KAHC SHREDDING PWS NEW CONTRACT 22 JULY 2025 v1.pdf
PDF 299 KB Posted
- Attached to
- SHREDDING SUPPORT SERVICES - Fort Lee, VA - KAHC Federal contract opportunity
- Solicitation number
- W91QF5-26-Q-A001
About this file
This is a Performance Work Statement (PWS) for On-Site Shredding Services at Fort Lee, Virginia. The contract requires a contractor to provide bi-weekly shredding services for HIPAA and sensitive documents across eight different medical and health-related facilities, including Kenner Army Health Clinic, Troop Medical Clinic, Bull Dental Clinic, and others. The service will involve collecting and securely destroying approximately 49 boxes of documents per service, with an option to shred an additional 180 boxes throughout the contract year.
The contract is a firm-fixed-price service with a base year from December 19, 2025, to December 18, 2026, and four 12-month option years extending through December 18, 2030. The contractor must meet strict destruction standards set by the National Association for Information Destruction (NAID) and National Institute of Standards and Technology (NIST), ensuring documents are cut to no larger than ¼" wide and ¼" in length. All contractor personnel must be HIPAA certified, and the service must be conducted between 0900 and 1300 hours, with a government representative escorting the contractor through the facilities. The contractor is responsible for providing lockable security containers, a serviceable truck for on-site shredding, and maintaining comprehensive quality control and breach response protocols.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| W91QF526QA001- Solicitation Questions2.docx | DOCX document | |
| FortLee Installation Vetting Policy.pdf | ||
| Instructions to Offerors - Section L- M.pdf | ||
| Solicitation - W91QF526QA001.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
On-Site Shredding Services
Part 1
General Information
1. GENERAL: This is a service contract to shred and properly dispose of Health Insurance Portability and Accountability Act (HIPAA) and sensitive documents.
The Government shall not exercise any control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.
1.1. Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, transportation, tools, materials, and other items and non-personal services necessary to perform the Shredding of HIPAA and other sensitive documents disposed by each clinic and facility as defined in this Performance Work Statement.
1.2. Background: For the past five (5) years, shredding services have been required to dispose of protected information within the Health Care facilities on the installation of Fort Lee, VA. The protected information includes HIPAA and (Personal Identifiable Information (PII).
1.3. Objectives:
• Bi-weekly service
• Service 49 boxes
• Start services at 0900hrs
• Option for additional 180 boxes to be shredded throughout each contractual year
1.4. Scope: Shredding Service will be conducted on a bi-weekly rate and conducted the first day of the week to every clinic and facility mentioned within the contract. The service will be specifically conducted by emptying out and properly disposing of the documents inside each unit of shredding boxes located within that specific building.
1.4.1. The shredding of all documents must meet or exceed requirements set forth by National Association for Information Destruction (NAID) and National Institute of Standards and Technology (NIST) Guidelines for Media Sanitization.
Final outcome of materials shall be to a degree that definitively ensures data is not readable or reconstruct able to any degree; no larger than ¼” inches wide, and ¼” inches in length. Contractors can propose equipment that will crosscut the materials and provide smaller cuts.
1.4.1.2. The contractor will ensure that the service provided is done in a timely manner and that every unit specified in the contract is serviced prior to close of business that day.
1.5. Period of Performance: The period of performance shall be for one (1) Base Year of 12 months and (4) 12-month option years. The Period of Performance reads as follows:
Base Year 19 Dec 2025 – 18 Dec 2026 Option Year I 19 Dec 2026 – 18 Dec 2027 Option Year II 19 Dec 2027 – 18 Dec 2028 Option Year III 19 Dec 2028 – 18 Dec 2029 Option Year IV 19 Dec 2029 – 18 Dec 2030
1.6. General Information
1.6.1. Quality Control: The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which he assures himself or herself that the work complies with the requirement of the contract. QCP is to be delivered within 30 days of the contractor’s proposal if it is an evaluation factor, three copies of a comprehensive written QCP shall be submitted to the KO and COR within five (5) working days when changes are made thereafter. After acceptance of the quality control plan the contractor shall receive the contracting officer’s acceptance in writing of any proposed change to his QC system.
1.6.2. Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.6.3. Recognized Holidays: The Contractor is not required to perform services on recognized Holidays but will resume services the following business day. The following are recognized Holidays:
New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veteran’s Day
Memorial Day Thanksgiving Day Independence Day Christmas Day Juneteenth
1.6.3.1. However, a designated time-frame for pick-up bi- will be coordinated with the vendor who the contract is awarded.
1.6.3.2. If these holidays fall on Saturday, the preceding Friday will be observed.
If these holidays fall on Sunday, the following Monday will be observed. If a holiday falls on a scheduled service day, the Contractor shall be responsible for rescheduling services for the first day post the holiday observance.
1.6.3.3. Post Closure. Service scheduled but not accomplished because of post closure due to weather, exercises, or actual alert, will be accomplished as soon as possible after re-opening the post.
1.6.3.4. Contractor must notify the COR two (2) business days prior to an interruption in the service schedule. At the time of notification, contractor must provide an alternate date of service for the interruption of service.
1.6.4. Hours of Operation: The contractor is responsible for conducting business, between the hours of 0900 to 1300 on the expected date of service covered within the contract except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. For other than firm fixed price contracts, the contractor will not be reimbursed when the government facility is closed for the above reasons. Although, for this specific service the contract has specified that if for any reason stated above the facilities are closed the contractor will then provide service the following business day; not requiring a reimbursement for no service provided on the date the facilities were closed. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.
1.6.5. Place of Performance: The work to be performed under this contract will be performed at the following locations listed below:
Kenner Army Health Clinic, 700th 24th St. Bldg. 8130, Fort Lee, VA 23801 Education and Training, Bldg. 8151, Fort Lee, VA 23801 Mosier Clinic, 18020 Edgewood Rd, Bldg. 18036, Fort Lee, VA 23801 Troop Medical Clinic (TMC) 1, B Avenue, Bldg. 3219, Fort Lee, VA 23801 Bull Dental Clinic 2601 C Ave, Bldg. 8204, Fort Lee, VA 23801 Medical Company, B. Ave, Bldg. 8200, Fort Lee, VA 23801
Army Wellness Center, 9205 Mahone Avenue, Fort Lee VA 23801 Veterinary Clinic, Bldg 11025, Fort Lee, VA 23801
1.6.6. Type of Contract: The government will award a Firm-Fixed Price (FFP) service contract.
1.6.7. Security Requirements: Contractor personnel performing work under this contract do not require a security clearance. However, the contractor shall be responsible for providing lockable security containers whether it is security bins, security bags, or security cabinets at no additional cost to the government.
1.6.7.1. PHYSICAL Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use, which in this contract should only be the use of government facilities. At the close of each service, government facilities, shall be secured.
1.6.7.2. Key Control: Not Applicable
1.6.7.3. Lock Combinations: Not Applicable
1.6.8. Special Qualifications: Contractor shall shred all PII in accordance with HIPAA regulations and be certified by the National Association for Information Destruction (NAID). The Contractor equipment shall meet the NAID requirements for Cross Cut or Pierce and tear destruction process. NOTE: The Government does not provide training to Contractors. Contractors must ensure that any personnel performing under this contract are fully trained, licensed, certified and qualified for the position in which they will be serving.
1.6.9. Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the contracting officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.6.10. Contracting Officer Representative (COR): The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance:
maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
1.6.11. Key Personnel: The following personnel are considered key personnel by the government: The contractor liaison that assist the government with this service will ensure they have another point of contact that can be reached to assist with any issues that may arise with authority to fix those unforeseen issues. The contracts alternate will be well informed of this contract so as to not breach it by making any changes without presenting them first to the Contracting Officer on behalf of the Government. The alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The alternate shall be available between 9:00 a.m. to 1:00p.m Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons.
1.6.12. Identification of Contractor Employees: All contract personnel working in situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. The contractors performing the service will need to wear something that will identify them as part of a service contract i.e.: uniform or badge that reflects their company or business name. They will not be required to wear a government issued badge as they will be escorted through each building by a government employee or military personnel
1.6.13. Contractor Travel: Not Applicable
1.6.14. Other Direct Costs: Not Applicable
1.6.15. Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.6.16. Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart
9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may effect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
1.6.17 Enterprise Contractor Manpower Reporting (ECMR): The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the Fort Lee, Virginia via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: https://www.ecmra.mil/, and then click on "Department of the Army ECMRA" or the icon of the DoD organization that is receiving or benefitting from the contracted services.
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during FY, all data shall be reported no later than October 31 of each calendar year, beginning with 2021.
Contractors may direct questions to the help desk by clicking on "Send an email" which is located under the Help Resources ribbon on the right side of the login page of the applicable Service/Component's ECMR website".
1.6.18 Safety Requirements. In the event of an accident, the Contractor shall take reasonable and prudent action to establish control of the accident scene, prevent further damage to persons or property, preserve evidence until released by the accident investigative authority, cooperate and assist Government personnel in the investigation of the accident, and submit an Accident/Incident Report.
PART 2
DEFINITIONS & ACRONYMS
2. DEFINITIONS AND ACRONYMS:
2.1. DEFINITIONS:
2.1.1. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.
2.1.2. CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. NOTE: The only individual who can legally bind the government.
2.1.3. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.4. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.
2.1.5. DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
2.1.6. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.7. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.1.8. QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
2.1.9. QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
2.1.10. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.
2.1.11. SUBCONTRACTOR. One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.
2.1.12. WORK DAY. The number of hours per day the Contractor provides services in accordance with the contract.
2.1.13. WORK WEEK. Monday through Friday, unless specified otherwise.
2.2. ACRONYMS:
ACOR Alternate Contracting Officer's Representative AFARS Army Federal Acquisition Regulation Supplement AR Army Regulation CFR Code of Federal Regulations CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTS Commercial-Off-the-Shelf DA Department of the Army DD250 Department of Defense Form 250 (Receiving Report) DFARS Defense Federal Acquisition Regulation Supplement FAR Federal Acquisition Regulation HIPAA Health Insurance Portability and Accountability Act of 1996 KO Contracting Officer LD Liquated Damages NAID National Association for Information Destruction OCI Organizational Conflict of Interest ODC Other Direct Costs PII Personal Identifiable Information POC Point of Contact PRS Performance Requirements Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Program TE Technical Exhibit
WAWF Wide Area Workflow
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
3. GOVERNMENT FURNISHED ITEMS AND SERVICES:
3.1. Services: The Government will provide a representative within the clinic to escort the employee throughout the specified locations in this contract, eight (8) building in total.
3.2. Facilities: Not Applicable
3.3. Utilities: Not Applicable
3.4. Equipment: Not Applicable
3.5. Materials: Not Applicable
PART 4
CONTRACTOR FURNISHED ITEMS AND SERVICES
4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:
4.1. General: The Contractor shall furnish all supplies, equipment, facilities and services required to perform work under this contract that are not listed under Section 3 of this PWS. The contractor will ensure all employee’s conducting collections are HIPPA certified.
4.2. Secret Facility Clearance: Not Applicable
4.3. Materials. Not Applicable
4.4. Equipment. The Contractor shall provide all 49 lockable bins with bags to allow for the collection of documents needed to be shredded and a serviceable truck that allows for on-site shredding.
4.5. HIPAA Non-Compliance.
4.5.1. Penalties for Non-compliance. Section 1320d-6 of Title 42, U.S.C., establishes civil and criminal penalties for non-compliance with the HIPAA rules.
For HIPAA Rule violations occurring on or after February 18, 2009, there are:
4.5.2. Civil penalties of not less than $100 for each violation.
4.5.3. Civil penalties of not more than $1,500,000 when identical violations during a calendar year occur.
4.5.4. (c) Criminal penalties of fines of up to $250,000 and imprisonment up to 1 year, for wrongful disclosure by any covered entity, employee, or other individual of individually identifiable health information.
4.5.5. Violations Attributed to Covered Entity. The covered entity is liable, in accordance with the federal common law of agency, for a civil money penalty for a violation based on the act or omission of any agent of the covered entity, including a workforce member or business associate, acting within the scope of the agency.
4.5.6. Privacy Violations of Business Associates. A business associate is liable, in accordance with the federal common law of agency, for a civil money penalty for a violation based on the act or omission of any agent of the business associate, including a workforce member or a subcontractor, acting within the scope of the agency.
PART 5
SPECIFIC TASKS
5. SPECIFIC TASKS:
5.1. Basic Services. The contractor shall provide services for the shredding of HIPAA and other sensitive documents for all sections that fall under Kenner Army Health Clinic. The shredding will take place on site at the time the service is conducted. The contractor will remain in compliance with all laws regarding
HIPAA.
5.2. Certification of Destruction: A signed certificate of destruction must be issued upon completion of each job/location. The certificate shall indicate the date of destruction, identify the material destroyed, method of destruction, and be signed by the individuals designated to destroy and witness the destruction.
Destruction officials shall be required to know, through personal knowledge, that such material was destroyed.
5.2.1 Contractor will also provide weigh tickets for all shred removed and destroyed for the previous month along with a written certificate validating the destruction.
5.2.2. After acceptance by the Government of the Certificate of Destruction invoices for payment shall be submitted via iRAPT formerly Wide Area Work Flow (WAWF) System.
5.3. Destruction of Material: If required, the contractor must destroy Government material in accordance with record disposition schedules established by the requiring activity.
5.4. Witness Destruction: Only appropriately cleared employees of the contractor shall destroy HIPAA and other sensitive documents.
5.5. License Requirements: All operations staff must be licensed and bonded.
All personnel that handle material from the Kenner Army Health Clinic (KAHC) must be HIPAA certified.
5.6. X-Ray file and films. The contractor shall provide services for the shredding of X-Ray files and films of HIPAA Kenner Army Health Clinic. The shredding will take place on site at the time the service is conducted, as needed. The contractor will remain in compliance with all laws regarding HIPAA.
5.6.1. All X-ray shredded films (only) will be shredded and put in bags and given to KAHC for disposal.
PART 6
APPLICABLE PUBLICATIONS
6. APPLICABLE PUBLICATIONS (CURRENT EDITIONS):
6.1. The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures.
6.1.1. Department of Defense Standard Contract Clause for Business Associates
PART 7
ATTACHMENT/TECHNICAL EXHIBIT LISTING
7. Attachment/Technical Exhibit List:
7.1. Attachment 1/Technical Exhibit 1 – Performance Requirements Summary
7.2. Attachment 2/Technical Exhibit 2 – Deliverables Schedule
7.3. Attachment 3/Technical Exhibit 3 – Estimated Workload Data
7.4. Attachment 4/Technical Exhibit 4 – Building Locations & Bin Quantity
7.5. Attachment 5/Technical Exhibit 5 – Business Associate Agreement
TECHNICAL EXHIBIT 1
PERFORMANCE REQUIREMENTS SUMMARY
Performance Objective (The Service required— usually a shall statement)
Standard Performance Threshold (This is the maximum error rate. It could possibly be “Zero deviation from standard”)
Method of Surveillance
PRS # 1.
The contractor shall provide shredding services to all clinics within KAHC at a Bi-weekly rate and according to Holiday re-schedule days covered in the contract.
The contractor provides up to standard service in accordance with Kenner Army Health clinics HIPAA requirements and standards.
Service provided cannot deviate less than 95% of the standard. Valid customer complaints do not exceed 2 per month.
The Government QA will receive complaints from 2 personnel and pass them to the QCI for correction.
PRS # 2
Perform Shredding Service accordance with the established turnaround times and quality standards.
The contractor provides up to standard service in accordance with Kenner Army Health clinics HIPAA requirements and standards.
Emergency response times met 99% of the time
The Government QA will receive complaints from 2 personnel and pass them to the QCI for correction
PRS # 3
The Contractor will be accountable for providing the service that meets quality control
The contractor provides service that meets quality control standards in accordance with the
QASP
Service provided cannot deviate less than 98% of the standard. Valid customer complaints do not exceed 2 per month.
The Government will send up monthly reports reflecting standard and substandard quality.
PRS # 4
Contractor will maintain written and oral communications with the government in regards to any issues or delays regarding the service that is provided in accordance to the contract
Effective Communication will be maintained at all times between both parties for anything that may affect the delivery of service to the government.
This will be met 99.9% of the time.
The Government will send up monthly reports reflecting the effectiveness in communication of the contractor.
TECHNICAL EXHIBIT 2
DELIVERABLES SCHEDULE
DELIVERABLE FREQUENCY # OF
COPIES
MEDIUM/FORMAT Submit To
Provide receipt of services completed after each collection.
Para 5.2, PWS
Bi-Weekly 24-48 hrs.
After collection is completed.
One (1)
Email PDF Document
COR on file
Invoice/WAWF By the 5th of every month.
Two (2)
Mail Hard Copy and Email PDF
DFAS (See Block 10, SF 1449) COR on file
TECHNICAL EXHIBIT 3
ESTIMATED WORKLOAD DATA
ITEM
NAME
ESTIMATED QUANTITY
1 LABOR HOURS 26
WEEKS
HOURS
2 LABOR HOURS 26
WEEKS
HOURS
3 LABOR HOURS 26
WEEKS
HOURS
4 LABOR HOURS 26
WEEKS
HOURS
5 LABOR HOURS 26
WEEKS
HOURS
TECHNICAL EXHIBIT 4
BUILDING LOCATIONS & BIN QUANTITY
LOCATION BIN QTY
KENNER ARMY HEALTH CLINIC; BLDG 8130 37 EA
EDUCATION & TRAINING; BLDG 8151 2 EA
MOSIER CLINIC; BLDG 18036 3 EA
BULL DENTAL CLINIC; BLDG 8204 2 EA
MEDICAL COMPANY; BLDG 8200 1 EA
TROOP MEDICAL CLINIC (TMC) 1; BLDG 3219 2 EA
Army Wellness Center, 9205 Mahone Avenue, Fort Lee VA 23801
1 EA
VERTERINARY CLINIC, BLDG 11025, FORT LEE, VA 23801 1 EA
Department of Defense (DoD) Business Associate Agreement (BAA)
Introduction
In accordance with 45 CFR §§164.502(e)(2), 164.504(e); the Health Information Technology for Economic and Clinical Health (HITECH) Act; and paragraph 3.3.c. of Department of Defense Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, and Chapter 1, Section 5 of the TRICARE Operations Manual, this document serves as a Business Associate Agreement (BAA) between the executing parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) as implemented by the HIPAA Rules and Department of Defense (DoD) HIPAA Issuances (as defined below). The parties are a DoD Component, acting as a HIPAA Covered Entity, and a Business Associate (i.e., a DoD Contractor creates, receives, maintains, and/or transmits protected health information (PHI) for the purpose of performing covered functions on behalf of the DoD Component). The HIPAA Rules (as defined below) require BAAs between covered entities and business associates. As such, this BAA implements and incorporates the applicable DoD HIPAA Issuances (including DoDI 6025.18 and the authorities incorporated therein) and provides the Business Associate requirements which apply to the relevant Business Associates contract or other agreement between the parties.
(a) Catchall Definition:: Except as otherwise provided in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Issuances : Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), PHI,, Required by Law, Secretary of HHS, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
(b) Specific definitions:
Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the DoD component signatory.
Breach means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses personally identifiable information; or (2) an authorized user accesses or potentially accesses
Personally Identifiable Information (PII) for an other than authorized purpose. The foregoing definition is based on the definition of breach in Office of Management and Budget (OMB) Memorandum M-17-12.
Business Associate shall generally have the same meaning as the term
“Business Associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [insert name of the non-federal Business Associate entity/signatory to this BAA].
Covered Entity shall generally have the same meaning as the term
“covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [insert name of the DoD Component entity/DoD signatory to this BAA].
Covered Functions are functions of a covered entity, the performance of which makes the entity a health plan or health care provider as outlined in DoDM 6025.18.
Defense Health Agency (DHA) Privacy Office means the DHA Privacy and Civil Liberties Office, with the responsibilities and authorities as outlined in DoDM 6025.18. The Chief of the DHA Privacy Office is the HIPAA Privacy and Security Officer for DHA.
DoD HIPAA Issuances means all DoD issuances implementing the
HIPAA Rules in the DoD Military Health System (MHS). These issuances include DoDM 6025.18 (2019), Department of Defense Instruction (DoDI) 6025.18, “Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs,” March 13, 2019; and DoDI 8580.02, “Security of Individually Identifiable Health Information in DoD Health Care Programs,” August 12, 2015.
DoD Privacy Program Issuances means the current DoD issuances implementing within DoD the Privacy Act and certain privacy-related authorities, as identified by DHA Privacy Office Guidance. These issuances are DoDI 5400.11, “DoD Privacy and Civil Liberties Programs,” January 29, 2019, DoDM 5400.11, Volume 2 “DoD Privacy and Civil Liberties Programs: Breach Preparedness and Response Plan,” May 6, 2021 and DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007. These issuances are available on the Washington Headquarters Services DoD Directives website (https://www.esd.whs.mil/DD/) or upon request.
Department of Health and Human Services (HHS) Breach means a breach that satisfies the HIPAA Breach Rule definition of breach found in 45
CFR §164.402.
https://www.esd.whs.mil/DD/
HIPAA Rules means the regulations issued by HHS pursuant to its authority to issue regulations on health information privacy, as provided by Section 264(c) of HIPAA. The HIPAA Rules, as amended by the Omnibus Final Rule, include the HIPAA Privacy Rule, the HIPAA Breach Rule, the HIPAA Security Rule, and the HIPAA Enforcement Rule.
I. Obligations and Activities of the Business Associate
(a) The Business Associate shall not use or disclose PHI other than as permitted or required by the Agreement or as required by law.
(b) The Business Associate shall use appropriate safeguards, and comply with the HIPAA Rules and DoD HIPAA Issuances incorporated by reference in this document Issuances with respect to PHI, to prevent use or disclosure of PHI other than as provided for by the Agreement.
(c) The Business Associate shall report to the Covered Entity any breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this agreement. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any cybersecurity provisions of the Agreement. If at any point the Business Associate becomes aware that a security incident involves a breach, the Business Associate shall immediately initiate breach response as required by PartV of this BAA.
(d) In accordance with DoDM 6025.18, paragraph 3.3.c.(3)(b)4, 45 CFR
§164.502(e)(1)(ii)) and §164.308(b)(2),the Business Associate shall ensure that any (and all) subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to PHI, specifically the responsibilities laid out in the DoD HIPAA Issuances incorporated by reference in this agreement. PHI.
(e) The business associate may disclose PHI to a business associate that is a subcontractor and may allow the subcontractor to create, receive, maintain, or transmit PHI on its behalf, if the business associate obtains satisfactory assurances, in accordance with DoDM 6025.18, paragraph 4.5.e.(1), that the subcontractor will appropriately safeguard the information.
(f) The Business Associate shall make available PHI in a Designated
Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR
§164.524 and DoDM 6025.18, paragraph 5.3.c.
(g) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR § and DoDM 6025.18, paragraph 5.4.
(h) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR §164.528 and DoDM 6025.18, paragraph 5.5.
(i) To the extent the Business Associate is to carry out one or more of
Covered Entity's obligation(s) under the HIPAA Privacy Rule and DoDM 6025.18, the Business Associate shall comply with the requirements of the HIPAA Privacy Rule and DoDM 6025.18, that apply to the Covered Entity in the performance of such obligation(s); and
(j) The Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI from, or created or received by the Business Associate on behalf of, the DoD Component available to the Secretary of HHS and to the Director, DHA, or their designee for purposes of determining compliance with the HIPAA Rules.
II. Permitted Uses and Disclosures by Business Associate
(a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in the Agreement or as required by law. The Business Associate is not permitted to de-identify PHI, nor is it permitted to use or disclose de-identified PHI, except as provided by the Agreement or directed by the Covered Entity with written approval from DHA’s HIPAA Privacy Officer.
(b) The Business Associate agrees to use, disclose, and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.
(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances if done by the Covered Entity.
(d) Except as otherwise limited in the Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in the Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in the Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of
Privacy Practices and Restrictions
(a) The Covered Entity shall provide the Business Associate with NoPP that the Covered Entity produces in accordance with 45 CFR §164.520 and DoDM 6025.18, paragraph 5.1.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR §164.522 and DoDM 6025.18, paragraph 5.2, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity
The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Federal regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity.
V. Breach Response
(a) In general.
In the event of a breach of PII/PHI held by the Business Associate, the
Business Associate shall follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA breach response requirements, as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Program Issuances breach response requirements only. If a breach involves PHI (a subset of PII), then the Business Associate shall comply with DoD Privacy Program Issuances breach response requirements. A breach involving PHI may or may not constitute a HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Program Issuances.
If the DHA Privacy Office determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Program Issuances, as directed by the DHA Privacy Office. If the DHA Privacy Office determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Program Issuances.
The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.
In general, for breach response, the Business Associate shall report the breach to the Covered Entity. Such breach shall be reported to the DHA Privacy Office within 24 hours at 703-275-6363 or dha.ncr.pcl.mbx.pii-breach@health.mil.
If such breach is a cybersecurity incident, an incident involving damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, electronic communication, including information contained therein, ensuring the availability, integrity, authentication, confidentiality, and nonrepudiation of data, as defined in Committee on National Security Systems Instruction (CNSSI) 4009 https://www.cnss.gov/CNSS/issuances/Instructions.cfm, the discovering party shall report the breach to the DHA NIWC CSSP Watch desk by dialing
1.866.786.4432 Cybersecurity and Infrastructure Security Agency potential-CERT) within one hour of the potential cybersecurity incident. The DHA NIWC CSSP Watch desk reports, and report to USCYBERCOM within 48 hours of being notified of the occurrence of a breach, and complete the breach response actions as required by DHA guidance https://health.mil/Military-Health-Topics/Privacy-and- Civil-Liberties/Breaches-of-PII-and-PHI?type=Policies#RefFeed.
mailto:dha.ncr.pcl.mbx.pii-breach@health.mil https://health.mil/Military-Health-Topics/Privacy-and-Civil-Liberties/Breaches-of-PII-and-PHI?type=Policies#RefFeed https://health.mil/Military-Health-Topics/Privacy-and-Civil-Liberties/Breaches-of-PII-and-PHI?type=Policies#RefFeed
The Business Associate is deemed to have discovered a breach as of the first day a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
The Business Associate shall submit a report to the U.S. Computer
Emergency Readiness Team (US-CERT), using the US-CERT report online form at https://us-cert.cisa.gov/forms/reporthttps://us-cert.cisa.gov/forms/report.
Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US- CERT Reporting Number. Although only limited information about the breach may be available as of the one-hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information to the Covered Entity as it is obtained.
The Business Associate shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office. Business Associate general questions about US-CERT reporting shall be directed to the DHA Privacy Office not the US-CERT office.
Additionally, the Business Associate will send to the DHA Privacy Office a completed Breach Report Form Report DD 2959 at https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf.
Encryption is not required, because Breach Report Forms must not contain
PII/PHI.
If multiple individuals are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the DHA Privacy Office as soon as possible if it believes that a “single event” breach response is appropriate. The DHA Privacy Office will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, individual notification, and mitigation.
When an initially submitted Breach Report Form is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions by denoting “UPDATE.” Examples of updated information the Business Associate shall report include but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions,, including sanctions, training, incident containment, follow-up, https://us-cert.cisa.gov/forms/report https://us-cert.cisa.gov/forms/report https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf etc. The Business Associate shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the DHA Privacy Office to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form.
The Business Associate is responsible for reporting all information needed by the DHA Privacy Office to enable timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy, Civil Liberties, and Transparency Division as required by DoD Privacy Program Issuances.
(b) Individual Notification Provisions
If the DHA Privacy Office determines that individual notification is required
IAW 5 CFR §§ 164.400-414, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than ten working days after the breach is discovered and the identities of the individuals are ascertained. The ten-day period begins when the Business Associate determines the identities (including addresses) of the individuals whose records were affected.
The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted for approval to the DHA Privacy Office.
Upon request, the Business Associate shall provide the DHA Privacy Office with the final text of the notification letter sent to the affected individuals. PII shall not be included with the text of the letter(s) provided.. Copies of further correspondence with affected individuals need not be provided unless requested by the DHA Privacy Office. Pursuant to 45 CFR §§ 164.400-414 and section 13407 of the HITECH Act, the Business Associate’s notification to the individuals, at a minimum, shall include the following:
—The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual of the nature and extent of any potentially PHI data elements that have been breached. In all cases, individuals should be notified as to the nature and extent of any compromised
PHI.
—The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
—The individual(s) must be informed of any steps the individuals should take to protect themselves from potential harm resulting from the breach.
—The individual(s) must be informed of what protective actions the Business
Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); Teletype (TTY):): 1-866- 653-4261.
—The individual(s) must also be informed of any mitigation support services
(e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services, and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information.
Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated point of contact (POC),), phone number, email address, and postal address.
If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the ten-day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10-day period, the Business Associate shall provide the approved notification to those individuals who can be reached.
Other individuals must be notified within ten days after their identities and addresses are ascertained. The Business Associate shall consult with the DHA Privacy Office, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with DHA Privacy Office approval.
The Business Associate shall, at no cost to the government, bear all costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
VI. Termination
(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors) with any requirement addressed in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the Agreement.
(b) Effect of Termination.
(1) If the Agreement has records management requirements, the
Business Associate shall handle such records in accordance with the records management requirements. If the Agreement does not have records management requirements, the records shall be handled in accordance with paragraphs…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .