N62645-16-R-0009_Amendment_01-_Extend_due_date.doc

DOC document 214 KB Posted

Attached to
Medical Coding Services Federal contract opportunity
Solicitation number
N62645-16-R-0009
Issued by
Department of the Navy Bureau of Medicine and Surgery

About this file

The purpose of this amendment is to extend the due date to 11 April 2016 1 00PM local time.

View the file

Other files for this federal contract opportunity

Other files attached to Medical Coding Services, newest first.
File Type Posted
Pricing_Workbook_for_N62645-16-R-0009-_Amendment_05.xlsx XLSX spreadsheet
N62645-16-R-0009_Amendment_05_for_FBO.docx DOCX document
Pricing_Workbook_for_N62645-16-R-0009-_Amendment_03.xlsx XLSX spreadsheet
Attachment_1_-_Past_Performance_Information_Sheet_Coding-_Amendment_03.docx DOCX document
N62645-16-R-0009_Amendment_03-_Extend_Due_Date_and_QA.doc DOC document
N62645-16-R-0009_Amendment_02-_Extend_due_date.doc DOC document
N62645-16-R-0009_FBO.docx DOCX document
PWS_Attachment_VII_PII _PHI_and_Fed_Info_Req.pdf PDF
Attachment_4_-_DFARS_252.209-7991.docx DOCX document
PWS_Attachment_VI_Confidentiality_Form.docx DOCX document
Attachment_IV_dd1423_c.pdf PDF
Pricing_Workbook_for_N62645-16-R-0009_LJL_Revised_2-29-16.xlsx XLSX spreadsheet
Attachment_IV_dd1423_a.pdf PDF
B2B_Attachment_1--Juniper_Networks_-_Product_Listings.pdf PDF
B2B_Attachment_3--DD2875.pdf PDF
Attachment_1_-_Past_Performance_Information_Sheet.docx DOCX document
B2B_Attachment_6--MDS2FormInstructions.pdf PDF
PWS_Attachment_II_BUMEDINST_6150.38A.pdf PDF
PWS_Attachment_I_BUMED_memo_6000_Ser_M3_HCO3_AT-23704_correcting_codes.pdf PDF
Attachment_2_-_SAM_Certification_Sheet.docx DOCX document
B2B_Attachment_2--NMLC_-_Vendor_Business_to_Business_(B2B)_Information_Request_Form.pdf PDF
PWS_Attachment_III_Coding_Program_Management_and_Training_Guidelines.pdf PDF
PWS_Attachment_V_Citizenship_Requirements.docx DOCX document
Attachment_3_-_Offeror's_Information_Form.docx DOCX document
Attachment_IV_dd1423_b.pdf PDF
Attachment_IV_dd1423_d.pdf PDF
B2B_Attachment_5--Tricare_Manual_(with_B2B_requirements_highlighted).pdf PDF
B2B_Attachment_4--B2B_Implementation_Briefing_2013.ppt PPT presentation
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION SF 30 BLOCK 14 CONTINUATION PAGE

SUMMARY OF CHANGES

SECTION SF 1449 - CONTINUATION SHEET

SOLICITATION/CONTRACT FORM

The required response date/time has changed from 01-Apr-2016 01:00 PM to 11-Apr-2016 01:00 PM.

The following have been modified:

ADDENDUM TO 52.212-1

ADDENDUM TO 52.212-1-- INSTRUCTIONS TO OFFERORS--COMMERCIAL ITEMS

THIS SECTION IS FOR SOLICITATION PURPOSES ONLY. THIS SECTION WILL BE PHYSICALLY REMOVED FROM ANY RESULTANT AWARD, BUT WILL BE DEEMED INCORPORATED BY REFERENCE. THIS ADDENDUM SUPPLEMENTS FAR 52.212-1.

Failure to comply with any of the instructions may result in the proposal being removed from further consideration.

1. SUBMISSION OF COST OR PRICING DATA.

1.1. It is expected that this contract will be awarded based upon a determination that there is adequate price competition; therefore, the offeror is not required to submit additional cost or pricing data (beyond that required by the solicitation) or to certify cost or pricing data with its proposal.

1.2. If, after receipt of the proposals, the Contracting Officer determines that adequate price competition does not exist in accordance with FAR 15.403-3 and FAR 15.403-4, the offeror shall provide other information requested to be submitted to determine fairness and reasonableness of price, or certified cost or pricing data as requested by the Contracting Officer.

2. PROPOSAL CONTENT AND INSTRUCTIONS FOR PREPARATION OF PROPOSALS

2.1. The instructions provided specify the format and content that Contractors shall use in response to this Request for Proposal (RFP). The intent is not to restrict the Contractors in the manner in which they will perform their work but rather to ensure a certain degree of uniformity in the format of the responses for evaluation purposes. This requirement is a 100% set-aside for small business concerns under NAICS 541611, Administrative Management and General Management Consulting. The size standard for NAICS 541611 is $15 million. Proposals will only be accepted from contractors who are registered in System for Award Management (SAM) under the NAICS code 541611. Contractors must submit a proposal that is legible and comprehensive enough to provide the basis for a sound evaluation by the Government. Information provided should be precise, factual, and complete. Legibility, clarity, completeness, and responsiveness are important. Proposals shall be in the form prescribed by, and shall contain a response to, each of the areas identified in the RFP. Any proposal that does not meet the requirements of the solicitation may be determined to be substantially incomplete and may result in rejection of the contractor’s entire proposal from further consideration.

2.1.1. The Contractor shall include four separate volumes in response to the RFP:

1. Technical

2. Past Performance

3. Business

4. Price

2.1.2. Complete Technical, Past Performance, Business and Pricing volumes shall be received at the same time via one electronic mail (e-mail) to usn.detrick.navmedlogcomftdmd.mbx.research@mail.mil by 1:00 pm local time on 11 April 2016. Any questions regarding this RFP shall also be submitted to this email address. Questions should be presented in writing to NMLC no later than ten (10) calendar days after the issue date of this solicitation. Questions shall be listed chronologically and reference the corresponding solicitation section and paragraph. NMLC’s responses to questions will be presented in the form of an amendment. The source of the questions will not be disclosed.

2.1.3. No hard copies of proposals will be accepted. Please note only 1 e-mail per contractor will be accepted. The e-mailed proposal (to include all four volumes) shall not be larger than 10 megabytes and shall be in Microsoft Office for Windows format (2007), either .docx or .xlsx files, as specified herein. If the e-mail is larger than 10 megabytes, it will not be accepted. Consent letters and forms that require signatures may be submitted as a .pdf file. The contractor is responsible for ensuring that proposals do not contain corrupted files such that they are not readable by the Government.

2.1.4. Each e-mailed proposal shall have the name of the contractor and the RFP number in the subject line. Any requests for hand delivery will not be honored. It is the Contractor’s responsibility to ensure that proposals are received by the due date and time required. The Government will acknowledge receipt of all proposals. If an acknowledgement is not received, it is the Contractor’s responsibility to follow-up with NMLC to guarantee receipt.

2.1.5. The Technical, Past Performance and Business volumes shall be in Microsoft Word for Windows (2007)(.docx), on 8 ½ X 11 inch size, with 1 inch margins all around, Times New Roman font of not less than 10 point font size inclusive of tables, charts, graphs, graphics, etc. Text, tables, charts, graphs, graphics, etc. that are not in compliance will not be considered by the Government in its evaluation. Each page of each document shall have a footer indicating the name of the contractor and “page X of Y.”

2.2. Technical. In accordance with electronic submission requirements given in this section, the contractor shall include the following:

2.2.1. The offeror shall address how its proposed management approach will be beneficial to the Government and how it reduces the risk of unsuccessful contract performance.

2.2.2. The offeror must submit a plan to describe any techniques, methods and actions that will be used by the offeror to mitigate anticipated risks to include 1) provision of Common Access Card (CAC) and security clearance for their contract coders/staff , 2) provision of support for coding backlog- a plan to be able to assist MTFs for government generated backlog and contractor generated backlog and 3) provide strategic plans to mitigate disruption of schedule, increased costs, degradation of performance, the need for increased Government oversight, or the likelihood of unsuccessful contract performance.

2.2.3. The offeror must describe how its specific hypothesis, methodologies, processes, and capabilities reflect their ability to effectively and efficiently manage the task order requirement detailed in the PWS. The offeror must demonstrate that adequate procedures are in place to ensure overall contract performance is achieved at an acceptable quality level. The offeror shall describe its ability to meet the challenges of managing this requirement. The offeror shall describe its management lines of authority and responsibilities and identify the span of control for its managers.

2.2.4. The offeror shall demonstrate in sufficient detail a technical approach that will successfully accomplish the solicitation requirements. The offeror should describe the risks associated with the solicitation requirements and any risks associated with the offeror’s proposed technical approach and should describe any techniques, methods and actions that will be used by the offeror to mitigate the risk(s) identified.

2.2.5. The technical volume shall include a discussion of the methods that will be used by the offeror to recruit and retain qualified, educated personnel with appropriate qualifications/skill levels and knowledge to meet the solicitation requirements. The offeror shall describe the labor mix and number of personnel required for each labor category to fulfill the task order requirements detailed in the PWS.

2.2.6. The offeror shall identify individuals and provide resumes for the primary personnel, who will be considered key personnel. If any proposed personnel are not currently employed with the offeror, the offeror shall submit letters of commitment along with the person’s resume.

2.2.7. The offeror shall provide the measures of employing the key personnel based on the following criteria: competency of proposed personnel in the areas of responsibilities, relevant work experience, and certification in the main program areas by reviewing resumes of the offeror's employees which must be included as part of the proposal. Likewise the offeror shall include the rationale used in the selection of the key personnel considering the benefit, the overall team performance and efficiency.

2.2.8. The offeror shall include a description of activities for timely, effective, and complete management of personnel during the life of the contract.

2.2.9. The offeror shall include a description of activities for timely, effective, and complete start of services to meet the solicitation requirements. The offeror shall describe its approach for tracking the timeliness, accuracy, and quality of deliverables. The offeror shall present a plan to describe its ability to manage the contractors work schedules and meet the challenges to immediately resolve the risk especially the coding backlog issues. The offeror shall provide critical path from award to startup.

2.2.10. In addition to the above evaluation factors, the offeror shall address the following:

2.2.10.1 The offeror shall discuss their understanding of FAR clause 52.222-17 and discussion shall demonstrate proper understanding of the clause.

2.2.10.2. If a subcontractor has been proposed, the contractor shall specifically address FAR 52.219-14, Limitations on Subcontracting; the contractor’s Technical volume shall clearly detail the nature of the relationship between the parties, (i.e. subcontractor, partner, etc.) and shall list the responsibilities of both the offeror and proposed subcontractor. The list shall demonstrate the offeror has the majority of duties and is responsible for overall contract management.

2.2.10.3. If the contractor is proposing as a mentor/protégé or business relationship other than subcontracting, the contractor’s Technical volume shall clearly detail the nature of the relationship between the parties, (i.e. mentor-protégé, joint venture, etc.) and shall address the responsibilities of all parties as they would relate to provision of services under the resultant contract.

2.2.11. The total number of the pages submitted for the Technical volume shall not exceed 15 pages (8 ½ X 11 inch), excluding a title page, table of contents and resumes. If the Technical volume contains more than 15 pages, only the first 15 pages will be evaluated. Cover letters are not required; any information contained in a cover letter will not be evaluated.

2.3. Past Performance. In accordance with electronic submission requirements given in this section, the contractor shall include the following:

2.3.1. The offeror shall complete at least three, but no more than five Past Performance Information Sheets (PPISs) (Attachment 1). Each of the PPISs shall be completed in its entirety. The Past Performance information listed on each sheet shall be for medical coding and auditing services. Each PPIS shall not exceed one page, inclusive of a narrative. If a PPIS contains more than one page, only the first page will be considered. The offeror shall complete Section I of the Past Performance Information Sheet and submit it to the customer Point of Contact (POC) for completion of Section II. The customer POC shall submit the entire completed Past Performance Information Sheet directly to the Contracting Officer via email to usn.detrick.navmedlogcomftdmd.mbx.matrix@mail.mil no later than the closing date and time of the solicitation. The Government will not consider Past Performance Information Sheets submitted after the closing date and time of the solicitation. The Government will provide acknowledgement of the Past Performance Information Sheets; however, evaluation will not occur until after the solicitation closes. Receipt of the Past Performance Information Sheet shall not be mistaken for evaluation. If more than five Past Performance Information sheets are submitted, only the first five Past Performance Information Sheets will be considered. The Government reserves the right to contact the customer POCs for verification or additional information.

2.3.2. For each of the Past Performance Information Sheet submitted the offeror shall describe the objectives achieved detailing how the effort is similar to the requirements of this solicitation (referencing PWS). For any contracts which did not/do not meet the original requirements with regard to original cost, schedule, or technical performance, the offeror shall provide a brief explanation of the reason(s) for such shortcomings and any demonstrated corrective actions taken to avoid recurrence. The offeror shall list each time the delivery schedule was revised and provide an explanation of why the revision was necessary. The offeror shall also provide a copy of any cure notices or show cause letters received on each contract listed and description of any corrective action taken. For any terminated contracts, the offeror shall indicate the type and reasons for the termination.

2.3.3. It is important that the offeror include a statement reflecting an annual account of records coded per type (Outpatient (OP) and Inpatient (IP)).

2.3.4. Each Past Performance Information Sheet may include multiple contracts or orders for the same contractor. Contracts cited must be current, or have ended not more than three years prior to the closing date of the solicitation. If the contract performance ended more than three years prior to the closing date of the solicitation the contract performance will be determined not relevant.

2.3.5. The offeror may submit past performance that demonstrates prior experience of key personnel. The past performance submission shall identify, by name, the key personnel and clearly identify their previous roles and responsibilities and their proposed roles and responsibilities under the resultant contract. The offeror shall discuss how the key personnel’s previous roles and responsibilities will contribute to successful contract operations under the resultant contract. If the submission does not clearly describe the roles and responsibilities of the key personnel and the how the key personnel will contribute to the performance under the resultant contract, it will be determined not relevant.

2.3.6. The offeror may submit past performance that demonstrates prior experience by teaming partners (e.g. proposed subcontractor, partner, mentor, protégé, parent company, sister company, etc.) ONLY if they will be performing in support of the contract resulting from this solicitation. Such past performance submissions shall clearly identify the relationship of the teaming partners to the offeror and the how they will contribute to the performance under the resultant contract. If the submission does not clearly describe the relationship of teaming partners to the offeror and the how the teaming partners will contribute to the performance under the resultant contract, it will be determined not relevant. A maximum of two Past Performance Information Sheets shall be for services provided by entities other than the offeror, members of SBA approved Joint Ventures, and key personnel. If more than two Past Performance Information Sheets are submitted for services provided by entities other than the offeror, members of SBA approved Joint Ventures, and key personnel, only the first two Past Performance Information Sheets will be considered relevant.

2.3.7. If Past Performance is submitted for a contract under which the offeror or teaming partner provided services as a subcontractor, partner, mentor, protégé, parent company, sister company, etc., the Past Performance Information Sheet shall clearly describe the corporate relationships among those who provided the services, citing key responsibilities for each, to include identifying the specific services provided (in terms of numbers and types of personnel, locations, etc) and nature of services provided (e.g., recruitment, payroll, benefits administration, etc). If the submission does not clearly detail the specific responsibilities and relationship under a contract, it will be determined not relevant.

2.3.8. If a teaming partner is proposed, the offeror shall submit written consent from that teaming partner to disclose their Past Performance information to the contractor. If such consent is not provided as part of the submission, the Past Performance of that teaming partner will be determined not relevant. The offeror shall submit the written consent as a separate document with the submission of their Technical, Pricing, and Business Volumes. The written consent shall not be submitted by the customer POC with the submission of the completed Past Performance Information Sheets.

2.3.9. If neither the offeror nor its teaming partner possesses relevant past performance, the offeror shall submit a statement affirming that it possesses no relevant Past Performance. The offeror shall submit the statement affirming that is possesses no relevant Past Performance as a separate document with the submission of their Technical, Pricing, and Business Volumes.

2.3.10. The Government may contact the POCs listed on the Past Performance Information Sheets. POCs shall be either Government personnel (civil service or military) or employees of private sector dental/medical facilities for which the contractor has provided services. Due to a potential conflict of interest, Past Performance Information Sheets that list POCs that work for, or have worked for, the offeror or with a teaming partner(s) directly or indirectly will be determined not relevant.

2.3.11. The total number of the pages submitted for Past Performance shall not exceed 5 pages (8 ½ X 11 inch), (one page for each PPIS), excluding a title page. If the Past Performance volume contains more than 5 pages, only the first 5 pages will be evaluated.

2.4. Business. In accordance with the requirements given in this section, the contractor shall complete the following:

2.4.1. This requirement is 100% set-aside for small businesses. The offeror shall be registered in SAM as a small business under the applicable NAICS code for this solicitation, 541611. The small business size standard is $7.5M. The offeror shall complete and submit FAR 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (OCT 2015) ALTERNATE I (OCT 2014). The offeror shall also complete and submit the SAM Certification Sheet (Attachment 2).

2.4.2. Offeror’s Information Form located in Attachment 3 shall be completed and submitted. Two points of contact shall be provided. Please note that all communication regarding this solicitation and proposals will be directed to the designated contacts on the form.

2.4.3. The offeror shall complete and submit DFARS clause 252.209-7991 (Attachment 4) REPRESENTATION BY CORPORATIONS REGARDING AN UNPAID DELINQUENT TAX LIABILITY OR A FELONY CONVICTION UNDER ANY FEDERAL LAW—FISCAL YEAR 2016 APPROPRIATIONS (DEVIATION 2016-O0002) (OCT 2015)

2.5. Pricing. The offeror shall provide a complete and detailed price proposal to perform the prospective contract successfully. The offeror’s price proposal shall support the offeror’s technical proposal. The contractor shall consider the information provided in the PWS included in this RFP in the development of its price. Proposed prices should be inclusive of any discounts provided. Pricing shall be valid for a period of 180 days.

2.5.1. Pricing for this solicitation represents initial quantities and two option years. All quantities are divided into lots. Lots for this requirement are outlined in the Addendum to 52.212-1 Enclosures 1-27. Pricing for travel is not required as it will be reimbursed in accordance with the Joint Travel Regulations.

2.5.2. The information contained in Addendum to 52.212-1 Enclosures 1-27 is provided to assist in the development of pricing for the CLINs. These enclosures shall not be submitted with the offeror’s pricing proposal; they are for informational purposes only. Pricing shall be completed in accordance with this section.

2.5.3. Offerors shall propose on all Lots provided in the Pricing Workbook provided with the solicitation.

2.5.4. All pricing information shall be completed in the Pricing Workbook.

2.5.5. The pricing workbook shall be submitted as the Price portion of the proposal.

3.0 Miscellaneous

3.1. Contractors shall not contact any incumbent workers during their official duty hours.

3.2. In accordance with the Naval Marine Corps Acquisition Regulation Supplement (NMCARS) 5232.903, for Prompt Payment Act purposes, contracts will be subject to the 7 calendar day constructive acceptance period.

3.3. Performance under the resulting contract is to begin on 01 September 2016 and go through 31 August 2019, if all options are exercised. It is to continue services currently being provided under contracts N62645-15-D-5044 with Caban Resources, LLC, N62645-15-D-5045 with Peak Government Services, Inc., and N62645-15-D-5046 with Diamond Solutions, Inc.

3.4. In accordance with FAR 52.232-18, funds are not presently available for the resulting contracts. The Government’s obligation under this solicitation is contingent upon the availability of appropriated funds from which payment for performance can be made. No legal liability on the part of the Government for any payment may arise until funds are made available to the Contracting Officer for the resulting contracts and until the Contractor receives notice of such availability, to be confirmed in writing by the Contracting Officer via the award of a task order.

3.5. Business to Business (B2B) Gateway

3.5.1. All Department of the Navy (DON) information systems as defined in Department of Defense Directive (DoDD) 8500.1 shall be certified and accredited (C&A) for operation. C&A is attained via the Defense Information Assurance Certification and Accreditation Process (DIACAP) and is applicable to all DON- owned or controlled information systems that receive, process, store, display or transmit Department of Defense (DoD) information, regardless of Mission Assurance Category (MAC) classification or sensitivity, except, per DoDD 8500.1 Paragraph 2.3; IT that is considered Platform Information Technology (PIT). Regardless of whether the system or device is considered PIT or whether it is determined that it requires a full accreditation, the following DIACAP artifacts shall be included with your proposal; System Identification Profile (SIP), DIACAP Implementation Plan (DIP), and Plan of Actions and Milestones (POA&M). A template has been included with this solicitation as B2B Attachment 6, MDS2F Form and Instructions. Completion of this form in its entirety will satisfy the requirement for the SIP, DIP and POA&M.

3.5.1.2. Navy PIT Designation

3.5.1.2.1. Certain medical technologies may be designated as PIT by the Navy Operational Designated Accrediting Authority (ODAA); however the PIT designation itself does not constitute an Approval to Operate (ATO). The PIT system will require a PIT Risk Analysis (PRA). The DIACAP SIP, DIP, POA&M and Risk Analysis documents are required in order to complete a PRA. Contractors will be required to scan the PIT system for vulnerabilities prior to delivery.

3.5.1.2.1.1. According to DoDD 85001, Paragraph E2.1.16.4; PIT refers to computer resources, both hardware and software, that are physically part of, dedicated to, or essential in real time to the mission performance of special-purpose systems. Medical technologies, and specifically medical imaging and monitoring systems are considered special-purpose mission technologies according to this definition.

3.5.1.2.1.2. The PIT designation issued by the ODAA may be used by the Program Manager (PM) to complete a PRA in order to prove compliance with C&A requirements, but is cautioned that the appropriate IA controls must still be built into the IT to comply with acquisition requirements. The contractor shall work with Navy Program Managers to ensure their systems meet these requirements.

3.5.1.3. The contractor shall establish appropriate administrative, technical, and physical safeguards to protect all government data, to ensure the confidentiality, integrity, and availability of government data under their control. At a minimum, this shall include provisions for personnel, electronic, and physical security.

3.5.1.4. The contractor shall propose an acceptable approach to selecting Information Awareness (I/A) controls starting from the baseline set on DoD Instruction 8500.2 B, commensurate with the system’s Mission Assurance Category (MAC) and Confidentiality Level. For medical systems, the MAC level assigned is typically MAC III sensitive.

3.5.2. The contractor shall comply with DIACAP requirements as specified by the DoD that meet appropriate DoD and Navy IA requirements. The contractor shall initiate the process by providing the required documentation necessary to receive an ATO. The contractor shall make their device or system delivered against this contract available for C&A testing and initiates the process well in advance of a contract delivery order. The requirements shall be met before the contractor's system is authorized to access DoD data or interconnect with any DoD network that receives, processes, stores, displays or transmits DoD data. An ATO, at a minimum, will be required before a device or system is installed. The contractor shall ensure that the proper contractor support staff is available to participate in all phases of the DIACAP process. They include but are not limited to;

3.5.2.1. Completing and maintaining all documentation necessary to obtain an ATO.

3.5.2.2. Attending and supporting DIACAP and C&A meetings with Navy IA representatives.

3.5.2.3. Supporting/conducting the vulnerability mitigation process to comply with IA controls listed in DoD Instruction 8500.2.

3.5.2.3. Supporting the C&A Team during system security testing.

3.5.2.4. Contractors must confirm that their systems are locked down prior to initiating C&A testing.

3.5.3. Post-Accreditation Review

An annual IA review shall be conducted that comprehensively evaluates existing policies and processes to ensure procedural consistency and that the IS continues to operate in the manner to which it was accredited. The annual review process should account for the analysis of projected policy needs, and produce a plan for development or implementation of new policies or processes.

3.5.4. Personnel Security and User Access Control

3.5.4.1. The contractor shall comply with DoDD 8500.1, “Information Assurance (IA)”, DoD Instruction (DODI)

8500.2 “Information Assurance (IA) Implementation”, DoDD 5400.11, “DoD Privacy Program”, DoD

6025.18-R, DoD Health Information Privacy Regulation and DoD 5200.2-R, “Personnel Security Program Requirements”. Contractor responsibilities for ensuring personnel security include, but are not limited to meeting the following requirements:

Follow the Privacy Office guidelines for submittal of IT security clearances and ensure all contractor personnel are designated as IT-I, IT-II or IT-III where their duties meet the criteria of the position sensitivity designations.

3.5.4.2. Because of the unique circumstances presented by DoD and DON networks, personnel security requirements shall be followed to ensure appropriate precautions are taken prior to allowing vendor personnel access to the network. Any vendor personnel that will be accessing the medical device/system while installed on the hospital network will be required to have a National Agency Check (NAC) completed. Typically, this requires an investigation to support a “Public Trust Position” and requires the person(s) to complete and submit a Standard Form 85P (SF85P), Questionnaire for Public Trust Positions, via the Electronic Personnel Security Questionnaire (EPSQ). Questions relating to SF85Ps and the EPSQ process may be directed to 1-888-282-7682 or online at http://www.dss.mil/index.htm. Contractor personnel accessing equipment connected to the hospital network will be required to complete a System Authorization Access Request-Navy (SAAR-N) (form OPNAV 5239/14). Copies of this form can be obtained from the Navy PACS Office. Additionally, contractor personnel are required to complete the annual DoD IA training requirements.

3.5.4.3. The contractor shall initiate, maintain and document personnel security investigations appropriate to the individual’s responsibilities and required access to Sensitive Information (SI).

3.5.4.4. Immediately report to the appropriate Navy POC and deny access to any automated information system (AIS), network, or information if a contractor employee filling a sensitive position receives an unfavorable adjudication, if information that would result in an unfavorable adjudication becomes available, or if directed to do so by the appropriate Navy representative for security reasons.

3.5.4.5. Ensure that all contractor personnel receive IA training before being granted access to DoD AIS’s.

3.5.4.6. Access to the medical devices will be limited to authorized users as determined by local policy. Vendors whose systems do not yet meet the requirement for CAC authentication must indicate their willingness to do so, and offer a timeline for compliance.

3.6. Operating Systems

To ensure that medical systems attain data confidentiality, integrity, and availability levels consistent with best industry practices, the use of current Operating Systems (OS) is highly recommended. Preference shall be given to systems that employ modern operating systems, including closed source, open source, or proprietary. Medical systems will employ whenever possible, operating systems that are fully supported by the manufacturer and are commercially available.

3.7. Domain Name System Realm/Directory Services

Contractor will be required to demonstrate, if applicable whether client/server topology based medical systems can integrate with Directory Services and support LDAP authentication.

3.8 Local Privileged and Administrative User/Local System Accounts

3.8.1. Contractor shall create a single local user account with administrative/root level privileges for purposes of conducting system repairs and maintenance only. This account shall be separate and distinct from the built-in local administrative/root account provided by the Operating System and shall comply with DoD policy. All factors required to complete successful identification, authentication and authorization against the built-in local Administrative/Root level account shall be provided to the Medical Treatment Facility (MTF) Biomedical Engineering Department. In addition, the MTF will be provided with access and instructions on how to change IP addresses, host names/AE titles, etc.

3.8.2. Complete administrative system rights shall be provided to the government System Administrator for the purpose of conducting device vulnerability scans as needed.

3.9. Antimalware

3.9.1. Medical systems that make use of a file system under direct control of an operating system instance whether physical and/or virtual shall provide the appropriate antimalware safeguards consistent with current security practices. Exemption from this requirement is applicable to medical systems which make use of a proprietary file system and/or operating system for which no commercially available antimalware application exists. This exemption should be documented in the C&A Initial Technical Questionnaire.

3.9.2. Preference may be given to medical systems capable of supporting antimalware applications, within tolerable specifications, that support the use of DISA approved McAfee, and/or Symantec solutions. Systems shall be configured as to allow for the update of malware definition signatures on a scheduled basis. Scanning shall encompass the entire system (file system, operating system, real-time processes), by default. In cases where the scanning of the entire system may negatively affect the operation of the system, the Contractor shall provide a detailed list of exclusions with justifications as part of the C&A Initial Technical Questionnaire.

3.10. Malware Handling and Threat Detection

The contractor shall monitor systems for malware incidents, such as viruses, spyware, and adware and prepare incident reports to include the location of the malware, severity, and course of action taken for cleanup. In cases where complete malware removal cannot be achieved, the Contractor shall re-image the system to support cleanup efforts. The contractor will provide the Government with full access to the antimalware application logs.

3.11. Navy Business to Business (B2B) Gateway

3.11.1. All contractor systems that will communicate with DON systems will interconnect through the established Military Health System (MHS) Business to Business (B2B) gateway. For all Web applications, contractors will connect to the DISA-established Web DMZ.

3.11.1.1. The Contractor shall connect to the B2B gateway via a contractor procured Internet Service Provider (ISP) connection and assume all responsibilities for establishing and maintaining their connectivity to the B2B gateway. This will include acquiring and maintaining the circuit to the B2B gateway and acquiring a FIPS-140-2 Virtual Private Network (VPN)/Firewall device compatible with the MHS VPN device. Maintenance and repair of contractor procured VPN equipment shall be the responsibility of the contractor.

3.11.1.1.2. The Contractor shall configure their network to support access to government systems (e.g., configure ports and protocols for access).

3.11.1.1.3. The Contractor shall provide full time connections to a TIER1 or TIER2 ISP. Dial-up ISP connections are not acceptable.

3.11.1.1.4. The Contractor shall comply with DoD guidance regarding allowable ports, protocols and risk mitigation strategies.

3.12. Prior to accessing DON networks, all contractors shall complete a DD Form 2875 System Authorization Access Request (SAAR), included as B2B Attachment 3, and submit to NMLC, Code 03, Imaging Informatics Division for processing. The contractor shall complete applicable DoD IA training.

3.13. IPv6

The proposed system shall be Internet Protocol version 6 (IPv6) capable or the vendor must provide a detailed project, migration or planning documentation to show when the proposed system shall be IPv6 capable.

3.13.1. Minimum IPv6 capabilities include:

3.1.13.1.1. Conformant with the IPv6 standards profile contained in the DoD IT Standards Registry

(DISR);

3.1.13.1.2. Maintaining interoperability in heterogeneous environments with IPv4;

3.1.13.1.3. Commitment to upgrade as the IPv6 standard evolves;

3.1.13.1.4. Availability of vendor IPv6 technical support.

3.14. The contractor must be able to demonstrate or provide documentation to prove that their product is IPv6 capable. As described in the DISR IPv6 standards profile, application vendors are expected to scan and test their code for IPv6 compliance and provide a letter of compliance indicating to what degree they comply. The letter shall be in vendor format and describe the standards used for testing and the results of the scans. IPv6 'capable' is defined as having the capability of receiving, processing and forwarding IPv6 packets and/or interfacing with other IPv6 capable systems/devices and in a manner similar to IPv4. In order to demonstrate IPv6 compliance, the vendor should submit the following documentation:

3.14.1. Provide a diagram showing IPv6 core configuration, to include IPv6 addressing, internal network connectivity and topology, external network connectivity, and IPv6 traffic flow;

3.14.2. Submit a list of core components to include vendor/manufacturer IPv6 compliance;

3.14.3. Submit a report that illustrates testing of IPv6 compliance, to include test scripting, logs and results.

3.15. Information Assurance Vulnerability Management (IAVM)

3.15.1. IAVM is focused on maintaining a secure platform as new vulnerabilities and exploits are discovered and released through various software developers and security agencies. The core tool of successful IAVM is the Information Assurance Vulnerability Alert (IAVA). The DoD releases IAVAs for local action on the various platforms across the enterprise network. Each Navy Healthcare Facility is responsible for managing their local network. Most DoD IAVAs originate from a real world event such as a patch release or vulnerability notification from a software vendor (e.g. Windows or Sun patch release), or a US-CERT released from the CERT Coordination Center at Carnegie Mellon University. To have an effective IAVM program, vendors must be proactive in monitoring emerging threats. Some recommended sources for IAVM support are:

3.15.1.1. General Vulnerability alerts, all platforms: http://www.cert.org/nav/index_red.html

3.15.1.2. Microsoft security resources: http://www.microsoft.com/technet/security/bulletin/notify.mspx

3.15.1.3. SUN Microsystems Security resources: http://sunsolve.sun.com/pub- cgi/show.pl?target=security/sec

3.15.2. As part of the IAVM program, the contractor shall provide a primary and secondary point of contact for compliance actions. The point of contact shall provide, upon receipt of a vulnerability message, an acknowledgement of that receipt. The vendor shall thoroughly test all mitigations for the vulnerability, and upon applying the mitigation to the system, report compliance. Receipt and compliance messages shall occur within the stipulated time window, as stated in the vulnerability message or other official notification.

3.15.3. Any vendor interested in meeting this requirement shall have a documented process to demonstrate an organizational culture embracing security throughout the system lifecycle. The processes shall clearly demonstrate security’s role in the product development phase, and the processes the vendor employs to react to vulnerabilities, validate required patches, communicate status and required actions to their customers, and the follow up service support to address patch implementation.

3.16. Health Insurance Portability and Accountability Act (HIPAA)

The contractor shall comply with the HIPAA Act of 1996 (Public Law 104-191) requirements, specifically the administrative simplification provision s of the law and the associated rules and regulations published by the Secretary, Health and Human Services (HHS). This includes the Standards for Electronic Transactions, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards.

3.17. Additional Attachments

3.17.1. B2B Attachment 1 contains a list of approved products available in the commercial marketplace that are compatible with a B2B with NMLC.

3.17.2. B2B Attachment 2 is a form for vendors to complete when requesting a B2B with NMLC.

3.17.3. B2B Attachment 3 is a blank DD 2875, System Authorization Access Form.

3.17.4. B2B Attachment 4 is a B2B Implementation Briefing for additional information regarding setting up a B2B.

3.17.5. B2B Attachment 5 is a Tricare Manual. Within this manual, sections that are highlighted represent B2B requirements.

3.17.6. B2B Attachment 6 is the Manufacturer Disclosure Statement for Medical Device Security. This form must be completed in its entirety before a B2B can be implemented.

List of B2B Attachments:

B2B Attachment 1--Juniper Networks - Product Listings

B2B Attachment 2--NMLC - Vendor Business to Business (B2B) Information Request Form

B2B Attachment 3--DD2875-System Authorization Access Form

B2B Attachment 4--B2B Implementation Briefing 2013

B2B Attachment 5--Tricare Manual (with B2B requirements highlighted)

B2B Attachment 6--MDS2 Form and Instructions List of Enclosures to FAR 52.212-1 Addendum:

FAR 52.212-1 Addendum Enclosure 1 – Lot A Performance Work Statement

FAR 52.212-1 Addendum Enclosure 2 – Lot B Performance Work Statement

FAR 52.212-1 Addendum Enclosure 3 – Lot C Performance Work Statement

FAR 52.212-1 Addendum Enclosure 4 – Lot D Performance Work Statement

FAR 52.212-1 Addendum Enclosure 5 – Lot E Performance Work Statement

FAR 52.212-1 Addendum Enclosure 6 – Lot F Performance Work Statement

FAR 52.212-1 Addendum Enclosure 7 – Lot G Performance Work Statement

FAR 52.212-1 Addendum Enclosure 8 – Lot H Performance Work Statement

FAR 52.212-1 Addendum Enclosure 9 – Lot I Performance Work Statement (End of Summary of Changes)

File details come from the government source that posted it. Updated .