N62645-15-T-1112.pdf

PDF 622 KB Posted

Attached to
Blood Gas Laboratory Analyzer Federal contract opportunity
Solicitation number
N6264515T1112
Issued by
Department of the Navy Bureau of Medicine and Surgery

About this file

Solicitation

View the file

Other files for this federal contract opportunity

Other files attached to Blood Gas Laboratory Analyzer, newest first.
File Type Posted
N62645-15-T-1112_0001.pdf PDF
Medical_Device_Cybersecurity_Assessment_-_version_2.0_-_20150603RX.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

N62645-15-T-1112 13-Aug-2015

b. TELEPHONE NUMBER

301-619-6914

8. OFFER DUE DATE/LOCAL TIME

09:00 AM 31 Aug 2015

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA X ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

N626459. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

DEREK J. BELL

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.X

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED ORX

SMALL BUSINESS

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

NAVAL MEDICAL LOGISTICS COMMAND

693 NEIMAN STREET

FORT DETRICK MD 21702-9239

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE 16. ADMINISTERED BY

SEE SCHEDULE

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

FAX:

TEL: SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

NAICS:

334516

X

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF50

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

N62645-15-T-1112

Section SF 1449 - CONTINUATION SHEET

ITEM NO SUPPLIES/SERVICES MAX

QUANTITY

UNIT UNIT PRICE MAX AMOUNT

0001 6,000 Each

CPRR-BLOOD GAS ANALYZER

FFP

Cost Per Reportable Result (CPRR) Blood Gas Analyzer

SEE STATEMENT OF REQUIREMENTS FOR DETAILS

NOTE: QUANTITY IS FOR FIVE (5) YEAR ORDERING PERIOD

(1,200/annually).

FOB: Destination

MAX

NET AMT

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0002 1 Each Medical Device Risk Assessment (MDRA)

FFP

Completed Gold Section returned to Naval Medical Logistics Command (NMLC) within 7 days after award.

NET AMT

STATEMENT OF REQUIREMENTS

1. Equipment

The requirement is for a cost-per-reportable-result (CPRR) contract for one (1) blood gas laboratory analyzer for

Naval Hospital Bremerton, brand name or equal (BNE) to the Radiometer America, Inc. ABL805. The contracted system shall be a single platform. The system shall be capable of performing the following blood gas tests: pH, pCO2, pO2, Lactate, and Ionized Calcium. The system shall be capable of processing an average workload of approximately 1,200 samples annually (6,000 samples for the five (5) year ordering period). The system shall be capable of using bar coded reagents. The system shall be fully automated. The system shall be capable of interfacing with the Composite Health Care System (CHCS) and the laboratory information system. The electrical requirements are 110VAC, 60 Hz. System installation, onsite and offsite training, and preventive maintenance coverage shall be included. Corrective system maintenance coverage shall include response times as specified in the Statement of Requirements. Support shall be provided for a period of five (5) years.

The units shall be compliant with the Food and Drug Administration (FDA) requirements to market and deliver medical products for use in the United States of America, even should delivery be requested outside of the United

States. The claims made for the product shall comply with the regulations of the FDA with respect to products for marketing and delivery of a medical product for use in the United States of America, even should delivery be requested outside of the United States. The system shall be installed in compliance with OSHA requirements.

Contractor shall be an Original Equipment Manufacturer (OEM) authorized dealer, authorized distributor or authorized reseller for the proposed equipment/system such that OEM warranty and service are provided and maintained by the OEM. All software licensing, warranty and service associated with the equipment/system shall be in accordance with the OEM terms and conditions.

Upon delivery, the contractor shall be responsible for uncrating the unit/system, transporting it through the facility to the location of intended use for installation, and removing of all trash created in this process. If interim storage is required, the vendor shall make arrangements for the storage.

2. Reagent and supply delivery

a. All supplied items and reagents shall be certified for use with the Vendor equipment provided.

b. All supplied items and reagents that require special handling, e.g. refrigeration, time sensitive, open immediately, etc., will be marked in a clear manner with a label that is easily read, understandable and a minimum of 3” x 3” (9 sq. inches). The label will be placed in three (3) or more locations on the container

(top & sides). Supplies/items that require refrigeration will have both the required Celsius and Fahrenheit temperature identified.

c. The contractor shall provide deliveries to the delivery point identified below:

Naval Hospital Bremerton

Commanding Officer

Laboratory Department

1 Boone Road

Bremerton, WA 98312-1898

3. Maintenance.

a. The Vendor shall provide trained, experienced, English-speaking personnel, labor, tools, diagnostic equipment, software, material, supplies, transportation, parts and equipment necessary to perform

Preventive Maintenance (PM), Calibration (CAL), Safety Testing (ST) and corrective maintenance.

b. The Vendor shall provide telephonic communications with the Government to discuss technical matters relating to the performance of this contract. A systems operator shall be made available to answer technical questions regarding system operations and applications.

c. Equipment listed in this contract will be maintained to meet and retain the original equipment manufacturer’s (OEM’s) specifications / equipment certification.

4. Preventive Maintenance Services.

a. Normal Business Hour Maintenance Coverage will be Monday through Friday, between 8:00 A.M. to

5:00 P.M. PST. Vendor shall provide full service preventive maintenance.

b. Preventive maintenance shall be performed in accordance with OEM recommendations.

c. Vendor shall perform Preventive Maintenance Service checks during the length of the ordering period at the OEM’s recommended intervals. Vendor will also perform Preventive Maintenance Service checks during each option year at a date and time mutually agreed upon by the Vendor and the Government.

d. All test equipment used in the performance of this contract shall be calibrated, as required by the OEM, and shall be in compliance with Joint Commission (JC), OEM, the College of American Pathologist’s

(CAP), and Food and Drug Administration (FDA) standards as required.

5. Corrective Maintenance

a. Vendor shall provide on-site corrective maintenance between the hours of 8:00 A.M. and 5:00 P.M. PST, Monday-Friday with unlimited service calls. Telephonic support shall be available 24 hours per day, 7 days per week.

b. A vendor service technician shall respond via telephone within two (2) hours after receipt of trouble call, and provide on-site service within twenty four (24) hours. Equipment shall be operational within 48 hours.

c. Government request for corrective maintenance will be placed by Biomedical Engineering Division

(BIOMED) personnel, to the Vendor. Corrective maintenance shall be completed during the hours specified in the contract.

d. Vendor’s response to requests for service may include telephone consultation with the equipment user/operator and a Vendor Field Service Engineer (FSE). Telephone consultation 1) shall provide instruction in determining operator error; 2) shall determine the most likely cause of the problem; 3) shall determine if resolution of the problem requires the dispatch of a FSE; and 4) should identify replacement parts likely to be required in order to return the equipment to 100% operational condition as specified by the OEM.

e. Vendor’s pricing shall be inclusive of all costs including parts, consumables, labor, travel and shipping.

f. The Vendor shall have his/her own service manuals, specifications, schematic diagrams, and parts lists to assist in the evaluation/repair of all equipment included in this contract.

6. Replacement Parts/Upgrades.

a. The Vendor shall have ready access to unique and/or high mortality replacement parts.

All parts supplied shall be compatible with the existing system. In the event that replacement parts are required to be shipped, shipping shall be performed in the fastest reasonable means possible at no additional cost to the Government.

b. The Vendor shall replace all worn or defective parts necessary to restore the equipment to 100% operational condition as specified by the OEM.

c. Freight, postage, and storage charges associated with shipment and receipt of replacement parts and the return of parts shall be the responsibility of the Vendor.

d. All replacement parts shall be new and certified as OEM replacement parts. In the event that new parts are not available, rebuilt parts and sub-assemblies are allowed provided that they are warranted to be free of defects for a period of time that meets or exceeds warranties of similar replacement parts. The Vendor shall specifically annotate on the Field Service Report the use and identification of rebuilt parts and the period of warranty. When discrepancies occur, the Government will make the final determination on whether a replacement part is of equal or better quality.

e. The Vendor shall include software revisions and upgrades (field service changes), which are required due to FDA or manufacturer announced safety-hazard recall, to include FDA Year 2000 Compliance Directive, as part of the contract at no additional cost to the Government. Upgrades shall be performed as soon as possible after release, but no later than the first scheduled Preventative Maintenance inspection after release. For any updates that have been identified as critical, or required for the proper operation of equipment by the OEM, vendor shall provide installation within 30 days of release regardless of

Preventative Maintenance schedules.

f. With approval from the government, the vendor may perform hardware/software upgrades as they become available.

7. Government furnished property, Materials and Services.

a. The Government will be responsible for maintaining the proper environment, including utilities and site requirements necessary for the system to function properly as specified by the OEM.

b. The Government will operate the system in accordance with the instruction manual provided by the

OEM.

c. The Government will not be responsible for the damage or loss due to fire, theft, accident, or other disaster of Vendor supplies, materials, or for the personal belongings brought onto Government property by

Vendor’s personnel.

8. Vendor Furnished Property and Material.

a. The Vendor shall provide all service literature, reference publications, laptop computers and diagnostic software to be used by the Vendor service technicians and as required for the completion of the services in accordance with this contract.

9. Vendor Report Requirements.

a. During normal duty hours, Vendor FSE personnel shall check-in with the Biomedical Engineering

Division/Technical Liasion upon arrival at the Government site and again prior to departure. The Vendor

FSEs shall personally notify BIOMED personnel/Technical Liasion of problems that result in the equipment being left disabled upon their departure. If equipment is left disabled, a method of physical use prevention of the disabled equipment shall be implemented, and the disabled equipment shall be locked out with a letter of intent in compliance with OSHA regulation to prevent any patient hazards. After normal duty hours, Vendor FSEs shall notify the Officer of the Day Desk and the systems operator designated by

BIOMED personnel/Technical Liasion.

b. The Vendor shall provide to BIOMED/Technical Liasion personnel a full service report within two (2) days after completion of all services performed. Each service report shall at a minimum document the following data legibly and in complete detail:

i. Name of Vendor

ii. Contract Number

iii. Name of field service technician performing service

iv. Vendor log/control number

v. Date, time (beginning and ending), and hours on-site for service call

vi. Description of problem reported by user

vii. Equipment identification factors to include: manufacturer, make, model, serial number and

Facility Equipment Control Number (ECN)

viii. Itemized description of service performed to include: labor and travel costs, parts used, parts cost, parts number/nomenclature, part new or reconditioned, part manufacturer, and problem/corrective action taken or recommended

ix. Problem resolution or pending action

x. Total billing cost

xi. Signatures:

1. Field Service Technician performing services

2. BMET verifying service rendered (Identify Medical Treatment Facility)

xii. In the event that agents / sub-vendors are used in the performance of repairs, said agent shall be identified on the service report by company name and contact information (i.e., telephone number)

10. Vendor Responsibility.

a. The Vendor shall be responsible for the repair/replacement of damaged Government owned equipment and property due to the negligence of the Vendor or his representatives. All such replacement or repair shall be at the Vendor's expense and shall be inspected to the satisfaction of the BIOMED/Technical

Liasion.

11. Removal of Government Property

a. No equipment shall be removed without the approval of the BIOMED/Technical Liasion and Materials

Management Department of the Medical Treatment Facility (MTF). Property passes for equipment removal shall be obtained by the Vendor via the Materials Management Department of the MTF. Any failure to obtain such passes which results in detainment or prosecution of service Vendor personnel are the sole responsibility of the service Vendor personnel.

b. The Vendor shall provide a detailed description of removed items in writing on the Vendor’s company letterhead. For associated items/accessories, Vendor to provide a detailed written description and quantities of items to be removed. Description to include, as a minimum, manufacturer’s serial numbers and equipment control numbers (ECNs) of all equipment / items removed. In the event that items / sub-assemblies / accessories are repaired via “Repair by Replacement,” a detailed description of replaced items is to be included upon return of repaired components.

c. No additional charge shall be allowed for work performed off-site, or any additional time required. All charges resulting from a Vendor determined requirement to transport Government owned property, covered by this contract, to and from an alternate repair location shall be the responsibility of the Vendor. The

Vendor shall provide insurance coverage for damage to or loss of equipment while in Vendor or service

Vendor’s custody.

d. In regards to patient information confidentiality and privacy, all vendors and/or service vendor shall not remove equipment containing patient information from the Government site. The equipment hard drive shall be removed at the MTF prior to removal. Furthermore, equipment removed from the MTF will be prorated from the date of removal for service maintenance fees. If hard drives are to be replaced, they shall be left at the MTF for disposal.

12. Service Beyond the Scope of the Contract

a. The Vendor shall immediately, but not later than 24 consecutive hours after discovery, notify

BIOMED/Technical Liasion, in writing, of the existence or the development of any defects in, or repair required to the scheduled equipment which the Vendor considers they are not responsible for under the terms of this contract.

b. At the same time of the notification, the Vendor shall furnish BIOMED/Technical Liasion with written estimate of the cost to make the necessary repairs. Repairs considered by the Contracting Officer to be outside the scope of this contract shall not be covered under this contract, but shall be ordered under a separate purchase order.

OTHER CONTRACTING REQUIREMENTS

All Department of the Navy (DON) information systems as defined in Department of Defense Directive (DoDD)

8500.1 shall be certified and accredited (C&A) for operation. C&A is attained via the Defense Information

Assurance Certification and Accreditation Process (DIACAP) and is applicable to all DON-owned or controlled information systems that receive, process, store, display or transmit Department of Defense (DoD) information, regardless of Mission Assurance Category (MAC) classification or sensitivity, except, per DoDD 8500.1 Paragraph

2.3; IT that is considered Platform Information Technology (PIT). Regardless of whether the system or device is considered PIT or whether it is determined that it requires a full accreditation, the following DIACAP artifacts shall be included with your proposal; System Identification Profile (SIP), DIACAP Implementation Profile (DIP), and

Plan of Actions and Milestones (POA&M). A template has been included with this solicitation as “Medical

Device Cybersecurity Assessment.” Completion of this form as instructed in the form will satisfy the requirement for the SIP, DIP and POA&M.

The contractor shall establish appropriate administrative, technical, and physical safeguards to protect all government data, to ensure the confidentiality, integrity, and availability of government data under their control. At a minimum, this shall include provisions for personnel, electronic, and physical security.

Navy PIT Designation

Certain medical technologies may be designated as PIT by the Navy Operational Designated Accrediting Authority

(ODAA); however the PIT designation itself does not constitute an Approval to Operate (ATO). The PIT system will require a PIT Risk Analysis (PRA). The DIACAP SIP, DIP, POA&M and Risk Analysis documents are required in order to complete a PRA. Contractors will be required to scan the PIT system for vulnerabilities prior to delivery.

According to DoDD 85001, Paragraph E2.1.16.4; PIT refers to computer resources, both hardware and software, that are physically part of, dedicated to, or essential in real time to the mission performance of special-purpose systems. Medical technologies, and specifically medical imaging and monitoring systems are considered special-purpose mission technologies according to this definition.

The PIT designation issued by the ODAA may be used by the Program Manager (PM) to complete a

PRA in order to prove compliance with C&A requirements, but is cautioned that the appropriate IA controls must still be built into the IT to comply with acquisition requirements. The contractor shall work with Navy Program Managers to ensure their systems meet these requirements.

The Contractor will be required to propose an acceptable approach to selecting IA controls starting from the baseline set on DoD Instruction 8500.2 B, commensurate with the system’s Mission

Assurance Category (MAC) and Confidentiality Level. For medical devices and systems the MAC level assigned is typically MAC III sensitive.

If the system or device is determined to be PIT, the Contractor shall support Navy Medicine IA representatives in creation of the PIT designation request packages to include all relevant configuration, software and IA data. The following documents will assist is creating the PIT designation request package;

Digital Imaging and Communications in Medicine (DICOM) Conformance

Statement (if applicable)

Food and Drug Administration (FDA) Certification (510k)

Integrating the Healthcare Enterprise (IHE) Integration Statement

International Organization for Standardization (ISO) Statement (if applicable)

Manufacturer Disclosure Statement for Medical Device Security (MDS2)

A full system diagram to include any PIT to PIT or other interconnections

DIACAP

For those systems that do not meet the requirements for designation as PIT, the contractor shall comply with

DIACAP requirements as specified by the DoD that meet appropriate DoD and Navy IA requirements. The contractor shall initiate the process by providing the required documentation necessary to receive an ATO. The contractor shall make their device or system delivered against this contract available for C&A testing and initiate the process well in advance of a contract delivery order. The requirements shall be met before the contractor's system is authorized to access DoD data or interconnect with any DoD network that receives, processes, stores, displays or transmits DoD data. An ATO, at a minimum, will be required before a device or system is installed. The contractor shall ensure that the proper contractor support staff is available to participate in all phases of the DIACAP process.

They include but are not limited to;

Completing and maintaining all documentation necessary to obtain an ATO.

Attending and supporting DIACAP and C&A meetings with Navy IA representatives.

Supporting/conducting the vulnerability mitigation process to comply with IA controls listed in DoD

Instruction 8500.2.

Supporting the C&A Team during system security testing.

Contractors must confirm that their systems are locked down prior to initiating C&A testing.

Post-Accreditation Review

An annual IA review shall be conducted that comprehensively evaluates existing policies and processes to ensure procedural consistency and that the IS continues to operate in the manner to which it was accredited. The annual review process should account for the analysis of projected policy needs, and produce a plan for development or implementation of new policies or processes.

Personnel Security and User Access Control

The contractor shall comply with DoDD 8500.1, “Information Assurance (IA)”, DoD Instruction (DODI) 8500.2

“Information Assurance (IA) Implementation”, DoDD 5400.11, “DoD Privacy Program”, DoD 6025.18-R, DoD

Health Information Privacy Regulation and DoD 5200.2-R, “Personnel Security Program Requirements”.

Contractor responsibilities for ensuring personnel security include, but are not limited to meeting the following requirements:

Follow the Privacy Office guidelines for submittal of IT security clearances and ensure all contractor personnel are designated as IT-I, IT-II or IT-III where their duties meet the criteria of the position sensitivity designations.

Because of the unique circumstances presented by DoD and DON networks, personnel security requirements shall be followed to ensure appropriate precautions are taken prior to allowing vendor personnel access to the network.

Any vendor personnel that will be accessing the medical device/system while installed on the hospital network will be required to have a National Agency Check (NAC) completed. Typically, this requires an investigation to support a “Public Trust Position” and requires the person(s) to complete and submit a Standard Form 85P (SF85P), Questionnaire for Public Trust Positions, via the Electronic Personnel Security Questionnaire (EPSQ). Questions relating to SF85Ps and the EPSQ process may be directed to 1-888-282-7682 or online at http://www.dss.mil/index.htm. Contractor personnel accessing equipment connected to the hospital network will be required to complete a System Authorization Access Request-Navy (SAAR-N) (form OPNAV 5239/14). Copies of this form can be obtained from the Navy PACS Office. Additionally, contractor personnel are required to complete the annual DoD IA training requirements.

The contractor shall initiate, maintain and document personnel security investigations appropriate to the individual’s responsibilities and required access to Sensitive Information (SI).

Immediately report to the appropriate Navy POC and deny access to any automated information system (AIS), network, or information if a contractor employee filling a sensitive position receives an unfavorable adjudication, if information that would result in an unfavorable adjudication becomes available, or if directed to do so by the appropriate Navy representative for security reasons.

Ensure that all contractor personnel receive IA training before being granted access to DoD AIS’s.

Access to the medical devices will be limited to authorized users as determined by local policy. Vendors whose systems do not yet meet the requirement for CAC authentication must indicate their willingness to do so, and offer a timeline for compliance.

Operating Systems

To ensure that medical systems attain data confidentiality, integrity, and availability levels consistent with best industry practices, the use of current Operating Systems (OS) is highly recommended. Therefore preference may be given to systems that employ modern operating systems, including closed source, open source, or proprietary. Medical systems will employ whenever possible, operating systems that are fully supported by the manufacturer and are commercially available.

Domain Name System Realm/Directory Services

Contractor will be required to provide technical evidence, if applicable, whether client/server topology based medical systems can integrate with Directory Services and support LDAP authentication.

Local Privileged and Administrative User/Local System Accounts

Contractor shall create a single local user account with administrative/root level privileges for purposes of conducting system repairs and maintenance only. This account shall be separate and distinct from the built-in local administrative/root account provided by the Operating System and shall comply with DoD policy. All factors required to complete successful identification, authentication and authorization against the built-in local Administrative/Root level account shall be provided to the MTF Biomedical Engineering Department.

Complete administrative system rights shall be provided to the government System Administrator for the purpose of conducting device vulnerability scans as needed.

http://www.dss.mil/index.htm

Navy Business to Business (B2B) Gateway

All contractor systems that will communicate with DON systems will interconnect through the established Military

Health System (MHS) Business to Business (B2B) gateway. For all Web applications, contractors will connect to the

DISA-established Web DMZ.

Contractors will connect to the B2B gateway via a contractor procured Internet Service Provider (ISP) connection and assume all responsibilities for establishing and maintaining their connectivity to the

B2B gateway. This will include acquiring and maintaining the circuit to the B2B gateway and acquiring a FIPS-140-2 Virtual Private Network (VPN)/Firewall device compatible with the MHS

VPN device. Maintenance and repair of contractor procured VPN equipment shall be the responsibility of the contractor.

Contractors shall configure their network to support access to government systems (e.g., configure ports and protocols for access).

Contractors shall provide full time connections to a TIER1 or TIER2 ISP. Dial-up ISP connections are not acceptable.

Contractors will comply with DoD guidance regarding allowable ports, protocols and risk mitigation strategies

Prior to accessing DON, all contractors will be required to complete a DISA Form 2875 System

Authorization Access Request form (SAAR) and submit it to NMLC, Code 03, Imaging Informatics Division for processing. The contractor will be required to complete applicable DoD IA training.

IPv6

The proposed system shall be Internet Protocol version 6 (IPv6) capable or the vendor must provide a detailed project, migration or planning documentation to show when the proposed system shall be IPv6 capable.

Minimum IPv6 capabilities include:

Conformant with the IPv6 standards profile contained in the DoD IT Standards Registry (DISR);

Maintaining interoperability in heterogeneous environments with IPv4;

Commitment to upgrade as the IPv6 standard evolves;

Availability of vendor IPv6 technical support.

The contractor must be able to demonstrate or provide documentation to prove that their product is IPv6 capable. As described in the DISR IPv6 standards profile, application vendors are expected to scan and test their code for IPv6 compliance and provide a letter of compliance indicating to what degree they comply. The letter shall be in vendor format and describe the standards used for testing and the results of the scans. IPv6 'capable' is defined as having the capability of receiving, processing and forwarding IPv6 packets and/or interfacing with other IPv6 capable systems/devices and in a manner similar to IPv4. In order to demonstrate IPv6 compliance, the vendor should submit the following documentation:

Provide a diagram showing IPv6 core configuration, to include IPv6 addressing, internal network connectivity and topology, external network connectivity, and IPv6 traffic flow;

Submit a list of core components to include vendor/manufacturer IPv6 compliance;

Submit a report that illustrates testing of IPv6 compliance, to include test scripting, logs and results.

Information Assurance Vulnerability Management (IAVM)

IAVM is focused on maintaining a secure platform as new vulnerabilities and exploits are discovered and released through various software developers and security agencies. The core tool of successful IAVM is the Information

Assurance Vulnerability Alert (IAVA). The DoD releases IAVAs for local action on the various platforms across the enterprise network. Each Navy Healthcare Facility is responsible for managing their local network. Most DoD

IAVAs originate from a real world event such as a patch release or vulnerability notification from a software vendor

(e.g. Windows or Sun patch release), or a US-CERT released from the CERT Coordination Center at Carnegie

Mellon University. To have an effective IAVM program, vendors must be proactive in monitoring emerging threats.

Some recommended sources for IAVM support are:

General Vulnerability alerts, all platforms: http://www.cert.org/nav/index_red.html

Microsoft security resources: http://www.microsoft.com/technet/security/bulletin/notify.mspx

SUN Microsystems Security resources: http://sunsolve.sun.com/pub-cgi/show.pl?target=security/sec

As part of the IAVM program, the contractor shall provide a primary and secondary point of contact for compliance actions. The point of contact shall provide, upon receipt of a vulnerability message, an acknowledgement of that receipt. The vendor shall thoroughly test all mitigations for the vulnerability, and upon applying the mitigation to the system, report compliance. Receipt and compliance messages shall occur within the stipulated time window, as stated in the vulnerability message or other official notification.

Any vendor interested in meeting this requirement shall have a documented process to demonstrate an organizational culture embracing security throughout the system lifecycle. The processes shall clearly demonstrate security’s role in the product development phase, and the processes the vendor employs to react to vulnerabilities, validate required patches, communicate status and required actions to their customers, and the follow up service support to address patch implementation.

Health Insurance Portability and Accountability Act (HIPAA)

The contractor shall comply with the HIPAA Act of 1996 (Public Law 104-191) requirements, specifically the administrative simplification provision s of the law and the associated rules and regulations published by the

Secretary, Health and Human Services (HHS). This includes the Standards for Electronic Transactions, the

Standards for Privacy of Individually Identifiable Health Information and the Security Standards.

Business Associate Agreement

In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy Regulation” the Contractor meets the definition of Business Associate. Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Contractor agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause, and DoD 6025.18-R and DoD 8580.02-R, as amended. Additional requirements will be addressed when implemented.

(a) Definitions. As used in this clause generally refer to the Code of Federal Regulations (CFR) definition unless a more specific provision exists in DODI 6025.18-R.

Individual has the same meaning as the term ``individual'' in 45 CFR 164.501 and 164.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).

Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.

Protected Health Information has the same meaning as the term ``protected health information'' in 45 CFR

164.501, limited to the information created or received by The Contractor from or on behalf of The Government.

Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.

Required by Law has the same meaning as the term ``required by law'' in 45 CFR 164.501 and 164.103.

http://www.cert.org/nav/index_red.html http://www.microsoft.com/technet/security/bulletin/notify.mspx http://sunsolve.sun.com/pub-cgi/show.pl?target=security/sec

Secretary means the Secretary of the Department of Health and Human Services or his/her designee.

Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part

164, subpart C.

Terms used, but not otherwise defined, in this Clause shall have the same meaning as those terms in 45 CFR

160.103, 164.501 and 164.304.

(b) The Contractor shall not use or further disclose Protected Health Information other than as permitted or required by the Contract or as Required by Law.

(c) The Contractor shall use appropriate safeguards to prevent use or disclosure of the Protected Health

Information other than as provided for by this Contract.

(d) The Contractor shall use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Contract.

(e) The Contractor shall mitigate, to the extent practicable, any harmful effect that is known to the

Contractor of a use or disclosure of Protected Health Information by the Contractor in violation of the requirements of this Contract.

(f) The Contractor shall report to the Government any security incident involving protected health information of which it becomes aware.

(g) The Contractor shall report to the Government any use or disclosure of the Protected Health

Information not provided for by this Contract of which the Contractor becomes aware of.

(h) The Contractor shall ensure that any agent, including a subcontractor, to whom it provides Protected

Health Information received from, or created or received by the Contractor on behalf of the Government agrees to the same restrictions and conditions that apply through this Contract to the Contractor with respect to such information.

(i) The Contractor shall ensure that any agent, including a subcontractor, to whom it provides electronic

Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.

(j) The Contractor shall provide access, at the request of the Government, and in the time and manner designated by the Government to Protected Health Information in a Designated Record Set, to the Government or, as directed by the Government, to an Individual in order to meet the requirements under 45 CFR 164.524.

(k) The Contractor shall make any amendment(s) to Protected Health Information in a Designated Record

Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government or an

Individual, and in the time and manner designated by the Government.

(l) The Contractor shall make internal practices, books, and records relating to the use and disclosure of

Protected Health Information received from, or created or received by the Contractor on behalf of, the Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner designated by the Government or the Secretary, for purposes of the Secretary determining the Government’s compliance with the Privacy Rule.

(m) The Contractor shall document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.

(n) The Contractor shall provide to the Government or an Individual, in time and manner designated by the

Government, information collected in accordance with this Clause of the Contract, to permit the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.

General Use and Disclosure Provisions

Except as otherwise limited in this Clause, the Contractor may use or disclose Protected Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health

Information would not violate the Privacy Rule, the Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the Government.

Specific Use and Disclosure Provisions

(a) Except as otherwise limited in this Clause, the Contractor may use Protected Health Information for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor.

(b) Except as otherwise limited in this Clause, the Contractor may disclose Protected Health Information for the proper management and administration of the Contractor, provided that disclosures are required by law, or the Contractor obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Contractor of any instances of which it is aware in which the confidentiality of the information has been breached.

(c) Except as otherwise limited in this Clause, the Contractor may use Protected Health Information to provide Data Aggregation services to the Government as permitted by 45 CFR 164.504(e)(2)(i)(B).

(d) Contractor may use Protected Health Information to report violations of law to appropriate Federal and

State authorities, consistent with 45 CFR 164.502(j)(1).

Obligations of the Government

Provisions for the Government to Inform the Contractor of Privacy Practices and Restrictions

(a) Upon request the Government shall provide the Contractor with the notice of privacy practices that the

Government produces in accordance with 45 CFR 164.520, as well as any changes to such notice.

(b) The Government shall provide the Contractor with any changes in, or revocation of, permission by

Individual to use or disclose Protected Health Information, if such changes affect the Contractor's permitted or required uses and disclosures.

(c) The Government shall notify the Contractor of any restriction to the use or disclosure of Protected

Health Information that the Government has agreed to in accordance with 45 CFR 164.522.

Permissible Requests by the Government

The Government shall not request the Contractor to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy Rule if done by the Government, except for providing Data

Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this clause.

Termination

(a) Termination. A breach by the Contractor of this clause, may subject the Contractor to termination under any applicable default or termination provision of this Contract.

(b) Effect of Termination.

(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below

(2) If this contract does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Contractor shall return or destroy all Protected Health Information received from the Government, or created or received by the Contractor on behalf of the Government. This provision shall apply to Protected Health Information that is in the possession of subcontractors or agents of the Contractor. The Contractor shall retain no copies of the Protected Health

Information.

(3) If this contract does not have records management provisions and the Contractor determines that returning or destroying the Protected Health Information is infeasible, the Contractor shall provide to the

Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the

Government and the Contractor that return or destruction of Protected Health Information is infeasible, the

Contractor shall extend the protections of this Contract to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such Protected Health Information.

Miscellaneous

(a) Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule means the section as in effect or as amended, and for which compliance is required.

(b) Survival. The respective rights and obligations of Business Associate under the ``Effect of Termination'' provision of this Clause shall survive the termination of this Contract.

(c) Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the

Government to comply with DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule

ADMINISTRATIVE INFORMATION

The point of contact for administrative concerns for this order at Naval Medical Logistics Command,693 Neiman

Street, Fort Detrick, MD 21702 is Derek Bell, 301-619-6914, derek.j.bell.civ@mail.mil.

CONTRACTOR SUPPORT

Notice: Navy Use Of Support Contractor For Contract Closeout Functions

Naval Medical Logistics Command (NMLC) uses two private contractors in support of the contract closeout process. Those companies are Contracting Resources Group (CRG) of Federal Hill, MD, doing business under the authority of the Small Business Administration’s 8(a) program and the Ability One Program, doing business under the authority of the Javits-Wagner O’Day Act (41 U.S.C. § 47).

The contract closeout process includes activities such as processing deobligation modifications, obtaining contractor and requiring activity concurrence, preparing the DD-Form 1594 (Contract Completion Statement), and preparing closed files for archiving. Support contractors may perform additional administrative duties, including filing and mailto:derek.j.bell.civ@mail.mil processing simple administrative modifications. Performing these functions require the contractor employees to have access to the contract file. Therefore, information you provide to the Government or information already in the possession of the Government may be viewed by these support contractors in the course of performing contract close-out functions. The information that may be made available to the contractor may include pricing and technical proposals and performance information.

NMLC has signed Non-Disclosure Agreements with each support contractor employee and has required both contractors to provide a Conflict of interest Mitigation Plan to ensure these employees are firewalled from all business development activity.

By submission of a quote, the offeror and its subcontractors consent to access of their business sensitive/confidential or proprietary data by the Government’s support contractor personnel in order to perform close out services.

INSTRUCTIONS TO QUOTERS

This section specifies the format and content that Quoters shall use in this Request for Quote (RFQ). Quoters shall submit a quote that is legible and comprehensive enough to provide the basis for a sound evaluation by the

Government. Any quote which does not provide, as a minimum, that which is required in the solicitation may be determined to be substantially incomplete and not warrant any further consideration.

Quotes may be submitted as MS Word, Excel or Adobe PDF attachments to derek.j.bell.civ@mail.mil. Any questions must be addressed to derek.j.bell.civ@mail.mill by email only no later than 2:00 pm local time on 17

August 2015. No phone calls accepted.

All Quoters shall provide the following company details:

Complete company name and address

Company Point of Contact (POC)

Email

Phone Number

CAGE Code

DUNS number

Place of Manufacture

Technical

The Quoter shall include information to enable the evaluation of the proposed product and its conformance to the specified brand name or equal product by part number, manufacturer and description. Equipment offered as equal to brand name shall meet at a minimum the essential characteristics (Statement of

Requirements) described in this solicitation, and the quoter shall provide descriptive literature in sufficient detail to determine if the items quoted are technically acceptable.

Offeros shall complete the Medical Device Risk Assessment (MDRA) Questionairre by follwing the instructions within the document at http://www.med.navy.mil/sites/nmlc/Pages/DBU-RFP.aspx (bottom of page).

Price

The Quoter shall provide pricing for all line items and a total contract price (all line items).

The Quoter shall provide acknowledgement of any amendments.

The proposed price will be evaluated by the Government and must be determined to be fair and reasonable for award.

Other Administrative Instructions

The Quoter shall complete and submit DFARS Provision 252.209-7992 Representation by Corporations

Regarding an Unpaid Delinquent Tax Liability or a Felony Conviction under any Federal Law—Fiscal

Year 2015 Appropriations.

mailto:derek.j.bell.civ@mail.mil mailto:derek.j.bell.civ@mail.mil mailto:%20xxxx.xxxx@med.navy.mil mailto:%20xxxx.xxxx@med.navy.mil http://www.med.navy.mil/sites/nmlc/Pages/DBU-RFP.aspx

Contractors must be registered in the System for Award Management (SAM) database at time of award.

Registration is free and can be completed on-line at https://www.sam.gov/portal/public/SAM/.

BASIS OF AWARD

This requirement will be evaluated as a Lowest Price Technically Acceptable (LPTA) requirement. Award will be made on the basis of the lowest evaluated price of quotes that meet or exceed the non-cost factors. The Government anticipates award of a firm fixed price (FFP) contract.

The Government intends to evaluate quotes and award a contract without discussions, but reserves the right to conduct discussions if later determined by the Contracting Officer to be necessary. The Government reserves the right to make no award as a result of this solicitation.

Technical Evaluation Factors

The quoter with the lowest overall quoted price and determined technically acceptable will receive an award and no further offers will be evaluated.

Conformance to Statement of Requirements

Evaluation shall include the ability to meet the brand name or equal of this requirement.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .