P01 - SOW_Local Emergency Laboratory Testing For AVAHCS_IDIQ.pdf
PDF 287 KB Posted
- Attached to
- Amarillo VAHCS Emergency Offsite Testing Federal contract opportunity
- Solicitation number
- 36C25726Q0297
About this file
This is a Statement of Work for Emergency Laboratory Testing services to be provided to the Amarillo VA Health Care System (AVAHCS) in Amarillo, Texas.
The Contractor shall provide local, off-site STAT (Stat) and Urgent laboratory testing services on an as-needed basis under an Indefinite Delivery, Indefinite Quantity (IDIQ) contract with Firm-Fixed-Price (FFP) unit pricing per test using CPT codes. No minimum quantity is guaranteed, and the Government may order any, all, or none of the services during the performance period. Services must be available 24 hours per day, 7 days per week, including weekends and federal holidays. The Contractor must provide courier services with specimen pickup within 30 minutes of notification, initiate testing within 30 minutes of pickup, deliver results within 60 minutes of testing start, and meet a maximum total turnaround time of 120 minutes from initial notification. These performance standards must be met for at least 85% of STAT/Urgent tests per monthly reporting period. The Contractor shall provide a secure, web-based electronic ordering and results reporting system available 24/7, communicate critical/panic values immediately and no later than 30 minutes after result availability, and make available its entire laboratory test compendium including in-house and referral laboratory tests. Attachment A identifies 81 commonly ordered tests with estimated volumes of 10 tests per CPT code. The Contractor must maintain CLIA certification, CAP and/or Joint Commission accreditation, AABB accreditation, and FDA registration, comply with HIPAA and VA privacy requirements, maintain personnel qualifications with documented competency records, and comply with all applicable Federal and state regulations including OSHA, FDA, AABB, and Texas State regulations. The performance period is August 1, 2026 through July 31, 2027 (Base Year), with four one-year options extending through July 31, 2031. Invoices shall be submitted monthly to the VA Financial Service Center via the Tungsten website with reagent pricing per unit, and no freight charges may be added. Specimens originate at Thomas E. Creek Amarillo VA Health Care System, Pathology & Laboratory Medicine Service/113, 6010 Amarillo Boulevard West, Amarillo, TX 79106.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| P02 - Sources Sought - Attachment A - Required Testing and Volume.docx | DOCX document | |
| S02 - 36C25726Q0297 - Sources Sought - 36C257-26-AP-2104.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
1. GENERAL INFORMATION
1.1. Title of Project: Emergency Laboratory Testing for AVAHCS
1.2. Background: The Amarillo VA Health Care System (AVAHCS), located in Amarillo, Texas, provides primary, secondary, and tertiary care to Veteran patients across the Texas Panhandle.
The Pathology and Laboratory Medicine Service (PLMS) supports inpatient, outpatient, emergency, and critical care services and must ensure continuous access to STAT and Urgent laboratory testing to support timely clinical decision-making. Due to limitations in in-house testing capability, instrument downtime risk, space constraints, and the need for rapid turnaround for select assays, PLMS requires a local off-site STAT/Urgent reference laboratory capable of rapid specimen pickup, expedited testing, and electronic ordering and results reporting. PLMS seeks to establish an Indefinite Delivery, Indefinite Quantity (IDIQ) contract to provide flexible, scalable STAT and Urgent laboratory testing services, ordered on an as-needed basis, with no guaranteed volume.
1.3. Scope of Work: The Contractor shall provide local, off-site STAT and Urgent laboratory testing services in support of the AVAHCS, PLMS, on an as-needed basis under an IDIQ contract. The Contractor shall furnish all personnel, facilities, equipment, transportation, and support services necessary to perform STAT and Urgent laboratory testing at the Contractor’s accredited laboratory facility or approved referral laboratories. Services shall be available 24 hours per day, 7 days per week, including weekends and federal holidays. The Contractor shall make available its full laboratory test compendium, including tests performed in-house or through referral laboratories. The Government may order any test available on the Contractor’s compendium, subject to the pricing provisions of the contract. The Government makes no representation or guarantee regarding the quantity or frequency of testing and may order any, all, or none of the services described herein during the period of performance. Attachment A identifies the tests most likely to be ordered along with anticipated volumes.
1.4. Performance Period:
1.4.1. August 1, 2026 – July 31, 2027 (Base Year), with four one-year options (through July 31, 2031).
1.5. Type of Contract:
1.5.1. This contract shall be an Indefinite Delivery, Indefinite Quantity (IDIQ) contract with Firm- Fixed-Price (FFP) unit pricing per test (CPT code).
1.5.1.1. Quantities are indefinite; No minimum quantity is guaranteed.
1.5.1.2. The Government may order any, all, or none of the services during the period of performance.
1.6. Place of Performance:
1.6.1. Testing shall be performed at the Contractor’s laboratory facility or approved referral laboratory.
1.6.2. Specimen origination site:
1.6.2.1. Thomas E. Creek Amarillo VA Health Care System
Pathology & Laboratory Medicine Service/113 6010 Amarillo Blvd., West Amarillo, TX 79106
2. REQUIREMENTS:
2.1. STAT / Urgent Laboratory Testing Services
2.1.1. The Contractor shall provide STAT and Urgent laboratory testing services on an as-needed basis, including but not limited to the tests listed in Attachment A.
2.1.2. The Contractor shall make available any test listed on its current laboratory test compendium, regardless of whether the test is performed in-house or through a referral laboratory.
2.1.3. Attachment A represents a non-exhaustive list of commonly ordered STAT and Urgent tests for pricing and evaluation purposes only.
2.2. Courier Services (Critical Requirement)
2.2.1. The Contractor shall provide 24/7 on-demand courier services for specimen pickup.
2.2.2. Meet response times:
2.2.2.1. STAT/Urgent pickup: Within 30 minutes of notification.
2.2.3. Couriers shall comply with OSHA bloodborne pathogen standards and all applicable specimen handling and temperature control requirements.
2.3. Testing Initiation & Turnaround Time (TAT)
2.3.1. The Contractor shall meet the following performance standards for STAT and Urgent testing:
Event Requirement
Specimen pickup ≤ 30 minutes from VA call
Testing initiation ≤ 30 minutes from pickup
Result availability ≤ 60 minutes from testing start
Maximum total TAT ≤ 120 minutes from VA call
2.3.2. The Contractor shall meet these TAT requirements for at least 85% of STAT/Urgent tests per monthly reporting period.
2.3.3. Tests inherently requiring extended processing times (e.g., cultures, susceptibility testing, prolonged incubation assays) are excluded from TAT calculations.
2.4. Critical / Panic Values
2.4.1. All critical or panic values shall be communicated immediately upon verification, and no later than 30 minutes after result availability, to authorized VA laboratory or clinical personnel.
2.4.1.1. Documentation of date/time/notification shall be maintained.
2.4.2. The Contractor shall adhere to the AVAHCS critical value reporting requirements for all tests identified in Attachment B. Critical values must be communicated in accordance with AVAHCS policies and procedures to ensure timely notification to clinical staff.
2.5. Electronic Ordering & Results Reporting System
2.5.1. The Contractor shall provide a secure, web-based electronic ordering and results reporting system that allows authorized VA personnel to:
2.5.1.1. Place electronic test orders
2.5.1.2. View specimen and test status
2.5.1.3. Retrieve finalized laboratory results
2.5.1.4. Access historical reports
2.5.2. The system shall:
2.5.2.1. Be available 24/7 (excluding scheduled maintenance)
2.5.2.2. Require no additional VA software or licensing costs
2.5.2.3. Comply with HIPAA and VA privacy requirements
2.5.3. Interface with VA EHR systems is not required.
3. WORK SITE ACCESS
3.1. Coordinate access with the COR and/or or AVAHCS laboratorian during normal hours (8:00 AM
– 4:30 PM, Monday–Friday, excluding federal holidays).
3.2. After-hours access will be permitted as necessary by the AVAHCS laboratorian.
3.3. Comply with VA security protocols, including background checks and ID verification for personnel, if necessary.
4. EXECUTION
4.1. Perform all work in a safe and efficient manner per OSHA (29 CFR 1910.1030), FDA, and AABB safety guidelines, or other applicable standards.
4.2. Optimize delivery/pickup schedules to minimize disruption, prioritizing STAT requests.
4.3. Designate a 24/7 POC for COR communication and conduct status meetings (virtual or in-person) as needed.
5. LICENSING, ACCREDITATION, AND REGULATORY COMPLIANCE
5.1. Regulatory Compliance
5.1.1. Comply with:
5.1.1.1. FDA.
5.1.1.2. AABB: Standards for blood banks and transfusion services.
5.1.1.3. CLIA: Laboratory testing requirements.
5.1.1.4. OSHA: Bloodborne pathogen standards (29 CFR 1910.1030).
5.1.1.5. Texas State Regulations: Applicable health and safety laws.
5.1.1.6. VA Policies: VA Handbook 1108.08 and local directives.
5.1.2. Pass FDA and AABB inspections, providing results to the COR within 30 days.
5.2. Accreditation
5.2.1. Maintain CLIA certification.
5.2.2. Maintain CAP and/or Joint Commission accreditation.
5.2.3. Maintain AABB accreditation and FDA registration.
5.2.4. Provide evidence upon request.
5.3. Personnel Qualifications
5.3.1. Ensure personnel are appropriately certified.
5.3.2. Maintain a training program with documented competency records, available for VA review.
6. SECURITY & CONFIDENTIALITY
6.1. The Contractor shall comply with:
6.1.1. HIPAA
6.1.2. Privacy Act (5 U.S.C. §552a)
6.1.3. 38 U.S.C. §§ 5701, 5705, 7332
6.1.4. VA Directive 6500 (as applicable)
6.2. The C&A requirements do not apply, and a Security Accreditation Package is not required.
6.3. Ensure tamper-proof handling and transportation.
6.4. The Contractor, their personnel, and their subcontractors shall be subject to all applicable
Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract. The Contractor shall also comply with all applicable Information Technology Security Requirements outlined in Attachment C, “Information Technology Security Requirements” which is hereby incorporated by reference into this Statement of Work.
7. BILLING AND INVOICING
7.1. Monthly billing and test report summaries shall begin on the first day of the month and include the last day of the month.
7.2. VA-FSC shall require the following information in compliance with the Prompt Pay Act and
Business Requirements.
7.2.1. Your Taxpayer ID number (TIN)
7.2.2. Your “Remit Address” information
7.2.3. The VA Purchase Order (PO) number
7.2.4. Your contact information: (Personal name, Email, and Phone)
7.2.5. Your VA Point of contact information (Personal name, Email, and Phone)
7.2.6. The Period of Performance dates (POP Beginning and Ending)
7.2.7. All discount information if applicable (Percent and Date Terms)
7.2.8. Reagents used with pricing per unit
7.2.9. No freight charges to be added to the invoice
7.3. Department of Veterans Affairs Financial Service Center:
7.3.1. Phone:1-877-353-9791
7.3.2. Email: vafscched@va.gov
7.4. AVAHCS shall not be responsible for payment of services and or supplies which were not requested Accordance with the contract.
7.5. AVAHCS will NOT pay for tests that are not clearly identified by product number on the invoice.
7.6. Invoices are to be separate for Amarillo and Lubbock laboratories, but the usage of the same
PO number is acceptable for billing purposes.
7.7. Invoices will be electronically submitted to the Tungsten website at:
7.7.1. http://ww.tungsten-network.com/uk/en/
7.7.2. Tungsten direct vendor support number is 877-489-6135 for VA contracts.
7.8. All invoices submitted through Tungsten to VA-FSC should mirror your current submission of
Invoice.
mailto:vafscched@va.gov http://ww.tungsten-network.com/uk/en/
ATTACHMENT A: EMERGENCY TEST LIST
TEST CPT ESTIMATED VOLUME
BASIC METABOLIC PANEL 80048 10
LIPID PROFILE 80061 10
ACUTE HEPATITIS PANEL 80074 10
CARBAMAZEPINE (TEGRETOL) 80156 10
DIGOXIN (LANOXIN) 80162 10
DIPROPYLACETIC ACID(VALPROIC) 80164 10
GENTAMICIN 80170 10
LITHIUM 80178 10
PHENOBARBITAL 80184 10
PHENYTOIN 80185 10
THEOPHYLLINE 80198 10
VANCOMYCIN PEAK/TROUGH 80202 10
TOXI SCREENURINE 80306 10
URINALYSIS AUTO W/ MICRO 81001 10
ACETONE/KETONES SERUM QN 82010 10
ALBUMIN SERUM QN 82040 10
ALBUMIN URINE OR OTHER SOURCE 82042 10
AMMONIA 82140 10
BILIRUBIN TOTAL 82247 10
CALCIUM IONIZED 82330 10
CHOLESTEROL 82465 10
CREATINE KINASE (CPK) MB ONLY 82553 10
GLUCOSE BODY FLUID 82945 10
GLUCOSE BLOOD QN 82947 10
GGT/GGTP 82977 10
HEMOGLOBIN GLYCOSYLATED 83036 10
LACTATE DEHYDROGENASE (LDH) 83615 10
MYOGLOBIN 83874 10
IMMUNOASSAY BNP 83880 10
IMMUNOASSAY BNP I-STAT 83880 10
OSMOLALITY BLD 83930 10
OSMOLALITY URINE 83935 10
PROGESTERONE 84144 10
PROCALCITONIN (PCT) 84145 10
PROTEIN SERUM 84155 10
PROTEIN URINE 84156 10
TOTAL PROTEIN BODY FLUID 84157 10
TRIGLYCERIDE 84478 10
TROPONIN I QN 84484 10
TROPONIN I QN I-STAT 84484 10
HCG QN 84702 10
HEMATOCRIT NON SPUN 85014 10
HEMOGLOBIN 85018 10
TEST CPT ESTIMATED VOLUME
CBC AUTO W/AUTO DIFF 85025 10
CBC AUTO W/O DIFF 85027 10
BLD CNT RETICULOCYTE AUTO 85045 10
FDP/FSP AGGLUTINATION SQ 85362 10
FIBRIN DEGRADATION D-DIMER QN 85379 10
FIBRINOGEN 85384 10
PLATELET AGGREGATION 85576 10
PROTHROMBIN TIME (PT) 85610 10
PTT 85730 10
AB ID PLATELET 86022 10
AB ID PLATELET ASSOC IGG 86023 10
AB HETEROPHILE SCREEN 86308 10
PARTICLE AGGLUT SCREEN 86403 10
AB HELICOBACTER PYLORI 86677 10
AB HIV-1 86701 10
AB HIV-2 86702 10
AB HEP B SURFACE (HBSAB) 86706 10
AB HEP A (HAAB) IGM 86709 10
AG ROTAVIRUS 86759 10
AB HEP C 86803 10
CULTURE AEROBIC OTHER QN 87071 10
MULT CULTURE AEROBIC OTHER QN 87071 10
AER ORGANISM ID EA ISOLATE 87077 10
CULTURE TYPING ID NA 87149 10
SMEAR MALARIA 87207 10
AG EIA QL CRYPTOSPORIDIUM 87328 10
AG EIA QL GIARDIA 87329 10
H PYLORI AG EIA STOOL 87338 10
AG EIA QL HEP B AG (HBSAG) 87340 10
NUC ACID PROBE AMP CHLAMYD T 87491 10
NUC ACID PROBE AMP C DIFF 87493 10
STOOL PATHOGEN PANEL 87506 10
NUC ACID PROBE AMP INFECTIOUS 87798 10
REF NUC ACID PROBE AMP INFECTIOUS 87798 10
REF2 NUC ACID PROBE AMP INFECTIOUS 87798 10
IMMUNO OPTICAL STREP GROUP B 87802 10
INF AGNT BY IA INFLUENZA 87804 10
INF AGENT AG DETECT IA/OPTC SCREEN NOC 87899 10
SEMEN ANALYSIS 89321 10
DRUG TEST DEF 1-7 CLASSES G0480 10
ATTACHMENT B: TABLE OF CRITICAL TEST RESULTS
Test Test Result Notes
Blood Culture Positive Direct Notification
CSF Culture Positive Direct Notification
“Fluids” Gram Stains Positive Direct Notification
Acid-Fast Bacillus Stain or Culture Positive Direct Notification
Incompatible Crossmatches Incompatible Direct Notification
Test Below Above Notification
Absolute Granulocyte 500 K/cumm NA Direct Notification
Acetaminophen NA 30 ug/ml Direct Notification
Calcium (ionized) <0.75 mmol/L >1.60 mmol/L Direct Notification
Calcium (serum) 6.5 mg/dL 12.0 mg/dL Direct Notification
Carboxyhemoglobin* NA NA Direct Notification
Digoxin (serum) NA 2.5 ng/mL Direct Notification
Fibrinogen 100 gm/dL NA Direct Notification
Glucose (serum) 50 mg/dL 500 mg/dL Direct Notification
Hct 24.0% 60% Direct Notification
Hgb 8.0 g/dL 20.0 g/dL Direct Notification
INR (non-therapy) NA 2.0 Direct Notification
INR (with therapy) NA 4.5 Direct Notification
Lithium (serum) NA 1.7 mmol/L Direct Notification
Lactic Acid NA ≥ 4.0 mmol/L Direct Notification
PCO2 <20 mmHg >70 mmHg Direct Notification pH <7.20 7.60 Direct Notification
Phenobarbital (serum) NA 50.0 ug/mL Direct Notification
Phenytoin (serum) NA 20.0 ug/mL Direct Notification
Phosphorus (serum/plasma) 1 mg/dL 8 mg/dL Direct Notification
Platelet Count 50,000 K/cumm 1,000,000 K/cumm Direct Notification
PO2 <40 mmHg NA Direct Notification
Potassium (serum) 3.0 mmol/L 6.0 mmol/L Direct Notification
Salicylate (serum/plasma) NA 30 mg/dl Direct Notification
Sodium (serum) 125 mmol/L 160 mmol/L Direct Notification
Tegretol/Carbamazepine NA 12 ug/ml Direct Notification
Theophylline (serum) NA 20.0 ug/mL Direct Notification
Tobramycin NA 10ug/ml Direct Notification hs-Troponin I (serum/plasma) NA 50 pg/mL Direct Notification
Valproic Acid NA 150 ug/ml Direct Notification
WBC 1,500 K/cumm 45,000 K/cumm Direct Notification
*All carboxyhemoglobin results must be called regardless of values.
ATTACHMENT C: INFORMATION TECHNOLOGY SECURITY REQUIREMENTS
1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.
2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any
Information Security and Privacy language. a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter
“contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.
b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA
Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR
52.227-14 Rights in Data – General.
c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.
d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and
VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.
e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.
f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA
Information Security Knowledge Service.
g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.
h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security
Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information
Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with
National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and
Use of Transport Layer Security (TLS) Implementations.
i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.
k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38
U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with
Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the
VA CO for response.
l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.
m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National
Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and
Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA
Records Control Schedules.
n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive
6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.
o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that are used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and
NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.
p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of VA CO.
3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.
a. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.
b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems.
Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.
c. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human
Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).
d. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.
e. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:
(1) Contractor/subcontractor personnel no longer have a need for access to VA information or VA information systems.
(2) Contractor/subcontractor personnel are terminated, suspended, or otherwise have their work on a VA project discontinued for any reason.
(3) Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.
(4) Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.
(5) Contractor/subcontractor personnel have their authorization to work in the United States revoked.
(6) Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.
f. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.
g. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and
PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.
4. TRAINING. This entire section applies to all acquisitions which include section 3.
a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:
(1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management
System (TMS) 10176) initially and annually thereafter.
(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and
(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].
b. The contractor shall provide the COR/CO a copy of the training certificates and certification of signing the
Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.
c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.
5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any
Information Security and Privacy language. a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s
Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.
b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:
(1) The date and time (or approximation of) the Security Incident occurred.
(2) The names of individuals involved (when applicable).
(3) The physical and logical (if applicable) location of the incident.
(4) Why the Security Incident took place (i.e., catalyst for the failure).
(5) The amount of data belonging to VA believed to have been compromised.
(6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.
c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.
d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information
Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.
e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive
Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.
g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.
h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach
Costs.
6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.
a. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic
Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal
Information Systems. Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC)
Architecture).
b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA
Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security
Knowledge Service to obtain an Authority to Operate (ATO). VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides security and privacy requirements for cloud environments.
c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable
VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and
Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced.
d. The contractor (including producers and resellers) shall comply with Office of Management and Budget
(OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M-22-18 (September 14, 2022). The term
“software” includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self-attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program
(FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self-attestation.
e. The contractor shall ensure all delivered applications, systems and information systems are compliant with
Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The-Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.
f. The contractor shall ensure all contractors delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common
Access Card (CAC), as determined by the business need and compliance with VA Information Security
Knowledge Service specifications.
g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information
Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository.
h. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on
VA systems.
i. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.
j. The contractor-delivered solutions shall reside with VA approved operating systems. Exceptions to this will only be granted with the written approval of the COR/CO.
k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management
Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and
Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.
l. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224-2 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.
m. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.
n. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security
Knowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or
Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as to not affecting the Systems within 10 business days.
7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (cloud and non-cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities.
a. The contractor shall comply with all Federal laws, regulations, and VA policies for Information systems
(cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities.
Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the information system or systems by or on behalf of VA. This includes conducting compliance risk assessments, security architecture analysis, routine vulnerability scanning, system patching, change management procedures and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures shall be the same as procedures used to secure VA-operated information systems.
b. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require Assessment and Authorization (A&A) of the contractor’s systems in accordance with VA Handbook 6500 as specified in VA Information Security Knowledge
Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor’s cloud computing systems shall comply with FedRAMP and VA
Directive 6517 requirements.
c. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.)
on non-VA leased or non-VA owned IT equipment used to store, process or access VA information to VA in accordance with A&A package requirements. This applies when the contract is terminated or completed and prior to disposal of media. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-88. The contractor shall send a self-certification that the data destruction requirements above have been met to the COR/CO within 30 business days of termination of the contract.
d. All external internet connections to VA network involving VA information must be in accordance with VA
Trusted Internet Connection (TIC) Reference Architecture and VA Directive and Handbook 6513, Secure
External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of
Understanding (MOU) and Interconnection Security Agreements (ISA).
e. Contractor procedures shall be subject to periodic, announced, or unannounced assessments by VA officials, the OIG or a 3PAO. The physical security aspects associated with contractor activities are also subject to such assessments. The contractor shall report, in writing, any deficiencies noted during the above assessment to the VA COR/CO. The contractor shall use VA’s defined processes to document planned remedial actions that address identified deficiencies in information security policies, procedures, and practices.
The contractor shall correct security deficiencies within the timeframes specified in the VA Information Security
Knowledge Service.
f. All major information system changes which occur in the production environment shall be reviewed by the VA to determine the impact on privacy and security of the system. Based on the review results, updates to the
Authority to Operate (ATO) documentation and parameters may be required to remain in compliance with VA
Handbook 6500 and VA Information Security Knowledge Service requirements.
g. The contractor shall conduct an annual privacy and security self-assessment on all information systems and outsourced services as required. Copies of the assessment shall be provided to the COR/CO. The
VA/Government reserves the right to conduct assessment using government personnel or a third-party if deemed necessary. The contractor shall correct or mitigate any weaknesses discovered during the assessment.
h. VA prohibits the installation and use of personally owned or contractor-owned equipment or software on VA information systems. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW, PWS, PD or contract. All security controls required for government furnished equipment must be utilized in VA approved Other Equipment (OE). Configuration changes to the contractor OE, must be funded by the owner of the equipment. All remote systems must use a VA-approved antivirus software and a personal (host-based or enclave based) firewall with a VA-approved configuration.
The contractor shall ensure software on OE is kept current with all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-virus software and the firewall on the non-
VA owned OE. Approved contractor OE will be subject to technical inspection at any time.
i. The contractor shall notify the COR/CO within one hour of disclosure or successful exploits of any vulnerability which can compromise the confidentiality, integrity, or availability of the information systems. The system or effected component(s) need(s) to be isolated from the network. A forensic analysis needs to be conducted jointly with VA. Such issues will be remediated as quickly as practicable, but in no event longer than the timeframe specified by VA Information Security Knowledge Service. If sensitive personal information is compromised reference VA Handbook 6500.2 and Section 5, Security Incident Investigation.
j. For cases wherein the contractor discovers material defects or vulnerabilities impacting products and services they provide to VA, the contractor shall develop and implement policies and procedures for disclosure to VA, as well as remediation. The contractor shall, within 30 business days of discovery, document a summary of these vulnerabilities or defects. The documentation will include a description of the potential impact of each vulnerability and material defect, compensating security controls, mitigations, recommended corrective actions, root cause analysis and/or workarounds (i.e., monitoring). Should there exist any backdoors in the products or services they provide to VA (referring to methods for bypassing computer authentication), the contractor shall provide the VA CO/CO written assurance they have permanently remediated these backdoors.
k. All other vulnerabilities, including those discovered through routine scans or other assessments, will be remediated based on risk, in accordance with the remediation timelines specified by the VA Information
Security Knowledge Service and/or the applicable timeframe mandated by Cybersecurity & Infrastructure
Security Agency (CISA) Binding Operational Directive (BOD) 22-01 and BOD 19-02 for Internet-accessible systems. Exceptions to this paragraph will only be granted with the approval of the COR/CO.
8. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT AND AUDITING. This entire section applies whenever section 6 or 7 is included.
a. Should VA request it, the contractor shall provide a copy of their (corporation’s, sole proprietorship’s, partnership’s, limited liability company (LLC), or other business structure entity’s) policies, procedures, evidence and independent report summaries related to specified cybersecurity frameworks (International
Organization for Standardization (ISO), NIST Cybersecurity Framework (CSF), etc.). VA or its third-party/partner designee (if applicable) are further entitled to perform their own audits and security/penetration tests of the contractor’s IT or systems and controls, to ascertain whether the contractor is complying with the information security, network or system requirements mandated in the agreement between VA and the contractor.
b. Any audits or tests of the contractor or third-party designees/partner VA elects to carry out will commence within 30 business days of VA notification. Such audits, tests and assessments may include the following: (a):
security/penetration tests which both sides agree will not unduly impact contractor operations; (b): interviews with pertinent stakeholders and practitioners; (c): document review; and (d): technical inspections of networks and systems the contractor uses to destroy, maintain, receive, retain, or use VA information.
c. As part of these audits, tests and assessments, the contractor shall provide all information requested by VA.
This information includes, but is not limited to, the following: equipment lists, network or infrastructure diagrams, relevant policy documents, system logs or details on information systems accessing, transporting, or processing VA data.
d. The contractor and at its own expense, shall comply with any recommendations resulting from VA audits, inspections and tests. VA further retains the right to view any related security reports the contractor has generated as part of its own security assessment. The contractor shall also notify VA of the existence of any such security reports or other related assessments, upon completion and validation.
e. VA appointed auditors or other government agency partners may be granted access to such documentation on a need-to-know basis and coordinated through the COR/CO.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .