RFI - Draft PWS - DaVINCI Data Services.pdf
PDF 283 KB Posted
- Attached to
- DaVINCI Data Services Federal contract opportunity
- Solicitation number
- VA-25-00030024
About this file
This is a Performance Work Statement (PWS) for DaVINCI Data Services (TAC-25-30024) issued by the Department of Veterans Affairs Office of Information & Technology. The contractor shall provide support efforts to expand and sustain the currently deployed DaVINCI Observable Medical Outcomes Partnership (OMOP) common data model, which is a secure cloud-computing infrastructure and modular analytical platform supporting benefits, services, quality, and safety investigations at the population level.
The scope includes system and database administration services, database maintenance, source DoD/VA data transfer and documentation, OMOP CDM data analysis and mapping design recommendations, ETL functional testing, and training for the VHA research community. The period of performance is a 12-month base period with four 12-month option periods, plus one optional task for transitional support. Work will be performed at contractor facilities, with anticipated travel to Salt Lake City, UT, Nashville, TN, and Washington, D.C. Key requirements include maintaining bi-directional transfer of clinical and administrative health data sources between DoD and VA systems, supporting the Military Health System Data Repository, Air Force Health Services Data Warehouse, Cerner Power Insight Enterprise Data Warehouse, and VA Corporate Data Warehouse access.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Body - DaVINCI Data Services.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology VA Informatics and Computing Infrastructure
DaVINCI Data Services
Date: Jan 7, 2025
TAC-25-30024
PWS Version Number: 2.0
DaVINCI Data Services TAC-25-30024
Contents
1.0 BACKGROUND
2.0 APPLICABLE DOCUMENTS
3.0 SCOPE OF WORK
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
4.2 PLACE OF PERFORMANCE
4.3 TRAVEL
5.0 SPECIFIC TASKS AND DELIVERABLES
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
5.1.2 REPORTING REQUIREMENTS
5.2 DoD & VA DATA ACCESS
5.3 SYSTEM ADMINISTRATION AND DATABASE MAINTENANCE SERVICES .. 9
5.4 SOURCE /VA DATA TRANSFER AND DOCUMENTATION
5.5 DoD TO OMOP CDM DATA ANALYSIS & MAPPING DESIGN
RECOMMENDATIONS
5.6 QUALITY ASSURANCE
5.7 Training
5.8 OPTIONs
5.8.1 OPTION PERIODS 1 THROUGH 4
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
e6.5.1 VA TECHNICAL REFERENCE MODEL
6.5.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT
6.5.3 INTERNET PROTOCOL VERSION 6
6.5.4 TRUSTED INTERNET CONNECTION
6.5.5 STANDARD COMPUTER CONFIGURATION
6.5.6 VETERAN FOCUSED INTEGRATION PROCESS
6.5.7 PROCESS ASSETT LIBRARY
6.5.8 AUTHORITATIVE DATA SOURCES
6.6 SECURITY AND PRIVACY REQUIREMENTS
6.6.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
6.6.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
6.7 METHOD AND DISTRIBUTION OF DELIVERABLES
6.8 PERFORMANCE METRICS
6.9 FACILITY/RESOURCE PROVISIONS
6.10 GOVERNMENT FURNISHED PROPERTY
6.11 SHIPMENT OF HARDWARE OR EQUIPMENT
TABLE 1: SUMMARY OF DELIVERABLES………………………………………………..23
ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED
ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM
SECURITY/PRIVACY LANGUAGE
1.0 BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OIT), and the Office of Research and Development, VA Informatics and Computing Infrastructure (VINCI) as a Resource Center is to provide researchers a nationwide view of high value VA patient data. VINCI is a research and development partnership and operational platform for health services research, epidemiology, decision support, and business intelligence. VINCI’s mission is to provide high-quality data, openly extensible information technology, and supporting services to generate and integrate new knowledge, methods, and technologies for research and medical-care communities to assess and improve Veterans’ healthcare and to provide benefits and services to Veterans. In meeting these goals, OIT strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care, as well as throughout all the points of the Veterans’ health care in an effective, timely, and compassionate manner. VA depends on Information Management/Information Technology (IM/IT) systems to meet mission goals.
VINCI has partnered with the Department of Defense (DoD), Air Force Health Services Data Warehouse (HSDW), in a project known as the DoD and VA Infrastructure for Clinical Intelligence (DaVINCI). The goal of DaVINCI is to increase DoD-VA data integration for interagency collaboration and resource sharing in support of the Joint Strategic Plan and each agency’s healthcare and benefits missions.
DaVINCI is a robust program that delivers a powerful capability to analyze combined DoD and VA healthcare data, addressing the problems of inefficient, piecemeal approaches to sharing and analyzing data. DaVINCI deploys and evaluates solutions for governance, data integration, data security, analysis, and supercomputing to provide a solid foundation for integrated clinical and business intelligence platforms. By allowing a more complete read-only view into a beneficiary’s records, DaVINCI can facilitate improved coordination of polytrauma patients and accelerated disability evaluations. By allowing more rapid analysis of many beneficiaries’ longitudinal records, this program can facilitate more accurate and efficient screening for syndromes such as traumatic brain injury and planning for joint activities such as inter-agency resource balancing of specialty-care.
As DaVINCI has matured and completed the Joint Incentive Fund project, this requirement is intended to continue to build and develop the DaVINCI resource.
DaVINCI is a dynamic and complete longitudinal database, and a necessary resource for both DoD and Veterans Health Administration (VHA) research communities.
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement (PWS), the Contractor shall comply with the following:
1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”
2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
3. 10 U.S.C. § 2224, "Defense Information Assurance Program"
4. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
5. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
6. VA Directive 0710, “Personnel Suitability and Security Program,” June 4, 2010, http://www.va.gov/vapubs/
7. VA Handbook 0710, Personnel Suitability and Security Program, September
10, 2004, http://www.va.gov/vapubs
8. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
9. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility
Standards,” July 1, 2003
10. Office of Management and Budget (OMB) Circular A-130, “Management of
Federal Information Resources,” November 28, 2000
11. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed
Services (CHAMPUS)”
12. An Introductory Resource Guide for Implementing the Health Insurance
Portability and Accountability Act (HIPAA) Security Rule, October 2008
13. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7,
14. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
15. VA Directive 6500, “Managing Information Security Risk: VA Information
Security Program,” September 20, 2012
16. VA Handbook 6500, “Risk Management Framework for VA Information
Systems – Tier 3: VA Information Security Program,” March 10, 2015
17. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
18. VA Handbook 6500.2, “Management of Breaches Involving Sensitive
Personal Information (SPI)”, October 28, 2015
19. VA Handbook 6500.3, “Assessment, Authorization, And Continuous
Monitoring Of VA Information Systems,” February 3, 2014
20. VA Handbook 6500.5, “Incorporating Security and Privacy in System
Development Lifecycle”, March 22, 2010
21. VA Handbook 6500.6, “Contract Security,” March 12, 2010
22. VA Handbook 6500.8, “Information System Contingency Planning”, April 6,
23. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.asp)
24. National Institute Standards and Technology (NIST) Special Publications
(SP)
25. VA Directive 6508, Implementation of Privacy Threshold Analysis and
Privacy Impact Assessment, October 15, 2014
26. VA Directive 6300, Records and Information Management, February 26,
27. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
28. OMB Memorandum, “Transition to IPv6”, September 28, 2010
29. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, February 17, 2011
30. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 20, 2014
31. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
32. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
33. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3,
34. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
35. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
36. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008
37. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
38. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013
39. Draft NIST Special Publication 800-157, Guidelines for Derived PIV
Credentials, March 2014
40. NIST Special Publication 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
41. Draft National Institute of Standards and Technology Interagency Report
(NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
42. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland
Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
43. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
44. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
45. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
46. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
47. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
48. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
49. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
50. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
51. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015
52. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
53. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
54. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
55. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote
Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
56. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
57. VA Memorandum, “Implementation of Federal Personal Identity Verification
(PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
58. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
59. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015;
https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
60. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
3.0 SCOPE OF WORK
The Contractor shall provide DaVINCI support efforts that continue to expand and sustain the currently deployed DaVINCI Observable Medical Outcomes Partnership (OMOP) common data model (CDM). The OMOP CDM is a secure cloud-computing infrastructure, and modular analytical platform that support benefits, services, quality, and safety investigations at the population level. Additionally, the contractor shall support the bi-directional transfer and use both clinical and administrative health data sources for DoD and VA to continue expansion of the DaVINCI OMOP CDM, access to the Military Health System Data Repository (MDR), the HSDW, Cerner Power Insight Enterprise Data Warehouse (PI-EDW), and the VA Corporate Data Warehouse (CDW).
Specifically, the Contractor shall provide data services to include: system and database administration; database maintenance services; source DoD/VA data transfer and documentation; OMOP CDM data analysis & mapping design recommendation documentation; extract transfer load (ETL) functional testing (in addition to quality assurance testing of the ETL process); and training in the use of DoD and VHA health data (in addition to support an optional task for transition of the data source when the Cerner Data warehouse application is deployed at the direction of the government).
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The period of performance (PoP) shall be 12 month base period with four (4) 12-month option periods, and one (1) optional task for transitional support. The optional task may be exercised at any time at the government’s discretion, independently of the yearly option periods.
There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
New Year's Day January 1 Independence Day July 4 Veterans Day November 11 Christmas Day December 25 Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November
If any of the above falls on a Saturday, then Friday shall be observed as a holiday.
Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
4.2 PLACE OF PERFORMANCE
Tasks under this PWS shall be performed at Contractor facilities.
4.3 TRAVEL
The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the PoP. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.
The total estimated number of trips in support of the program related meetings for this effort is four (4) trips during the base period and each option period (20 trips over the total PoP, if exercised). Travel is anticipated to Salt Lake City, UT, Nashville, TN, and Washington, D.C., with the potential for other training locations throughout the U.S.
Each trip is estimated at four (4) days in duration and will require up-to four (4) Full Time Equivalents.
5.0 SPECIFIC TASKS AND DELIVERABLES
The Contractor shall perform the following:
5.1 PROJECT MANAGEMENT
5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated quarterly. The Contractor shall update and maintain the VA PM approved CPMP throughout the PoP.
Deliverable:
A. Quarterly Contractor Project Management Plan
5.1.2 REPORTING REQUIREMENTS
The Contractor shall provide the Contracting Officers Representative (COR) with Quarterly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month.
The Quarterly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Information and Communication Technology (ICT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.
Deliverable:
A. Quarterly Progress Report
5.2 DoD & VA DATA ACCESS
Data for this project is provided from Defense Health Agency’s data warehouse generated from MHS GENESIS EHR data and legacy Composite Health Care System/Armed Forces Health Longitudinal Technology Application sites. VHA’s data warehouse is populated from Oracle Cerner EHR data and more than 150 unique instances of Veterans Health Information Systems & Technology Architecture (VistA)/Computerized Patient Record System.
The Contractor shall obtain full access to data sources for both DoD and VA within five
(5) business days from date of award. The Contractor shall work with VHA Privacy Office within VA and Defense Health Agency Privacy Office within DoD to obtain the required access. The Contractor shall submit user account access forms to the VHA Privacy Office and Health Agency Privacy Office and perform any required supplemental processes required for data access. The Contractor shall ensure that it obtains and executes all data use agreements and that it safeguards the data per the requirements of Addendum B and VA Information and Information System Security/Privacy Language, VA Handbook 6500.6, Appendix C, March 12, 2010. As part of obtaining access the Contractor shall prepare and submit whatever documents, information, etc. is necessary, and submit for and obtain approval for all user account access forms.
5.3 SYSTEM ADMINISTRATION AND DATABASE MAINTENANCE SERVICES
The Contractor shall provide Systems and Database Administration services to support the DaVINCI Project. The Contractor shall
a. Provide system administration services, such as maintain current and set up new as needed, ETL, allocating file directory spaces, assigning passwords, implementing security protocols, backup, and maintenance. The Contractor shall provide a maintenance log that includes the type of maintenance/backups performed and the date and time. The maintenance log shall be incorporated into the Quarterly Progress Report.
b. Maintain and configure the DaVINCI database located at the Austin Information Technology Center. The DaVINCI database handles DoD and VA OMOP data and Observational Health Data Sciences and Informatics tools. The Contractor shall support the ongoing use of the system through regular execution and validation of ETL transfers for the production data for both VA and DoD with regards to the destination OMOP CDM. The Contractor shall provide maintenance throughout the operating hours for VINCI (Monday through Friday;
8:30AM to 10:30PM EST).
c. Provide database administration to optimize OMOP tables (indices, partitions, for parallel process) / optimize ETL processes / optimized queries for common tasks.
5.4 SOURCE VA DATA TRANSFER AND DOCUMENTATION
The Contractor shall provide quarterly updates, at a minimum, to the Interface Control Documents, describing the feeds from the DoD and VA systems that support DaVINCI.
The Contractor shall also provide a data dictionary for the common source files between DoD and VA and develop a living DoD/VA data dictionary which will be updated as required and provided to researchers who want to use the DoD/VA source data as needed.
Deliverables:
A. Quarterly Interface Control Documents
B. DoD/VA Data Dictionary
5.5 DOD TO OMOP CDM DATA ANALYSIS & MAPPING DESIGN
RECOMMENDATIONS
The Contractor shall analyze existing DoD data structures and prepare a table that summarizes the structure of each of the clinical domains of interest (see table below for examples of VA Clinical Domains of Interest) with regards to the transformation to the OMOP CDM. The Contractor shall develop an ETL design that continues to develop the OMOP CDM and document updates in the existing ETL Design Document. The Contractor shall coordinate with stakeholders such as the VA business ETL team to continue development of the ETL design. The VA business ETL team will execute the ETL design document into operational programming code. If unexpected issues (such as data variables, data value, mapping problems and missing data) arise, the Contractor shall provide further discovery and design recommendations. Any further iterations of the ETL design documentation shall be the responsibility of the Contractor to complete until the ETL is functioning properly. It is expected that the Contractor will leverage much of the discovery and deliverables of previous ETL iterations to maintain continuity of the System Administration and Database Maintenance Services and Source/VA Date Transfer and Documentation sections above. The Contractor shall update the existing Data Analysis and Mapping Design document describing the ETL design regarding any new data mapping from DoD source to the latest OMOP CDM.
The document shall include all pertinent new data source information, including mapping design and ETL requirements as new data elements are identified and included in the DaVINCI dataset to reflect the most status of the DaVINCI ETL process.
The Contractor shall map each identified data element from DoD data stores onto the OMOP CDM, identifying the source of each variable correlating and comparing the DoD source variable with the corresponding VA variable. The Contractor shall identify all relevant DoD clinical data tables for clinical domains of interest, relevant to the conversion of the DoD data to the OMOP CDM and provide evidence of discovery in the DoD Table Clinical Domains of Interest. Information regarding clinical domains can be in many places and can be different flavors for specific content (orders, administrations, business/cost, etc.). The table below contains a list of clinical domains of interest relevant to the VA conversion of VISTA CDW data to the OMOP CDM. This list, while inclusive of VISTA CDW data, may be amended over time with the inclusion of additional data elements that enrich the content of the DaVINCI Dataset as designated by the Government. During discovery, it is expected that not all these domains may exist in the DoD. The Contractor shall update any DoD data element limitations or recommended transformation, or cleaning efforts required for use in the CDM in the existing DoD Data Limitations Document. The Contractor shall update the process to identify and execute the transformational rules and document all rules that are approved by the relevant stakeholders in the existing DoD Data Limitations Document. The Contractor shall also recommend and update data cleaning and transformation rules as needed.
Deliverables (updated versions to the following, as required):
A. DoD Table of Clinical Domains of Interest B. ETL Design Document C. Data Analysis and Mapping Design Document D. DoD Data Limitations Document
5.6 QUALITY ASSURANCE
The Contractor shall conduct quality assurance and ETL testing in collaboration with the VA business ETL team to clean and transform DoD and VA healthcare data into a the OMOP CDM. The Contractor shall provide testing to ensure the ETL process has not corrupted the core data. Testing shall consist of generic checks for concept mapping by table, null value searches, source data without concept or higher level (RxNorm) mapping, volume/Activity Review, Value-Range Review, hierarchy/vocabulary mapping review, specific, high interest data review by data group, Quality Improvement Indicator, Quality of Life, User requests (VA station in the visit table, local drug text from source in drug exposure table, etc.). The contractor shall conduct Quality Assurance Testing to include Checksum, # distinct values between OMOP and source, rows source vs rows OMOP; Proportion of top 10, 50, 100 values between OMOP and source, proportion of values in OMOP, similar in source data; Min, max, etc. for clinically relevant values;
Discontinued codes from null value search; The Contractor shall document the results in a test report.
Deliverable:
a. Test Report
5.7 TRAINING
The Contractor shall provide training for the VHA research community in the use of health data in a variety of settings, including classrooms, conferences, and webinars.
Examples of VA Clinical Domains of Interest Outpatient Medications Patient Demographics Inpatient Medications Laboratory Administrative Data (Conditions, Procedures)
Narrative Clinical Notes
HealthCare Cost Radiology Pathology Microbiology Surgery Clinical Registries of Interest (Oncology, Sexual
Trauma, Polytrauma, PTSD, Mental Health, Implantable Medical Devices)
Immunizations Allergies Consults Clinical Team Assignments (Primary Care, Sub-
Specialty, Etc.)
Ancillary Services Eligibility Outpatient Encounters Inpatient Encounters
Training shall consist of guidance for researchers on the use of electronic medical record data including identifying strengths and weaknesses of data, designing data files, helping with privacy aspects, such as de-identification; and use of DOD Source Data and application of completed and transformed DOD Data into the OMOP CDM. The Contractor shall develop user guides and other educational materials and shall conduct quarterly training sessions. Each session will last one (1) hour, with 45 minutes of presentation and 15 minutes allowed for question and answer. The number of students estimated for classroom training session is 30 students. Most of the training sessions are anticipated to be conducted virtually. The training sessions shall include written training material for each student which will include information on what types of data can be made available and the strengths and weaknesses of it. The Contractor shall maintain all required training and training materials which may require periodic updating.
Deliverable:
A. Training Materials
5.8 OPTIONS
5.8.1 OPTION PERIODS 1 THROUGH 4
If Option Periods 1, 2, 3 and/or 4 are exercised, the Contractor shall perform all tasks identified in Sections 5.1 through 5.7.
5.8.2 TRANSITION SUPPORT (Optional Task)
Activities related to this task will be exercised if/when the Government decides the Cerner Warehouse application is prepared to begin accepting and functioning as the joint data warehouse solution.
The Contractor shall prepare a comprehensive Transition Plan within 30 days of exercise of the optional task. The Transition Plan shall address required tasks during the last 30 days of the PoP. The PoP for the Optional task is 60 days. The Transition Plan shall enable a deliberate transition with minimal disruption to services.
The Transition Plan must be comprehensive, beginning with administration of resources and ending with a full operational handoff to the Cerner Application team.
The Transition Plan shall cover at a minimum:
Knowledge Management DaVINCI Process Documentation o DoD Table of Clinical Domains of Interest o ETL Design Document o Data Analysis and Mapping Design Document o Requirements Document o DoD Data Limitations Document
Familiarization Training Schedule Development and Management Risk Management
Phased Operational Handoff
The Transition Plan shall include a Contract Transition Team Roster including an itemized activity matrix that links tasks to members of the Cerner Application Transition team. The matrix shall identify the required task, level of risk to services, resources identified to perform the task, and artifacts associated with tasks. The matrix shall cover the scope of transition to include accountability and disposition of Government furnished information, hardware, software, and artifacts (historical documents, processes, procedures, knowledge management tools, manuals, code, etc.), if any.
Deliverable:
A. Contract Transition Team Roster B. Transition-Out Plan
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
6.1.1 VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
6.1.2FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT
The Contractor shall ensure Commercial Off-The-Shelf product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M- 05-24, and M-11-11 can be found at:
https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy 2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11- 11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support the following:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VAIQ# 7712300 Mandate to meet PIV requirements for new and existing systems.
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4846
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
6.1.3 INTERNET PROTOCOL VERSION 6
The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2005/m05-22.pdf) and September 28, 2010 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transiti on-to-ipv6.pdf). IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance (https://csrc.nist.gov/publications/sp) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at:
https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.
6.1.4 TRUSTED INTERNET CONNECTION
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/f y2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.
6.1.5 STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Office 365 ProPlus. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Windows 10. However, Windows 10 is not the VA standard yet and is currently approved for limited use during its rollout. We are in-process of this rollout and making Windows 10 the standard for OIT. Upon the release approval of Windows 10 as the VA standard, Windows 10 will supersede Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
6.1.6 VETERAN FOCUSED INTEGRATION PROCESS
The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products
6.1.7 PROCESS ASSETT LIBRARY
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards.
The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf.
The main PAL can be accessed at www.va.gov/process.
6.1.8 AUTHORITATIVE DATA SOURCES
The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable (see below). The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support the following:
1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.
2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.
3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. eCMS is the authoritative source for VA procurement actions data.
4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.
5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.
6. Interfacing with VA/DoD Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in the VA.
6.2 SECURITY AND PRIVACY REQUIREMENTS
It has been determined that protected health information (PHI) may be disclosed or accessed and a signed Business Associate Agreement (BAA) shall be required. The Contractor shall adhere to the requirements set forth within the BAA, referenced in Section D of the contract, and shall comply with VA Directive 6066.
Deliverable:
A. Business Associate Agreement
6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task
Task Number Tier1 / Low Risk Tier 2 / Moderate Risk
Tier 4 / High Risk
5.1.1 5.1.2 5.2 5.3 5.4 5.5 5.6
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
6.2.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
Contractor Responsibilities:
a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.
b. Within 3 (three) business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 (one) business day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the PoP. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.
c. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.
d. The Contractor shall ensure the following required forms are submitted to the COR within 5 (five) calendar days after contract award:
1) Optional Form 306
2) Self-Certification of Continuous Service
3) VA Form 0710
4) Completed SIC Fingerprint Request Form
e. The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).
f. The Contractor employee shall certify and release the e-QIP document, print, and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note:
OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 (three) business days that documents were signed via e-QIP).
g. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.
h. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor shall be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of
OPM.
i. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.
j. Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.
k. Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, always displaying their badges, and returning the identity credentials upon termination of their relationship with
VA.
Deliverable:
A. Contractor Staff Roster
6.3 METHOD AND DISTRIBUTION OF DELIVERABLES
The Contractor shall deliver documentation in electronic format, unless otherwise directed. Acceptable electronic media include MS Word 2000/2003/2007/2010, MS Excel 2000/2003/2007/2010, MS PowerPoint 2000/2003/2007/2010, MS Project 2000/2003/2007/2010, MS Access 2000/2003/2007/2010, MS Visio 2000/2002/2003/2007/2010, AutoCAD 2002/2004/2007/2010, and Adobe Postscript Data Format (PDF).
6.4 PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
Performance Objective
Performance Standard Acceptable Levels of Performance
A. Technical / Quality of Product or Service
1. Demonstrates understanding of requirements
2. Efficient and effective in meeting requirements
3. Meets technical needs and mission requirements
4. Provides quality services/products
Satisfactory or higher
B. Project Milestones and Schedule
1. Established milestones and project dates are met
2. Products completed, reviewed, delivered in accordance with the established schedule
3. Notifies customer in advance of potential problems
Satisfactory or higher
C. Cost & Staffing 1. Currency of expertise and staffing levels appropriate
2. Personnel possess necessary knowledge, skills, and abilities to perform tasks
Satisfactory or higher
D. Management 1. Integration and coordination of all activities to execute effort
Satisfactory or higher
The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS in an acceptable level of performance. The Government reserves the right to alter or change the surveillance methods in the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.
6.5 FACILITY/RESOURCE PROVISIONS
The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.
The Contractor shall request other Government…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .