PWS.pdf
PDF 334 KB Posted
- Attached to
- Reverse Osmosis Preventive Maintenance Federal contract opportunity
- Solicitation number
- HT941025N0110
- Issued by
- Defense Health Agency
About this file
This Performance Work Statement (PWS) details a preventive maintenance contract for Reverse Osmosis (RO) devices at the Naval Medical Center San Diego. The contract covers three AmeriWater Centurion RO machines (S/N CEN210041 and CEN210043) used in the Nephrology/Dialysis Clinic, with a performance period from September 30, 2025 to September 29, 2026.
The contractor is required to perform annual preventive maintenance and as-needed repairs, ensuring the RO devices meet industry standards and manufacturer protocols. Key requirements include using fully qualified field engineers, conducting system update changes to resolve reliability problems, providing emergency response within two hours, and performing AAMI water testing annually. The maintenance is critical to the clinic's ability to provide hemodialysis services, with the contractor responsible for maintaining the equipment's functional capabilities, using OEM-recommended tools and lubricants, and extending all commercial warranties on replacement parts.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Notice of Intent.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Defense
Defense Health Agency
Performance Work Statement
Reverse Osmosis (RO) Devices
Preventative Maintenance (PM) Contract
NMC/NMRTC – San Diego
Directorate of Medical Services/Department of Internal Medicine
Nephrology Clinic/Dialysis Unit
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide maintenance and services to Reverse
Osmosis (RO) Devices.
1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform maintenance as defined in this Performance Work
Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.
1.3 Background: Naval Medical Center San Diego is requesting services, materials and equipment necessary for the repair/preventive maintenance of three (3)
CENTURION Reverse Osmosis devices. These machines were purchased, however due to the finalization of installation and training not being completed, a new preventative maintenance (PM) contract is required for two (2) of the three (3) RO devices. Reverse
Osmosis devices are mission critical and without the repairs and maintenance of these devices NMC/NMRTC San Diego will not be able to provide hemodialysis services to patients who require them.
1.4 Objectives:
NMCSD PREVENTIVE MAINTENANCE REQUIREMENTS:
• Perform service repair/preventive maintenance to industry standards.
• Ensure that only FULLY QUALIFIED FIELD ENGINEERS and TECHNICIANS who have gone through original equipment manufacturer (OEM) or comparable third-party service schools for the above-mentioned equipment, shall be employed in the performance of any and all work performed under this contract. Upon request, contractor shall provide training certificates (or notarized copies) to the Material Management
Department, Biomed Repair Department division for verification. The highest standard of professional capability and electrical/mechanical workmanship is to be maintained throughout the life of this contract.
• Make repairs to the extent necessary (as determined by inspection tests or disassembly) to ensure a functional system that will efficiently serve its intended purpose.
• Installation of system update changes to resolve specific product reliability problems.
Hardware and software changes to resolve specific product reliability problems.
Hardware and software upgrades, defined as those changes that enhance or add product features, are not included.
• Contractor shall perform all scheduled preventative maintenance as agreed up on during the initial contact with the contract administrator.
NMCSD CORRECTIVE MAINTENANCE REQUIREMENTS:
• Correct inoperable condition in a timely manner. Immediately upon contract award, the contractor will provide Material Management Department BIOMED division, Naval
Medical Center San Diego, an emergency telephone number. Contractor will respond no later than two (2) hours after telephone notification Monday-Friday, hours of 0800–1600.
• Provide only the work necessary to restore the equipment to a serviceable/operating condition by adjustments, replacement parts, or minor repairs when it is determined that extensive repairs and parts replacements are not necessary.
• Equipment improvements/modifications shall be made only upon Material Management
Department, Biomed Repair Department written approval and direction.
• Notify the Material Management Department, Naval Medical Center San Diego, Biomed
Repair Department immediately upon receipt of OEM or replacement parts/equipment safety recalls notices.
• Ensure that original design and functional capabilities will not be changed, modified, or altered unless the Material Management Department, Biomed Repair Department, Naval
Medical Center, San Diego authorizes such changes in writing.
• Provide suitable OEM recommended repair equipment/tools required for the satisfactory execution of all repairs made.
• Furnish manufacturer OEM approved lubricants and lubricate wear points within the equipment.
• Extend to the Government all commercial warranties on replacement parts consistent with standard industry inventory.
Scope: The contractor is required to provide all services, materials and equipment necessary for the repair/preventive maintenance of three (3) Reverse Osmosis (RO) Machines by AmeriWater.
AmeriWater Product ID: #103453
S/N CEN210041 ECN162758
S/N CEN210043 ECN162756
“Repair” means any (a) modification, adjustment, or replacement of the hardware that corrects a malfunction by bringing the hardware into material conformity with the technical specifications for the hardware or (b) a procedure or routine that, when observed in the regular operation of the hardware, avoids the material adverse effect of the applicable nonconformity. As a result, ensures dependable and reliable equipment operation. The scope of work performed under these specifications includes the furnishing of all labor and parts to perform all repairs on equipment listed to assure continued operation at their designed efficiency and capacity.
1.5 Period of Performance (PoP): 30 SEP 2025 – 29 SEP 2026
1.6.1.1.1 The contractor shall comply with transition-in requirements of the DHA, as listed in paragraph 1.11.1, for contractors needing to be issued Common Access Card (CAC) identification, including Department of Defense (DoD) and DHA-directed training and forms submission, prior to network access.
1.6.1.2 Transition-out period: The transition-out plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract. See Part 7, Technical Exhibit 1
1.6.1.2.1 The contractor shall comply with transition-out requirements of the DHA for contractors who have been issued a CAC or who generate “records”, as defined by DoD (records manual), including DoD-directed disposition of records, and others displayed on the In/Out (I/O)
Processing Portal.
1.7 Administrative specifications
1.7.1 Place of performance: The work shall be performed at Nephrology/Dialysis Clinic:
Bldg 1, Floor 3, Rm 3D-18H1-CD.
Naval Medical Center San Diego
34800 BOB WILSON DRIVE
SAN DIEGO, CA. 92134-5000
1.7.2 Recognized Federal holidays:
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Memorial Day Thanksgiving Day
Juneteenth Day Christmas Day
Independence Day
1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru
Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.7.4 Emergency Services: On occasion, services may be required to support an activation or exercise of contingency plans outside the normal duty hours.
1.8 Contractor travel: NONE
Federal Acquisition Regulation (FAR) Part 31.2, Travel Costs and the limitations of funds specified in this contract. All travel requires Government approval/authorization and notification to the Contracting Officer Representative (COR).
RESPONSE TIME: Contractor shall use commercially reasonable efforts to:
• Respond by telephone to any report of a malfunction requiring repair within two (2) hours of notification by NMCSD Monday – Friday, 0800-1600.
• Provide on-site support within one (1) business day of notification by NMCSD Biomed
Repair Department personnel.
1.9 Other Direct Costs (ODC): NONE
1.10 Quality
1.10.1 Quality Control (QC): NOT APPLICABLE
1.10.2 Quality assurance (QA): The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.11 Contractor personnel
SERVICES SHALL BE REQUIRED BASED UPON THE FOLLOWING AGREED
SCHEDULES:
PREVENTIVE MAINTENANCE: (Check One)
___X___ One (1) time per fiscal year
_______ Two (2) times per fiscal year
AAMI WATER TESTING:
___X___ One (1) time per fiscal year
______ Two (2) times per fiscal year
REPAIR: (Check One)
___X___ Monday - Friday, 0800-1600
_______ Seven (7) days per week, 24-hour coverage
1.11.1 CAC requirements: For all contractors who will work in Government facilities, the
Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the
Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the
PWS. A CAC is the standard identification for eligible DoD contractor personnel.
1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).
1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements:
1.11.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA
Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx
1.11.2.2 The DHA’s contractor training instructions embedded at Part 7 Section 7.1.2.
(Government (DHA) requirements development staff must cut/paste onboarding checklist at https://info.health.mil/sites/DOP/OnboardingCtr/Contractor_OnBoarding_Checklist.pdf and embed most up-to-date form in Part 7, Section 7.1.2.)
https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx https://info.health.mil/sites/DOP/OnboardingCtr/Contractor_OnBoarding_Checklist.pdf
1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at:
https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure
(PKI)-restricted, printed versions available).
1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use.
1.11.4 Key control: The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas.
The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.
1.11.4.1 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon direction of the CO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor.
In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.
1.11.4.2 The contractor shall prohibit the use of Government issued keys/key cards by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the CO.
1.11.5 Lock combinations: The contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the contractor’s
QCP.
1.12 Key personnel (Contractor: The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO. The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between [8:00 a.m. to 4:30 p.m.], Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons. Qualifications for all key personnel are listed below:
https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx
1.13 Data rights: Reserved
1.14 Reporting
1.14.1 Contractor Manpower Reporting (CMR): RESERVED.
1.14.2 Non-Disclosure Agreement (NDA): NOT APPLICABLE
1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.15 Contractor Identification
1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy
Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.
Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with
Government and/or other contract representatives to meet the requirements of this order.
Contractor personnel shall make their contractor status known during introductions.
1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's
Personnel Security Office for a background investigation.
1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the
DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.17 Personnel Security
1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce
Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated
March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance
Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care
Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA
Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM
5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security
Office can be reached at (703) 275-6038.
1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE
PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-
Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-
Services)
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The
Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the
Government’s plan.
2.2 Acronyms:
AIS Automated Information System
APL Approved Products List APL
AQL Acceptable Quality Level
ARRT Acquisition Requirements Roadmap Tool
ATO Authority to Operate
B2B Business-2-Business
CAC Common Access Card
CAP Cloud Access Point
CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme
CDI Covered Defense Information
CE Computer Environment
CDRL Contract Data Requirement List
CIO Chief Information Officer
CJCSM Chairman of the Joint Chiefs of Staff Manual
CMMC Cybersecurity Maturity Model Certification
CMR Contractor Manpower Reporting
CNSSI Committee on National Security Systems Instruction
CO Contracting Officer(s)
CONUS Continental United States (excludes Alaska and Hawaii)
COR Contracting Officer Representative
COTR Contracting Officer's Technical Representative
CSP Cloud Service Provider
CSSP Cyber Security Service Provider
CUI Controlled Unclassified Information
DAD-A Deputy Assistant Director for Acquisition
DC3 DoD Cyber Crime Center
DD Form 254 Department of Defense Contract Security Requirement List (if applicable)
DB Design-Build
DBB Design-Bid-Build
DFARS Defense Federal Acquisition Regulation Supplement
DHA Defense Health Agency
DISA Defense Information System Agency
DoD Department of Defense
DoDD Department of Defense Directive
DoDI Department of Defense Instruction
DSAs Data Sharing Agreements
DSAA Data Sharing Agreement Application
DMZ Demilitarized Zone
DoDM Department of Defense Manual
DPCLO DHA Privacy and Civil Liberties Office
DUA Data Use Agreement eMSM Enhanced Multi-Service Markets
EULA End User License Agreement
EVM Earned Value Management
FAR Federal Acquisition Regulation
FCI Federal contract information
FE Facilities Enterprise
FedRAMP Federal Risk Authorization and Management Program
FISMA Federal Information Security Modernization Act
FRCS Facility Related Control Systems
FSO Facilities Security Officer
HA Health Affairs
HIPAA Health Insurance Portability and Accountability Act
HCA Head of the Contracting Activity
HIT Health Information Technology
IGCE Independent Government Cost Estimate
IA Information Assurance
IO Initial Outfitting
I/O In/Out Processing Portal
IPv Internet Protocol Version
IS Information System
ISP Internet Service Provider
IT Information Technology
ISCM Information Security Continuous Monitoring
IV&V Independent Verification & Validation
MedCOI Medical Community of Interest
MHS Military Health System
MIL-STD Military Standard
MTFs Military Treatment Facilities
NCR National Capitol Region
NDA Non-Disclosure Agreement
NIAP National Information Assurance Partnership
NIST National Institute of Standards and Technology
OCONUS Outside Continental United States (includes Alaska and Hawaii)
ODC Other Direct Costs
OPM Office of Personal Management
OSD Office of the Secretary of Defense
P-ATO Personal Authorization to Operate
P&R Personnel and Readiness
PGI Procedures, Guidance and Information
PDT Project Delivery Team
PHI Protected Health Information
PII Personally Identifiable Information
PIT Platform Information Technology
PK Public Key
PKI Public Key Infrastructure
POA&M Plan of Action and Milestones
POC Point of Contact
PMO Program Management Office
PoP Period of Performance
PP Personal Property
PPSM Ports, Protocols, and Services Management
PRS Performance Requirements Summary
PSP Personnel Security Program
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Plan
RFP Request for Proposal
RFQ Request for Quotation
RMF Risk Management Framework
SP Special Publication
SPRS Supplier Performance Risk System
SRM Sustainment, Restoration and Modernization
SRG Security Requirements Guides
STIG Security Technical Implementation Guides
TOS Terms of Service
US United States
UFC Unified Facilities Criteria
VPN Virtual Private Network
XML Extensible Markup Language
2.3 Applicable Publications, DHA Administrative Instructions (AI), etc: NONE
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
Facilities Only
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government:
☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
3.2 Facilities: The Government:
☒ WILL provide Facilities in support of this contract/task orders. The Government provided
Facilities are described below:
Nephrology Clinic/Dialysis Unit NMRTC San Diego. 34800 Bob Wilson Dr. STE 308 San
Diego, CA 92134
Phone Number: 619-532-8840
3.3 Utilities: The Government:
☒ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is
Not Applicable.
3.4 Equipment: The Government:
☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.
3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application
Contracting Office Responsibilities:
The Contracting Office shall ensure close coordination and validation of the GFP items with the
COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the
PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.
The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the
Contracting Office, and requested within the PIEE/GFP Module system.
Contractor Responsibilities:
A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.
The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation.
Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise
Environment Standards, DHA Administrative Instruction 094 and DHA Guidance.
3.5 Materials: The Government:
☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.
PART 4
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 Services: The Contractor:
☒ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.
4.3 Secret Facility Clearance: NONE
4.4 Materials: NONE
4.5 Equipment: NONE
4.6 Facilities: The contractor shall use the Nephrology Clinic & Dialysis Unit at NMRTC San
Diego to provide services under this contract.
PART 5
5.0 SPECIFIC TASKS
5.1 Machine Maintenance:
The contractor shall provided preventative maintenance services for all reverse osmosis machines annually to adhere to NMRTC San Diego policy, as well as manufacturer’s protocol.
The contractor shall provide as-needed on-site maintenance for all reverse osmosis machines to ensure proper working order of all units as detailed below:
NMCSD PREVENTIVE MAINTENANCE REQUIREMENTS:
• Perform service repair/preventive maintenance to industry standards.
• Ensure that only FULLY QUALIFIED FIELD ENGINEERS and TECHNICIANS who have gone through original equipment manufacturer (OEM) or comparable third-party service schools for the above-mentioned equipment, shall be employed in the performance of any and all work performed under this contract. Upon request, contractor shall provide training certificates (or notarized copies) to the Material Management
Department, Biomed Repair Department division for verification. The highest standard of professional capability and electrical/mechanical workmanship is to be maintained throughout the life of this contract.
• Make repairs to the extent necessary (as determined by inspection tests or disassembly) to ensure a functional system that will efficiently serve its intended purpose.
• Installation of system update changes to resolve specific product reliability problems.
Hardware and software changes to resolve specific product reliability problems.
Hardware and software upgrades, defined as those changes that enhance or add product features, are not included.
• Contractor shall perform all scheduled preventative maintenance as agreed up on during the initial contact with the contract administrator.
NMCSD CORRECTIVE MAINTENANCE REQUIREMENTS:
• Correct inoperable condition in a timely manner. Immediately upon contract award, the contractor will provide Material Management Department BIOMED division, Naval
Medical Center San Diego, an emergency telephone number. Contractor will respond no later than two (2) hours after telephone notification Monday-Friday, hours of 0800–1600.
• Provide only the work necessary to restore the equipment to a serviceable/operating condition by adjustments, replacement parts, or minor repairs when it is determined that extensive repairs and parts replacements are not necessary.
• Equipment improvements/modifications shall be made only upon Material Management
Department, Biomed Repair Department written approval and direction.
• Notify the Material Management Department, Naval Medical Center San Diego, Biomed
Repair Department immediately upon receipt of OEM or replacement parts/equipment safety recalls notices.
• Ensure that original design and functional capabilities will not be changed, modified, or altered unless the Material Management Department, Biomed Repair Department, Naval
Medical Center, San Diego authorizes such changes in writing.
• Provide suitable OEM recommended repair equipment/tools required for the satisfactory execution of all repairs made.
• Furnish manufacturer OEM approved lubricants and lubricate wear points within the equipment.
• Extend to the Government all commercial warranties on replacement parts consistent with standard industry inventory.
The contractor is required to provide all services, materials and equipment necessary for the repair/preventive maintenance of three (3) Reverse Osmosis Machines by AmeriWater.
AmeriWater Product ID: #103453
S/N CEN210041 ECN162758
S/N CEN210043 ECN162756
5.2 AAMI Water Testing:
The contractor shall provide/perform AAMI water testing kits for all reverse osmosis machines annually to adhere to NMRTC San Diego policy, AAMI water standards, as well as manufacturer's protocol.
The contractor shall provide AAMI water testing for all reverse osmosis machines to ensure proper working order of all units as detailed below:
NMCSD PREVENTIVE MAINTENANCE REQUIREMENTS:
• Perform AAMI standard water test kit to industry standards.
• Ensure that only FULLY QUALIFIED FIELD ENGINEERS and TECHNICIANS who have gone through original equipment manufacturer (OEM) or comparable third-party service schools for the above-mentioned equipment, shall be employed in the performance of any and all work performed under this contract. Upon request, contractor shall provide training certificates (or notarized copies) to the Material Management
Department, Biomed Repair Department division for verification. The highest standard of professional capability and electrical/mechanical workmanship is to be maintained throughout the life of this contract.
• Make repairs to the extent necessary (as determined by inspection tests or disassembly) to ensure a functional system that will efficiently serve its intended purpose.
• Installation of system update changes to resolve specific product reliability problems.
Hardware and software changes to resolve specific product reliability problems.
Hardware and software upgrades, defined as those changes that enhance or add product features, are not included.
• Contractor shall perform all scheduled preventative maintenance as agreed up on during the initial contact with the contract administrator.
NMCSD CORRECTIVE MAINTENANCE REQUIREMENTS:
• NONE; NMCSD does not imply requirements following the corrective maintenance of a pass or fail AAMI quality standard test kit.
• If a machine does not meet AAMI standards, it is the obligation of the Nephrology Clinic to discontinue use of the reverse osmosis device.
• PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 All work under this contract is unclassified.
6.2 The TIER level and position sensitivity designation for positions under this contract is:
TIER II: Non-critical sensitive position (A position where an individual is responsible for systems design, operation, testing, maintenance, and/or monitoring that is carried out.
6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements: NONE: Contractor has no access to
PHI/PII.
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes
PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office
(DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into
DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect
MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.
After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements: NONE
6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity
Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.
6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD
8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:
6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and
6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by
DoD 8570.01–M.
6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.
6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS: Reserved
6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication
(SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information
Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-
171), in accordance with DFARS clause 252.204-7012.
6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-
171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment
Methodology requirement flows down to subcontractors.
6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier
Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)
6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD
Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.
See Attachment 2, Deliverable Schedule Table.
6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.
6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.
6.5.4 Cybersecurity Maturity Model Certification (CMMC): The CMMC https://www.sprs.csd.disa.mil/
(DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment
Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk. The CMMC requirement flows down to subcontractors.
6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization
(3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.
6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.
6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management
Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.
6.5.8 Cyber Incident Reporting Requirement
6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:
6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user https://www.cmmcab.org/ https://www.fedramp.gov/ accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and
6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-
Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/
6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.
6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a
DoD-approved medium assurance certificate, see https://public.cyber.mil/
6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.
6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
https://dibnet.dod.mil/portal/intranet/ https://manuals.health.mil/ https://public.cyber.mil/
6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).
6.5.15. The contractor shall mitigate supply chain risk to the government by complying with
DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN
Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).
6.6 Risk Management Framework (RMF) for DoD IT All IS, Platform Information
Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI
8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal
Information Security Modernization Act (FISMA) security control testing. IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction
(CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.
6.6.1 All systems subject to RMF must present evidence of authorization in the System Security
Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of CO request.
Evidence of FISMA compliance must be presented in the form of a POA&M. Systems must have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions
(ATO-C) by contract award.
6.6.2 The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework
(RMF) and DoDI 8510.01, Risk Management Framework (RMF).
6.6.3 The contractor shall configure the information system in accordance with Defense
Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).
6.6.4 The contractor shall ensure that the information system conforms to the requirements of
DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.
6.6.5 The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.
6.6.6 The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure
(PKI) and Public Key (PK) Enabling”.
https://aplits.disa.mil/processAPList
6.6.7 The contractor will be responsible for compliance with the Joint Force Head Quarters –
Department of Defense Information Network issuances and IA Vulnerability Management
(IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.
6.6.8 The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.
6.6.9 The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA
Cybersecurity Architectures.
6.6.10 Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.
6.6.11 Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP
800-137.
6.6.12 The contractor shall mitigate supply chain risk to the government by complying with
DFARS 252.239-7018 and only…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .