N6264521Q0034.docx

DOCX document 129 KB Posted

Attached to
DOFEMS Virtualization Federal contract opportunity
Solicitation number
N6264521Q0034
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This document is a sole source solicitation for virtualization services. The Naval Medical Logistics Command seeks to deploy the Defense Optical Fabrication Enterprise Management System production environment into a new virtual-based environment with redundancy. The scope of work includes allocating four virtual machines, procuring necessary configurations, installing operating systems and applications, establishing communications, migrating the production database, and maintaining security compliance. The contractor must provide remote support services such as patching, testing system upgrades, and keeping production and continuity of operations environments synchronized. Quotes are due by September 2, 2021 to be considered for award of a firm fixed-price contract to the incumbent, Optical Lab Software Solutions, Inc.

View the file

Other files for this federal contract opportunity

Other files attached to DOFEMS Virtualization, newest first.
File Type Posted
Attachment 1- CAP.pdf PDF
Attachment II-Pricing Workbook for N6264521Q0034.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

N6264521Q0034

SOLE SOURCE PROCUREMENT

This solicitation notice is for informational purposes only. This is not a request for proposals and is not soliciting for competition. A determination by the Government not to compete this proposed contract action based upon responses to this solicitation is solely within the discretion of the Government. Information received will normally be considered solely for the purpose of determining whether to conduct a competitive procurement. Responses in any form may be reviewed but the Government is under no obligation to award a contract as a result.

No funds are available to pay for preparation of responses to this announcement.

The proposed contract action is for virtualization services for which the Government intends to solicit and negotiate with one source, Optical Lab Software Solutions, Inc. (OLSS)

The combined synopsis/solicitation number is N62645-21-Q-0034 and the NAICS code is 541511.

This requirement is for a service contract to provide to virtualization of the Defense Optical Fabrication Enterprise Management System (DOFEMS). System at Naval Ophthalmic Support and Training Activity (NOSTRA) with a delivery date of 31 December 2021.

The scope of the requirement is listed in the Performance Work Statement.

Exhibit/Attachment Table of Contents

DOCUMENT TYPE
DESCRIPTION
PAGES
DATE
Attachment 1
Contract Administration Plan
15
30-SEP-2021
Attachment 2
Pricing Workbook for N6264521Q0034
2
30-SEP-2021
ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1
Each

DOFEMS Virtualization

FFP

The contractor shall provide services to provide virtualization of the Defense Optical Fabrication Enterprise Management System (DOFEMS) -in accordance with the Performance Work Statement (PWS)

FOB: Destination

NET AMT

PERFORMANCE WORK STATEMENT

DOFEMS Virtualization

Project Description The project is to deploy the current Defense Optical Fabrication Enterprise Management System (DOFEMS) Production Environment into a new Virtual based environment, and create a new Virtual Continuity of Operations Planning (COOP) Environment to provide full redundancy to the Production Environment.

Current Environment The DOFEMS system currently is comprised of:

· Two physical servers. One Production Server is dedicated to providing the application to the end users and running the production manufacturing equipment. A second server is dedicated to being a read only hot backup to production and providing a reporting application to end users.

· A Virtual Test Environment (PreProd) consisting of a duplicate is installed at the Interoperability Test Center (ITC) with a static copy of the DOFEMS physical servers.

New Architecture A 2 Virtual Machine (VM) architecture of the current DOFEMS physical servers has been approved by Defense Health Agency (DHA)/Authorizing Official (AO) that negates the standard requirement to separate the logical components of the system into pieces but still allows the system to be moved to the MilCloud enclaves. Virtualizing the DOFEMS systems with a 2 VM architecture utilizes the same components as the physical server but builds in redundancy by providing a full DOFEMS environment at the COOP location. The Reports server shall be duplicated and synced at both Primary and COOP locations to improve failover of the system if need should arise. This will provide a much faster and easier failover process when the Production environment has failed. This will also ensure the performance of the COOP environment matches the performance of the production environment in case of failover.

The functional components of the current Physical Production/Reports servers shall be installed to the new Virtual Systems as a mirror image at each the Primary and the COOP locations:

· Application/Database VM

· Reports Application/Reports Database VM

* The new Virtual environment shall include 4 VM servers, provided by the government, as represented in the table below:

Server Description
Server Type
# CPUs
GB RAM
Storage 1 (GB)
Storage 2 (GB)
DOFEMS Production
Application/Database
24
256
80
4,096
DOFEMS Reports
Application/Database
24
256
80
4,096
COOP DOFEMS Production
Application/Database
24
256
80
4,096
COOP DOFEMS Reports
Application/Database
24
256
80
4,096

Each of the VM’s shall be built in accordance with the Risk Management Framework (RMF) standards following the Checklists and Scans that are administered by DHA.

In this architecture each VM must communicate with the other VM’s in order to function. To achieve this Ports and Protocols of each server shall be established to provide the proper communications between them to the laboratories equipment, printers, computers and Spectacle Request Transmission System (SRTS).

The government will provide new Ports and Protocols of each VM server to establish and provide the proper communications between the VM’s as well as the laboratories equipment, printers, computers and SRTS.

Each Production and Reports VM shall be duplicated at the COOP site to provide redundancy to the production environment. These Servers shall be a complete set of VM’s identical to production except for the names and IP addresses. In the event of a production VM failure the entire environment shall be switched over to the COOP environment. This will require keeping the COOP environment VM’s in sync with the production VM’s in near real time.

In Case of a failover to the COOP VM, switching back to the production VM shall be completed up to 30 days from the failover.

Implementation The implementation of the VM environment shall be a phase approach comprised of the following steps.

Pre Cutover

· Allocate 4 VM’s per the specification above

· Procure IP address, gateway, subnet masks and Domain Name Servers for each server

· Procure DoD Signed Certificates for the new environment

· Install the Red Hat Linux Operating System on all VM’s

· Install the Oracle Database Software on each Database VM

· Install the Web Server Application on the Application VM’s

· Install the Pentaho Reports Application on the Reports Application VM

· Install the DIGI software on all VM’s

· Harden each VM to meet RMF security requirements

· Move an initial copy of the production database over from the Physicals to the VM’s for testing

· Copy all machine interface configuration from production over for testing

· Copy all Reports over for testing

· Perform Scans of each VM for security vulnerabilities and resolve

· Test Application Performance from at least 2 Optical Laboratories

· Validate SRTS communications

· Test Machine interfaces from at least 2 Optical Laboratories

· Test Printing from at least 2 Optical Laboratories

· Establish a process for moving server names and IP address to VM’s

· Build scripts to sync all production VM’s to COOP VM’s

· Establish DoD Signed Certificates for Production and COOP application servers

· Establish DoD Signed Client Certificates for Production and COOP application servers

· Establish fail over procedures from Production to COOP.

Cut Over

· Stop all activities in all laboratories

· Stop all SRTS communications with DOFEMS

· Backup physical servers

· Disconnect all DIGI’s from the Physical Production Server

· Export the production and report databases from the Physical Servers

· Move IP address and Server names to new VM’s

· Establish all DIGI’s on the application VM’s

· Import the production and report databases into the VM’s

· Switch SRTS to the new VM

· Start up all lab equipment interfaces

· Verify each lab is connected and able to run jobs through the lab

· Start SRTS interface to receive orders

Additional Requirements This section lists the responsibilities that are provided by the contractor to keep the Virtual Environments up to date with security requirements and functional. The tasks shall be provided remotely by contractor personnel authorized to access the DHA AVHE desktop and VM’s.

1. Installation and validation of Red Hat 8 Linux security patches

2. Installation and validation of Oracle Database critical security patches

3. Installation and validation of new Apache and Tomcat versions

4. Installation and Validation of new OLSS DOFEMS versions

5. Perform new STIG checklist manual validation and resolve any vulnerabilities

6. Review DHA scans of the system to identify and resolve any vulnerabilities

7. Install, patch and maintain HBSS software in accordance with DHA requirements

8. Installation and validation of new Red Hat 8 Linux versions as required by DHA for security compliance

9. Installation and validation of new Oracle Database versions as required by DHA for security compliance

10. Maintain synchronization scripts between Production and the COOP VM’s

11. Build and Maintain an Oracle Database Synchronization strategy between the 4 servers.

12. Sync Data from the Production Environment to the Test Environment on an as needed basis for testing

Performance Standard: The contractor shall provide remote access assistance as required with a 95% accuracy rate and 100% completion rate of required security patches within agreed upon time limits.

Quality Assurance Surveillance Plan (QASP)

PWS Section
Performance Requirement
Surveillance Method
Frequency
Acceptable Quality Level
New Architecture
All VM’s built in accordance with RMF standards and pass all current checklists and scans prior to install in production.
Information System Security Manger (ISSM) and Engineering Solution Architecture-Business Analytics Division (ESA-BAD) approve requirement specifications and standards upon review and testing.
100% initial inspection of all contract deliverables.
>95% of deliverables submitted timely and without rework required.
New Architecture
Physical servers duplicated and synced at both Primary and COOP locations and communicating properly.
ISSM and ESA-BAD verify functionality and operational ability of the new VM’s.
100% initial inspection of all contract deliverables.
100% functionality with no loss or degradation of database during transition.
New Architecture
Synchronization of Primary and COOP VM’s in near real time.
ISSM and Program Manager verify sync log and data currency.
Periodic
Databases at both locations shall be a mirror image of each other >95% of the time.
Contractor Responsibilities Item 12.
Sync data from Production environment to Test environment as needed to maintain system currencies for testing.
Inspection by the ISSM and Information Systems Security Officer (ISSO).
Periodic
>95% currency of prod test VM prior to any testing of new system upgrades or patches.

INSTRUCTIONS TO QUOTERS

ADDENDUM TO FAR 52.212-1 INSTRUCTIONS TO OFFERORS – COMMERCIAL ITEMS

This section specifies the format and content that contractors shall use in this Request for Quote (RFQ). The intent is not to restrict the contractors in the manner in which they will perform their work but rather to ensure a certain degree of uniformity in the format of the responses for evaluation purposes. Vendors shall submit a quote that is legible and comprehensive enough to provide the basis for a sound evaluation by the Government. Information provided shall be precise, factual, and complete. Legibility, clarity, completeness, and responsiveness are of the utmost importance. Quotes shall be in the form prescribed by, and shall contain a response to each of the areas identified. This document is linked to Notice of Intent Posting N62645-21-Q-0034. The contractor shall submit a quote in response to the requirement to the Naval Medical Logistics Command (NMLC). In accordance with FAR part 13.5 procedures, NMLC intends to award a Firm Fixed Price (FFP) contract to Optical Lab Software Solutions, Inc. (OLSS).

The quote shall be submitted in two separate volumes:

Volume I- Business Volume II – Price

A complete Volume I – Business and Volume II – Price shall be submitted by the closing date specified in this solicitation. If any, one volume is received past the stated closing date specified in the solicitation, the entire quote may be considered late.

VOLUME I: BUSINESS.

· The quoter must be registered in System for Award Management (SAM) in accordance with FAR 52.212-3. The quoter shall verify its SAM record is current, accurate, complete and applicable to this combined synopsis/solicitation as of the date of this quote and is incorporated in this offer by reference. The quoter shall be registered in SAM under the applicable NAICS code for this combined synopsis/solicitation, 541511 Custom Computer Programming Services. The small business size standard is $25M. The quoter shall complete and submit FAR 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (OCT 2015) ALTERNATE I (OCT 2014).

· The quoter shall complete and submit FAR Clause 52.209-11 [Representation By Corporations Regarding Delinquent Tax Liability or a Felony Conviction under any Federal Law (Feb 2016)].

· The quoter shall complete and submit FAR Clause 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT

VOLUME II: PRICE – (Attachment II Pricing Workbook for N62645-21-Q-0034).

The quoter will be evaluated for Completeness and Reasonableness. The Government anticipates award of a Firm Fixed Price contract. The quoter shall submit firm fixed pricing for the above requirement on the attached Microsoft Excel Workbook (Attachment II Pricing Workbook for N62645-21-Q-0034). Include commercial price lists and if applicable, any FSS schedule numbers and pricing; any applicable discounts to the Government.

QUOTE SUBMISSION

The quote shall be submitted via email to usn.detrick.navmedlogcomftdmd.mbx.matrix@mail.mil, SUBJECT: N62645-21-Q-0034. The quote shall be submitted via email only. The quote shall be due no later than 1300 Eastern Time, 02 September 2021.

(End of addendum)

EVALUATION FACTORS FOR AWARD

52.212-2 EVALUATION--COMMERCIAL ITEMS (OCT 2014)

(a) The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:

Evaluation of price will be based on the quoter’s total price for all line items. Past Performance is not an evaluation factor for this acquisition, however information from the Past Performance Information Retrieval System (PPIRS) shall be used in making a responsibility determination.

The quoter’s initial quote shall contain the quoter’s best terms from a price standpoint. The Government intends to evaluate quotes and award a contract without discussions, but reserves the right to conduct discussions if later determined by the Contracting Officer to be necessary. The Government reserves the right to make no award as a result of this solicitation.

VOLUME I: BUSINESS

Completeness – Quoter is registered in SAM, completed and submitted FAR 52.212-3 Alternate I, and completed and submitted FAR 52.209-11 and FAR 52.204-24.

VOLUME II: PRICE

Reasonableness – The degree to which the quoter’s total proposed price represents a fair and reasonable price. Pricing will be examined to determine the degree to which proposed price compares to the price a reasonable prudent person would expect to incur for the same or similar services. Only a quote determined fair and reasonable will be eligible to receive a contract award.

(End of provision)

CONTRACTOR SUPPORT

Notice: Navy Use Of Support Contractor For Contract Closeout Functions

Naval Medical Logistics Command (NMLC) uses two private contractors in support of the contract closeout process. Those companies are Contracting Resources Group (CRG) of Federal Hill, MD, doing business under the authority of the Small Business Administration’s 8(a) program and the Ability One Program, and National Industries for the Blind (NIB) (Ability One Program), doing business under the authority of the Javits-Wagner O’Day Act (41 U.S.C. § 47).

The contract closeout process includes activities such as processing deobligation modifications, obtaining contractor and requiring activity concurrence, preparing the DD-Form 1594 (Contract Completion Statement), and preparing closed files for archiving. Support contractors may perform additional administrative duties, including filing and processing simple administrative modifications. Performing these functions require the contractor employees to have access to the contract file. Therefore, information the Contractor provides to the Government or information already in the possession of the Government may be viewed by these support contractors in the course of performing contract close-out functions. The information that may be made available to the contractor may include pricing and technical responses and performance information.

NMLC has signed Non-Disclosure Agreements with each support contractor employee and has required both contractors to provide a Conflict of interest Mitigation Plan to ensure these employees are firewalled from all business development activity.

By signature of this contract, the quoter consents to access of their business sensitive/confidential or proprietary data by the Government’s support contractor personnel in order to perform close out services.

OTHER CONTRACTING REQUIREMENTS

Risk Management Framework (RMF)

The contractor shall comply with RMF requirements, as specified by the Defense Health Agency (DHA) that meet appropriate DoD, DHA and Navy Cybersecurity requirements. The contractor shall initiate the process by providing the required documentation necessary to submit their system to the Authorizing Official (AO) for assessment and authorization (A&A) for this contract. The requirements shall be met before the contractor's system is authorized to access DoD data or to interconnect with any DoD network or system that receives, processes, stores, displays or transmits DoD data. The contractor shall ensure the proper contractor support staff is available to participate in all phases of the RMF process. This includes, but is not limited to;

Attending and supporting RMF and A&A meetings with Navy and DHA cybersecurity representatives as required.

Support/conduct vulnerability mitigation to comply with cybersecurity controls listed in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53; Security and Privacy Controls for Federal Information Systems and Organizations and DHA Administrative Instruction 77. In order for a system to be authorized, there shall be zero Category 1 findings.

Support the A&A Team during system security testing.

Once the system has been authorized, the contractor shall maintain an acceptable security baseline consistent with the authorization granted by the AO throughout the life of the system. This includes ensuring that all vulnerabilities affecting the operating system, primary application, database and all third party software have validated and applied within 30 days.

Cybersecurity

The vendor shall establish appropriate administrative and technical safeguards to protect any and all data, to ensure the confidentiality, integrity, and availability of Government data under their control. At a minimum, this shall include provisions for vendor personnel security and electronic security.

The proposed system shall be capable of supporting the use of Defense Information Systems Agency (DISA) approved antimalware applications. The Navy uses McAfee Host Based Security System (HBSS) as their solution. The vendor shall provide technical specifications that clearly demonstrate whether the proposed solution can integrate and support, either fully or partially the operation without performance degradation of the medical system/device. In cases where the operation of HBSS is not technically achievable, the vendor shall provide detailed justification and a Plan of Actions and Milestones (POA&M) describing steps towards compliance with this requirement.

The vendor must provide their Antivirus (AV) policy and a list of AV Exceptions (if applicable) to the NMLC prior to AV installation on the system/device. AV must be installed on all devices before they are placed on the Navy network.

Systems shall be configured in such a way to allow for the updating of malware definition signatures on a scheduled basis. Scanning shall encompass the entire system (file system, operating system, real-time processes), by default. In cases where scanning of the entire system may negatively affect its operation, the vendor shall provide a detailed list of exclusions with justifications.

Vulnerability Management

Vulnerability mitigation strategies include security updates, service packs, and changes to operating procedures as physical and cyber vulnerabilities are detected. Operating systems, servers, development platforms and the application being delivered to the Navy shall be in compliance with all known applicable guidelines. The vendor shall agree to be proactive in working with the Navy to mitigate new threats as they emerge.

All vendor validated and approved patches, up to and including the date of install, must be loaded on the system prior to system go-live. Security scans will be run during government acceptance testing. All Category I (CAT I) findings must be remediated prior to government acceptance of the system. A CAT I vulnerability is any vulnerability, the exploitation of which will, directly and immediately result in loss of Confidentiality, Availability, or Integrity. There shall be no more than 10 Category II (CAT II) findings at the time of government acceptance. CAT II vulnerabilities are any vulnerability, the exploitation of which has a potential to result in loss of Confidentiality, Availability, or Integrity.

Domain Name System Realm/Directory Services Contractor will be required to provide technical evidence, if applicable, whether client/server topology based medical systems can integrate with Directory Services and support LDAP authentication.

Local Privileged and Administrative User/Local System Accounts Contractor shall create a single local user account with administrative/root level privileges for purposes of conducting system repairs and maintenance only. This account shall be separate and distinct from the built-in local administrative/root account provided by the Operating System and shall comply with DoD policy. All factors required to complete successful identification, authentication and authorization against the built-in local Administrative/Root level account shall be provided to the MTF Biomedical Engineering Department.

Complete administrative system rights shall be provided to the government System Administrator for the purpose of conducting device vulnerability scans as needed.

DHA Business to Business (B2B) Gateway. All contractor systems that will communicate with DON systems will interconnect through the established DHA Business to Business (B2B) gateway.

Contractors will connect to the B2B gateway via a contractor procured Internet Service Provider (ISP) connection and assume all responsibilities for establishing and maintaining their connectivity to the B2B gateway. This will include acquiring and maintaining the circuit to the B2B gateway and acquiring a Virtual Private Network (VPN) device compatible with the DHA VPN device. Maintenance and repair of contractor procured VPN equipment shall be the responsibility of the contractor.

Contractors shall configure their network to support access to government systems (e.g., configure ports and protocols for access).

Contractors shall provide full time connections to a TIER1 or TIER2 ISP. Dial-up ISP connections are not acceptable.

Contractors will comply with DoD guidance regarding allowable ports, protocols and risk mitigation strategies prior to accessing DoD/DHA networks. All contractors will be required to complete a DISA Form 2875, System Authorization Access Request form (SAAR) and submit it to the Navy PACS Office for processing. Contractor personnel will be required to complete applicable DoD cybersecurity training.

IPv6

The proposed system shall be Internet Protocol version 6 (IPv6) capable or the vendor shall provide a detailed project, migration or planning documentation to show when the proposed system shall be IPv6 capable.

Minimum IPv6 capabilities include:

1. Conformant with the IPv6 standards profile contained in the DoD IT Standards Registry (DISR);

1. Maintaining interoperability in heterogeneous environments with IPv4;

1. Commitment to upgrade as the IPv6 standard evolves;

1. Availability of vendor IPv6 technical support.

1.

The contractor shall be able to demonstrate or provide documentation to prove that their product is IPv6 capable

Health Insurance Portability and Accountability Act (HIPAA) The contractor shall comply with the HIPAA Act of 1996 (Public Law 104-191) requirements, specifically the administrative simplification provision s of the law and the associated rules and regulations published by the Secretary, Health and Human Services (HHS). This includes the Standards for Electronic Transactions, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards.

Business Associate Agreement

This Business Associate Agreement (BAA) incorporates HIPAA/HITECH Act requirements under the HHS Final Omnibus Rule (78 FR 5566, published 25 Jan 2013), effective 23 Sep 2013. This BAA is for use by MHS components outside of DHA.

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a business associate agreement (BAA) between the signatory parties for purposes of the Health Insurance Portability and Accountability Act (HIPAA) and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where 12 Nov 2013 Page 2 of 10 persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein.

Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the contractor.

Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean the Government facility(s) and office(s) that are supported under this contract.

DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD).

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007).

HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by the Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of the Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA.

(d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively), as applicable, the Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI.

(e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524.

(f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526.

(g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528.

(h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and

(i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

II. Permitted Uses and Disclosures by Business Associate

(a) The Business Associate may use or disclose PHI only as necessary to perform the services set forth in the Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by the Agreement or directed by the Covered Entity.

(b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances.

(c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs.

(d) Except as otherwise limited in the Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(e) Except as otherwise limited in the Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Except as otherwise limited in the Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.

III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) The Covered Entity shall provide the Business Associate with the notice of privacy practices that the Covered Entity produces in accordance with 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances.

(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.

(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.

IV. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.

V. Breach Response

(a) In general.

In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.

If the DHA Privacy Office determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the DHA Privacy Office, regardless of whether the breach occurs at DHA or at one of the Service components. If the DHA Privacy Office determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office. The following provisions of Part V set forth the Business Associate’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches.

This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.

(b) Government Reporting Provisions

The Business Associate shall report the breach within one hour of discovery to the US Computer Emergency Readiness Team (US CERT), and, within 24 hours of discovery, to the DHA Privacy Office and the other parties set forth below. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an worker, officer or other agent of the Business Associate.

The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office and the applicable Service-Level Privacy Office, if requested by either. Business Associate questions about US-CERT reporting shall be directed to the DHA or Service-Level Privacy Office, not the US-CERT office.

The Business Associate report due within 24 hours shall be submitted by completing the New Breach Reporting Form DD 2959 at the Breach Response page on the DHA Privacy Office web site and emailing that form to, as applicable, the DHA Privacy Office, the Service-Level Privacy Office, the Contracting Officer (CO) and Contracting Officer’s Representative (COR) and the Business Associate’s DoD point of contact (POC) unless the POC specifies another addressee for breach reporting. Encryption is not required, because Breach Report Forms should not contain PII/PHI. The email address for notices to the DHA Privacy Office is provided at the Privacy Office website breach response page. If electronic mail is not available, telephone notification is also acceptable, but all notifications and reports delivered telephonically must be confirmed by email as soon as technically feasible.

If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the DHA Privacy Office as soon as possible if it believes that “single event” breach response is appropriate; the DHA Privacy Office will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.

When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, follow-up, etc. The Business Associate shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the DHA Privacy Office to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Reporting Form. The Business Associate is responsible for reporting all information needed by the DHA Privacy Office to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.

In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the DHA Privacy Office (or the Service-Level Privacy Office, which will consult with the Privacy Office as appropriate) when determinations on applying the above requirements are needed.

(c) Individual Notification Provisions

If the DHA Privacy Office determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.

The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph V(a) for their review, and for approval by the DHA Privacy Office. Upon request, the Business Associate shall provide the DHA Privacy Office with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group. (PII shall not be included with the text of the letter(s) provided.) Copies of further correspondence with affected individuals need not be provided unless requested by the Privacy Office. The Business Associate’s notification to the individuals, at a minimum, shall include the following:

—The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.

—The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.

—The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.

—The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information.

Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Business Associate and/or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, email address, and postal address.

If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report Form. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the DHA Privacy Office, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with Privacy Office approval.

The Business Associate shall, at no cost to the Government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.

Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber security incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forthhere. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.

VI. Termination

(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subcontractors) with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the Agreement.

(b) Effect of Termination.

(1) If the Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If the Agreement does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below. If the Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if DHA gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or DHA direction.

(2) If the Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of the Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.

(3) If the Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of the Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.

VII. Miscellaneous

(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of the Agreement.

(b) Interpretation. Any ambiguity in the Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA Rules.

Applicable References:

DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT) NIST SP 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems of February 2010, as amended NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .