N68908-17-Q-0034.pdf

PDF 470 KB Posted

Attached to
Cameras and other security equipment Federal contract opportunity
Solicitation number
N68908-17-Q-0034
Issued by
Department of the Navy Bureau of Medicine and Surgery

About this file

Conformed solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to Cameras and other security equipment, newest first.
File Type Posted
N68908-17-Q-0034_Amendment_01.pdf PDF
LSJ_Security_System_GulfPort,_MS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SEE ADDENDUM

(No Collect Calls)

N6890817Q0034 27-Jun-2017

b. TELEPHONE NUMBER

757-953-2671

8. OFFER DUE DATE/LOCAL TIME

05:00 PM 01 Jul 2017

5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 2/2012)

Prescribed by GSA – FAR (48 CFR) 53.212

(TYPE OR PRINT)

(SIGNATURE OF CONTRACTING OFFICER)

ADDENDA ARE

26. TOTAL AWARD AMOUNT (For Gov t. Use Only )

23.

CODE 10. THIS ACQUISITION IS

SUCH ADDRESS IN OFFER

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT

BELOW IS CHECKED

TELEPHONE NO.

N689089. ISSUED BY

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

MICHAEL G. DAVIS

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER

(TYPE OR PRINT)

30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.

25. ACCOUNTING AND APPROPRIATION DATA

1. REQUISITION NUMBER

20.

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

N6890817RC1R202

ARE NOT ATTACHED

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:

. YOUR OFFER ON SOLICITATION

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN

% FOR:SET ASIDE:UNRESTRICTED ORX

SMALL BUSINESS

17a.CONTRACTOR/ CODE FACILITY

OFFEROR CODE

NAVY MEDICINE EAST

ATTN: MICHAEL DAVIS

SUITE 1400

620 JOHN PAUL JONES CIRCLE

PORTSMOUTH VA 23708-2106

18a. PAYMENT WILL BE MADE BY CODE

RATED ORDER UNDER

DPAS (15 CFR 700)

13a. THIS CONTRACT IS A

13b. RATING

CODE15. DELIVER TO CODE N39375 16. ADMINISTERED BY

12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

14. METHOD OF SOLICITATION

RFQ IFB RFPX

NAVAL HEALTH CLINIC GULFPORT

LT PAUL BENOIT

5501 MARVIN SHIELDS BLVD

GULFPORT MS 39501

TEL: 228-822-5765 FAX:

FAX:

TEL: 757-753-7537

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

8(A)

HUBZONE SMALL

BUSINESS

SIZE STANDARD:

$20,500,000

NAICS:

561612

OFFER DATED

29. AWARD OF CONTRACT: REF.

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

EMAIL:

TEL:

31c. DATE SIGNED

SEE SCHEDULE

SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT

24.22.21.19.

WOMEN-OWNED SMALL BUSINESS (WOSB)

ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS

(CONTINUED)

PAGE 2 OF15

ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE

37. CHECK NUMBER

FINALPARTIALCOMPLETE

36. PAYMENT35. AMOUNT VERIFIED

CORRECT FOR

34. VOUCHER NUMBER

FINAL

33. SHIP NUMBER

PARTIAL

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42a. RECEIVED BY (Print)

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 2/2012) BACK

Prescribed by GSA – FAR (48 CFR) 53.212

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

SEE SCHEDULE

20.

SCHEDULE OF SUPPLIES/ SERVICES

21.

QUANTITY UNIT

22. 23.

UNIT PRICE

24.

AMOUNT

19.

ITEM NO.

N6890817Q0034

Section SF 1449 - CONTINUATION SHEET

SECTION A

TIN:

CAGE:

DUNS:

Vendor Point of Contact:

Phone:

Vendor email:

Naval Medicine East Contracting Division

Michael G. Davis

Phone: 757-953-7357

Fax: 757-953-0361

Email: michael.g.davis179.civ@mail.mil

Billing/Payment in Arrears.

Product/Services for:

Navy Medicine East

Vendor to reference RFQ number N68908-17-Q-0034 on all inquires.

Reference:

PROMPT PAYMENT

For Prompt Payment Act Purposes, this contract is:

Subject to the 7-calender day constructive acceptance period.

mailto:michael.g.davis179.civ@mail.mil

ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 1 Lot Security System for a new building

FFP

The below table contains all the information for a security system at Naval Health

Clinic, MS. This table also includes labor/installation and delivery.

FOB: Destination

MILSTRIP: N6890817RC1R202

PURCHASE REQUEST NUMBER: N6890817RC1R202

NET AMT

SECTION B

Qty Manufacturer Part# Description Unit Price

Ext. Price

16 DSX Access Systems, Inc.

921P MultiCLASS SE RPK40 Contactless Smart

921PHRNEK0002D

5 Lenel LNL-1320 Dual Reader Interface Module (Series 2 – Supports OSDP Readers) – 12/24 VDC, 2 Reader Interface, W/M, 8 inputs, 6 (5A) form C relays, RoHS, CE, C-Tick and UL294 certified

1 Lenel 32ES-32RUP 32 Access Readers upgrade for all 32ES systems (max of 64 readers).

3 Lenel LNL-2220 Intelligent Dual Reader Controller – 12 or 24 VDC @ 700mA, size (6 (152mm) W x 8 (203mm) L x 1 (25mm)H), (5 year lithium battery or 3 months full run) 6 MB standard cardholder flash memory, 50,000 of Event memory, maximum of 32 devices, On-board Ethernet, on-board two door control, eight inputs, four outputs, cabinet tamper and power fault input monitors. RoHS, CE, C-Tick and UL 294.

4 Lenel LNL-AL600ulx-

4CB6

Lenel UL Listed Power Supply

– 12VDC 6A output, 115VAC (1.6 amps) input, continuous supply current with enclosure (24” x 18” x 4.5”), lock, tamper switch, power distribution module, UPS capable (Battery Optional) UL & CUL Approved

10 Honeywell WG-11041101 HW:22/4 STR JKT 1M BX WHT

5 Honeywell WG-11181101 HW:18/2 STR JKT 1M BX WHT

5 Honeywell WG-12061109 HW:22/6 STR OAS 1M BX

GRY

1 Security Door Controls

PTH-4Q SDC:Four (4) Conductor Power Transfe

1 Interlogix (UTC Fire & Security)

1078CTW-N UTC:Magnetic Contact, Steel Door, Recess

6 Power Sonic Corp

PS1270 PWS:Battery, 12V, 7AMP Hour, F1

1 Cisco SRW208P-K9-

NA

CIS:SF 302-08P 8-Port 10/100 PoE

2 Altronix AL600ULACMCB ALT:Access Control 8 PTC P/S 12/24

1 Corbin Russwin ML20906 66

SEC M922

Corbin Russwin Electric Mortise

2 Axis Communications

0804-001 M3045-V

3 Axis Communications

0515-001 Axis M3007-PV

5 Lenel SW-LNR-CH1 Lenel Network Video Recorder Software – Includes a single channel software license for one IP / Network based camera channel to be used with either a customer provided PC or adding onto a turnkey system. The customer provided PC must meet or exceed the Minimum DVC-EX PC configuarion requirements listed above (maximum of 63 IP/network channels per recorder based on video resolution, framerate, quality and processing options being utilized).

2 Honeywell WG-50921006 HW:23/4PR CAT6+ CMR 1M

RL BLU

1 Dell 7040 Optiplex Optiplex 7040 SFF 1020180203140

1 Warranty

1 Connectors, Fasteners, Fittings, Cable Hangars, Labeling, data jacks.

2 Securadyne 110200-500 “SS:22-4C Plen Shld 500”

WHT

2 Honeywell 6160V HW:Keypad, Alpha, Ademco, Voice

261 Installation

30 PM Internal

15 CAD

24 Travel

1 Freight

INSPECTION AND ACCEPTANCE TERMS

Supplies/services will be inspected/accepted at:

CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY

0001 Destination Government Destination Government

DELIVERY INFORMATION

CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /

CAGE

0001 31-AUG-2017 1 NAVAL HEALTH CLINIC GULFPORT

LT PAUL BENOIT

5501 MARVIN SHIELDS BLVD

GULFPORT MS 39501

228-822-5765

FOB: Destination

N39375

CLAUSES INCORPORATED BY REFERENCE

52.204-9 Personal Identity Verification of Contractor Personnel JAN 2011

52.209-2 Prohibition on Contracting with Inverted Domestic

Corporations--Representation

NOV 2015

52.209-6 Protecting the Government's Interest When Subcontracting

With Contractors Debarred, Suspended, or Proposed for

Debarment

OCT 2015

52.209-10 Prohibition on Contracting With Inverted Domestic

Corporations

NOV 2015

52.209-11 Representation by Corporations Regarding Delinquent Tax

Liability or a Felony Conviction under and Federal Law

FEB 2016

52.211-17 Delivery of Excess Quantities SEP 1989

52.212-1 Instructions to Offerors--Commercial Items JAN 2017

52.212-2 Evaluation - Commercial Items OCT 2014

52.212-3 Offeror Representations and Certifications--Commercial

Items

JAN 2017

52.212-4 Contract Terms and Conditions--Commercial Items JAN 2017

52.212-5 (Dev) Contract Terms and Conditions Required to Implement

Statutes or Executive Orders--Commercial Items (Deviation

2013-O0019)

JAN 2017

52.222-3 Convict Labor JUN 2003

52.222-19 Child Labor -- Cooperation with Authorities and Remedies OCT 2016

52.222-21 Prohibition Of Segregated Facilities APR 2015

52.222-26 Equal Opportunity SEP 2016

52.222-50 Combating Trafficking in Persons MAR 2015

52.223-18 Encouraging Contractor Policies To Ban Text Messaging

While Driving

AUG 2011

52.232-33 Payment by Electronic Funds Transfer--System for Award

Management

JUL 2013

52.232-40 Providing Accelerated Payments to Small Business

Subcontractors

DEC 2013

52.233-3 Protest After Award AUG 1996

52.233-4 Applicable Law for Breach of Contract Claim OCT 2004

252.203-7000 Requirements Relating to Compensation of Former DoD

Officials

SEP 2011

252.203-7002 Requirement to Inform Employees of Whistleblower Rights SEP 2013

252.203-7005 Representation Relating to Compensation of Former DoD

Officials

NOV 2011

252.204-7003 Control Of Government Personnel Work Product APR 1992

252.204-7008 Compliance With Safeguarding Covered Defense Information

Controls

OCT 2016

252.204-7012 Safeguarding Covered Defense Information and Cyber

Incident Reporting

OCT 2016

252.204-7015 Notice of Authorized Disclosure of Information for Litigation

Support

MAY 2016

252.211-7003 Item Unique Identification and Valuation MAR 2016

252.223-7006 Prohibition On Storage, Treatment, and Disposal of Toxic or

Hazardous Materials

SEP 2014

252.223-7008 Prohibition of Hexavalent Chromium JUN 2013

252.225-7000 Buy American--Balance Of Payments Program Certificate--

Basic (Nov 2014)

NOV 2014

252.225-7001 Buy American And Balance Of Payments Program-- Basic

(Dec 2016)

DEC 2016

252.225-7002 Qualifying Country Sources As Subcontractors DEC 2016

252.225-7048 Export-Controlled Items JUN 2013

252.232-7003 Electronic Submission of Payment Requests and Receiving

Reports

JUN 2012

252.232-7006 Wide Area WorkFlow Payment Instructions MAY 2013

252.232-7010 Levies on Contract Payments DEC 2006

252.237-7010 Prohibition on Interrogation of Detainees by Contractor

Personnel

JUN 2013

252.243-7001 Pricing Of Contract Modifications DEC 1991

252.244-7000 Subcontracts for Commercial Items JUN 2013

252.246-7000 Material Inspection And Receiving Report MAR 2008

252.246-7008 Sources of Electronic Parts OCT 2016

CONTRACTOR ACCESS

SUP 5252.204-9400 Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information (July 2013)

Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement

Federal security standards for Federal employees and contractors. The Deputy Secretary of Defense Directive-Type

Memorandum (DTM) 08-006 - "DoD Implementation of Homeland Security Presidential Directive - 12 (HSPD-12)" dated November 26, 2008 (or its subsequent DoD instruction) directs implementation of HSPD-12. This clause is in accordance with HSPD-12 and its implementing directives.

APPLICABILITY

This clause applies to contractor employees requiring physical access to any area of a federally controlled base, facility or activity and/or requiring access to a DoN or DoD computer/network/system to perform certain unclassified sensitive duties. This clause also applies to contractor employees who access Privacy Act and Protected

Health Information, provide support associated with fiduciary duties, or perform duties that have been identified by

DON as National Security Position, as advised by the command security manager. It is the responsibility of the responsible security officer of the command/facility where the work is performed to ensure compliance.

Each contractor employee providing services at a Navy Command under this contract is required to obtain a

Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Navy Command's Security Manager upon arrival to the Navy

Command and shall out-process prior to their departure at the completion of the individual's performance under the contract.

ACCESS TO DOD IT SYSTEMS

In accordance with SECNAV M-5510.30, contractor employees who require access to DoN or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to information protected under the Privacy Act, to include Protected Health Information (PHI).

All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity's Command Information

Assurance Manager. Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) which is a higher level investigation than the

National Agency Check with Law and Credit (NACLC) described below. Due to the privileged system access, a

SSBI suitable for High Risk public trusts positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1, and must be trained and certified on the Operating System or Computing Environment they are required to maintain.

Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to

IT systems is required for performance of the contractor employee's duties, such employees shall in-process with the

Navy Command's Security Manager and Information Assurance Manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual's performance under the contract.

Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-Ni therefore, the government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the "supervisor".

The SAAR-N shall be forwarded to the Navy Command's Security Manager at least 30 days prior to the individual's start date. Failure to provide the required documentation at least 30 days prior to the individual's start date may result in delaying the individual's start date.

When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Information Assurance (IA) training, and maintain a current requisite background investigation. The Contractor's Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.

INTERIM ACCESS

The Navy Command' s Security Manager may authorize issuance of a DoD CAC and interim access to a DoN or

DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.

DENIAL OR TERMINATION OF ACCESS

The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.

CONTRACTOR'S SECURITY REPRESENTATIVE

The contractor shall designate an employee to serve as the Contractor's Security Representative. Within three work days after contract award, the contractor shall provide to the requiring activity's Security Manager and the

Contracting Officer, in writing, the name, title, address and phone number for the Contractor's Security

Representative. The Contractor's Security Representative shall be the primary point of contact on any security matter. The Contractor's Security Representative shall not be replaced or removed without prior notice to the

Contracting Officer and Command Security Manager.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS OR PERFORMING SENSITIVE

DUTIES

Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Navy recognizes contractor employees under this contract as Non-

Critical Sensitive [ADP/IT-II] when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and Protected Health

Information (PHI), provide support associated with fiduciary duties, or perform duties that have been identified by

DON as National Security Positions. At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The NACLC consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:

* SF-86 Questionnaire for National Security Positions (or equivalent OPM investigative product)

* Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)

* Original Signed Release Statements

Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than 10 years) throughout the contract performance period. The Contractor's

Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.

Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the Navy

Command's Security Manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy Command's Information Assurance Manager. Completion and approval of a System

Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information

Technology resources. The SAAR-N shall be forwarded to the Navy Command's Security Manager at least 30 days prior to the individual's start date. Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date.

The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual

Information Assurance (IA) training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the Navy Command

Security Manager. The Navy Command's Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (OPM). Suitability/security issues identified by the Navy may render the contractor employee ineligible for the assignment. An unfavorable determination made by the Navy is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The Navy Command's Security

Manager will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DON Central Adjudication Facility (CAF) for a determination.

If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a Visit Authorization Request (VAR) via the Joint Personnel Adjudication System (JPAS) or a hard copy

VAR directly from the contractor's Security Representative. Although the contractor will take JPAS "Owning" role over the contractor employee, the Navy Command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The contractor shall include the IT

Position Category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee's performance under the contract.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO OR PERFORMING NON-SENSITIVE DUTIES

Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc ...) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:

* Must be either a US citizen or a US permanent resident with a minimum of 3 years legal residency in the United

States (as required by The Deputy Secretary of Defense DTM 08-006 or its subsequent DoD instruction) and

* Must have a favorably completed National Agency Check with Written Inquiries (NACI) including a FBI fingerprint check prior to installation access.

To be considered for a favorable trustworthiness determination, the Contractor's Security Representative must submit for all employees each of the following:

* SF-85 Questionnaire for Non-Sensitive Positions

* Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)

* Original Signed Release Statements

The contractor shall ensure each individual employee has a current favorably completed National Agency Check with Written Inquiries (NACI) or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM.

Failure to provide the required documentation at least 30 days prior to the individual's start date may result in delaying the individual's start date.

* Consult with your Command Security Manager and Information Assurance Manager for local policy when IT-III

(non-sensitive) access is required for non-US citizens outside the United States.

CLAUSES INCORPORATED BY FULL TEXT

PRIVACY AND SECURITY OF PROTECTED HEALTH INFORMATION

1. Introduction

In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy Regulation,” January 24, 2003, the Contractor meets the definition of Business Associate. Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Business Associate agrees to abide by all applicable

HIPAA Privacy and Security requirements regarding health information as defined in this clause, and in DoD

6025.18-R and DoD 8580.02, as amended. Additional requirements will be addressed when implemented.

a. Definitions. As used in this clause generally refer to the Code of Federal Regulations (CFR) definition unless a more specific provision exists in DoD 6025.18-R or DoD 8580.02.

(1) HITECH Act shall mean the Health Information Technology for Economic and Clinical Health Act included in the American Recovery and Reinvestment Act of 2009.

(2) Individual has the same meaning as the term “individual” in 45 CFR 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).

(3) Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.

(4) Protected Health Information has the same meaning as the term “protected health information” in 45 CFR

160.103, limited to the information created or received by the Business Associate from or on behalf of the

Government pursuant to the Contract.

(5) Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.

(6) Required by Law has the same meaning as the term “required by law” in 45 CFR 164.103.

(7) Secretary means the Secretary of the Department of Health and Human Services or his/her designee.

(8) Security Incident will have the same meaning as the term “security incident” in 45 CFR 164.304, limited to the information created or received by Business Associate from or on behalf of Covered Entity.

(9) Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part

164, subpart C.

(10) Terms used, but not otherwise defined, in this Clause shall have the same meaning as those terms in 45

CFR 160.103, 160.502, 164.103, 164.304, and 164.501.

b. The Business Associate shall not use or further disclose Protected Health Information other than as permitted or required by the Contract or as Required by Law.

c. The Business Associate shall use appropriate safeguards to maintain the privacy of the Protected Health

Information and to prevent use or disclosure of the Protected Health Information other than as provided for by this

Contract.

d. The HIPAA Security administrative, physical, and technical safeguards in 45 CFR 164.308, 164.310, and

164.312, and the requirements for policies and procedures and documentation in 45 CFR 164.316 shall apply to

Business Associate. The additional requirements of Title XIII of the HITECH Act that relate to the security and that are made applicable with respect to covered entities shall also be applicable to Business Associate. The Business

Associate agrees to use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Contract.

e. The Business Associate shall, at their own expense, take action to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of Protected Health Information by the

Business Associate in violation of the requirements of this Clause. These mitigation actions will include as a minimum those listed in the TMA Breach Notification Standard Operating Procedure (SOP), which is available at:

http://www.tricare.mil/tmaprivacy/breach.cfm

f. The Business Associate shall report to the Government any security incident involving protected health information of which it becomes aware.

g. The Business Associate shall report to the Government any use or disclosure of the Protected Health

Information not provided for by this Contract of which the Business Associate becomes aware.

h. The Business Associate shall ensure that any agent, including a sub Business Associate, to whom it provides

Protected Health Information received from, or created or received by the Business Associate, on behalf of the

Government, agrees to the same restrictions and conditions that apply through this Contract to the Business

Associate with respect to such information.

i. The Business Associate shall ensure that any agent, including a subBusiness Associate, to whom it provides electronic Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.

j. The Business Associate shall provide access, at the request of the Government, and in the time and manner reasonably designated by the Government to Protected Health Information in a Designated Record Set, to the

Government or, as directed by the Government, to an Individual in order to meet the requirements under 45 CFR

164.524.

k. The Business Associate shall make any amendment(s) to Protected Health

Information in a Designated Record Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government, and in the time and manner reasonably designated by the Government.

l. The Business Associate shall make internal practices, books, and records relating to the use and disclosure of

Protected Health Information received from, or created or received by the Business Associate, on behalf of the

Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner reasonably designated by the Government or the Secretary, for purposes of the Secretary determining the

Government’s compliance with the Privacy Rule.

m. The Business Associate shall document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.

n. The Business Associate shall provide to the Government or an Individual, in time and manner reasonably designated by the Government, information collected in accordance with this Clause of the Contract, to permit the

Government to respond to a request by an Individual for an accounting of disclosures of Protected Health

Information in accordance with 45 CFR 164.528.

2. General Use and Disclosure Provisions

Except as otherwise limited in this Clause, the Business Associate may use or disclose Protected Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health

Information would not violate the HIPAA Privacy Rule, the HIPAA Security Rule, DoD 6025.18-R or DoD 8580.02 if done by the Government. The additional requirements of Title XIII of the HITECH Act that relate to privacy and that are made applicable with respect to covered entities shall also be applicable to Business Associate.

3. Specific Use and Disclosure Provisions

a. Except as otherwise limited in this Clause, the Business Associate may use Protected Health Information for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the

Business Associate.

b. Except as otherwise limited in this Clause, the Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

c. Except as otherwise limited in this Clause, the Business Associate may use Protected Health Information to provide Data Aggregation services to the Government as permitted by 45 CFR 164.504(e)(2)(i)(B).

d. Business Associate may use Protected Health Information to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).

4. Obligations of the Government

Provisions for the Government to Inform the Business Associate of Privacy Practices and Restrictions

a. The Government shall provide the Business Associate with the notice of privacy practices that the Government produces in accordance with 45 CFR 164.520.

b. The Government shall provide the Business Associate with any changes in, or revocation of, permission by

Individual to use or disclose Protected Health

Information, if such changes affect the Business Associate’s permitted or required uses and disclosures.

c. The Government shall notify the Business Associate of any restriction to the use or disclosure of Protected

Health Information that the Government has agreed to in accordance with 45 CFR 164.522.

5. Permissible Requests by the Government

The Government shall not request the Business Associate to use or disclose

Protected Health Information in any manner that would not be permissible under the HIPAA Privacy Rule, the

HIPAA Security Rule, or any applicable Government regulations (including without limitation, DoD 6025.18-R and

DoD 8580.02) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Business Associate as otherwise permitted by this clause.

6. Termination

a. Termination. A breach by the Business Associate of this clause, may subject the Business Associate to termination under any applicable default or termination provision of this Contract.

b. Effect of Termination.

(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below

(2) If this contract does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Business Associate shall return or destroy all

Protected Health Information received from the Government, or created or received by the Business Associate on behalf of the Government. This provision shall apply to Protected Health Information that agents of the Business

Associate may come in contact. The Business Associate shall retain no copies of the Protected Health Information.

(3) If this contract does not have records management provisions and the Business Associate determines that returning or destroying the Protected Health Information is infeasible, the Business Associate shall provide to the

Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the

Government and the Business Associate that return or destruction of Protected Health Information is infeasible, the

Business Associate shall extend the protections of this Contract to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such Protected Health Information.

7. Miscellaneous

a. Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02, Privacy Rule or Security Rule means the section currently in effect or as amended, and for which compliance is required.

b. Survival. The respective rights and obligations of Business Associate under the “Effect of Termination” provision of this Clause shall survive the termination of this Contract.

c. Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the

Government to comply with DoD 6025.18-R, DoD 8580.02, the HIPAA Privacy Rule or the HIPAA Security Rule.

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

FAR Clauses http://acquisition.gov/far/

DFAR Clauses http://www.acq.osd.mil/dpap/dars/dfars/index.htm http://acquisition.gov/far/

(End of clause)

File details come from the government source that posted it. Updated .