PWS - FY24 MTIO Special Projects Final_21May2024.docx
DOCX document 2 MB Posted
- Attached to
- Market Technology Integration Office (MTIO) Special Projects Federal contract opportunity
- Solicitation number
- HT001124R0069
- Issued by
- Defense Health Agency
About this file
This document is a Performance Work Statement (PWS) for the Market Technology Integration Office (MTIO) Special Projects contract. The PWS provides information and requirements for a non-personal services contract to provide program management, operational planning, technical, and system administrative support services for the Special Medical Unit (SMU) clinics that receive support from the Defense Health Agency (DHA) and operate on the White House Communication Agency network.
The key objectives of the SMU Project program are to support system testing and evaluation, meet regulatory and agency standards, provide local IT support, facilitate communication, and proactively manage risks and issues. The contractor shall provide subject matter expertise in areas such as technical program management, system administration, network operations, cybersecurity, and program management. The period of performance includes a base year and four option years. Facility clearances, security clearance levels, travel requirements, quality control, and contractor personnel requirements are also detailed in the PWS.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Answers_12Jul 2024.pdf | ||
| Questions_2 Jul 2024.xlsx | XLSX spreadsheet | |
| Amendment HT001124R0069-0001.pdf | ||
| MTIO Combined Synopsis-Solicitation HT001124R0069.pdf | ||
| DD1423-1 Consolidated MTIO Special Projects.pdf | ||
| MTIO Combined Synopsis-Solicitation HT001124R0069.pdf | ||
| 09 - QASP MTIO Special Projects.docx | DOCX document | |
| DD254_MTIO Special Projects.pdf | ||
| Atch 5 Addendum to 52.212-1 and 52.212-2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Defense Defense Health Agency Performance Work Statement
Market Technology Integration Office (MTIO) Special Projects
PEO Medical Systems / CIO(J-6)
Market Technology Integration Office (MTIO)
Solicitation Number:
Version: 1 Date: 5/21/2024
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide program management, operational planning, technical, and system administrative support services.
1.2 Description of services/introduction: Provide Special Medical Unit (SMU) support, which is made up of several clinics that receive parent infrastructure support from Walter Reed, and enterprise support services from DHA J6. These clinics and users also operate on the White House Communication Agency (WHCA) network and require coordination and configuration support for IT and business changes. The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform SMU Projects program management, operational planning, and technical activities to support the services defined in this Performance Work Statement (PWS). The contractor shall perform to the standards in this PWS.
1.3 Background: As the Defense Health Agency (DHA) moves forward to meet the security mandates required by federal laws, standards, and guidance, a more advanced conceptual and continuous approach to security will be required to ensure the safeguarding of information entrusted to the agency. This program can be accomplished: (1) by continuing to implement and update National Institute of Standards and Technology (NIST)-compliant policies, and procedures, (2) by engineering and implementing solutions to new requirements that arise both from advances in technology and from new Federal and regulations and directives and (3) by maintaining information technology (IT) system resiliency with effective contingency planning, evaluation, and testing.
Mission: Information Management/Information Technology (IM/IT) central trusted leader for all Chief Information Officer/Information Technology (CIO/IT) Directors by championing unified communications and business services.
Vision: Seamlessly integrate Military Treatment Facility (MTF) CIOs/IT Directors into the DHA Enterprise.
1.4 Objectives: The following are objectives of the SMU Project program:
· Support system(s) product testing and evaluation to satisfy DHA IT and security standards for new services and systems being considered on the MedCOI.
· Meet DHA, WHCA, and DoD regulatory and agency documented standards and guidance.
· Follow DHA regulations and service practices to support the SMUs IT requirements
· Provide local IM/IT support to the SMUs.
· Facilitate communication between WHCA and DHA agencies to support SMUs requirements.
· Proactively manage risks and resolve issues before they impact clinical care.
· Keep MTIO informed of SMU operations, risks, issues, requests, and clinic personnel changes
1.5 Scope: Provide subject matter expertise in technical program management, system administration, network operations, cybersecurity, and program management for SMUs administering clinical care for executive very important people (VIP) beneficiaries.
1.6 Period of Performance (PoP):
| Base Year | August 28, 2024 – February 27, 2025 |
| Option Year 1 | February 28, 2024 – February 27, 2025 |
| Option Year 2 | February 28, 2025 – February 27, 2026 |
| Option Year 3 | February 28, 2026 – February 27, 2027 |
| Option Year 4 | February 28, 2027 – February 27, 2028 |
1.6.1 Transition: Transition-in/transition-out period
1.6.1.1 Transition-in period: Full performance start date is 10-days after the start of the Base Year PoP. Transition-in performance is defined as upon award, fulfilling the staff that provide support onsite at the SMUs. During the transition-in period, the contractor shall prepare to meet all contract requirements and ensure incoming personnel are functionally trained, authorized, and qualified on the full performance start date except SMU support requirements, which must be fully adhered during transition and full performance periods. The remaining staff fulfillment shall be trained and qualified within 30 days.
1.6.1.1.1 The contractor shall comply with DHA and WHCA transition-in requirements listed in paragraph 1.11.
1.6.1.2 Transition-out period: The transition-out plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract. (Deliverable 1).
1.6.1.2.1 The contractor shall comply with transition-out requirements of the DHA and WHCA for contractors who have been issued a CAC, authentication access, or who generate “records”, as defined by DoD (records manual), including DoD-directed disposition of records, and others displayed on the In/Out (I/O) Processing Portal.
1.7 Administrative specifications
1.7.1 Place of performance: The work shall be performed at the contractor site and the SMUs (All CONUS).
1.7.1.1 Upon award, SMU physical addresses will be provided.
1.7.1.2 Telework is authorized and approved at the discretion of the COR.
1.7.2 Recognized Federal holidays: The contract is not required to perform work on holidays.
| New Year’s Day | Labor Day | |||
| Martin Luther King Jr.’s Birthday | Columbus Day | |||
| President’s Day | Veteran’s Day | |||
| Memorial Day | Thanksgiving Day | |||
| Juneteenth Day National Independence Day | Christmas Day |
Independence Day
1.7.3 Hours of operation: The contractor is responsible for conducting business Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must, at all times, maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. Ad hoc and scheduled support is required outside of normal clinic hours to support configuration changes, installations, and troubleshooting that have the potential to effect clinical care delivery and/or must be scheduled around beneficiaries’ appointments.
1.8 Contractor travel: Contractor will be required to travel to attend DHA conferences in support of the PWS. Contractors shall be authorized travel expenses consistent with the cost principles and procedures in Federal Acquisition Regulation (FAR) Part 31.2, Travel Costs and the limitations of funds specified in this contract. All travel requires Government approval/authorization and notification to the Contracting Officer Representative (COR).
1.8.1 Arrangements and costs of all travel, transportation, meals, lodging, and incidentals are the responsibility of the Contractor. Travel costs shall be incurred and billed in accordance with FAR Part 31 and Department of Defense Instruction (DoDI) 5154.31, Commercial Travel Management. Costs for these expenses will be reviewed, certified, and approved by the COR. All travel and transportation shall utilize commercial sources and carriers. The Government will not pay for business class or first-class travel. Lodging and meals shall be reimbursed in accordance with regulations defined in FAR PART 31 and DoDI 5154.31, Commercial Travel Management.
1.8.2 The Government is providing a fixed price not to exceed travel line item. However, approval from the COR and proper expense reporting is mandatory prior to invoicing any travel expenses. All travel will be billed in increments set forth by the quantities outlined in the award. All excess funding not used will be de- obligated from the travel line item. Additional (adhoc) travel requirements may be required and will be incorporated via a modification to the contract.
1.8.3 OCONUS Travel: This requirement includes activity that may require Contractor travel to destinations outside of the United States. The Contractor shall ensure that assigned participants allow sufficient lead- time to obtain valid passports, country clearances, and immunizations to support project activities. For traveling to OCONUS sites, the Contractor shall make all travel/security clearance/passport/country clearance submittal arrangements for their employees. Any contractor going OCONUS TDY on behalf of the government is still obligated to complete all mandatory training prior to travel. The Contractor is responsible for country clearances, theater clearances, entering travel data into APACS (Aircraft and Personnel Automated Clearance System), Department of Defense Contractor Personnel Office (DOCPER) Contractor Online Processing System (DCOPS), Technical Expert Status Accreditation (TESA), NATO Status of Forces Agreement (SOFA) Status Accreditation of Contractor Employees (NSSACE) and entering data into the SPOT (Synchronized Pre-deployment Operational Tracker) database. The SPOT-generated LOA shows to anyone in theater that the contractor is on official Government business/travel.
For OCONUS travel, Contractor personnel shall complete the following training:
| • | ISOPREP (Isolated Personnel Report) form |
| • | SERE 100.1 Personnel Recovery |
| • | Anti-Terrorism/Force Protection |
The government will notify the contractor of any new or changing requirements for travel.
1.8.4 Government annual travel projections:
| Destination |
| Number of Trips |
| Number of People |
| Duration of Stay |
| Travel expected in: |
| DHITS |
| 1 |
| 1 |
| 5 days |
| All Options |
| NATO - CWIX |
| 1 |
| 1 |
| 17 days |
| All Options - Excluding Base Year |
| Germany |
| 2 |
| 1 |
| 6 days |
| Base Year Only |
1.9 Other Direct Costs (ODC): N/A
1.10 Quality
1.10.1 Quality Control (QC): The contractor shall develop and maintain an effective QC program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure nonrecurrence of defective services. The contractor’s QC program is the means by which the work complies with stated requirements. The QCP will initially be submitted with the offeror’s proposal and will be updated upon award. The QCP shall document how the Contractor will meet and comply with the quality standards established in this statement of work. After acceptance of the Quality Control Plan (QCP) the contractor shall receive the CO’s acceptance in writing of any proposed change to his QC system. See Part 7, Technical Exhibit 1 - CDRL A001.
1.10.2 Quality assurance (QA): The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.11 Contractor personnel
1.11.1 CAC requirements: For all contractors who will work in Government facilities, the Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the PWS. A CAC is the standard identification for eligible DoD contractor personnel.
1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).
1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements:
1.11.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx
1.11.2.2 The DHA’s contractor training instructions embedded at Part 7 Section 7.1.2.
1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at: https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure (PKI)-restricted, printed versions available).
1.11.2.4 The DHA’s new employee handbook at Part 7 Section 7.1.4.
1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
1.11.4 Key control: Reserved
1.11.5 Lock combinations: Reserved
1.11.6 SMU Access: The contractor shall complete the WHCA badge and access process.
1.11.6.1 SMU visits: For ad hoc SMU visits, the contractor shall provide advance notice and comply with the visitor request process.
1.12 Key personnel (Contractor): The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the COR. The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to operations for the contract. The contract manager or alternate shall be available between 8:00 am and 4:30 pm, Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons. Qualifications for all key personnel are listed below:
1.12.1 Contract Manager
· Have an active TS clearance,
· Must hold a minimum of a master’s degree in business management,
· Possess the following certifications: Program Management Professional (PMP) and Information Technology Infrastructure Library (ITIL) v4,
· Must have a minimum of 5 years of experience in::
· A proven track record of organizing, coordinating, and implementing IT services
· In budgeting and scheduling lifecycle management
· Providing contract management for DoD projects
· Managed and maintained IT systems, troubleshooted and resolved IT issues, and provided guidance and support
· Must be able to communicate effectively and work well in a team environment
· Possess excellent problem-solving and critical-thinking skills
· Be proficient in relevant IT tools, procedures, processes, and services
1.12.2 Subject Matter Expert:
· Have an active TS SCI (Yankee White) clearance,
· Must hold at a minimum a bachelor’s degree in an IT discipline,
· Possess the following certifications: Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Network Defense Architect (CNDA), Certified Penetration Tester (CPT)
· Must have a minimum of 5 years of experience:
· Testing, evaluating, implementing, and sustaining IT systems
· Providing system and network administration
· Enforcing cybersecurity protections and adhering to DoD security policies within a clinical environment
· Managed and maintained IT systems, troubleshooted and resolved IT issues and provided guidance and support
· Must be able to communicate effectively and work well in a team environment,
· Possess excellent problem-solving and critical-thinking skills
· Be proficient in relevant IT tools, procedures, processes, and services
1.13 Data rights: Reserved
1.14 Reporting
1.14.1 Contractor Manpower Reporting (CMR): RESERVED.
1.14.2 Non-Disclosure Agreement (NDA): (Deliverable 2) All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the contract. The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than the first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide a copy to the COR.
1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.14.4 Post award conference/periodic progress meetings: The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with FAR Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.15 Contractor Identification
1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and contract status. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all government provided telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DHA understands that the person is contractor support personnel. Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their contractor status known during introductions.
1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.
1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.17 Personnel Security
1.17.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM 5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 275-6038.
1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-Services)
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.
2.2 Acronyms:
| AIS | Automated Information System | ||
| APL | Approved Products List APL | ||
| AQL | Acceptable Quality Level | ||
| ARRT | Acquisition Requirements Roadmap Tool | ||
| ATO | Authority to Operate | ||
| B2B | Business-2-Business | ||
| CAC | Common Access Card | ||
| CAP | Cloud Access Point | ||
| CCEVS | Common Criteria Cybersecurity Evaluation and Validation Scheme | ||
| CDI | Covered Defense Information | ||
| CE | Computer Environment | ||
| CDRL | Contract Data Requirement List | ||
| CIO | Chief Information Officer | ||
| CJCSM | Chairman of the Joint Chiefs of Staff Manual | ||
| CMMC | Cybersecurity Maturity Model Certification | ||
| CMR | Contractor Manpower Reporting | ||
| CNSSI | Committee on National Security Systems Instruction | ||
| CO | Contracting Officer(s) | ||
| CONUS | Continental United States (excludes Alaska and Hawaii) | ||
| COR | Contracting Officer Representative | ||
| COTR | Contracting Officer's Technical Representative | ||
| CSP | Cloud Service Provider | ||
| CSSP | Cyber Security Service Provider | ||
| CUI | Controlled Unclassified Information | ||
| CWIX | Coalition Warrior Interoperability Exercise | ||
| DAD-A | Deputy Assistant Director for Acquisition | ||
| DC3 | DoD Cyber Crime Center | ||
| DD Form 254 | Department of Defense Contract Security Requirement List (if applicable) | ||
| DB | Design-Build | ||
| DBB | Design-Bid-Build | ||
| DFARS | Defense Federal Acquisition Regulation Supplement | ||
| DHA | Defense Health Agency | ||
| DISA | Defense Information System Agency | ||
| DoD | Department of Defense | ||
| DoDD | Department of Defense Directive | ||
| DoDI | Department of Defense Instruction | ||
| DSAs | Data Sharing Agreements | ||
| DSAA | Data Sharing Agreement Application | ||
| DMZ | Demilitarized Zone | ||
| DoDM | Department of Defense Manual | ||
| DPCLO | DHA Privacy and Civil Liberties Office | ||
| DUA | Data Use Agreement | ||
| eMSM | Enhanced Multi-Service Markets | ||
| EULA | End User License Agreement | ||
| EVM | Earned Value Management | ||
| FAR | Federal Acquisition Regulation | ||
| FCI | Federal contract information | ||
| FE | Facilities Enterprise | ||
| FedRAMP | Federal Risk Authorization and Management Program | ||
| FISMA | Federal Information Security Modernization Act | ||
| FRCS | Facility Related Control Systems | ||
| FSO | Facilities Security Officer | ||
| HA | Health Affairs | ||
| HIPAA | Health Insurance Portability and Accountability Act | ||
| HCA | Head of the Contracting Activity | ||
| HIT | Health Information Technology | ||
| IGCE | Independent Government Cost Estimate | ||
| IA | Information Assurance | ||
| IO | Initial Outfitting | ||
| I/O | In/Out Processing Portal | ||
| IPv | Internet Protocol Version | ||
| IS | Information System | ||
| ISP | Internet Service Provider | ||
| IT | Information Technology | ||
| ISCM | Information Security Continuous Monitoring | ||
| IV&V | Independent Verification & Validation | ||
| MedCOI | Medical Community of Interest | ||
| MHS | Military Health System | ||
| MIL-STD | Military Standard | ||
| NATO | North Atlantic Treaty Organization | ||
| MTFs | Military Treatment Facilities | ||
| NCR | National Capitol Region | ||
| NDA | Non-Disclosure Agreement | ||
| NIAP | National Information Assurance Partnership | ||
| NIST | National Institute of Standards and Technology | ||
| OCONUS | Outside Continental United States (includes Alaska and Hawaii) | ||
| ODC | Other Direct Costs | ||
| OPM | Office of Personal Management | ||
| OSD | Office of the Secretary of Defense | ||
| P-ATO | Personal Authorization to Operate | ||
| P&R | Personnel and Readiness | ||
| PGI | Procedures, Guidance and Information | ||
| PDT | Project Delivery Team | ||
| PHI | Protected Health Information | ||
| PII | Personally Identifiable Information | ||
| PIT | Platform Information Technology | ||
| PK | Public Key | ||
| PKI | Public Key Infrastructure | ||
| POA&M | Plan of Action and Milestones | ||
| POC | Point of Contact | ||
| PMO | Program Management Office | ||
| PoP | Period of Performance | ||
| PP | Personal Property | ||
| PPSM | Ports, Protocols, and Services Management | ||
| PRS | Performance Requirements Summary | ||
| PSP | Personnel Security Program | ||
| PWS | Performance Work Statement | ||
| QA | Quality Assurance | ||
| QAP | Quality Assurance Program | ||
| QASP | Quality Assurance Surveillance Plan | ||
| QC | Quality Control | ||
| QCP | Quality Control Plan | ||
| RFP | Request for Proposal | ||
| RFQ | Request for Quotation | ||
| RMF | Risk Management Framework | ||
| SP | Special Publication | ||
| SPRS | Supplier Performance Risk System | ||
| SRM | Sustainment, Restoration and Modernization | ||
| SRG | Security Requirements Guides | ||
| STIG | Security Technical Implementation Guides | ||
| TOS | Terms of Service | ||
| US | United States | ||
| UFC | Unified Facilities Criteria | ||
| VPN | Virtual Private Network | ||
| XML | Extensible Markup Language |
2.3 Applicable Publications, DHA Administrative Instructions (AI), etc. Not applicable
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government:
☒ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below:
3.2 Facilities: The Government:
☐ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Facilities in support of this contract/task orders. The Government provided Facilities are described below:
The Government will provide the necessary workspace for the contractor staff to provide the support outlined in this PWS necessary to maintain an office environment within the Government facility. The Government will provide at the Government facility, workstations to include telephones, facsimile machines, copiers and computer equipment to include laptops for use in performance under this contract/task order. This equipment is authorized for transaction of official Government business only and shall not be used for personal business. Personal long-distance calls are not authorized, and the cost of all personal long-distance calls made by contractor or subcontractor employees may be deducted from the contractor/s invoice payments. Telephones, facsimile machines, and computer equipment to include laptops are subject to communications security monitoring at all times. Contractor and subcontract employees may be issued keys signed for at scheduled and unscheduled key control inspections. The contractor shall be required to reimburse the Government for lost keys, or lockset (if lockset is required to be replaced) as a result of lost keys. The cost of replacement of keys/locksets may be deducted from payments to the contractor. Items issued will remain the property of the Government and the contractor will maintain proper accountability of issued equipment. Equipment shall not be removed from the facilities shown in paragraph 3.2 above, unless otherwise specified in the PWS. They are to be used, turned in and/or disposed of as directed by the COR or CO.
3.3 Utilities: The Government:
☐ Will NOT provide Utilities in support of this contract/task order.
☒ WILL provide Utilities in support of this contract/task orders. The Government provided Utilities are described below:
The Government will provide all utilities in the facility that will be available for the contractor’s use in performance of tasks outlined in this PWS. The Contractor shall instruct employees in utilities conservation practices. The contractor shall be responsible for operating under conditions that preclude the waste of utilities, which include turning off the water faucets or valves after using the required amount to accomplish cleaning vehicles and equipment.
3.4 Equipment: The Government:
☒ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Equipment in support of this contract/task orders.
3.5 Materials: The Government:
☒ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ IS providing Materials in support of this contract/task orders.
PART 4
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 Services: The Contractor:
☒ Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Contractor Furnished Services required in support of this contract/task orders. These Services are described below:
4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.
4.3 Secret Facility Clearance: The contractor shall possess and maintain a TOP SECRET facility clearance from the Defense Security Service. The Contract Manager shall have a TOP SECRET security clearance, the SME shall have a TOP SECRET SCI (Yankee White), and the remaining contract staff shall have a SECRET security clearance from the Defense Counterintelligence and Security Agency.
4.4 Materials: Not Applicable
4.5 Equipment: Not Applicable
4.6 Facilities: Not Applicable
PART 5
5.0 SPECIFIC TASKS
Basic Services: The contractor shall perform analysis, life-cycle management, configuration management, financial, project management, communication management, scheduling, cybersecurity, implementation planning, deployment, sustainment, maintenance and decommissioning for DHA HIT initiatives, capabilities, systems, and services supporting the MTIO and SMUs.
5.1 SMU Support: Under guidance provided by the Government Task Lead, the contractor shall support and provide expertise to the MTIO and SMUs. Specific activities will be performed in support of each government objective and priority spanning from research prior to development to sunsetting of hardware/software systems and services. Additional support includes but is not all inclusive:
· Ensure that execution of all tasks are aligned with DoD policies and regulations and DHA processes and guidelines.
· Coordinate with all DHA Shared Services Divisions and Federal Agency stakeholders to initiate, run, facilitate, and manage meetings in support of the COR.
· Participate in and facilitate meetings as required by the government TM and COR, providing a broad spectrum of program, engineering, system administration, technical, and cybersecurity support activities.
· Administer IT, network, cyber, and system administrative support as needed to ensure security controls are consistently implemented and integrate technology with IT security standards.
5.1.1 Review and assess the future direction of and developments in HIT to ensure architectures and management structures under this contract evolve to take advantage of new product releases (hardware and software), IT innovations, and advances in technology and to retire technologies that are no longer cost effective to operate and maintain.
5.1.2 Develop test and evaluation plans for assessed hardware/software.
5.1.3 Provide monthly scans and findings for systems hosted on the MedCOI.
5.1.4 Create and submit a plan of action and milestones for high and medium scoring risks. Coordinate with Walter Reed and J6 cybersecurity division for risk assessment and authority to connect prior to implementation on the MedCOI.
5.1.5 Advise on user requirements and request for changes in services and capabilities.
5.1.6 Work with strategic partners to evaluate potential technologies to determine functionality, feasibility, and merit. Utilize modeling, hands-on testing, market surveys, prototyping and pathfinder techniques and invite customer participation in the evaluation process.
5.1.7 Develop various whitepapers on IT systems, capabilities, and security solutions and technologies.
5.1.8 Provide executive summaries on issues or high risk items.
5.1.9 Conduct and report the results of special studies that include the development of business cases, hypothetical investigations, benchmarks, standards migration, pricing, and trade studies. (Deliverable 4).
5.1.10 Assist suppliers with integration of technologies and services into the SMUs.
5.1.11 Develop, document, and coordinate implementation plans for new services and supporting systems.
5.1.12 Attend briefings
5.1.13 Update DHA J6 tools, workflows, and enterprise capability staff with SMU configuration information and changes. Participate and adhere to J6 change enablement processes.
5.1.14 Produce knowledge transfer document, per SMU prior to contract closeout (Deliverable 8).
5.1.15 The Contractor shall provide technical support to the MTIO and defense global missions in line with DOD INSTRUCTION 2000.30 and the FY23-28 Defense Health Agency Strategic Plan by providing information technology (IT) support, SOPs and contingency plans, leveraging emerging scientific and technological advancements, expanding partnerships, and adopting new models of health and wellness, with the aim of improving preparedness of local and global medical teams. Contractor shall link theater strategic requirements to national strategic medical capacity through defined organizations, processes, and tasks.
5.2 IT Project Management Support: Plan, organize, coordinate, and execute all activities associated with an assigned project and/or task. Project and task management services include:
5.2.1 Oversee management of contract performance IAW PWS tasks and corresponding performance standards.
5.2.2 Provide direction and supervision to team members.
5.2.3 Identify task order level risks and issues and develop mitigation plans and/or actions plans as necessary.
5.2.4 Create program and technical management plans supporting DHA and MTIO initiatives involving the SMUs.
5.2.5 Develop a configuration plan for DHA SMU equipment.
5.2.6 Provide a list of DHA SMU support and requirements (resources) for Ektropy tracking.
5.2.7 Provide executive summaries on SMU activities.
5.2.8 Perform a Quality Control review on all documents that will be circulated outside the MTIO.
5.2.9 Maintain management for the list of projects/task/subtasks and who is assigned to each.
5.2.10 Manage Annual Performance metrics and taskers (Deliverable 5). Prepare metrics. Provide pre-briefings. Submit metrics on behalf of MTIO. Act as POC for annual performance metrics.
5.2.11 Prepare project documentation in support of clinic changes (Deliverable 6).
5.2.12 Update/Prepare and respond to PEO Medical Systems/CIO (J-6) taskers. Solicitate input. Compile responses. Submit for approval by Division Lead. Submit approved file to Directorate (J-6) (Deliverable 7).
5.2.13 Review and update support agreement
5.2.14 Provide a weekly status report (Deliverable 3), identifying work completed, planned, and address issues, risks, configuration changes, and customer SMU key personnel changes.
PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 Work under this contract is considered unclassified and up to and including Top Secret/Sensitive Compartmented Information (TS/SCI). The Contract Manager shall have a TOP SECRET security clearance, the SME shall have a TOP SECRET SCI (Yankee White), and the remaining contract staff shall have a SECRET security clearance from the Defense Industrial Security Clearance Office. An executed DD254 are required to be part of the contract.
6.2 The TIER 1 or TIER 2 levels and position sensitivity designation for positions under this contract is:
6.2.1 TIER II: Non-critical sensitive position
6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements: Refer to Clause Section, Attachments 1 and 2 of DHA Procedures, Guidance and Information 224.90, Personally Identifiable Information (PII), PHI), and Federal Information Requirement) (Adherence to DHA Administrative Instruction-110, Safeguarding Procurement Sensitive Information, is required.)
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office (DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data. After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees shall comply with DHA and DoD training requirements, maintain certifications, and shall identify, document, track, and report qualifications of contract support.
6.4.1.1 Training: All contractor and associated subcontractor employees must complete DHA training to stay in compliance with DHA standards.
6.4.1.2 Certification: The contractor shall ensure that personnel maintain their certifications and if accessing IS have the proper and current certification to perform functions at contract award in accordance with DoD and DHA requirements. The contractor shall meet the applicable certification requirements as outlined in DFARS 252.239-2001, including:
6.4.1.2.1 DoD-approved workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and
6.4.1.2.2 Appropriate operating system certification for technical positions as required by DoD 8570.01–M.
6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the certification status of personnel performing functions.
6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS:
6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171), in accordance with DFARS clause 252.204-7012.
6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment Methodology requirement flows down to subcontractors.
6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/).
6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.
6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.
6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.
6.5.4 Cybersecurity Maturity Model Certification (CMMC) The CMMC (DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk. The CMMC requirement flows down to subcontractors.
6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization (3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.
6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.
6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.
6.5.8 Cyber Incident Reporting Requirement
6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:
6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and
6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI-Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/.
6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.
6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/.
6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.
6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
6.5.14 The contractor shall maintain within the US or US territories all Government data that…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .