circumstances necessitating the proposed substitution, a complete resume and any other information required by CPI.

All proposed substitutions must have qualifications equal to or greater than the person(s) being replaced. It is the CONTRACTOR’s responsibility to provide evidence that the proposed key personnel’s qualifications are equal or greater than the person(s) being replaced, the proposed key personnel meet the requirement of never having been sanctioned or excluded from the Medicare/Medicaid programs, and any current or prior licensure have no restrictions and/or disciplinary actions.

System Security

The Contractor shall be in compliance with all requirements outlined in Appendix A-C.

Accessibility Standards

The Contractor shall be in compliance with all requirements outlined in Appendix D.

Specific Requirements

1. Task 1 – Administrative Requirements

1.1 Kickoff Meeting

CMS will arrange a Kickoff Meeting with the Contractor within five business days of award to review the contract, answer any questions that the Contractor has, and to assure that both the Contractor and the CMS have a joint understanding of all work, timeframes, and deliverables required by the SOW and Contract. The Contractor shall work with CMS to compile the agenda for this meeting and shall submit the agenda to the CMS COR no later than three business days prior to the Kickoff Meeting. The Contractor shall be prepared to provide CMS with a brief presentation outlining ideas for completing the requirements of the SOW. The Contractor shall take notes during this meeting, prepare minutes, and submit them to the CMS COR no later than three business days after the Kickoff Meeting.

1.2. Transition-In

When applicable, the Contractor shall work together with the outgoing Contractor to transition activities from the outgoing State Medicaid Program Integrity (PI) Audits Contractor to the incoming State Medicaid Program Integrity (PI) Audits contractor. CMS will set-up a folder in Box for the outgoing Contractor to upload all relevant documentation for the Contractor to retrieve (workpapers, templates, mitigation plans, § 1902(e)(14) waivers, all state provided documentation to support the audit work, etc.), which will include but is not limited to any open states that will require completion by the Contractor. The transition-in period will be 60 days. Following the 60-day transition-in period the contractor shall be fully operational and prepared to take on workload. The Outgoing contractor will be available for continued support for an additional 30-days following the transition-in period. During the 60-day transition period, the incoming Contractor shall participate as an observer to the outgoing Contractor during any beneficiary eligibility audit meetings with the states and/or CMS and observe the process of drafting and finalizing the final program integrity audit reports. In addition to observing ongoing beneficiary eligibility audits and meeting, the outgoing Contractor will provide training to the Contractor on how the work under each of the Tasks is performed which includes the pre-audit and post-audit activities.

1.2.1 Transition Plan

The draft Transition Plan shall be presented during the Kickoff meeting specifying the activities/tasks necessary to transition all work. The final Transition Plan is due within three business days of receipt of comments from COR.

1.2.2. Transition Meetings

The Contractor shall begin conducting weekly Transition Meetings starting the first week after the kick-off meeting to address the open issues, risks, and transition activities/tasks related to the transitioning of the workload. The Contractor shall incorporate the Transition Meetings into the standard Weekly Status Meeting as long as no other CMS Contractor needs to be present. All meetings will be held virtually, unless a business need arises for a face-to-face meeting.

1.3 Project Management and Staffing Plan

The Contractor shall develop and maintain a Project Management and Staffing Plan detailing strategies for accomplishing each task. The draft Project Management and Staffing Plan shall be presented during the Kickoff meeting and shall contain all deliverables, project tasks, staffing, milestones, assumptions and constraints, and associated timeframes for performing each task. The Final plan is due within five business days of receipt of comments from COR.

1.4 Monthly Progress Reports

The Contractor shall submit a Monthly Progress Report to the COR for the previous month’s effort, no later than the fifth of every month. The COR may request hard copies as necessary. All electronic files shall be submitted in a form that is compatible with Microsoft Office, or as directed by CMS. The Monthly Progress Report shall briefly state the progress made and difficulties encountered during the reporting period (and remedial actions taken), as well as a statement of activity anticipated during the subsequent reporting period. At a minimum, each report shall include:

A status on the development of audit protocols and/or questionnaires, and other audit related materials, as well as any issues identified with any of the audits and recommendations for further action;

A description of the accomplishments to date on any other projects or tasks, remaining activities to be completed, and the status of the project or task compared with its schedule;

Any significant problem(s) encountered and the anticipated or actual impact on the schedule of the project; and, the contractor’s actual or proposed resolution for all problems; and The number of audits conducted to date, including a status on the progress or phase the audit is in, to include, but not limited to the following:

· Date start letter was issued

· Audit completed

· Report in development

The COR shall provide the Contractor with comments on reports within five business days of receipt of the report(s), unless otherwise indicated. If no response is received within five business days and the COR has not informed the Contractor that comments are forthcoming, the Contractor shall assume that the report is approved.

1.5 Monthly Invoice Report

In addition to the Invoice Processing Platform Invoice requirements outlined in the payments clause of the contract. The Contractor, in accordance with established policy, shall submit monthly invoices via the CMS Analysis, Reporting, and Tracking (CMS ART) to the COR no later than the 20th of the month following the period for which the Contractor is billing. In addition to required contractual responsibilities for invoicing, detailed documentation required to support invoice payment includes:

All contract incurred costs and invoices, including current and cumulative budgetary status to date for the period of contract performance.

All contract tasks related travel invoices and receipts, including current and cumulative budgetary status to date for the period of contract performance.

All contract employee hourly rates, hours worked, and tasks performed (both current and cumulative) for the period of contract performance.

1.6 Meetings

The Contractor shall conduct status calls with the COR biweekly or as needed via a conference call and the Contractor shall provide the call-in number, the date, and time. CMS reserves the right to request an in-person status meeting if necessary. The Contractor shall submit meeting minutes to the COR no later than three business days after meeting. Ad-hoc conference calls shall be held as deemed necessary. Issues and concerns shall be brought up at these meetings, along with the status of the project. Standing agenda items shall include the following:

Questions and Answers;

Updates of accomplishments to date, remaining activities to be completed, and the status of the project compared with its schedule;

Updates of significant findings, if any; and Updates of significant problems encountered or anticipated and their impact on the schedule of the program integrity audits, protocol, questionnaire or any reports including an update of actual or anticipated resolution for all problems.

1.7 Lessons Learned/Best Practices Report

The Contractor shall provide a final Lessons Learned/Best Practices Report to the COR no later than twenty business days before the end of each period of performance. The report shall include recommended modifications to protocols, program integrity questionnaires, program integrity processes, documentation, process and best practice improvements. This shall be a comprehensive report of all significant recurring issues identified throughout the audits with recommendations for improvement (interim issues and/or concerns needing attention will be discussed in monthly progress reports and meeting calls).

2. Task 2 – Program Integrity Audits

As directed, the Contractor shall conduct virtual and/or onsite audits (if deemed necessary) program integrity audits of state Medicaid programs. The Contractor shall provide pre-audit activity to the COR no later than 15 business days from the date the task is assigned. The objective of these audits is to determine if the state and/or related entities (e.g., Medicaid managed care plans) are compliant with federal and state regulations and other requirements. CMS expects the contractor staff to participate in each aspect of every audit; therefore, the contractor staff shall understand the subject matter they are auditing and be fully aware of and understand all protocol requirements. The Contractor shall provide the post-audit draft report to the COR no later than 30 calendar days upon completion of each review. The Contractor shall provide the final report to the COR no later than 10 business days upon receiving the comments from the CMS COR/BFL (which will include informal comments from the states).

These audits shall include steps as:

Selecting states and topics for review based on risk analyses. The risk analyses could be based on recent federal and state audits, such as from the Department of Health and Human Services Office of Inspector General (HHS-OIG) and State Auditors, findings and data from the Payment Error Rate Measurement (PERM) program, CMS-identified vulnerabilities, or other CMS requirements as applicable.

Developing a sampling and auditing methodology by which it can calculate a statistically valid error rate and extrapolated dollar amount in error for the universe under audit, as well as the dollar amount in error in the sample, if applicable to the selected audit format.

Researching applicable federal and state policy.

Reviewing policies and procedures, member handbooks, program integrity case files, selected claims, and any other documents provided by the state.

Developing and revising new and existing review materials.

Conducting interviews and notetaking.

Facilitating walk-throughs of systems and processes.

Conducting data analyses to identify areas of regulatory non-compliance and program vulnerabilities.

Reviewing medical documentation provided by the state, such as claims that have undergone prior authorization or medical review.

Creating draft and final reports detailing CMS’ findings, conclusions, and recommendations for assigned program integrity audits.

Identifying promising practices, vulnerabilities and/or risks, and recommendations for addressing such vulnerabilities and/or risks.

Examples of pre-audit activities include:

Reviewing documentation submitted by the state under review and evaluating it for completeness and reasonableness.

Providing CMS with a summary of the documentation.

Analyzing and evaluation of state contracts.

Creating additional interview questions while reviewing completed Review Guide Modules.

Reviewing documentation from the previous review as a baseline.

Attends meetings with CMS staff.

Researching regulations and policies applicable to the audit prior to the start.

Examples of post-audit activities include:

Collaborating with CMS staff to draft the audit report(s).

Providing CMS with briefing documents that include all elements of the findings, as well as all impact analyses performed.

Advising CMS immediately of any items that may need to be referred for further review and recommended approach.

Maintaining an ongoing dialogue with the CMS COR and assigned staff regarding any findings and/or issues noted during the review.

Preparing written reports for CMS review that contain the findings from the audit, which will also be shared with the states.

Preparing a summary of findings from completed program integrity audits, which may be used to inform CMS of potential areas of technical assistance or educational opportunities for states.

Developing a mechanism to track all program integrity audits scheduled, in progress, and completed.

1. Task 3: Beneficiary Eligibility Determination Audits

As directed, the Contractor shall conduct virtual and/or onsite audits (if deemed necessary) beneficiary audits of state Medicaid programs. The Contractor shall provide the beneficiary eligibility audit plan to the COR no later than 15 business days from the date the task is assigned. The objective of these audits is to determine if the state is making accurate and timely Medicaid and CHIP beneficiary eligibility determinations so that services are provided to those who are truly eligible for each program and to ensure that those who are eligible are not inappropriately terminated from coverage. CMS expects the contractor staff to participate in each aspect of every audit; therefore, the contractor staff shall understand the subject matter they are auditing and be fully aware of all protocol requirements. The Contractor shall provide the beneficiary eligibility findings audit report to the COR no later than 30 calendar days upon completion of each review.

These audits shall include steps as:

Selecting states for audit based on risk analyses. The risk analysis will be, in part, based on recent federal and state audits, from HHS-OIG and State Auditors, findings and data from the PERM program and the Medicaid Eligibility Quality Control (MEQC) program, as well as Consolidated Appropriations Act (CAA) reporting metrics or other CMS requirements as applicable.

Developing a sampling and auditing methodology by which it can calculate a statistically valid error rate and extrapolated dollar amount in error for the universe under audit, as well as the dollar amount in error in the sample, if applicable to the selected audit format.

Reviewing beneficiary eligibility systems and supporting documentation used by state agencies to assess the accuracy of eligibility determinations for the Medicaid and CHIP populations, as directed by CMS.

Researching applicable federal and state policy.

Reviewing policies and procedures, member handbooks, program integrity case files, selected claims, and any other documents provided by the state.

Developing new and revising existing review materials.

Conducting interviews and notetaking.

Facilitating walk-throughs of systems and processes.

Conducting data analyses to identify high-risk states, eligibility groups, or other vulnerabilities.

Reviewing medical documentation provided by the state, such as claims that have undergone prior authorization or medical review.

Creating draft and final reports detailing CMS’ findings, conclusions, and recommendations for assigned program integrity audits.

Identifying promising practices, vulnerabilities and/or risks, and recommendations to address such vulnerabilities and/or risks.

CMS will determine whether each audit will be a comprehensive or targeted format. A comprehensive audit will look at a broad range of eligibility categories, eligibility determinations, and may require a statistically valid sample. Targeted audits will focus on small select eligibility categories, eligibility determination types, or other focused eligibility-related issues. The project may include, but not be limited to the review of:

A sample of Medicaid beneficiary eligibility determinations at the point of application and/or redetermination to determine if the State appropriately determined beneficiary eligibility and if those beneficiaries were assessed the correct Federal Medical Assistance Percentage (FMAP).

A sample of CHIP beneficiary eligibility determinations at the point of application and/or redetermination to determine if the State appropriately determined beneficiary eligibility and if those beneficiaries were assessed the correct FMAP.

A sample of Medicaid termination determinations to ensure that individuals were not inappropriately terminated from the Medicaid program.

A sample of CHIP termination determinations to ensure that individuals were not inappropriately terminated from the CHIP program.

The impact of changes to state eligibility policies or processes due to changes in eligibility requirements. For example, compliance with state mitigation plans and waivers as a result of Medicaid unwinding.

All audits will include the following steps:

Recommending a sample size based on the type of audit. Comprehensive audits may require a statistically valid sample size by which an error rate and extrapolated dollars in error can be calculated. Targeted audits may require a fixed sample size. CMS will take into consideration the Contractor’s recommended sample size and will make the final determination on sample size based on CMS’ needs.

Recommending potential target states and populations.

Conducting virtual audits to determine whether eligibility determinations or termination determinations were appropriate based on federal and state regulations, rules, and policies.

Thoroughly documenting all factors of eligibility reviewed to determine the appropriateness of the eligibility determination or termination for each sample case reviewed.

Calculating a statistically valid error rate and extrapolated dollar amount in error for the universe under examination, as well as the dollar amount in error in the sample, if applicable.

Reviewing reports and data from the PERM and MEQC programs, and other similar reviews conducted by other entities, such as the State Auditors and HHS-OIG, to identify potential vulnerabilities and determine if findings are similar and/or have been addressed.

Preparing final audit reports that identify findings and observations as a result of the audit, opportunities for improvement, best practices, any identified vulnerabilities, and recommendations to address findings and vulnerabilities.

1. Task 4: Transition-Out (Optional)

4.1. Closeout Activities

When applicable, the Contractor shall work together with the incoming Contractor to transition activities from the outgoing State Medicaid Program Integrity (PI) Audits Contractor to the incoming State Medicaid Program Integrity (PI) Audits contractor. The Transition-Out period will last 90 days. Weekly Transition meetings shall be conducted virtually unless a business need arises for a face-to-face meeting.

4.2. Transition-Out Activities

The Contractor shall implement and manage the activities necessary to transition services from their effort to CMS or a designated Contractor with no breaks in service levels and no delays in support for new and ongoing services. Outgoing transition activities shall begin 90-calander days prior to the end of the final contract period of performance. In addition to the transition activities, the Contractor shall also be fully operational and continue to work towards the completion of existing work during the first 60-calendar days of the transition-out period. The Contractor shall not take on any new audits during the 90-calendar day transition-out period. All existing work shall be completed or transferred to the incoming contractor at the conclusion of the 60-calander day period. The last 30-calender days of the transition-out will be solely dedicated to transition activities and providing continued support to the incoming contactor.

The Contractor shall complete Transition-Out activities prior to the end of the contract.

During this transition-out period, the Contractor remains responsible for meeting all transitional requirements under this task order. The Contractor shall work with CMS and the subsequent contractor to avoid the disruption or degradation of services. This includes, but is not limited to, activities as:

· Providing documents, existing protocols, and notes to CMS via BOX for:

· All draft reports not finalized for State Medicaid PI focused/comprehensive reviews;

· All draft reports not finalized for the beneficiary eligibility audits;

· Reporting and Summarizing Report templates of managed care, personal care services, and comprehensive;

· Desk Review Reporting and Summary Report templates of US territories, opioid, services after death, terminated providers, telehealth, and payment suspensions;

· SMPIR monthly report templates;

· Tracking status report for State Medicaid PI focused/desk reviews.

· Review Guide Module (RGM) templates of managed care focused State Medicaid Agency (SMA) and Managed Care Entity (MCE) comprehensive SMA; and personal care services SMA, MCE, and Provider Agency;

· Approved COVID-19 Mitigation Plan, and remote review methods & technology assessment; and

· Research on new desk review topics including telemedicine white paper.

· Providing records, logs, and documentation of activities covering all tasks of the contract via BOX.

· Providing training to the incoming State Medicaid Program Integrity (PI) Audits contractor on the steps to conduct State Medicaid PI audits, and beneficiary eligibility audits.

· Interfacing with the new contractor at all working levels (e.g. management, technical, etc.).

· Turnover of items such as system documentation and user training guides/manuals for all systems software, products, databases, and applications developed in support of the task order beginning with the transition to a new State Medicaid Program Integrity (PI) Audits development and maintenance contractor, and also to a new State Medicaid Program Integrity (PI) Audits platform contractor, respectively.

· Planning and transitioning of all historical data including backups and working papers for all focused/comprehensive and desk review work as well as all beneficiary eligibility audits.

· Closing out any CMS system access.

4.2.1. Closeout Project Plan

The Contractor shall deliver a draft Closeout Project Plan specifying the activities/tasks necessary to transition or closeout all work at the conclusion of the first week of the 90-day transition-out period. The final Closeout Project Plan shall be delivered 10 business days after CMS feedback is received.

4.2.2. Closeout Meetings

The Contractor shall begin conducting weekly Closeout Meetings with CMS and the Incoming Contractor on the first day of the 90-day transition-out period to address the open issues, risks, and transition activities/tasks related to the ending of the contract or transition to another contractor. The Contractor shall incorporate the Closeout Meetings into the standard Weekly Status Meeting if no other CMS Contractor needs to be present. All meetings will be held virtually, unless a business need arises for an in-person meeting.

A. Schedule of Deliverables The Contractor shall submit all deliverables via secured (encrypted) email to the COR, in accordance with the following schedule. If the deliverable or other required information is scheduled for a Saturday, Sunday, or Federal holiday, the Contractor shall have until 11am EST/EDT (whichever is applicable during that time in the calendar) the next business day to submit the deliverable.

Item #
Task Ref.
Description
CMS Delivery System
Delivery Date (or as approved by the COR)
1
1.1
Kickoff Meeting
Password- protected file
Within five business days after award.
2
1.1
Agenda for Kickoff Meeting
Password- protected file
No later then three business days prior to the Kickoff Meeting .
3
1.1
Kickoff Meeting Minutes
Password- protected file
Within three business

days after the Kickoff meeting.

4
1.2.1
Transition Plan

Draft due during Kickoff meeting and Final due three days after receipt of comments.

1.3 Project Management/Staffing Plan

Password- protected file
Draft due during the Kickoff Meeting and Final due five days after receipt of comments.

1.4

Monthly Progress Reports

Password- protected file
No later than the 5th of every month.
7
1.5
Monthly Invoice Reports
CMS ART
No later than the 20th of the month following the period for which the Contractor is billing.

1.6

Meeting Minutes

Password- protected file
Within three business

days following each meeting.

1.7

Final Lessons Learned/Best Practices Report
Password- protected file
Twenty business days before the end of each period of performance.
Post-Audit Draft Report
Password- protected file
Within 30 calendar days upon completion of each review.
11
2
Post-Audit Final Report
Password-protected file
Within 10 business days upon receiving the draft report which includes the states informal comments.
12
3
Beneficiary Eligibility Audit Plan
Password- protected file
Within 15 business days from the date the task is assigned.
13
3
Beneficiary Eligibility Findings Audit Report
Password- protected file
Within 30 calendar days

upon completion of each audit.

14
4
Draft Closeout Project Plan
Password- protected file
At the conclusion of the first week of the 90-day transition-out period.
15
4
Final Closeout Project Plan
Password-protected file
Within 10 business days after CMS feedback is received.
16
Contract

Section G.8

Contract Funds Management (CFM) Report and Estimate at Completion (Sample provided in Attachment J.2)
Email to CO, CS, and COR
Submitted at least quarterly, or as deemed appropriate by the CO beginning from date of award within 15 calendar days of the following month to capture the previous month’s data (e.g. August 15 to capture data through July 31)

Appendix A

· System Security

1. Baseline Security Requirements

a. Applicability. The requirements herein apply whether the entire contract or modification (hereafter "contract"), or portion thereof, includes either or both of the following:

i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

b. Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with HHS/ CMS policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) must:

i. Protect the:

· Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

· Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

· Availability, which means ensuring timely and reliable access to and use of information.

ii. Categorize all information owned and/or collected/managed on behalf of HHS/CMS and information systems that store, process, and/or transmit HHS information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Based on information provided by the ISSO, CISO, CMS SOP, or other representative, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:

· Confidentiality: [ ] Low [X ] Moderate [ ] High

· Integrity: [ ] Low [ X ] Moderate [ ] High

· Availability: [ ] Low [X ] Moderate [ ] High

· Overall Impact Level: [ ] Low [ X ] Moderate [ ] High

iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of HHS/CMS regardless of location or purpose.

iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s).

v. Adopt and implement all applicable policies, procedures, controls, and standards required by the HHS/CMS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain all applicable security and privacy policies by contacting the CO/COR or HHS/CMS security and/or privacy officials.

c. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor FAR and HHSAR clauses as needed.

d. Privacy Compliance. Comply with the E-Government Act of 2002, NIST SP 800-53, and applicable HHS/CMS privacy policies, and complete all the requirements below:

i. Per the Office of Management and Budget (OMB) Circular A-130, Personally Identifiable Information (PII), is "information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual." Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother's maiden name, biometric records, etc.

ii. Based on information provided by the ISSO, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[ ] No PII [ X ] PII

iii. The Contractor must support the agency with conducting a Privacy Threshold Analysis (PTA) for the information system and/or information handled under this contract to determine whether or not a full Privacy Impact Assessment (PIA) needs to be completed.

· If the results of the PTA show that a full PIA is needed, the Contractor must support the agency with completing a PIA for the system or information within [CMS to insert contract-specific timeline] after completion of the PTA and in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.

· The Contractor must support the agency in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

e. Controlled Unclassified Information (CUI). Executive Order 13556 defines CUI as "information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information." The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term "handling" refers to "…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information." 81 Fed. Reg. 63323. The requirements below apply only to nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, must be:

i. Marked appropriately;

ii. Disclosed to authorized personnel on a Need-To-Know basis;

iii. Protected in accordance with NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

iv. Returned to HHS control, destroyed when no longer needed, or held until otherwise directed. Information and/or data must be disposed of in accordance with NIST SP 800-88, Guidelines for Media Sanitization.

f. Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) must protect all government information that is or may be sensitive by securing it with a solution that is validated with current FIPS 140 validation certificate from the NIST CMVP.

g. Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS must be used only for the purpose of carrying out the provisions of this contract and must not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and must ensure that all work performed by its employees and subcontractors must be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed must be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information must be protected in accordance with HHS and CMS policies. Unauthorized disclosure of information will be subject to the HHS/CMS sanction policies and/or governed by the following laws and regulations:

i. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

ii. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

iii. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

h. Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol must comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).

i. Information and Communications Technology (ICT). ICT products and services from prohibited entities/sources must not be used/acquired in compliance with Public Law 115-232, Section 889 Parts A and B, FAR 4.21, FAR 52.204.23, FAR 52.204.24, and FAR 52.204.25. The contractor (and/or any subcontractor) must notify the government if they identify prohibited ICT products and/or services are used during the contract performance.

j. Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS must enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, HTTPS is not required, but it is highly recommended. Consult the HHS Policy for Internet and Email Security for additional information.

k. Contract Documentation. The Contractor must use provided templates, policies, forms and other agency documents found at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Information-Security-Library to comply with contract deliverables as appropriate.

Standard for Encryption. The Contractor (and/or any subcontractor) must:

i. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

ii. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with encryption solution that is validated with current FIPS 140 validation certificate from the NIST CMVP.

iii. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CMS-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

iv. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with current FIPS 140 validation certificate from the NIST CMVP. The Contractor must provide a written copy of the validation documentation to the COR [CMS-provided delivery date].

v. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys http://csrc.nist.gov/publications/. Encryption keys must be provided to the COR upon request and at the conclusion of the contract.

l. Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract must complete the CMS non-disclosure agreement. Contractors (and/or subcontractors) must submit a copy of each signed and witnessed NDA to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.

2. Training Requirements

a. Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract must complete the applicable HHS/CMS Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees must complete CMS Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training must be compliant with HHS training policies.

b. Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.

c. Training Records. The Contractor (and/or any subcontractor) must maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records must be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

3. Rules of Behavior

a. The Contractor (and/or any subcontractor) must ensure that all employees performing on the contract comply with the HHS…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .