About this file

Amendment 01 to N62645-19-Q-0031

View the file

Other files for this federal contract opportunity

Other files attached to Medical Logistics Authoritative Data Exchange and Medical Logistics Database Subscriptions, newest first.
File Type Posted
Redacted_J&A.pdf PDF
Pricing_Workbook__for_N664519Q0031.xlsx XLSX spreadsheet
N62645-19-Q-0031.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

N6264519Q0031

SECTION SF 30 BLOCK 14 CONTINUATION PAGE

SUMMARY OF CHANGES

SECTION SF 1449 - CONTINUATION SHEET

The following have been modified:

STATEMENT OF WORK

Statement of Work Medical Logistics Authoritative Data Exchange and Medical Logistics Database Subscriptions

PART 1

1.0 DEFINITIONS & ACRONYMS

1.1 Definitions:

1.1.1 Availability: Ensuring timely and reliable access to and use of information. Timely, reliable access to data and information services for authorized users.

1.1.2 Confidentiality: Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.

1.1.3 Contracting Officer (KO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

1.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the KO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

1.1.5 External IT services: IT services that are outside the user organization’s Service authorization boundary and the user’s Service has no direct control over the application or assessment of required security controls. DoD organizations that use IT services are typically not responsible for authorizing them (i.e., issue an authorization decision), reference (DoDI 8510.01 p. 13). DoD organizations that use external IT services provided by a non-DoD Federal Government agency must ensure the categorization of the IS is appropriate to the confidentiality, integrity, and availability needs of the information and mission, and that the IS is operating under a current authorization from that agency. In accordance with DoD Instruction 8500.01, “Cybersecurity,” March 14, 2014, interagency agreements or Government statements of work for these external services must contain requirements for service level agreements (SLAs) that include the application of appropriate security controls.

1.1.6 Integrity: Guarding against improper information modification or destruction, inclusive of ensuring information non-repudiation and authenticity.

1.1.7 National Security Information: Information that has been determined pursuant to Executive Order 12958, as amended by Executive Order 13292 or any predecessor order, or by the Atomic Energy Act of 1954 as amended, to require protection against unauthorized disclosure and is marked to indicate its Classified status.

1.1.8 National Security System: Any information system (including any telecommunications system) used by or operated by an agency, or by a Contractor of an agency, or another organization on behalf of an agency having the function, operation, or use of which (i)involves intelligence activities; (ii) involves cryptologic activities related to national security; (iii) involves command and control of military forces; (iv) involves equipment that is an integral part of a weapon or weapons system; or (v) is critical to the direct fulfillment of military or intelligence missions (excluding a system that is to be used for routine administrative and business applications, for example, payroll, finance, logistics, and personnel management applications).

1.1.9 Non-personal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.

1.1.10 System Security Plan (SSP): Formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements. (Reference: NIST Special Publication 800-18, Revision 1)

1.1.11 Quality Assurance Surveillance Plan (QASP): An organized, written document specifying the surveillance methodology to be used for surveillance of Contractor performance. The Government may either prepare the QASP or require the offerors to submit a proposed QASP for the Government’s consideration in development of the Government’s plan.

1.1.12 Technical Liaison (TL): The individual designated and authorized in writing by the KO to assist the COR in performing specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

1.2 Acronyms:

ATOAuthority to Operate
B2BBusiness to Business
CCBConfiguration Control Board
CJCSMChairman of the Joint Chiefs of Staff Manual
CNSSCommittee on National Security Systems
CORContracting Officer’s Representative
COTRContracting Officer's Technical Representative
CUIControlled Unclassified Information
DMLSSDefense Medical Logistics Standard Support
DML-ESDefense Medical Logistics – Enterprise Solution
DHADefense Health Agency
DHACDefense Health Agency Component
DISADefense Information Systems Agency
DoDDepartment of Defense
DoDIDepartment of Defense Instruction
DoDINDepartment of Defense Information Network
FARFederal Acquisition Regulation
HARHazard, Alerts and Recalls
IAInformation Assurance
ISInformation System
KOContracting Officer
MMQCMedical Materiel Quality Control
NDANon-Disclosure Agreement
NISTNational Institute of Standards and Technology
NSSNational Security System
PKPublic Key
PKIPublic Key Infrastructure
POA&MPlan of Action and Milestones
POCPoint of Contact
PoPPeriod of Performance
PPSPorts, Protocols, and Services
PPSMPorts, Protocols, and Services Management
PRSPerformance Requirements Summary
SOWStatement of work
QASPQuality Assurance Surveillance Plan
QCQuality Control
RMFRisk Management Framework
SARSecurity Assessment Report
SPSpecial Publication
SRGSecurity Requirements Guide(s)
SSPSystem Security Plan
STIGSecurity Technical Implementation Guide(s)
TEWLSTheater Enterprise-Wide Logistics System
TLTechnical Liaison
UMDNSUniversal Medical Device Nomenclature System
VPNVirtual Private Network

PART 2

2.0 GENERAL INFORMATION

2.1 This contract is to provide a Medical Logistics Authoritative Data Exchange and Medical Logistics Database Subscriptions.

2.2 Description of requirement: The Contractor shall provide a Medical Logistics Authoritative Data Exchange and Medical Logistics Database Subscription as defined in this Statement of Work (SOW), except for those items specified as Government furnished property and services. Immediately upon award, the Contractor shall be able to strictly adhere to the standards within this Statement of work (SOW).

2.3 Background:

2.3.1 The intent of this requirement is to support the Congressional guidance set forth in Title VII of the National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2017, as amended by the NDAAs for FY 2018 and 2019, that seeks to eliminate separate silos of military health and to integrate military healthcare under the authority, direction, and control (ADC) of the Defense Health Agency (DHA), consistent with the direction provided by the Secretary of Defense. The DHA Medical Logistics Division supports the DHA's Implementation Plan for transitioning the ADC of the military medical treatment facilities (MTFs) from the Services’ medical departments to the DHA beginning on 1 October 2019.

2.3.2 The Department of Defense (DoD) medical logistics community supports diverse lines of business (LOBs), to include: equipment property and biomedical maintenance management; pharmaceuticals and medical surgical inventory management; purchasing and quality assurance; and, assemblage and facilities management. The primary Information Systems (IS) supporting these LOBs are the Defense Medical Logistics Standard Support (DMLSS) system and the Theater Enterprise-Wide Logistics System (TEWLS). Over the last twenty (20) years, these two (2) systems have inherited as-built data from a number of Army, Navy and Air Force logistics and property legacy applications. As a result of these historical data merges, the two (2) aforementioned systems contain data variances and data diversion. The lack of authoritative source data has impeded effective decision analysis and constrained optimized business processes.

2.3.3 The Defense Health Agency (DHA) and Joint Medical Logistics Development Center (JMLFDC) have initiated a major technical refresh that will merge both the programmatic and technical components of all existing Defense Medical Logistics applications [DMLSS, TEWLS and Joint Medical Asset Repository (JMAR)] into a single program, the Defense Medical Logistics – Enterprise Solution (DML-ES) and a single application called LogiCole.

2.4 Objectives: Using industry standard data, the objective is to normalize, cleanse and structure an authoritative equipment and supply data standardization mapping process, allowing for enhanced audit readiness, increased business process effectiveness in new procurement standardization and existing product recall identification, and management of unnecessary data duplication.

2.5 Scope: To create an authoritative data exchange and database subscription service that support modernization and data standardization in Health Alerts and Equipment Management LOBs. The authoritative data exchange and database subscription services will be Information Technology (IT) services, external to the DoD. The IT services are not National Security Systems (NSS) and will neither interconnect with a NSS nor transmit National Security information. Specific subscriptions required will have the potential to fluctuate over time, based on the dynamic nature of the Government’s various LOBs and their respective accountable Government property and personnel changes. However, the aggregate requirement and level of effort will remain relatively constant over the life of the contract. Any changes will be executed through an official contract modification with approval signature by the Contracting Officer (KO).

2.5.1 The contract will establish terms and conditions, consistent with any trust relationship established with organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to access the information system from external information systems and process, store, or transmit organization-controlled information using external information systems.

2.6 Administrative Specifications

2.6.1 The list of locations the contractor will be providing subscription services is identified in Technical Exhibit 1.

2.6.2 Technical Liaisons are identified in Attachment 1.

2.6.3 The Contractor Point of Contact (POC): The Contractor shall provide, in writing, the name and telephone number of a primary and alternate, English-speaking, individual to act as their representative. The Contractor shall provide, in writing, an escalation process to follow if neither the primary nor alternate Contractor representatives can be reached. This escalation process shall also be usable in instances when neither the primary representative, the alternate representative, nor the Contractor personnel can effectively meet specific contractual deliverables.

2.6.3.1 Response time: Within two (2) hours of notification by the Government, the Contractor shall respond by telephone.

2.6.4 Modifications to Contract: Only the Contracting Officer has the authority to obligate the Government, and then only in writing. No modification or instruction from any party shall be construed to authorize the Contractor to take any action for which they expect compensation without written authorization from the Contracting Officer.

2.6.5 Compliance with Applicable Laws: Contractor shall be knowledgeable of and comply with all applicable Federal, State, and local laws, regulations, and requirements regarding the conduct of business.

2.6.6 Work Performed by Others: When work performed by the Government or other Contractors is expected to affect the Contractor’s performance of work, the Government shall coordinate with the Contractor and provide necessary information (plans, specifications, etc.) for such work to the Contractor that will allow the Contractor potential for scheduling allowances. The TLs shall resolve any schedule conflicts between the Contractor and work performed by the Government or other Contractors. Such actions shall not result in additional cost to the Government under this contract.

2.6.7 The Contractor shall use teleconferencing and web conferencing to facilitate communications, when required, to complete the associated tasks. The Government reserves the right to schedule meetings to discuss or resolve issues/problems, as it deems to be critical, at no additional cost to the Government.

2.6.8 Upon award and at time of any future request by the TLs, the Contractor will provide continuing education training to DoD personnel for the purpose of showing the full extent of all functions and features of the provided subscription services. This training can be conducted via Defense Connect Services (DCS), pre-recorded video tutorials accessible on an online portal, and/or in-person training.

2.6.9 Technical documentation and software: The Contractor shall obtain, have on file, and make available to its personnel all operational and technical documentation, which is required to meet the performance requirements of this Contract. This documentation shall include any software needed for, or beneficial in, completion of the deliverables within this SOW. The Contractor shall ensure that they are in possession of legally-licensed software necessary for rapid, efficient, and effective performance.

2.7 Security:

2.7.1 The Contractor shall not have access to nor require access to protected health information (PHI) or personally identifiable information (PII) in order to provide the services described herein.

2.7.2 Medical Logistics Authoritative Data Exchange Service Cybersecurity Requirements - Responsibilities of the Parties: When the Contractor or external service providers require(s) remote networking connections from non-Government IT equipment to DoD IT equipment, whether via server to server (S2S) or client to server (C2S) model, the only approved access shall be through a DHA Business to Business (B2B) gateway, allowing for the safe processing, storing, or transmitting of DoD data. External service providers shall document and enforce security controls (PS-3) in accordance with the ECRI System Security Plan (Deliverable 1 in section 1.10.2.6).

2.7.2.1 DHA responsibilities:

2.7.2.1.1 Ensure all hosts that encompass the complete authoritative data exchange service system, whether physical and/or virtual, maintain an acceptable security baseline consistent with DoD cybersecurity requirements. This includes the timely implementation of cybersecurity countermeasures to address both well-known and emerging vulnerabilities affecting the system. Mitigation and remediation actions shall be carried out in response to Information Assurance Vulnerability Alerts (IAVA) and manufacturers’ information security best practices.

2.7.2.1.2 Attain a Risk Management Framework (RMF) Authorization to Operate (ATO) that encompasses all components of the authoritative data exchange service system as defined in the authorization boundary. The System Owner (SO) will ensure that the system is issued a DHA RMF “Type” (and not Site) Authorization, which allows the system to be installed and operate within any Unclassified DoD enclave, unless the ATO specifically states applicability for use within Classified enclaves.

2.7.2.1.3 For the authoritative data exchange service system, comply and adhere to Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) requirements for DoD-owned Information Systems (located at https://public.cyber.mil/stigs/http://iase.disa.mil/stigs/a-z.html).

2.7.2.2 Contractor responsibilities:

2.7.2.2.1 Contractor shall immediately notify designated points of contact (POCs) by telephone or e-mail in the event of a security incident.

2.7.2.2.2 Contractor technical staff shall immediately notify designated POCs by telephone or e-mail in the event of a disaster or other contingency that disrupts the normal operation of the interface, which is dependent on the Contractor.

2.7.2.2.3 Both Government and Contractor shall notify each other when POCs change because of separation, long term absence, or role change.

2.7.2.2.4 Contractor shall notify designated POCs of impending changes to the authoritative data exchange service system configuration (30 calendar days in advance) or changes to the data exchange (60 calendar days in advance) as are detailed in this statement of work, deliverables, attachments, and cited supporting documents. Attachment 1 lists JMLFDC’s POCs.

2.7.2.2.5 Contractor shall notify designated POCs at least one (1) month before it connects its ECRI Hazards, Alerts and Recalls (HAR) system with any other IT system, including systems that are owned and/or operated by third parties.

2.7.2.2.6 See Attachment 1 for Points of Contact (POCs) designated for purposes identified in this statement of work.

2.7.2.3 Both parties agree to abide by the security agreements specified. Both parties certify that their respective system is designed, managed, and operated in compliance with all relevant Federal laws, regulations, and policies.

2.7.2.4 General Cybersecurity requirements – Information Systems. The Contractor shall comply with the following publications:

2.7.2.4.1 - DoDI 8582.01, "Security of Unclassified DoD Information on Non-DoD Information Systems"

2.7.2.4.2 - DoDI 8500.01, “Cybersecurity,” March 14, 2014

2.7.2.4.3 - National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, “Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach”

2.7.2.4.4 - NIST SP 53a, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans”

2.7.2.4.5 - NIST SP 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems”

2.7.2.5 The Contractor shall identify the security controls in accordance with Committee on National Security Systems (CNSS) Instruction No. 1253, “Security Categorization and Control Selection for National Security Systems”, as outlined within NIST SP 800-171, based on the categorization of confidentiality, availability and integrity of the information type and IT provided by the Government. The Government has aligned the requested services with NIST SP 800-60 Volume II, Sections C.3.1.1, “Facilities, Fleet and Equipment Management and Supply Chain Management” and C.3.4.3, “Logistics Management Information Type”, with respective security categories of Confidentiality =Low, Integrity = Low, and Availability = Low.

2.7.2.6 The Contractor shall tailor appropriately to determine the set of security controls necessary for the subscriptions requested. The Contractor shall identify the security approach, methodology and provide verification in the form of a System Security Plan (SSP) (DELIVERABLE 1). The Government will assess the adequacy of security proposed by potential service providers, accept the proposed approach, and/or negotiate changes to the approach to meet DoD needs. The Contractor shall submit the initial SSP no later than 30 calendar days after contract award. Thereafter, the Contractor shall submit the SSP annually or if there are significant security changes to/for the ECRI/LogiCole interface.

2.7.2.7 The Contractor shall provide a response to the Government’s Security Assessment Report (SAR) of the SSP by providing evidence of the stated security plan control implementations and the Plan of Action & Milestones (POA&M) to become compliant with the applicable NIST 800-171 security controls (DELIVERABLE 2) for compliance of testing Information Assurance (IA) controls. The Contractor shall submit the initial SAR no later than 30 calendar days after contract award and then annually thereafter.

2.7.2.8 The Contractor shall provide to the Government, a SSP (DELIVERABLE 1) and any associated POA&Ms developed to satisfy the adequate security requirements of Department of Defense Federal Acquisition Regulations (DFARS) 252.204-702, and in accordance with NIST Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” at the time the solicitation is issued or as required by the Contracting Officer, to describe the Contractor’s unclassified information system(s)/network(s) where covered DoD information, associated with the execution and performance of this contract, is processed, is stored, or is transmitted.

2.7.2.9 Contractor shall, upon request, provide the Government with access to the SSP, extracts and/or any associated POA&Ms for each of the Contractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s) and for the subcontractor(s)’ tier one level subcontractor(s), vendor(s), and or supplier(s), those who process, store, or transmit covered DoD information associated with the execution and performance of this contract.

2.7.2.10 The Contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37, “Risk Management Framework (RMF)” and NIST SP-171 revision 1, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”

2.7.2.11 The Contractor shall ensure that the IS conforms to the requirements of DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”. The Contractor shall conform to the Government B2B Gateway requirements for Ports, Protocols, and Services (PPS) implementation, to guarantee the ability to securely communicate across Department of Defense Information Network (DoDIN) and to limit PPS used to conduct official business or required to address quality of life issues authorized by competent authority. To comply with DoD Directive (DoDD) 5530.3 (Reference (i)), PPS to be used in DoDIN connections with mission partners will be documented in this contract.

2.7.2.12 The Contractor shall reference RMF Knowledge Service (KS), located at https://rmfks.osd.mil/rmf/Pages/default.aspx and/or https://public.cyber.mil/, to access information on:

2.7.2.12.1 An unclassified on-line, web-based, and machine-to-machine interfaced authoritative source for current Ports, Protocols, and Services Management (PPSM) policies and procedures, allowing for a uniform application of PPSM standards and implementation strategies developed and distributed by the PPSM Configuration Control Board (CCB) for PPS used within DoD IT.

2.7.2.12.2 Data storage and retrieval, federation of relevant information from appropriate DoD Component RMF repositories, automated assessments and compliance verifications, summary reporting, and similar capabilities which support the discovery and analysis methodology.

2.7.2.12.3 A mechanism for the DoD cybersecurity community to post and share PPSM practical solutions and documents with other DoD community and mission partners.

2.7.2.13 The Contractor shall ensure that the authoritative data exchange service authenticates all entities as specified in DoDI 8520.03, “Identity Authentication for Information Systems” prior to granting access to the aforementioned entities.

2.7.2.14 The Contractor shall Public Key enable the authoritative data exchange, implementing digital signature and encryption requirements as specified in DoDI 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK) Enabling”, dated May 24, 2011. DoD mission partners shall use certificates issued by the DoD External Certification Authority (ECA) program or a DoD-approved PKI, when interacting with the DoD in unclassified domains. DoD ECA PKI and External PKI certificates are not used in the DoD classified domain. All DoD web servers shall require a DoD-approved certificate to initiate Secure Socket Layer/Transport Layer (SSL/TLS) server authentication, support data integrity, and maintain confidentiality as necessary to meet the sensitivity level requirements of the information stored on the respective web servers. (Reference: http://www.dtic.mil/whs/directives/corres/pdf/852002p.pdf)

2.7.2.15 The Contractor shall be responsible for patch management of the technologies for the ECRI HAR information system portion of the ECRI/LogiCole interface. The Contractor shall implement patches within thirty (30) calendar days from publication and/or notification of available patches for the ECRI HAR system’s technologies.

2.7.2.16 The Contractor shall implement system level protection and detection capabilities, those that are consistent with its contract, for NIST Security requirements that meet DoD and DHA Cybersecurity Architectures.

2.7.2.17 The Contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.

2.7.2.18 Risk Management Framework for DoD IT: The Contractor shall comply with DoDI 8510.01. The Contractor shall ensure the security protections of the authoritative data exchange service system are appropriate to the confidentiality, integrity, and availability needs of the DoD organization's information and mission.

2.7.2.19 Vulnerability Scanning. The Contractor shall perform monthly vulnerability scanning (DELIVERABLE 3) and provide a Vulnerability Assessment and Mitigation Report (DELIVERABLE 4) for vulnerabilities that could not be completely mitigated/addressed.

2.7.3 Physical Security: Place of performance is not at a Government Facility. The Government shall provide Virtual Private Network (VPN) Equipment as specified in Part 3. Adequate security shall be provided for all unclassified DoD information on non-DoD information systems.

2.8 Data Rights: The Contractor shall comply with Federal Acquisition Regulation (FAR) Subpart 227.7103-5, “Government Rights”. The Government retains unlimited data rights to data that is sent to the Contractor for cleansing, normalization and standardization. The Government retains unlimited data rights to data furnished by the Contractor after the Government has applied the authoritative data services to the Government data sets.

2.9 Reporting

2.9.1 Non-Disclosure Agreement (NDA): The Contractor shall submit a NDA (DELIVERABLE 5) at the organizational level to ensure Government data is properly handled. The Contractor shall maintain the originally signed NDA and provide a copy to the NDA signed submission POC. The NDA is listed below as Attachment 2.

2.9.2 Post-award conference/periodic progress meetings: The Contractor agrees to attend any post-award conference convened by the Contracting Officer in accordance with FAR Subpart 42.5. The Contracting Officer and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings the Contracting Officer will apprise the Contractor of how the Government views the Contractor's performance and the Contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government.

PART 3

3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

3.1 DoD Services: Sustainment and maintenance of GFE.

3.2 Equipment: The Government shall provide DHA approved B2B gateway VPN Equipment: Cisco ISR 4451 AX Bundle with APP and SEC license. Quantity 2.

3.3 Database Subscriptions: The Government will identify a representative or representatives to be super-user(s), having ability to vet and grant various levels of subscription access, within the confines of this contract, to requesting service members at DoD Components and Support Activities listed within Technical Exhibit 1. These Government representatives will be named as Technical Liaisons TLs, if/when required by the Contracting Officer.

PART 4

4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES

4.1 Materials: The Contractor shall provide data formats, data schema and other information to facilitate the transmission of the authoritative data exchange services.

4.2 Database Subscriptions: Through the use of an internet-based portal, access to subscriptions will be via unique/individual username and password entry. The Contractor shall provide super-user access to the identified Government TLs, allowing the ability of the Government TLs to vet and grant various levels of subscription access, within the confines of this contract, to requesting service members at DoD Components and Support Activities listed within Technical Exhibit 1. The Contractor will provide subscription access usage analytics to show quantity of individuals accessing the various database subscriptions on a 6 month and 12 month basis, as requested by DHA. The following database information will be provided:

4.2.1 Repository of all hazards, alerts, and recalls (HAR) for Government Medical Devices and Equipment (MDE) with sortable data points, to include respective HAR: accession number, priority, subject/headline, device code, manufacturer, common model, publication date, status, status date, and U.S. Food & Drug Administration (FDA) class of recall.

4.2.2 MDE procurement and cost analytics tools sets and services, to include: comparative product evaluations, price benchmarking data, vendor proposal analyses, service/maintenance contract analyses, consumable/reagent contract analyses, fair market value analyses, market share/sector intelligence, request for proposal analysis, request for proposal (RFP) templates, user experience reviews, justification analysis, capital budget reviews.

4.2.3 Dynamic ranking/comparative matrices of highly prevalent industry manufacturers’ product line common models within a device code.

4.2.4 Product identification tool sets for industry functional equivalents of medical-surgical supplies and implants, to include pricing analytics.

4.2.5 Utilization analytics

4.3 Contractor Supplies and Equipment. The Contractor supplies and equipment shall comply with Federal, State, municipal, and industry or OEM specifications.

4.4 The Contractors personnel shall comply with the Department of Defense (DoD) Information Assurance Policies applicable.

4.5 Contractors are required to maintain a drug and alcohol free workplace.

PART 5

5.0 AUTHORITATIVE DATA EXCHANGE SPECIFIC TASKS

5.1 The Contractor shall provide the following s:

5.1.1 Data Integration Support: The Contractor shall create an authoritative data exchange to support modernization and data standardization in Health Alerts and Equipment Management LOBs. The contractor shall include three (3) custom data feeds via a manual mechanism and/or through DHA approved B2B gateway to support product catalog data attributes and data standardization, which will (i) assist in normalizing data before it is committed to the database and exercised in a business process; (ii) matches equipment and supplies to provide an accurate, timely identification of all product recalls. Any required changes to data exchanges will be bi-laterally agreed upon before implementation. The Contractor shall accomplish matching services for supplies and capital medical equipment. The Contractor shall provide data standardization to include analysis of medical device inventory, normalization of product attributes [leveraging Universal Medical Device Nomenclature System (UMDNS)], and providing product catalog data. Product catalog data to be provided shall include product identifier, product name/common model nomenclature, code/catalog number, manufacturer identifier, UMDNS term/nomenclature, industry status, and product type (to include, Supply Classification (FSC), risk level, life expectancy, accountability status, required maintenance activities (i.e. maintenance action type), required maintenance frequency (i.e. interval/periodicity) and device definitions of MDE.

5.1.2 Technical Integration Support:

The Contractor shall transmit the authoritative data exchange via a manual mechanism and/or over a DHA approved B2B gateway, while strictly adhering to Cybersecurity requirements.

5.1.3 Test Planning and Performance: The Contractor shall participate in LogiCole/ECRI interface testing to support functionality and performance evaluations.

5.2 Interconnection Security Agreement - IAW NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems:

5.2.1 Interconnection statement of requirements. The requirements for interconnection between the Contractor and the Government are for the express purpose of exchanging data between ECRI HAR System (owned by the Contractor) and LogiCole (owned by the Government). The Government requires the use of the Contractor’s ECRI HAR System database, and inversely the Contractor requires the use of the Government’s LogiCole database, as specified in the Office of Management and Budget (OMB) Circular A-130, Appendix III, for system interconnection and information sharing. The expected benefit is to expedite the processing of data associated with HARs within prescribed timelines.

5.2.2 System security considerations - General information/data description. The interconnection between ECRI HAR System and LogiCole is a bi-directional connection. The purpose of the interconnection is to exchange information on supplies and equipment used by DoD Components for the purpose of receiving HAR and for identifying on the ECRI website HAR that match medical supplies or equipment used or owned by a specific DoD Component.

5.2.3 This connection exchanges data between the Contractor’s system and the Government’s system via a dedicated, DHA approved B2B gateway.

5.2.4 Data sensitivity. The sensitivity of data exchanged between the Contractor and the Government is Controlled Unclassified Information (CUI). Information type for this data exchange is “Official Information Dissemination” and “Logistics Management”, as categorized Low (confidentiality), Low (integrity), and Low (availability) in accordance with NIST SP 800-60, “Guide for Mapping Types of Information and Information Systems to Security Categories”.

5.2.5 Information exchange security. The security of the information routed within this bi-directional feed shall be protected through the use of Federal Information Process Standards (FIPS) Publication 140-2 approved encryption mechanisms. The connections at each end are and shall be located within controlled access facilities. The Contractor shall ensure that data access is verifiable and controlled.

5.2.6 Trusted behavior expectations. The Contractor is expected to protect the Government’s data in accordance with the Privacy Act and Trade Secrets Act (18 U.S. Code 1905) and the Unauthorized Access Act (18 U.S. Code 2701 and 2710).

5.2.7 Incident reporting. The party discovering a security incident shall report it in accordance with its incident reporting procedures.

5.2.8 Audit and monitoring responsibilities. Both parties (Contractor and Government) are responsible for auditing application processes and activities involving the interconnection. Audit logs and/or reports will be retained for one (1) year from logged/reported event. Audit logs and/or reports will only be purged in a first in, first out (FIFO) fashion. Activities that will be recorded include event type, date and time of event, user identification, workstation identification (by IP address and/or MAC address), and success or failure of access attempts.

Elevated audit and monitoring activities, to record the security actions taken to mitigate specific audit issue(s) or event(s), shall be afforded to system administrators (SAs) or security officers.

PART 6

6.0 APPLICABLE PUBLICATIONS

6.1 Applicable Publications (Current Editions):

· Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, dated July 10, 2012, current as of December 18, 2014

· Committee on National Security Systems (CNSS) Glossary, dated April 6, 2015

· Committee on National Security Systems (CNSS) Instruction 1253, Security Categorization and Controls Selection for National Security Systems, dated March 27, 2014

· DoD Directive (DoDD) 5530.3, International Agreements, dated June 11, 1987, current as of November 21, 2003

· DoD Instruction 8320.02, Sharing Data, Information, and Information Technology (IT) Services in the Department of Defense, dated Aug 5, 2013

· DoD Instruction 8500.01, Cybersecurity, dated March 14, 2014

· DoD Instruction 8551.01 Ports, Protocols and Service Management (PSSM), dated May 28, 2014, incorporating changes from July 27, 2017

· DoD Instruction 8582.01, Security of Unclassified DoD information on Non-DoD Information System, dated June 6, 2012, incorporating changes from October 27, 2017

· DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), dated July 28, 2017

· DoD Instruction 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, dated May 24, 2011

· DoD Instruction 8520.03, Identity Authentication for Information Systems, dated July 27, 2017

· Executive Order 13556, Controlled Unclassified Information, November 4, 2010

· Federal Information Process Standards (FIPS) Publication (PUB) 200 Minimum Security Requirements for Federal Information and Information Systems, dated March 2006

· National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 1, Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations, dated December 2016, including updates as of February 20, 2018

· NIST SP 800-18 Revision 1, Guide for Developing Security Plans for Federal Information Systems, dated February 2006

· NIST SP 800-37, Risk Management Framework (RMF) Guide for Applying the Risk Management Framework to Federal Information Systems, as well as emerging DoD Cybersecurity, dated December 2018

· NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems, dated August 2002

· NIST SP 800-50, Building an Information Technology Security Awareness and Training Program, dated October 2003

· NIST SP 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, dated April 2013

· NIST SP 800-53a Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, dated December 2014

· NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, Volume I, dated August 2008

· NIST SP 800-171, Revision 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, dated December 2016

PART 7

7.0 ATTACHMENT/TECHNICAL EXHIBIT LISTING

7.1 Attachment 1: Points of Contact

7.2 Attachment 2: DHA Form 49, DHA Contractor Non-Disclosure Agreement (“Agreement”) (July 22, 2014). This form is designed to be completed at the organizational level after contract award as designated by the KO.

7.3 Technical Exhibit 1: Deliverables Schedule & Locations

ATTACHMENT 1

POINT OF CONTACTS

Organization
Technical Liaison Name
Phone #
Email
DHA
Rich Fulmer
(301) 619-4099
richard.b.fulmer.civ@mail.mil
JMLFDC
Donna Totten
(301) 619-3974
donna.j.totten.civ@mail.mil
Navy
Melissa Lynn

Anthony Angelo

(301) 619-7251

(301) 619-7002 melissa.a.lynn.civ@mail.mil anthony.j.angelo18.civ@mail.mil

Army
TBD
TBD
TBD
Air Force
Dave Baker

Richard Koleszar TSgt Arthur Williams

(301) 619-7487

(301) 619-4039

(301) 619-9090 david.d.baker26.civ@mail.mil richard.j.koleszar.civ@mail.mil arthur.a.williams24.mil@mail.mil

Event
Joint Medical Logistics Development Center POCs
Security Events
Wanda Hazel, ISSM

Email: wanda.l.hazel2.civ@mail.mil Phone: 571 259-4831

Brenda Norris, Service Operations Manager Email: brenda.l.norris.civ@mail.mil Phone: 301-619-9772

Disaster/Contingency
Brenda Norris, Service Operations Manager

Email: brenda.l.norris.civ@mail.mil Phone: 301-619-9772

System Configuration Changes
Brenda Norris, Service Operations Manager

Email: brenda.l.norris.civ@mail.mil Phone: 301-619-9772

Data Exchange Changes
Gary Hatcher, MMQC Lead

Email: Gary.L.Hatcher3.civ@mail.mil Phone: 301-619-7022

Wanda Hazel, ISSM Email: wanda.l.hazel2.civ@mail.mil Phone: 571 259-4831

Connection to other IT Systems
Brenda Norris, Service Operations Manager

Email: brenda.l.norris.civ@mail.mil Phone: 301-619-9772

NDA – Signed Submission
Brenda Norris, Service Operations Manager

Email: brenda.l.norris.civ@mail.mil Phone: 301-619-9772

ATTACHMENT 2

DHA CONTRACTOR NON-DISCLOSURE AGREEMENT (“AGREEMENT”)

I,_________________________________________, am an employee of, or an employee of a subContractor to,_________________________________________________ (Business Name), a Contractor to the Defense Health Agency (DHA) under Contract No. _____________________________________, through Delivery Order No. (as applicable) __________________________________.

I understand that, in my performance under this contract, I may have access to, or otherwise receive, sensitive or proprietary business, technical, financial, and/or source selection information belonging to the Government or other Contractors. This information includes, but is not limited to, cost/pricing data, Government spend plan data, Contractor technical proposal data, Contractor trade secrets, independent government cost estimates, proposal and evaluation and source selection information, negotiation strategies and Contractor data presented in negotiations, contracting plans, and statements of work. I agree not to discuss, divulge, or disclose any such information or data to any person or entity, except those persons directly involved, on behalf of the DHA, in the acquisition or contract action to which the protected information pertains, as identified to me by the DHA contracting officer. I acknowledge that the unauthorized disclosure, use or negligent handling of the information by me could cause irreparable injury to the owner of the information.

As used in this Agreement, sensitive information is an overarching term that also includes, but is not limited to, sensitive but unclassified information/data, Protected Health Information, For Official Use Only information/data, and Privacy Information. This includes information in routine Department of Defense payroll, finance, logistics, inventory, and personnel management systems. The loss of, misuse of, or unauthorized access to or modification of this information could adversely affect the national interest or the conduct of Federal programs or the privacy to which individuals are entitled under Section 552a of Title 5, as amended, but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.

I attest that I am aware of, and will comply with the standards for access, dissemination, handling, and safeguarding of the information to which I am granted access as cited in this Agreement and in accordance with the guidance provided to me relative to the specific category of information.

I understand that the United States Government may seek any remedy available to it to enforce this Agreement, including, but not limited to, application for a court order prohibiting disclosure of information in breach of this Agreement. Court costs and reasonable attorney fees incurred by the United States Government may be assessed against me if I lose such action. I understand that another business entity might file a separate claim against me if I have misused its proprietary information.

Sensitive, proprietary, confidential commercial, or source selection information/data will be handled in accordance with Government regulations, policies, and procedures. I understand that I will be required to sign a new NDA for the contract in which I am performing, on an annual basis, prior to the Government granting me access to such information. I further understand that my obligations under this Agreement continue indefinitely, and are not limited by the signing of a new agreement or by the term of my employment as a Government Contractor employee. I fully understand that information does not lose its protected nature due simply to the passage of time, and my obligation of non-disclosure continues unless and until the information clearly falls under categories a through d in the next paragraph.

The obligations imposed herein do not extend to information/data which:

1. is in the public domain at the time of receipt or it came into the public domain through no act of mine;

1. is disclosed with the prior written approval of the DHA designated Contracting Officer;

1. is demonstrated to have been developed by______________________________(Business Name) or me independently of disclosures made hereunder; and

1. is disclosed pursuant to court order, after notification to the DHA designated Contracting Officer.

In the event that I seek other employment, I will reveal to any prospective employer the continuing obligation in this Agreement prior to accepting any employment offer.

I have read this Agreement carefully and my questions, if any, have been answered to my satisfaction.

__________________________________________________________________
(Printed Name of Employee or SubContractor Employee)Date
___________________________________________________________________
(Signature of Employee or SubContractor Employee)Business Entity
_____________________________________________________________
(Witness Signature)Date

TECHNICAL EXHIBIT 1

DELIVERABLES SCHEDULE

The following abbreviations are used in the delivery / deliverable schedule:

Abbreviation
Definition
KO
Contracting Officer
COR
Contracting Officer's Representative for the Task Order
DACA
Days after contract award (award of this order)
Days
Calendar Days unless otherwise specified
NLT
Not Later Than
SOW Ref
Statement of work Reference (paragraph number)

A summary of Deliverables follows. Copies are to be provided to the Government officials indicated in electronic file (E) and/or hard copy (H).

Item
SOW Ref
Title
Distribution
E
H
Initial Submission (After award)
Subsequent Submission

(Updates to initial deliverables)

Deliverable 1
1.10.2.6
System Security Plan
COR/JMLFDC ISSO and ISSM
1
1
NLT 30 DACA
Annually or if there are significant security changes to/for the ECRI/LogiCole interface
Deliverable 2
1.10.2.7
Security Assessment Report (SAR)
TLISSM
1
1
NLT 30 DACA
Updated Annually
Deliverable 3
1.10.2.20
Monthly Vulnerability Scans
TL/JMLFDC ISSO and ISSM
30 DACA
Monthly
Deliverable 4
1.10.2.20
Vulnerability Assessment and Mitigation Report
TL/JMLFDC ISSO and ISSM

As Required

Deliverable 5
1.12.2 &

Attachment 2

Non-Disclosure Agreement (NDA)
DHA CO

Signed statements are due, from each employee assigned, prior to performing ANY work on this contract.

LIST OF LOCATIONS. The following subscriptions are required for all sites listed below:

Alerts Tracker (section 4.2.1. of the SOW) SELECTplus (section 4.2.2 of the SOW) TruVu (section 4.2.3 of the SOW) CrossCHEQ (section 4.2.4 of the SOW) Utilization Analytics (section 4.2.5 of the SOW)

Subscriptions required for JMLFDC and DHA MEDLOG (all sections except for 4.2 of SOW):

Alerts for FYI only Alerts Automatch - Equipment Alerts Automatch - Supplies Supply - Data Standardization Equipment - Data Standardization PriceGuide (Includes Data Standardization for Supplies) Product Catalog Cybersecurity

Army Sites

Location
STATE
UNIT NAME
BEDS
FT CARSON
CO
Evans Army Community Hospital (EACH)
66
FT BLISS
TX
William Beaumont Army Medical Center (WBAMC)
209
FT RILEY
KS
Irwin Army Community Hospital
44
FT LEWIS
WA
Madigan Army Medical Center (MAMC)
227
FORT IRWIN
CA
Weed Army Community Hospital
27
FT WAINWRIGHT
AK
Bassett Army Community Hospital
24
FT HUACHUCA
AZ
Raymond W. Bliss Army Hospital
Amb. Surg.
FT LEONARD WOOD
MO
Leonard Wood Army Community Hospital (GLWACH)
42
FT LEAVENWORTH
MO
Munson Army Medical Center
FT SAM HOUSTON
TX
San Antonio Military Medical Center (BAMC now SAMMC)
226
FT HOOD
TX
Carl R. Darnell Army Medical Center (DAMC)
109
FT GORDON
GA
Dwight D. Eisenhower Army Medical Center (DDEAMC)
107
FT STEWART
GA
Winn Army Community Hospital (WACH)
37
FT CAMPBELL
KY
Blanchfield Army Community Hospital (BACH)
66
FT JACKSON
SC
Moncrieff Army Community Hospital MACH)
FT RUCKER
AL
Lyster Army Health Clinic (LACH)
FT SILL
OK
Reynolds Army Community Hospital (RACH)
FT POLK
LA
Bayne-Jones Army Community Hospital (B-JACH)
13
FT BENNING
GA
Martin Army Community Hospital (MACH)
57
Redstone Arsenal
AL
Fox Army Health Center
FORT MEADE
MD
Kimbrough Ambulatory Care Center
Amb. Surg.
ABERDEEN PG
MD
Kirk Army Community Hospital
Monitored by Kimbrough
Carlisle Barracks
PA
Dunham Army Health Clinic
Monitored by Kimbrough
FT KNOX
KY
Ireland Army Community Hospital (IACH)
WEST POINT
NY
Keller Army Community Hospital
20
FT LEE
VA
Kenner Army Community Hospital
FT EUSTIS
VA
McDonald Army Health Center
Amb. Surg.
FT DRUM
NY
Guthrie Army Health Clinic
Korea
Brian Allgood Army Community Hospital (BAACH)
48
TRIPLER
HI
Tripler Army Medical Center (TAMC)
194
LANDSTUHL
DEU
Landstuhl Regional Medical Center (LRMC)
310
ABERDEEN
MD
Public Health Command (PHC)
Lab
Ft. Belvoir
VA
Regional Health Command Atlantic
HONOLULU
HI
Regional Health Command Pacific
Fort Sam Houston
TX
Regional Health Command Central
Germany
Regional Health Command Europe

FT DETRICK

Medical Research and Materiel Command (MRMC)

FT DETRICK
MD
US Army Medical Research Institute of Infectious Diseases (USAMRIID)
Lab
FT RUCKER
AL
US Army AeroMedical Research Laboratory (USAARL)
Lab
FT SAM HO
TX
US Army Institute of Surgical Research (USAISR)
NATIK
MA
US Army Research Institute of Environmental Medicine (USARIEM)
Lab
FT DETRICK
MD
US Army Center for Environmental Health Research (USACEHR)
Lab
ABERDEEN PG
MD
US Army Medical Research Institute of Chemical Defense (USAMRICD)
Lab
SILVER SPRING
MD
Walter Reed Army Institute of Research (WRAIR)
Lab
WASHINGTON
DC
Armed Forces Research Institute of Medical Sciences (AFRIMS)
FT SAM HOUSTON
TX
Army Medical Department Center and School (AMEDDC&S)
FT DETRICK
MD
AMLC (SITES BELOW)

10TH COMBAT SUPPORT HOSPITAL

115TH COMBAT…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.