P01 PWS OMLA NPDB Contract_ISO Lang (002).docx
DOCX document 102 KB Posted
- Attached to
- R499--Request for Information - OMLA Review Panelists Federal contract opportunity
- Solicitation number
- 36C10X22Q0059
About this file
This Request for Information from the Department of Veterans Affairs seeks input on the capability to provide evaluation of the standard of care associated with paid malpractice claims. Responses are requested by January 24, 2022 to be submitted to two Contracting Officers.
The agency intends to use responses to inform acquisition planning and strategy for a potential future contract. The attached draft Performance Work Statement outlines requirements for a wide array of physician specialties and allied health professionals to participate as Contract Panel members in reviews. Interested parties are asked to describe their technical understanding of and capability to meet the needs, including strategies for attracting and maintaining healthcare personnel, onboarding processes, and technology support. Relevant past performance examples are also requested.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10X22Q0059_1.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS) OMLA Review Panelists
1. GENERAL:
1.1. Services Provided: The Department of Veterans Affairs (VA) Veterans Health Administration (VHA) Office of Medical-Legal Affairs (OMLA), requires Contractor assistance to support OMLA’s provision of high-quality Paid Malpractice Claim Review Panel (RPs). This requires a Contractor that can provide a very diverse group of physician specialty/sub-specialty, allied health, and other professions that can participate, via phone, in RP discussions and determinations regarding standard of care and potential Veteran’s Health Administration (VHA) National Practitioner Data Bank (NPDB) reporting. Contract Panel Participants (CPPs) must be able to provide a thorough, accurate, well organized, CPP Written Summary and Evaluation of Care (WSEC) and participate in the required RP.
1.1.1. A large portion of paid claims involve multiple practitioners from diverse physician specialties and subspecialties as well as allied health and other professions. This requires readily available access to diverse types of practitioners for RP participation and determination.
1.1.2. This contract is for an estimated 725 OMLA tasks per order.
1.1.2.1. A task is defined as providing a WSEC and participating in the RP.
1.1.3. The entire process for NPDB can be found in VHA Handbook 1100.17 National Practitioner Data Bank (NPDB) Reports, December 28, 2009.
1.2. Scope: OMLA oversees the evaluation of the standard of care associated with paid malpractice claims. Domain knowledge criteria are specified below:
1.2.1. Contractor Personnel Requirements: Personnel proposed shall have an in-depth knowledge of health care processes in addition to the following:
1.2.1.1. Provide key personnel to support cadre of CPPs
1.2.1.2. Recruit/retain a large, diverse group of experienced actively practicing practitioners with availability for scheduling RP participation and determination
1.2.1.3. Support VA remote access to VA electronic review materials.
1.2.1.4. Provide key personnel to support RP determination
1.2.1.5. Coordinate schedules of diverse group of actively practicing practitioners
1.2.1.6. Ensure attendance at agreed upon date and time
1.2.1.7. Manage CPP RP participation in the RP determination
1.2.1.8. Provide key personnel to support WSEC
1.2.1.9. Provide in-depth knowledge of review of medical records for standard of care determinations
1.2.1.10. Assess review materials for completeness and identify involved practitioners
1.2.1.11. Ensure accuracy and completeness in WSEC
1.2.1.12. Ensure format, clarity, spelling, and grammar meet requirements.
1.2.1.13. Support quality deliverables per schedule
1.3. Place of Performance – Services shall be at the Contractors geographical location. There will be no work conducted on any Government Property. All services shall be off-site with no reimbursement for travel.
1.4. Authority Title 38 C.F.R 46 Policy Regarding Participation in National Practitioner Data Bank https://www.govinfo.gov/content/pkg/CFR-1998-title38-vol2/pdf/CFR-1998-title38-vol2-part46.pdf
1.5. Applicable Documents The contractor shall be subject to the following policies, including any subsequent updates during the period of performance: Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA and VHA Directives and Handbooks as VA and VHA personnel regarding information and information system security, unless exception approved by VA.
1.5.1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”
1.5.2. 38 U.S.C. §7332, “HIV Infection and Sickle Cell Anemia Medical Records”.
1.5.3. 38 U.S.C. §5701, “VA Claims Confidentiality Statute”.
1.5.4. Federal Information Security Management Act (FISMA).
1.5.5. Privacy Act and the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
1.5.6. Public Law 109-461, 5725, Confidentiality of Drug Abuse, Alcoholism and Alcohol Abuse.
1.5.7. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
1.5.8. FIPS Pub 201, “Personal Identity Verification of Federal Employees and Contractors,” March 2006
1.5.9. 10 U.S.C. § 2224, "Defense Information Assurance Program"
1.5.10. Software Engineering Institute, Software Acquisition Capability Maturity Modeling (SA CMM) Level 2 procedures and processes
1.5.11. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
1.5.12. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
1.5.13. Department of Veterans Affairs (VA) Directive 0710, “Personnel Suitability and Security Program,” June 04, 2010
1.5.14. VA Directive 6102, “Internet/Intranet Services,” July 15, 2008
1.5.15. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
1.5.16. OMB Circular A-130, “Management of Federal Information Resources,” November 28, 2000
1.5.17. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services CHAMPUS)/TRICARE”
1.5.18. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
1.5.19. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998
1.5.20. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
1.5.21. VA Directive 6500, Managing Information Security Risk: VA Information Security Program, September 20, 2012
1.5.22. VA Handbook 6500, Risk Management Framework for VA Information Systems– Tier 3: VA Information Security Program, March 10, 2015
1.5.23. VA Handbook 6500.1, Electronic Media Sanitization, November 03, 2008
1.5.24. VA Handbook 6500.2, Management of Data Breaches Involving Sensitive Personal Information (SPI), July 28, 2016
1.5.25. VA Handbook 6500.3, Certification and Accreditation of VA Information Systems, February 03, 2014
1.5.26. VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle, March 22, 2010
1.5.27. VA Handbook 6500.6, “Contract Security,” March 12, 2010
1.5.28. VA Technical Reference Model (TRM) (reference at https://www.voa.va.gov/)
1.5.29. National Institute Standards and Technology (NIST) Special Publications
1.5.30. VA Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment, October 15, 2014
1.5.31. VA Directive 6300, Records and Information Management, February 26, 2009
1.5.32. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
1.5.33. VHA Handbook 1100.17, National Practitioner Data Bank (NPDB) Reports, December 28, 2009.
1.5.34. OMB Memorandum, “Transition to IPv6”, September 28, 2010
1.5.35. Federal Rules of Civil Procedure, Rule 26(b)(4)
1.5.36. VHA Directive 1083: Notification of Medical Malpractice (tort) Claims to involved Practitioners
1.5.37. VA’s Memorandum of Understanding for VA participation in the National Practitioner Data Bank
1.6. Definitions/Acronyms- Terms used in this contract shall be interpreted as follows unless the context expressly requires a different construction and/or interpretation. In case of a conflict in language between the definitions and other sections of this contract, the language in this section shall govern.
1.6.1. Contracting Officer (CO) – The person executing this contract on behalf of the Government with the authority to enter into and administer contracts and make related determinations and findings.
1.6.2. Contracting Officer’s Representative (COR) – A person appointed by the CO to take necessary action to ensure the Contractor performs in accordance with and adheres to the specifications contained in the contract and to protect the interest of the Government. The COR shall report to the CO promptly any indication of non-compliance in order that appropriate action can be taken.
1.6.3. CPP – Contract Panel Participant
1.6.4. CPARS: Contractor Performance Assessment Reporting System
1.6.5. EMR – Electronic Medical Records – The official system of health care records used by the Department of Veterans Affairs
1.6.6. ERM – Electronic Review Materials – Additional review materials provided by OMLA
1.6.7. Episode of Care – Is broadly defined as the dates of the relevant health care encounters that led to the paid tort claim. This includes care that was provided (or failed to be provided) at relevant health care encounters (or omission of encounters) or associated relevant care (or omission of care).
1.6.8. HIPAA: Health Insurance Portability and Accountability Act
1.6.9. ISO: Information Security Officer
1.6.10. MOU – Memorandum of Understanding - Per VHAs Memorandum of Understanding with the Department of Health and Human Services, VHA reviews the episode of care associated with a paid VHA malpractice claim and when substandard care was provided by a licensed practitioner, the involved practitioner is reported by VHA to the NPDB.
1.6.11. NPDB – National Practitioner Data Bank is a congressionally mandated repository of health care practitioner information for licensed practitioners whose care is associated with a paid malpractice claim. Veterans Health Administration (VHA) malpractice claims are filed against the government and not a specific VHA practitioner; however, VHA does participate in the NPDB malpractice claim reporting process
1.6.12. OMLA – Office of Medical-Legal Affairs
1.6.13. Paid Claim - This contract is limited to paid medical malpractice (tort) claims for damages, submitted through the Federal Tort Claims Act process, associated with alleged personal injury or death caused by the negligent or wrongful act or omission of a Government employee (including contract personnel acting on behalf of the government) while acting within the scope of his or her office or employment, under circumstances where the United States government, if a private person, would be liable in accordance with the law of the place where the act or omission occurred.
1.6.14. Physician Panelist – See description under key personnel.
1.6.15. POP: Period of Performance
1.6.16. PWS: Performance Work Statement
1.6.17. Practitioner Statement – Per VA Regulation, all practitioners involved in the episode of care are to be notified of a paid claim. The OMLA RP will be convened for the purpose of determining if an NPDB report is required. This is without regard to their employment status of attending, resident, fellow, other trainee, or supervising practitioner at the time of the episode of care. This applies equally to practitioners that are still in the VA system, prior VA practitioners that are now in the community and contract providers. This Regulation does not mandate a statement be provided by the practitioner, only that the practitioner is offered the opportunity to provide a statement for the RP members’ consideration.
1.6.18. PM – Project Manager
1.6.19. PMBOK – Project Management Body of Knowledge
1.6.20. PMP – Project Management Plan
1.6.21. QASP: Quality Assurance Surveillance Plan
1.6.22. RMP – Risk Management Plan
1.6.23. RP – OMLA Paid Malpractice Claim Review Panel - A group of at least three reviewers discussing the episode of care for a paid malpractice claim. The RP will have at least one member of the same specialty as the care under review. The group will decide if the standard of care was met. The group will decide if there in an involved practitioner that needs to be reported to the NPDB. The group may decide there was a systems issue. The Director of OMLA (or designee) is present at all panels to provide guidance and is a non-voting member.
1.6.24. Substandard Care – Not meeting the standard of care in effect at the time of the incident
1.6.25. Standard of Care - The ordinary level of skill and care that any health care practitioner would be expected to observe in caring for patients.
1.6.26. VA – Department of Veterans Affairs
1.6.27. VHA - Veterans Health Administration : The central office for administration of the VA medical centers throughout the United States.
1.6.28. WSEC – Written Summary and Evaluation of Care – CPPs written evaluation of assigned task to review, based on review of practitioner statement(s), electronic medical records and/or other pertinent review materials.
2. QUALIFICATIONS:
2.1. All Contract Personnel – Conflict of Interest: The Contractor and all CPP(s) are responsible for identifying and communicating to the CO and/or COR conflicts of interest at the time of proposal and during the entirety of contract performance. CPPs assigned to this contract must disclose a conflict of interest with a different VA or VHA contract that involves the review of protected patient records or protected review materials such as peer review determinations. If conflict is found, CPPs involvement will be determined by the government.
2.1.1. All Contractor personnel and all CPPs are subject to immediate removal from performance of this contract if they are involved in a violation of the law, VA security, confidentiality requirements, and/or other disciplinary reasons.
2.1.2. The Government reserves the right of refusal to any Contractor personnel and all CPPs on the roster.
2.2. CPP Personnel: In support of VHA’s required participation in the NPDB paid malpractice claim reporting process, the Contractor shall provide CPPs for RP Participation. The types of CPPs required are determined by each paid malpractice claim’s medical specialty and/or profession involved in the episode of care. OMLA historical data (attachment C) was used to develop a table of predicted yearly OMLA notifications for CPPs by type and volume. This is provided in attachment D. OMLA notifications for CPPs may vary from the types and amount listed. The requirements and qualifications for panelists are:
2.2.1. License – The CPP shall have a current license to practice medicine (or non-physician license, if applicable) in any State, Territory, or Commonwealth of the United States or the District of Columbia.
2.2.2. Experience - minimum of five years of experience in their specialty, subspecialty or profession for which they are listed.
2.2.3. Board Certification - Shall be board certified in the specialty they are reviewing according to the American Board of Specialties or equivalent (e.g., American Board of Physician Specialties). With suitable credentials (e.g., multiple board certifications), Contractor may list the same CPP for more than one specialty listed in attachment D.
2.2.4. Shall be in active practice at least 20-hours per month. Short-term exceptions to this requirement will be considered on a case-by-case basis by the COR.
2.2.5. Possess knowledge of current evidence-based standards of care relevant to the case under review.
2.2.6. Not be employees or contractors of VA providing direct care to Veterans; (limited exceptions may be considered on a case-by-case basis).
2.2.7. Training (VA MANDATORIES): Contractor shall meet all VA educational requirements and mandatory course requirements defined herein; all training must be completed by the contractor’s as required by the VA. Other training may become required. VA will communicate any changes to the training requirement to the contractor. All training required is listed here (TMS courses) and associated time.
| Training |
| Frequency (once a year, etc.) |
| Annual Hours |
| VA Privacy and Information Security Awareness and Rules of Behavior (10176) |
| 1 |
| 1 |
| VHA Privacy and HIPAA Focused Training (10203) |
| 1 |
| 1 |
2.2.8. All VA on-boarded CPPs (required and optional) shall be contract personnel for the duration of the contract and are responsible for completion of all deliverables, unless a replacement is approved by OMLA.
2.2.9. Submissions shall include a resume or curriculum vitae (CV) for each CPP listed. These shall clearly state the type of CPP practice and board certification(s).
2.2.10. Not be excluded from receiving payment from any Federal healthcare program confirmed through screening through the Health and Human Services (HHS) Office of Inspector General (OIG) List of Excluded Individuals and Entities (LEIE).
2.2.11. The contractor shall verify eligibility of reviewers via current URAC credentialing standards.
2.2.12. If contractor’s physician(s) is/are not credentialed and privileged or has credentials/privileges suspended or revoked, the Contractor shall remove the CPP from the roster. The Contractor must provide a substitute without any additional cost to the government. If the CPP is removed in the midst of a task, the replacement is at no cost to the government.
2.2.13. Type of CPPs: See attachment D for the type of CPP specialties to be provided for this contract.
2.2.13.1. Required Specialty: Specialty is a requirement in panel roster
2.2.13.2. Optional Specialty: Specialty is not a requirement in panel roster, however, OMLA may request to onboard if a task notification requires specified tort claim specialty.
2.2.13.3. Managing CPP turnover – If Contractor is aware of a departure from employment of an existing CPP, the Contractor shall provide a CPP change form (attachment E) within 5 business days. Replacement CPP must meet the requirements as listed and onboard in compliance with this document.
2.2.13.4. OMLA CPP Addition - If OMLA has a newly identified need for a specialty, subspecialty, or profession, OMLA will notify the Contractor of the needed CPP. The Contractor shall onboard in compliance with this document.
2.3. Key Personnel - Certain skilled experienced professional and/or technical personnel are essential for meeting the requirements. These individuals are defined as “Key personnel”. A list of key Personnel shall be included on the monthly roster deliverable.
2.3.1. Team members that are included in Key Personnel must include:
2.3.1.1. Project Manager
2.3.1.2. Medical Director must
2.3.1.2.1. Be a Physician
2.3.1.2.2. Represent knowledge and ability to perform oversight in the following Disciplines: Medicine, Surgery, Mental Health, Primary Care, Emergency Medicine
2.3.1.2.3. Have access to consult with personnel with a requested medical specialty on an ad hoc basis.
2.3.1.2.4. Review the WSECs for clinical sufficiency and serve as a resource for clinical guidance.
2.3.1.2.5. Review the credentialing files and provide any other medical guidance for clinical oversight.
2.3.1.2.6. Participate in calls at the request of the VA
2.3.1.3. Clinical Abstractors –
2.3.1.3.1. Must be an RN, exceptions to this requirement will be considered on a case-by-case basis by the COR.
2.3.1.3.2. Review allegation of paid tort claim
2.3.1.3.3. Compile chronology of health encounters for tort claim
2.3.1.4. IT Personnel
2.3.1.5. Quality Assurance – Is not required to be licensed clinician
2.3.1.6. Physician Panelist – A cadre of at least 10 (ten) Physicians to be available at the government’s discretion, to serve as a panel quorum member. Same qualifications apply as per CPPs. Physician Panelist will be present for panel purposes only, no task notification or WSEC deliverable required. There are no restrictions on Physician specialty but must be able to speak to the assigned task.
2.3.2. Personnel assigned by the Contractor to the performance of work on this contract’s requirements shall be acceptable to VA in terms of personal and professional conduct and technical knowledge.
2.3.3. Employment and staffing difficulties shall not be justification for failure to meet the timeliness metric in the QASP.
2.4. Kick-Off Meeting - The contractor shall not commence performance on the tasks in this Performance Work Statement (PWS) until the Contracting Officer has conducted a kick-off meeting or the Contracting Officer has advised the Contractor that a kick-off meeting is waived. The kick-off meeting will be held via teleconference and will last approximately one hour.
2.5. Weekly Meetings - The contractor shall meet with the program office once per week during the ramp up phase, or as often as needed to accomplish the ramp up. The COR will assess the effectiveness of the Contractor and may decrease the frequency of teleconference meetings
2.6. Monthly Meetings - The Contractor shall meet with the program office monthly or as needed to discuss users and technical aspects (e.g., errors in reports, one-off discussion points, panel depth concerns, individual on-boarding updates and concerns). The COR will assess the effectiveness of the Contractor and may decrease the frequency of teleconference meetings
3. CONTRACTOR RESPONSIBILITIES
3.1. The contractor shall abide by all government requirements for dissemination of Protected Health Information (PHI) and Personally Identifiable Information (PII). Approved mechanisms are available from the Contracting Officer or COR.
3.1.1. The Government will not provide computer equipment to Contract Personnel
3.1.2. The Government will provide the contractor with necessary procedural guides, business rules, reference materials, and program documentation to meet task objectives.
3.2. Security Investigation, Required Trainings: The following is required for all Contract personnel (Key Personnel, support staff and all CPPs) as listed on the monthly roster deliverable.
3.2.1. Contractor shall ensure all Contract personnel have completed Tier 1 security investigation requests and TMS trainings within 20 business days upon award. Government delays for initial adjudication will not be held against the Contractor.
3.2.1.1. Contract personnel to complete the on-boarding requirements as defined by VA and OPM
3.2.1.2. All onboarding documents and procedures will be given to Contractor at Kick-Off meeting.
3.2.2. PIV card:
3.2.2.1. All Contractor personnel are required to obtain VA issued PIV Badges to support this requirement. PIV badges shall be obtained in accordance with Homeland Security Personnel Directive (HSPD) requirements.
3.2.2.2. PIV card readers are required to be in compliance with HSPD-12 and will not be provided by the government.
3.2.3. VA remote access:
3.2.3.1. All Contract Personnel shall establish and maintain VA remote access to VA network and VA EMR systems.
3.2.3.2. Contractor Personnel must log into their accounts at least once every 30 days.
3.2.3.3. Contractor Personnel shall have and maintain national access to the EMR.
3.2.3.4. Contractor Personnel shall have access to and maintain OMLA review materials.
3.2.4. Written Summary and Evaluation of Care (WSEC) The WSEC is a written report that consists of two main components: a comprehensive chronology of the episode of care (written by Clinical Abstractor) and rationale for standard of care determination including a self-written chronology of applicable health care encounters (written by the CPP). The WSEC focuses on the care provided by the practitioner(s) of the same specialty, subspecialty, or profession as the assigned CPP, and within the context of the episode of care under review. The WSEC is based on the pertinent medical records, statements from involved practitioners, and other review materials provided by OMLA.
3.2.4.1. WSEC Requirements
3.2.4.1.1. OMLA requests for task notification will be communicated to the Contractor key personnel via encrypted email with the required CPP specialty needed to review the tort claim.
3.2.4.1.2. The WSEC shall be properly formatted per OMLA specifications, well written, free from grammatical, punctuation, and spelling errors, accurate, and without omissions of fact. (See attachments A and B)
3.2.4.1.3. The Contractor shall communicate to OMLA if the need for additional review materials, practitioner statements and/or other specialty reviews is required for CPP to complete task.
3.2.4.1.4. CPP rationale for determination may include specialties outside of their own. If statements are needed for those specialties, Contractor will notify OMLA of the need for additional information.
3.2.4.1.5. The Contractor shall ensure all assigned CPPs have access to all review materials provided to Contractor and that the provided review material is sufficient to support the provision of a high quality WSEC and RP determination.
3.2.4.1.6. The WSEC will include:
3.2.4.1.6.1. A cover page that shall include:
3.2.4.1.6.1.1. Allegation of tort claim,
3.2.4.1.6.1.2. List of practitioner statements
3.2.4.1.6.1.3. List of review materials
3.2.4.1.6.1.4. Acknowledgement certifying that the CPP had access to and reviewed the pertinent medical records and practitioner statements.
3.2.4.1.6.2. A brief Summary of Care and a comprehensive chronology of the episode of care that led to the paid tort claim completed by Contractor Clinical Abstractor.
3.2.4.1.6.3. The assigned CPP’s Evaluation of Care
3.2.4.1.7. Contractor shall securely provide OMLA with electronic copies of completed WSECs through Government approved methods i.e., encrypted emails.
3.2.4.1.8. The start date is the business day after OMLA grants access to the case review materials.
3.2.4.1.9. All WSECs are due by 3 PM ET on the 15th business day.
3.2.4.1.10. WSECs that require correction of deficiencies will be returned for revision.
3.2.4.1.11. Contractor revisions for WSEC errors need to be submitted by the original due date.
3.2.4.1.12. Notations in WSEC asking for additional review materials, practitioner statements, etc. will result in a revision. Contractor revisions to address additional information or practitioner statements are to be provided within 10 business days of deliverance of the additional information per OMLA approval.
3.2.4.1.13. The Government may authorize an extension related to an assigned CPP’s VA-remote-access issue for cases where the CPP has attempted to log into the VA system and was not successful. Extensions require the remote access help desk ticket number. This extension will not be granted if the CPP failed to maintain VA systems access.
3.2.5. Review Panel (RP) Participation and Determination
3.2.5.1. CPPs are required to attend and participate in the RP portion that will discuss their assigned case(s).
3.2.5.2. Physician Panelists are required to attend and participate in RP as assigned.
3.2.5.3. OMLA will provide the Contractor with a listing of task notifications (cases) that are ready for RP scheduling, the required CPPs for each case, and the number of Physician Panelists.
3.2.5.3.1. Within 5 business days of the receipt of this list, the contractor shall provide OMLA, via secure email the dates and times (per below) that the required Panelists are available for RP.
3.2.5.3.2. Contractor shall provide three (3) separate dates and their times that the required Panelists are available to attend RP and present the case(s).
3.2.5.3.3. When more than one CPP is required for a case, the Contractor shall provide three (3) separate dates and their times that the required CPPs are available to attend the RP and present the case.
3.2.5.3.4. CPP RP dates provided to OMLA shall be between 10 and 20 business days (preferably evenly spread over 2-3 weeks) after the OMLA notification to the Contractor to acquire CPP RP dates/times
3.2.5.4. The Contractor is responsible to provide the Panelists with their agreed-upon call-in date with the specified time.
3.2.5.5. Review Panel conferences are scheduled for 15 minutes. If the case involves 3 or more reviewers, the panel is scheduled for 30 minutes.
3.2.5.6. A representative of Contractor key personnel shall be present on RP to ensure Panelist preparedness and attendance.
3.2.5.7. The expectation of RP can be found in the SOP which will be provided at Kick-off.
3.2.5.8. For a small portion of RP determinations, a practitioner identified for NPDB report may provide OMLA with substantive new information not available at the time of the RP determination. This new information may lead to an additional RP consisting of original Panel members. This additional task will be invoiced at half the CLIN.
3.2.5.9. Occasionally an additional review or provider statement will be identified at the RP. All members of original RP will be issued a half-cost task notification for the repanel. The additional CPP will be issued a full-cost task notification.
3.2.5.10. At the Government’s discretion, OMLA may determine that a CPP will not be needed to attend the RP. The task will still be reimbursable at the full CLIN.
3.2.6. Document Management
3.2.6.1. Contractors shall adhere to requirements of VA Handbook 6500.6 Contract Security, VA Handbook 6500.3 Certification and Accreditation of VA Information Systems, and VA Directive 6371 Destruction of Temporary Paper Records and all other VA and VHA privacy and information security policies and practices.
3.2.6.2. If the Contractor makes duplicate copies of provided review materials due to contractual need, these are at no cost to the government.
3.3. SPECIFIC MANDATORY TASKS AND ASSOCIATED DELIVERABLES
3.3.1. Specific Mandatory Tasks and Associated Deliverables: The Contractor shall perform the tasks and complete the associated deliverables as follows by the scheduled dates as stated.
3.3.2. The Contractor shall provide deliverables associated with OMLA notifications for CPP RP participation and determination. Specialty of CPP will be specified by the government and this will occur on an ongoing basis based on the needs of the Government.
3.3.3. Project Management Documents – Zero Costs deliverable
3.3.3.1. The Contractor shall provide the following project management documents within 10 business days of award:
3.3.3.1.1. Description of the workflow required
3.3.3.1.2. Identified resources such a specified Key Personnel
3.3.3.1.3. Risk management plan
3.3.3.1.4. Quality Control Plan
3.3.3.2. The following tasks are considered critical and must be included in at least one of the above referenced documents:
3.3.3.2.1. Key Personnel/CPPs initial and ongoing readiness for use
3.3.3.2.2. Appropriate document management and provision of review materials to CPPs
3.3.3.2.3. Guidelines for how WSECs will meet technical and non-technical requirements
3.3.3.2.4. Efficient process for establishing RP date/time
3.3.3.2.5. CPP RP attendance and participation
3.3.3.2.6. RP discussion and determination per schedule
3.3.3.2.7. Contract transition and close out with completion of all deliverables
3.3.3.3. Any alterations made to project management documents must be made with concurrence of the government.
3.3.4. Attendance at Agreed-Upon Date/Time
3.3.4.1. The Contractor shall ensure the assigned Panelists dial into OMLA’s RP.
3.3.4.2. Failure to appear at agreed upon RP may result in government request for Panelist to be removed from Contractor roster.
3.3.5. Reports
3.3.5.1. The Contractor shall provide a report to the OMLA team to: (See attachment F and G)
3.3.5.1.1. Identify any potential barriers (as needed no more than once a day by 3pm ET)
3.3.5.1.2. Respond to OMLA identified performance issues (as needed no more than once a day by 3pm ET)
3.3.5.1.3. Provide status updates on previously identified issues (as needed no more than once a day by 3pm ET)
3.3.5.1.4. Roster of key personnel and CPPs with dates of initial adjudication for security clearance and date of training completion. (by the 1st business day of each month)
3.3.5.1.5. Proof of in-process or completed background investigations and completion/maintenance of mandatory annual training (as occurs)
3.3.5.1.6. Status update of active task notifications. (24 hours before scheduled monthly meeting)
3.3.5.1.7. For each type of task, the percent of tasks that have not met their original schedule due dates since last report and plans for remediation. (24 hours before scheduled monthly meeting)
3.3.5.2. OMLA may provide a task status report to the contractor for reconciliation and potential remedy. The contractor is responsible to closely monitor these paid claim reviews and provide prompt remedy when indicated.
SPECIAL CONTRACT REQUIREMENTS
Deliverables are due to VHA Monday through Friday, No Later Than (NLT) 3:00PM, Eastern Time (ET). Any deliverable submitted after 3:00PM ET shall be considered as received the following business day. See Deliverable Schedule for each type.
3.3.6.
| Section |
| What |
| Submit as noted |
| Submit To |
| Quality Control Plan: Description and reporting reflecting the contractor’s plan for meeting of contract requirements and performance standards. |
| Upon quote and as frequently as indicated in the performance standards. |
| COR |
| Provider credentialing/privileging file must comply with URAC standards |
| To be kept on file at vendor |
| COR as requested |
CV which includes all licenses, board certifications, NPI
| Upon renewal of licenses or change of key personnel. |
| CO/COR; renewal or new key personnel |
| Active roster with certification that staff, key personnel and CPPs list has been compared to HHS LEIE |
| Monthly by 1st business day of each month |
| COR |
| Required TMS Certificates of Completion |
| Upon hiring and annual training |
| COR |
| Subcontracting Plan |
| Upon Award |
| Contracting Officer and COR |
| Business Associate Agreement |
| Upon Award |
| Contracting Officer and COR |
4. QUALITY STANDARDS FOR DELIVERABLES – PERFORMANCE MEASURES:
4.1.1. Quality Management/Quality Assurance Surveillance: Contract personnel shall be subject to Quality Management measures. Contractor performance will be monitored by the government using the standards as outlined in this Performance Work Statement (PWS) and methods of surveillance detailed in the Quality Assurance Surveillance Plan (QASP). (See attachment H)
5. GOVERNMENT RESPONSIBILITIES
VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY language FOR Inclusion into CONTRACTS, as appropriate
1. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
ACCESS to VA INFORMATION AND VA INFORMATION SYSTEMS
1. A contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
1. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
VA INFORMATION CUSTODIAL Language
1. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.
Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.
For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.
INFORMATION SYSTEM DESIGN AND DEVELOPMENT
1. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COTR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.
The contractor/subcontractor shall certify to the COTR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.
The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default “program files” directory and silently install and uninstall.
Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, VA Handbook 6500, Information Security Program and VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle.
The contractor/subcontractor is required to design, develop, or operate a System of Records Notice (SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.
The contractor/subcontractor agrees to:
1. Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:
(a) The Systems of Records (SOR); and
(b) The design, development, or operation work that the contractor/subcontractor is to perform;
1. Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and
1. Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.
In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish an agency function, the contractor/subcontractor is considered to be an employee of the agency.
1. “Operation of a System of Records” means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.
1. “Record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person’s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.
1. “System of Records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as “Systems”), throughout the life of this contract and any extension, warranty, or maintenance periods. This includes, but is not limited to workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the Systems.
The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than ____ days.
When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within ____ days.
All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph (e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA Assistant Secretary for Office of Information and Technology.
INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
1. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerablity scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COTR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.
1. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .