N6264521Q0017.docx

DOCX document 134 KB Posted

Attached to
DOFEMS Maintenance Federal contract opportunity
Solicitation number
N6264521Q0017
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This combined synopsis/solicitation notice is for a proposed sole source, firm-fixed price contract to provide maintenance and support services for the Defense Optical Fabrication Enterprise Management System (DOFEMS). The services are required at ten Navy laboratory sites located across the United States and Japan. The incumbent contractor, Optical Lab Software Solutions, Inc., manufactured the DOFEMS software and would negotiate the contract directly with the government. The proposed contract would have a one-year base period of performance from July 25, 2021 to July 24, 2022, along with four one-year option periods to extend to July 24, 2026. The scope of work is defined in the Performance Work Statement and includes software maintenance, technical support, and compliance with Department of Defense cybersecurity requirements.

View the file

Other files for this federal contract opportunity

Other files attached to DOFEMS Maintenance, newest first.
File Type Posted
Amedment 01 N6264521Q0017.docx DOCX document
Revised Attachment II-Pricing Workbook for N6264521Q0017.xlsx XLSX spreadsheet
Attachment II-Pricing Workbook for N6264521Q0017.xlsx XLSX spreadsheet
Legally Sufficient JA Redacted.pdf PDF
Attachment 1- CAP.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

N6264521Q0017

SOLE SOURCE PROCUREMENT

This solicitation notice is for informational purposes only. This is not a request for proposals and is not soliciting for competition. A determination by the Government not to compete this proposed contract action based upon responses to this solicitation is solely within the discretion of the Government. Information received will normally be considered solely for the purpose of determining whether to conduct a competitive procurement. Responses in any form may be reviewed but the Government is under no obligation to award a contract as a result.

No funds are available to pay for preparation of responses to this announcement.

The proposed contract action is for maintenance services for which the Government intends to solicit and negotiate with one source, Optical Lab Software Solutions, Inc. (OLSS)

The combined synopsis/solicitation number is N62645-21-Q-0017 and the NAICS code is 811219.

This requirement is for a service contract to provide maintenance and support services, for the Defense Optical Fabrication Enterprise Management System (DOFEMS) manufactured by Optical Lab Software Solutions, Inc. (OLSS) located at the Naval Ophthalmic and Training Support Activity (NOSTRA), Yorktown, VA and nine other Navy labs (ten labs total) located in the Continental United States (CONUS) and Outside the Continental United States (OCONUS). The sites are: Camp Lejeune, North Carolina; Great Lakes, Illinois (FHCC Lovell); Mayport, Florida; Parris Island, South Carolina; Quantico, Virginia; Yokosuka, Japan; Bremerton, Washington; San Diego, California; and Camp Pendleton, California. This combined synopsis/solicitation will result in a sole sourced, firm-fixed price contract with a period of performance of a base (25 July 2021-24 July 2022) and four one year option periods for a contract end date of 24 July 2026.

The scope of the requirement is listed in the Performance Work Statement.

Exhibit/Attachment Table of Contents

DOCUMENT TYPE
DESCRIPTION
PAGES
DATE
Attachment 1
Contract Administration Plan
15
28-MAY-2021
Attachment 2
Pricing Workbook for N6264521Q0017
3
28-MAY-2021
ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12
Months

DOFEMS LMS Maintenance and Support

FFP

The contractor shall provide maintenance and support for the DOFEMS LMS Application-in accordance with the Performance Work Statement (PWS) FOB: Destination

NET AMT

ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12
Months
OPTION
DOFEMS LMS Maintenance and Support FFP

The contractor shall provide maintenance and support for the DOFEMS LMS Application-in accordance with the Performance Work Statement (PWS) FOB: Destination

NET AMT

ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12
Months
OPTION
DOFEMS LMS Maintenance and Support

FFP

The contractor shall provide maintenance and support for the DOFEMS LMS Application-in accordance with the Performance Work Statement (PWS) FOB: Destination

NET AMT

ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12
Months
OPTION
DOFEMS LMS Maintenance and Support FFP

The contractor shall provide maintenance and support for the DOFEMS LMS Application-in accordance with the Performance Work Statement (PWS) FOB: Destination

NET AMT

ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
12
Months
OPTION
DOFEMS LMS Maintenance and Support FFP

The contractor shall provide maintenance and support for the DOFEMS LMS Application-in accordance with the Performance Work Statement (PWS)

NET AMT

PERFORMANCE WORK STATEMENT

MAINTENANCE AND SUPPORT FOR THE DEFENSE OPTICAL FABRICATION ENTERPRISE MANAGEMENT SYSTEM (DOFEMS)

1.0 GENERAL INFORMATION

1.1 General: The Government has a requirement for a maintenance and support contract for the product packaged and contracted to the government as the Defense Optical Fabrication Enterprise Management System (DOFEMS) that includes the Lab Management System (LMS) software manufactured by Optical Lab Software Solutions Inc. under the commercial software brand Optuitive.

1.2. Scope: This service contract shall provide software maintenance, technical support services, and cyber security maintenance of the system per Department of Defense (DoD) and Defense Health Agency (DHA) guidance’s and Risk Management Framework (RMF) for the Lab Management System (LMS) and all associated software packaged to operate with or in support of the product known to the government as DOFEMS as well as web services between the government’s Spectacle Request Transmission System (SRTS) order entry system to ensure the DoD Optical Fabrication Enterprise maintains operational readiness to its beneficiaries.

The DOFEMS Production Environment is the live operational environment installed on two physical servers located inside DoD Datacenters. The Test Virtual Machine Environment is a non-production static environment installed and managed by DHA/DCOPS (Data Center Operations) and maintained and used by the vendor and NOSTRA personnel to test and validate the systems operational performance post modifications before deployment to the actual Production Environment.

1.3. Authorized Locations:

The Authorized Locations means the optical laboratory locations who are licensed to operate DOFEMS. The Authorized Locations include 10 Navy optical lab locations, as follows:

Navy Fabrication Labs
Lab Size
Yorktown, Virginia (NOSTRA)
Large
Bremerton, Washington
Medium
San Diego, California
Medium
Camp Lejeune, North Carolina
Small
Great Lakes, Illinois (FHCC Lovell)
Small
Mayport, Florida
Small
Parris Island, South Carolina
Small
Quantico, Virginia
Small
Camp Pendleton, California
Small
Yokosuka, Japan
Small

1.4 Usage:

Current authorized locations produce an estimated maximum of 900k jobs per year.

1.5. Directive for Security Compliance

The Information Assurance Security Technical Implementation Guide (STIG) (V-57561) states:

“an application server must install security-relevant software updates within the time period directed by an authoritative source (e.g. Information Assurance Vulnerability Management, Chief Technology Officers, Directive-Type Memorandums, and Security Technical Implementation Guides). Security flaws with software applications are discovered daily. Contractors are continually updating and patching their products to address newly discovered security vulnerabilities.

Organizations (including any contractor to the organization) are required to promptly install security-relevant software updates (e.g., patches, service packs, and hot fixes) to production systems after thorough testing of the patches within a lab environment…” Additional IA guidance per Change Management (CM4) states “the organization analyzes changes to the information system in a separate test environment before implementation in an operational environment, looking for security impacts due to flaws, weaknesses, incompatibility, or intentional malice.”

1.5.1. The contractor shall comply with all requirements of STIG V-57561. Vulnerabilities shall be resolved when found throughout the life of the contract.

2.0 PERFORMANCE REQUIREMENTS

2.1. Maintenance Management

The contractor shall be responsible to provide the following to keep the Production Environment and the Test Environment in compliance with DoD 8500 series documentation for cybersecurity policy and DHA requirements.

2.1.1. Contractor Maintenance Management Responsibilities:

The following tasks shall be provided remotely via DHA AVHE Desktop by the contractor personnel who are authorized to access the DOFEMS systems.

· Installation, and validation, and maintenance that include updates, required upgrades, and security patches for the following:

· Red Hat Linux

· Oracle Database

· Apache and Tomcat

· HBSS Client

· Any associated supporting software is included in the system packaged as DOFEMS (e.g.Pentaho)

· DOFEMS (Optuitive)

· Any associated supporting software’s included in the system packaged as DOFEMS (e.g. Pentaho)

· Installation and validation of Oracle Database critical security patches

· Installation and validation of new Apache and Tomcat versions

· Installation and validation of new DOFEMS versions

· Installation, updates and validation as required of associated supporting software’s included in the system packaged as DOFEMS (e.g. Pentaho)

· Alpha and Beta testing with SRTS system

· Maintain and perform new Security Technical Implementation Guide (STIG) checklist manual validation and resolve any vulnerabilities

· Perform Security Content Automation Protocol (SCAP) Compliance Checker/Security Content Automation Protocol scans of the system to identify and resolve any vulnerabilities

· Install, patch and maintain HBSS software in accordance with DHA requirements

· Installation and validation of new Red Hat Linux versions as required by DHA for security compliance

· Installation and validation of new Oracle Database versions as required by DHA for security compliance

· Perform periodic data synchronization as needed from the DOFEMS production servers to the Test Environment keep data current for testing

· Maintain synchronization between primary and Continuity of Operations Planning (COOP) servers in near real time

· Provide Oracle embedded licensing at cost to the government

2.1.2. All non-work stoppage requirements identified in the Contractor Maintenance Management Section of the PWS are completed within a mutually agreed upon timeframe. If cyber related, within timeline identified by the update requirement. Critical work stoppage related issues identified shall be completed within 24 hours.

2.2 Technical Support

Contractor shall provide, as needed, maintenance and support services during the contract performance period.

2.2.1. Contractor Technical Support Services Responsibilities:

The services shall include the following:

· Technical Support. Services shall be available 0400 – 2200 Central Standard USA Time, Monday through Friday, excluding federal holidays.

· The Customer shall follow documented standardized reporting procedures, currently utilized by the contractor, to align with its current support center operations.

· The Contractor shall respond to support calls initially by email, and person to person if need be, within 15 minutes, but may take up to 120 minutes to respond.

· Support shall include troubleshooting issues, answering questions, and providing advice concerning the use and operation of DOFEMS.

2.2.2. The contractor shall post a service support after action status report within the customer support portal of their online customer service system within (7 days) of an incident/technical support call.

2.4. Other Requirements

2.4.1 Bi-Annual Visits. Provide two (2) on-site service support visits per year at no additional cost to the NOSTRA surfacing lab located in Yorktown, VA.

2.4.2. Maintain, inspect, and if necessary, repair the system if the system is not performing in accordance within accustomed operational norms or obvious failure. This maintenance shall include the following:

2.4.3. Prepare for and execute the required maintenance of the DOFEMS application, database, servers, and operating systems to ensure continual operational readiness, and compliance with DHA cyber security requirements.

2.4.4. Schedule and install DOFEMS software updates, including general releases, revisions, patches, and or updates at a time as to minimize downtime to production and at no additional cost. DOFEMS software refers to the Optuitive Lab Management Software and supportive software such as, but not limited to Apache Tomcat, Pentaho.

2.4.5. Schedule and install Oracle upgrades as to minimize downtime to production and at no additional cost. Note that RHEL upgrades are covered under a Government BPA.

2.4.6. All maintenance shall be completed in accordance with the requirements and defined roles and responsibilities above.

2.4.7. All maintenance shall be cleared with NOSTRA’s DOFEMS Program Manager prior to actual work performed to schedule a time least inhibitive to negative effects on production.

3.0 QUALITY ASSURANCE SURVEILLANCE PLAN

PWS Section
Performance Requirement
Surveillance Method
Frequency
Acceptable Quality Level
Technical Support Services Paragraph 2.2.1
Troubleshooting issues, answering questions, and providing advice concerning the use and operation of DOFEMs. The Contractor shall attempt to respond to support calls initially by email, and person to person if need be, within 15 minutes, but may take up to 120 minutes to respond during subscribed support hours.
COR shall review log of trouble tickets submitted to vendor customer service desk and verify response times against NOSTRA internal tracking documentation.
100% inspection of all contract deliverables.
>95% of deliverables submitted timely and without rework required.
Other Requirements Paragraph 2.4
Bi-Annual Visits. Provide two (2) on-site service support visits per fiscal year at no additional cost to the NOSTRA surfacing lab located in Yorktown, VA.
COR shall monitor date of receipt and completeness of service support after action reports.
100% inspection of all contract deliverables.
100% completion
Other Requirements Paragraph 2.3
Maintain, inspect, and if necessary, repair the system
Inspection by the COR/Technical Liaison
Periodic
Equipment shall be in working order 100% of the time
Contractor Maintenance Management Responsibilities Paragraph 2.1.
All non work stoppage requirements identified in the Contractor Maintenance Management Section of the PWS are completed within a mutually agreed upon timeframe. If cyber related, within timeline identified by the update requirement. Critical work stoppage related issues identified shall be completed within 24 hours.
Inspection by the COR/Technical Liaison
100% inspection of all contract deliverables.
100% completion of identified issues
Invoicing
Monthly invoices per contract procedures are timely and accurate.
Review & acceptance of the invoice by Technical Liaison and COR
Monthly
100% accuracy

INSTRUCTIONS TO QUOTERS

ADDENDUM TO FAR 52.212-1 INSTRUCTIONS TO OFFERORS – COMMERCIAL ITEMS

This section specifies the format and content that contractors shall use in this Request for Quote (RFQ). The intent is not to restrict the contractors in the manner in which they will perform their work but rather to ensure a certain degree of uniformity in the format of the responses for evaluation purposes. Vendors shall submit a quote that is legible and comprehensive enough to provide the basis for a sound evaluation by the Government. Information provided shall be precise, factual, and complete. Legibility, clarity, completeness, and responsiveness are of the utmost importance. Quotes shall be in the form prescribed by, and shall contain a response to each of the areas identified. This document is linked to Notice of Intent Posting N62645-21-Q-0017. The contractor shall submit a quote in response to the requirement to the Naval Medical Logistics Command (NMLC). In accordance with FAR part 13.5 procedures, NMLC intends to award a Firm Fixed Price (FFP) contract to Optical Lab Software Solutions, Inc. (OLSS).

The quote shall be submitted in two separate volumes:

Volume I- Business Volume II – Price Volume III--Small Business Subcontracting Plan and Small Business Commitment

A complete Volume I – Business and Volume II – Price shall be submitted by the closing date specified in this solicitation. If any, one volume is received past the stated closing date specified in the solicitation, the entire quote may be considered late.

VOLUME I: BUSINESS.

· The quoter must be registered in System for Award Management (SAM) in accordance with FAR 52.212-3. The quoter shall verify its SAM record is current, accurate, complete and applicable to this combined synopsis/solicitation as of the date of this quote and is incorporated in this offer by reference. The quoter shall be registered in SAM under the applicable NAICS code for this combined synopsis/solicitation, 811219 Other Electronic and Precision Equipment Repair and Maintenance. The small business size standard is $22M. The quoter shall complete and submit FAR 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (OCT 2015) ALTERNATE I (OCT 2014).

· The quoter shall complete and submit FAR Clause 52.209-11 [Representation By Corporations Regarding Delinquent Tax Liability or a Felony Conviction under any Federal Law (Feb 2016)].

· The quoter shall complete and submit FAR Clause 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT

VOLUME II: PRICE – (Attachment II Pricing Workbook for N62645-21-Q-0017).

The quoter will be evaluated for Completeness and Reasonableness. The Government anticipates award of a Firm Fixed Price contract. The quoter shall submit firm fixed pricing for the above requirement on the attached Microsoft Excel Workbook (Attachment II Pricing Workbook for N62645-21-Q-0017). Include commercial price lists and if applicable, any FSS schedule numbers and pricing; any applicable discounts to the Government.

QUOTE SUBMISSION

The quote shall be submitted via email to usn.detrick.navmedlogcomftdmd.mbx.matrix@mail.mil, SUBJECT: N62645-21-Q-0017. The quote shall be submitted via email only. The quote shall be due no later than 1300 Eastern Time, 07 July 2021.

VOLUME III: SMALL BUSINESS SUBCONTRACTING PLAN AND SMALL BUSINESS PARTICIPATION COMMITMENT DOCUMENT

Small Business Subcontracting Plan - The quoter shall submit a Small Business Subcontracting Plan in accordance with FAR Clause 52.219-9 and DFARS Clause 252.219-7003 (for reference see FAR 19.704 and DFARS 219-704). The Department of Defense (DOD) has established small business goals as an assistance to assure small business receives a fair proportion of DOD awards. The small business subcontracting goal for this requirement is 5% of the total contract value. The Government recognizes that these goals are stated as a percentage of the total contract value for the small business participation plan; whereas, the goals included in the subcontracting plan (FAR Clause 52.219-9) are stated in terms of a percentage of total subcontract dollars. Master subcontracting plans can be included as an appendix to the subcontracting plan. The proposal shall include the name of any proposed subcontractors and any applicable references. If the quoter believes there are no subcontracting possibilities, the quoter shall submit documentation sufficient to support its position.

Small Business Participation Commitment - A quoter (regardless of size status under NAICS 541511, Custom Computer Programming Services) shall submit evidence of their Small Business Participation Commitment in accordance with FAR 15.304 and DFARS 215.304. The quoter shall describe their Small Business Participation Commitment in terms of how small businesses will be utilized in this requirement and/or to what extent the quoter has previously utilized small businesses. If the quoter does not intend to use utilize small businesses for this requirement or does not generally utilize small businesses, the quoter shall provide documentation sufficient to justify its position. Addressing the extent of small business performance shall be separate from subcontracting plans submitted pursuant to the clause at FAR 52.219-9.

(End of addendum)

EVALUATION FACTORS FOR AWARD

52.212-2 EVALUATION--COMMERCIAL ITEMS (OCT 2014)

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:

Evaluation of price will be based on the quoter’s total price for all line items. Past Performance is not an evaluation factor for this acquisition, however information from the Past Performance Information Retrieval System (PPIRS) shall be used in making a responsibility determination.

The quoter’s initial quote shall contain the quoter’s best terms from a price standpoint. The Government intends to evaluate quotes and award a contract without discussions, but reserves the right to conduct discussions if later determined by the Contracting Officer to be necessary. The Government reserves the right to make no award as a result of this solicitation.

VOLUME I: BUSINESS

Completeness – Quoter is registered in SAM, completed and submitted FAR 52.212-3 Alternate I, and completed and submitted FAR 52.209-11 and FAR 52.204-24.

VOLUME II: PRICE

Reasonableness – The degree to which the quoter’s total proposed price represents a fair and reasonable price. Pricing will be examined to determine the degree to which proposed prices compare to the prices a reasonable prudent person would expect to incur for the same or similar services. Only a quote determined fair and reasonable will be eligible to receive a contract award.

Options. The Government will evaluate offers for award purposes by adding the total price for all options to the total price for the basic requirement. The Government may determine that an offer is unacceptable if the option prices are significantly unbalanced. Evaluation of options shall not obligate the Government to exercise the option(s).

VOLUME III: SMALL BUSINESS SUBCONTRACTING PLAN AND SMALL BUSINESS PARTICIPATION COMMITMENT DOCUMENT

The Small Business Subcontracting Plan will be evaluated in accordance with FAR Clause 52.219-9 and DFARS Clause 252.219-7003. The Government will also evaluate the quoter’s Small Business Participation Commitment to determine the extent a quoter’s proposal demonstrates a realistic commitment to utilize small businesses; or whether the quoters’s proposal sufficiently demonstrates their rationale not to utilize small businesses. Both the Small Business Subcontracting Plan and the Small Business Participation Commitment discussion will be evaluated individually on a pass/fail basis and be determined to be either acceptable (pass) or unacceptable (fail).

(End of provision)

CONTRACTOR SUPPORT

Notice: Navy Use Of Support Contractor For Contract Closeout Functions

Naval Medical Logistics Command (NMLC) uses two private contractors in support of the contract closeout process. Those companies are Contracting Resources Group (CRG) of Federal Hill, MD, doing business under the authority of the Small Business Administration’s 8(a) program and the Ability One Program, and National Industries for the Blind (NIB) (Ability One Program), doing business under the authority of the Javits-Wagner O’Day Act (41 U.S.C. § 47).

The contract closeout process includes activities such as processing deobligation modifications, obtaining contractor and requiring activity concurrence, preparing the DD-Form 1594 (Contract Completion Statement), and preparing closed files for archiving. Support contractors may perform additional administrative duties, including filing and processing simple administrative modifications. Performing these functions require the contractor employees to have access to the contract file. Therefore, information the Contractor provides to the Government or information already in the possession of the Government may be viewed by these support contractors in the course of performing contract close-out functions. The information that may be made available to the contractor may include pricing and technical responses and performance information.

NMLC has signed Non-Disclosure Agreements with each support contractor employee and has required both contractors to provide a Conflict of interest Mitigation Plan to ensure these employees are firewalled from all business development activity.

By signature of this contract, the quoter consents to access of their business sensitive/confidential or proprietary data by the Government’s support contractor personnel in order to perform close out services.

OTHER CONTRACTING REQUIREMENTS

Risk Management Framework (RMF)

The contractor shall comply with RMF requirements, as specified by the Defense Health Agency (DHA) that meet appropriate DoD, DHA and Navy Cybersecurity requirements. The contractor shall initiate the process by providing the required documentation necessary to submit their system to the Authorizing Official (AO) for assessment and authorization (A&A) for this contract. The requirements shall be met before the contractor's system is authorized to access DoD data or to interconnect with any DoD network or system that receives, processes, stores, displays or transmits DoD data. The contractor shall ensure the proper contractor support staff is available to participate in all phases of the RMF process. This includes, but is not limited to;

Attending and supporting RMF and A&A meetings with Navy and DHA cybersecurity representatives as required.

Support/conduct vulnerability mitigation to comply with cybersecurity controls listed in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53; Security and Privacy Controls for Federal Information Systems and Organizations and DHA Administrative Instruction 77. In order for a system to be authorized, there shall be zero Category 1 findings.

Support the A&A Team during system security testing.

Once the system has been authorized, the contractor shall maintain an acceptable security baseline consistent with the authorization granted by the AO throughout the life of the system. This includes ensuring that all vulnerabilities affecting the operating system, primary application, database and all third party software have validated and applied within 30 days.

Cybersecurity

The vendor shall establish appropriate administrative and technical safeguards to protect any and all data, to ensure the confidentiality, integrity, and availability of Government data under their control. At a minimum, this shall include provisions for vendor personnel security and electronic security.

The proposed system shall be capable of supporting the use of Defense Information Systems Agency (DISA) approved antimalware applications. The Navy uses McAfee Host Based Security System (HBSS) as their solution. The vendor shall provide technical specifications that clearly demonstrate whether the proposed solution can integrate and support, either fully or partially the operation without performance degradation of the medical system/device. In cases where the operation of HBSS is not technically achievable, the vendor shall provide detailed justification and a Plan of Actions and Milestones (POA&M) describing steps towards compliance with this requirement.

The vendor must provide their Antivirus (AV) policy and a list of AV Exceptions (if applicable) to the NMLC prior to AV installation on the system/device. AV must be installed on all devices before they are placed on the Navy network.

Systems shall be configured in such a way to allow for the updating of malware definition signatures on a scheduled basis. Scanning shall encompass the entire system (file system, operating system, real-time processes), by default. In cases where scanning of the entire system may negatively affect its operation, the vendor shall provide a detailed list of exclusions with justifications.

Vulnerability Management

Vulnerability mitigation strategies include security updates, service packs, and changes to operating procedures as physical and cyber vulnerabilities are detected. Operating systems, servers, development platforms and the application being delivered to the Navy shall be in compliance with all known applicable guidelines. The vendor shall agree to be proactive in working with the Navy to mitigate new threats as they emerge.

All vendor validated and approved patches, up to and including the date of install, must be loaded on the system prior to system go-live. Security scans will be run during government acceptance testing. All Category I (CAT I) findings must be remediated prior to government acceptance of the system. A CAT I vulnerability is any vulnerability, the exploitation of which will, directly and immediately result in loss of Confidentiality, Availability, or Integrity. There shall be no more than 10 Category II (CAT II) findings at the time of government acceptance. CAT II vulnerabilities are any vulnerability, the exploitation of which has a potential to result in loss of Confidentiality, Availability, or Integrity.

Domain Name System Realm/Directory Services Contractor will be required to provide technical evidence, if applicable, whether client/server topology based medical systems can integrate with Directory Services and support LDAP authentication.

Local Privileged and Administrative User/Local System Accounts Contractor shall create a single local user account with administrative/root level privileges for purposes of conducting system repairs and maintenance only. This account shall be separate and distinct from the built-in local administrative/root account provided by the Operating System and shall comply with DoD policy. All factors required to complete successful identification, authentication and authorization against the built-in local Administrative/Root level account shall be provided to the MTF Biomedical Engineering Department.

Complete administrative system rights shall be provided to the government System Administrator for the purpose of conducting device vulnerability scans as needed.

DHA Business to Business (B2B) Gateway. All contractor systems that will communicate with DON systems will interconnect through the established DHA Business to Business (B2B) gateway.

Contractors will connect to the B2B gateway via a contractor procured Internet Service Provider (ISP) connection and assume all responsibilities for establishing and maintaining their connectivity to the B2B gateway. This will include acquiring and maintaining the circuit to the B2B gateway and acquiring a Virtual Private Network (VPN) device compatible with the DHA VPN device. Maintenance and repair of contractor procured VPN equipment shall be the responsibility of the contractor.

Contractors shall configure their network to support access to government systems (e.g., configure ports and protocols for access).

Contractors shall provide full time connections to a TIER1 or TIER2 ISP. Dial-up ISP connections are not acceptable.

Contractors will comply with DoD guidance regarding allowable ports, protocols and risk mitigation strategies prior to accessing DoD/DHA networks. All contractors will be required to complete a DISA Form 2875, System Authorization Access Request form (SAAR) and submit it to the Navy PACS Office for processing. Contractor personnel will be required to complete applicable DoD cybersecurity training.

IPv6

The proposed system shall be Internet Protocol version 6 (IPv6) capable or the vendor shall provide a detailed project, migration or planning documentation to show when the proposed system shall be IPv6 capable.

Minimum IPv6 capabilities include:

1. Conformant with the IPv6 standards profile contained in the DoD IT Standards Registry (DISR);

1. Maintaining interoperability in heterogeneous environments with IPv4;

1. Commitment to upgrade as the IPv6 standard evolves;

1. Availability of vendor IPv6 technical support.

1.

The contractor shall be able to demonstrate or provide documentation to prove that their product is IPv6 capable

Health Insurance Portability and Accountability Act (HIPAA) The contractor shall comply with the HIPAA Act of 1996 (Public Law 104-191) requirements, specifically the administrative simplification provision s of the law and the associated rules and regulations published by the Secretary, Health and Human Services (HHS). This includes the Standards for Electronic Transactions, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards.

Business Associate Agreement

This Business Associate Agreement (BAA) incorporates HIPAA/HITECH Act requirements under the HHS Final Omnibus Rule (78 FR 5566, published 25 Jan 2013), effective 23 Sep 2013. This BAA is for use by MHS components outside of DHA.

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where 12 Nov 2013 Page 2 of 10 persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the contractor.

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the Government facility(s) and office(s) that are supported under this contract.

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by the Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of the Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively), as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may use or disclose PHI only as necessary to perform the services set forth in the Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by the Agreement or directed by the Covered Entity.

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in the Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in the Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in the Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall provide the Business Associate with the notice of privacy practices that the Covered Entity produces in accordance with 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

If the DHA Privacy Office determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the DHA Privacy Office, regardless of whether the breach occurs at DHA or at one of the Service components. If the DHA Privacy Office determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office. The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(b) Government Reporting Provisions

The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the DHA Privacy Office and the other parties set forth below. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an worker, officer or other agent of the Business Associate.

The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office and the applicable Service-Level Privacy Office, if requested by either. Business Associate questions about US-CERT reporting shall be directed to the DHA or Service-Level Privacy Office, not the US-CERT office.

The Business Associate report due within 24 hours shall be submitted by completing the New Breach Reporting Form DD 2959 at the Breach Response page on the DHA Privacy Office web site and emailing that form to, as applicable, the DHA Privacy Office, the Service-Level Privacy Office, the Contracting Officer (CO) and Contracting Officer’s Representative (COR) and the Business Associate’s DoD point of contact (POC) unless the POC specifies another addressee for breach reporting. Encryption is not required, because Breach Report Forms should not contain PII/PHI. The email address for notices to the DHA Privacy Office is provided at the Privacy Office website breach response page. If electronic mail is not available, telephone notification is also acceptable, but all notifications and reports delivered telephonically must be confirmed by email as soon as technically feasible.

If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the DHA Privacy Office as soon as possible if it believes that “single event” breach response is appropriate; the DHA Privacy Office will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, follow-up, etc. The Business Associate shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the DHA Privacy Office to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the DHA Privacy Office to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the DHA Privacy Office (or the Service-Level Privacy Office, which will consult with the Privacy Office as appropriate) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

If the DHA Privacy Office determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph V(a) for their review, and for approval by the DHA Privacy Office. Upon request, the Business Associate shall provide the DHA Privacy Office with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group. (PII shall not be included with the text of the letter(s) provided.) Copies of further correspondence with affected individuals need not be provided unless requested by the Privacy Office.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .