RFO_10815130.pdf

PDF 817 KB Posted

Attached to
RFO 10815130 eFax Software Solution State and local contract opportunity
Solicitation number
0000036674
Issued by
California

About this file

This is a Request for Offer (RFO) 10815130 issued by California Correctional Health Care Services (CCHCS) for procuring an Electronic Fax (eFax) software solution. The RFO seeks a cloud-based software solution with 600 fax lines capable of handling 550,000 electronically faxed pages annually. The solicitation requires the software to be accessed via an encrypted web portal, integrate with Microsoft Azure Active Directory, be compatible with Windows 11 and Microsoft Edge, support Azure Single Sign-On, and operate in a Zero Trust infrastructure. The contract term is upon approval, not to exceed 12 months, with key response dates including September 22, 2025, for last day to submit questions, September 24, 2025, for last day to respond to questions, and September 26, 2025, as the final date to submit an RFO package.

The pricing and evaluation will be based on a "Best Value" methodology, with contractors required to complete a cost worksheet detailing unit prices for fax lines and pages. The assessment will include administrative requirements, technical evaluation of mandatory and desirable requirements, and a cost assessment. Mandatory requirements include encryption, automated notifications, legally binding fax signatures, and FIPS 140-2 compliance. Desirable requirements include HITRUST certification, mobile applications, role assignment capabilities, and SOC 2 Type II certification. The contract includes extensive security provisions, particularly around protecting Protected Health Information (PHI), with requirements for data protection, breach notification, and compliance with HIPAA regulations.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR OFFER (RFO) 10815130

September 15, 2025

You are invited to review and respond to RFO# 10815130 California Correctional Health Care Services (CCHCS) to procure an Electronic Fax software solution. By submitting your offer, you agree to comply with the instructions contained in this document as well as the requirements described in the associated Exhibit A – Scope of Work. Please read the enclosed document carefully.

The proposed term of the Agreement is upon approval not to exceed 12 months. The Agreement award is subject to availability of funds approved for this purpose and only by mutual consent of the parties in writing.

RFOs must be received no later than the date and time specified in Section Key Action Dates. Failure to comply with any of the instructions may cause the offer to be rejected.

Please note that no verbal information given will constitute a binding agreement with CCHCS unless such information is issued in writing as an official addendum.

CCHCS Procurement Official: Kamran Khalid Phone: 916-691-2369 Email: Kamran.Khalid@cdcr.ca.gov

RFO # 10815130

CALIFORNIA CORRECTIONAL HEALTH CARE SERVICES

Table of Contents

I. Response Guidelines

II. Exhibit A – Scope of Work

III. Exhibit B – Budget Detail and Payment Provisions

IV. Exhibit C – Cost Worksheet

V.

Exhibit D – Information Technology – General Provisions Cloud Computing Services

VI. Exhibit E – HIPAA Business Associate Agreement

VII. Required Attachments Checklist

Attachment 1 Agreement Cover Letter

Attachment 2 Mandatory Requirements

Attachment 3 Desirable Requirements

Attachment 4 Bidder’s Declaration Form, GSPD-05-105

Attachment 5 Disabled Veteran Business Enterprise Declarations, DGS PD 843

Attachment 6 Iran Contracting Act Verification Form

Attachment 7 California Civil Rights Laws, DGS OLS 04

Attachment 8 Darfur Contracting Act Certification, DGS PD 1

Attachment 9 Payee Data Record, STD. 204

Attachment 10 Supplement Vendor Payee Data Record

Attachment 11 Generative Artificial Intelligence Disclosure & Factsheet, AMS 708

I.

Response Guidelines

This RFO, including all exhibits, and Offeror’s response, will be made part of the CCHCS IT ordering department’s purchase documents and/or procurement contract file.

1. Submission of Quotes

The complete RFO package submission must be emailed to Kamran.Khalid@cdcr.ca.gov. The email subject must start with “RFO 10815130”. If attachments are too large for a single email, then you may split the response into multiple emails.

Note: It is the sole responsibility of the Offeror to contact the Contract Analyst to verify receipt of submitted Quote. CCHCS is not responsible for e-mail loss or delivery delays.

2. Key Action Dates

Time is of the essence both for the RFO submittal and contract completion. Please take note of the key dates and times shown below:

EVENT DATE AND TIME

1 Last Day to Submit Questions

All questions regarding the content of this RFO should be submitted in writing electronically to Kamran.Khalid@cdcr.ca.gov. To be considered, questions must be received by September 22, 2025. Questions not submitted as required may not be addressed.

Last Day to Respond to Questions

September 24, 2025

Final Date to Submit an RFO Package

September 26, 2025

3 Agreement Term Upon approval, not to exceed 12 months

3. RFO Response Requirements and Content

RFO response must contain all requested information and data and must conform to the format described in this RFO. It is the Offeror’s responsibility to provide all necessary information for assessment by CCHCS. Responses will be verified and Offeror’s ability to perform under the RFO will be determined by CCHCS as outlined in the RFO.

A. Offerors must include all applicable items listed on the Required Attachments

Checklist. RFO packages that are conditional or fail to submit the required documentation by the date and time shown in the Key Action Dates may cause CCHCS to deem the Offer as non-responsive.

B. The specific tasks associated with this RFO are included in the Exhibit A - Scope of Work (SOW). Offerors must be submitted for the performance of all services described herein. Any deviation from the work specifications will eliminate the Offeror from further consideration and award.

C. CCHCS will not accept alternate contract language from the Offeror. CCHCS objects to and will not evaluate or consider any additional terms or conditions submitted by an Offeror. There will be No negotiations of any terms or conditions.

If a contract is awarded to the Offeror, the Offeror agrees to execute CCHCS terms and conditions in:

• Exhibit D - Information Technology – General Provisions Cloud Computing Services

By responding to RFO# 10815130, the Offeror agrees to the state’s Terms and Conditions above. If the Offeror refuses to agree to the state’s Terms and Conditions after an award is made, then that refusal could be grounds to rescind the award and award the contract to another Offeror.

D. Costs incurred for the development of Offers, in anticipation of award, are entirely the responsibility of Offeror and shall not be charged to CCHCS or the State of California.

E. CCHCS may amend or modify the RFO prior to the Final Date for Offer Submission indicated in the Key Action Dates of this RFO. All modifications and/or amendments to the RFO will be made in writing and released to all parties who received the RFO.

Additionally, CCHCS may extend the submission date of the RFO.

F. Offers submitted as Small Business (SB) and/or Disabled Veteran Business

Enterprise (DVBE) must provide and include a SB/DVBE Certification. In accordance with California Government Code Section 14837(d) and California Military and Veterans Code Section 999, all SB and DVBE contractors, subcontractors and suppliers that offer on or participate in a State contract, shall perform a Commercially Useful Function (CUF) and provide a CUF declaration.

G. CCHCS is not required to make an award under this RFO.

4. Generative Artificial Intelligence (GenAI) Notification Requirements

The State of California seeks to realize the potential benefits of GenAI, through the development and deployment of GenAI tools, while balancing the risks of these new technologies.

Bidder / Offeror must notify the State in writing if it: (1) intends to provide GenAI as a deliverable to the State; or (2), intends to utilize GenAI, including GenAI from third parties, to complete all or a portion of any deliverable that materially impacts: (i) functionality of a State system, (ii) risk to the State, or (iii) Contract performance. For avoidance of doubt, the term “materially impacts” shall have the meaning set forth in State Administrative Manual (SAM) § 4986.2 Definitions for GenAI.

Failure to report GenAI to the State may result in disqualification. The State reserves the right to seek any and all relief to which it may be entitled to as a result of such non-disclosure.

Upon notification by a Bidder / Offeror of GenAI as required, the State reserves the right to incorporate GenAI Special Provisions into the final contract or reject bids/offers that present an unacceptable level of risk to the State.

Government Code 11549.64 defines “Generative Artificial Intelligence (GenAI)” as an artificial intelligence system that can generate derived synthetic content, including text, images, video, and audio that emulates the structure and characteristics of the system’s training data.

5. Contractor Minimum Qualifications

A. Must currently be in good standing to do business in the State of California.

B. Must meet all requirements specified in Exhibit A – Scope of Work.

6. Assessment and Selection Process All offers are reviewed for Responsiveness and Completeness as defined in the requirements of the RFO. Incomplete offers will not be considered.

The CCHCS Assessment and Selection Team will compare responsive offers based on the “Best Value” methodology, which includes costs as a factor. Best value will be determined based on the criteria listed below:

• Completeness of Offer and adherence to all Administrative Requirements

• Desirable Qualifications

• Cost Worksheet – Exhibit C

Award of a contract resulting from this RFO will be based on a “Best Value” with cost as one of the criteria. CCHCS is not constrained to accept the lowest cost bid and will compare all bids to determine best value, which means the bid that best meets, and potentially exceeds, CCHCS requirements at the most reasonable overall cost.

Administrative Requirements

The Assessment Team reviews the Offers to determine whether all Administrative Requirements were provided. Responsiveness to the requirements in this RFO will be either given a “pass” (e.g., complied with requirements, completed, and returned documents) or “fail” (e.g., did not comply with requirements, did not complete or return documents). Only those Offers that receive a passing score will proceed to the next step.

Technical Evaluation

A. Review and verify the Mandatory Requirements in Attachment 2. Offeror shall mark an

“X” for each Mandatory Requirement that can be met. Responsiveness to the Mandatory Requirements will be either given a “pass” (e.g., all requirements are selected as “Can Meet”) or “fail” (e.g., one or more requirements are selected as “Cannot Meet”).

B. Review and verify the Desirable Requirements in Attachment 3. Offeror shall mark an “X” for each Desirable Requirement that can be met and receive one (1) point per criteria. If a Contractor does not meet the Desirable Requirement, the candidate will receive zero (0) point.

Cost Assessment

Contractors must provide a Cost Worksheet – Exhibit C listing the total price.

Calculated as follows:

Lowest Offered Cost divided by Higher Cost = Cost Ratio. Cost Ratio multiplied by Total Cost Points = Awarded Cost Points

Example:

Lowest Proposed Offer x 89= Offeror’s Points

Offeror’s Total Cost

$120 x 89 = 82.15 points $130

Administrative Requirement Evaluation Criteria

Attach all applicable documents, complete all exhibits, and compliance with RFO response:

1. Scope of Work, Exhibit A

2. Cost Worksheet, Exhibit C

3. Agreement Cover Letter, Attachment 1

4. Mandatory Requirements, Attachment 2

5. Desirable Requirements, Attachment 3

6. Bidder’s Declaration Form, GSPD-05-105, Attachment 4

7. Disabled Veteran Business Enterprise Declarations, DGS

PD 843, Attachment 5

8. Iran Contracting Act Certification, Attachment 6

9. California Civil Rights Laws, DGS OLS 04, Attachment 7

10. Darfur Contracting Act Certification, DGS PD 1, Attachment 8

11. Payee Data Record, STD. 204, Attachment 9

12. Supplement Vendor Payee Data Record, Attachment 10

13. Generative Artificial Intelligence Disclosure & Factsheet, AMS 708, Attachment 11

Pass/Fail

Technical Evaluation

Review and verify Mandatory Requirements in Attachment 2 (All items checked as “Can Meet”

Evaluation Criteria

Pass/Fail

Review and verify Desirable Requirements in Attachment 3 (1 Point for each requirement)

11 Points Maximum

Cost Assessment Evaluation Criteria

Cost Worksheet - Exhibit C - Cost Assessment 89 Points Maximum

II.

Exhibit A

Scope of Work

1. Contract Description:

California Correctional Health Care Services (CCHCS) Information Technology Services Division is requesting to procure an Electronic Fax (eFax) software solution.

Contractor agrees to provide CCHCS the certain software licenses as identified in Exhibit C - Cost Worksheet, of this Agreement. The licenses, warranties, and maintenance will be provided by the manufacturer.

2. Working Location:

All work performed by all parties shall be performed remotely.

3. Period of Performance:

The term of the Agreement is upon approval through twelve (12) months.

4. Proposed Software Solution Mandatory Requirements:

The eFax software solution shall comply with the following Mandatory Requirements.

To ensure compliance with the Mandatory Requirements, Contractors must complete

Attachment 2 - Mandatory Requirements, of this document.

a) Six-hundred (600) fax lines

b) Five-hundred and fifty-thousand (550,000) pages faxed annually

c) Cloud-based software

d) Software is accessed via an Encrypted Web Portal (TLS v1.3)

e) Send eFax via electronic mail (email)

f) Cover Sheet feature

g) Automated Notifications via email such as faxes sent/received

h) Ability to create a fax signature that is legally binding

i) Encrypted incoming/outgoing communication

j) Ability to be utilized without a Virtual Private Network

k) No additional hardware required to utilize all core features

l) Integrates with Microsoft Azure Active Directory

m) Compatible with Azure Single Sign-On (SSO)

n) Compatible with Windows 11 Operating Systems

o) Compatible with Microsoft Edge

p) Compatible with Zero Trust Infrastructure

q) Compatible with Netskope

r) FIPS 140-2 Compliant

s) System for Cross-Domain Identity Management (SCIM) Provisioning

t) Exportable audit logs in CSV file format or similar. Data should include a log of faxes sent/received with general data points (phone numbers, date, etc).

5. Proposed Software Solution Desirable Requirements:

Each Desirable Requirement listed will be awarded one point if met. To receive points for the Desirable Requirements, Contractors must complete Attachment 3 -

Desirable Requirements of this document.

a) HITRUST (r2) certified

b) iOS application

c) Android application

d) Assign roles via Azure Active Directory Groups

e) Ability to assign roles via eFax web interface

f) Integrated with Print2Fax program

g) Compatible with Google Chrome web browser

h) Installable Windows 11 client

i) FIPS 140-2 Validated

j) FIPS 140-3 Compliant

k) Current SOC 2 Type II certification

6. Security:

Software Solution needs to operate in a Zero Trust network environment. This includes Netskope Private Access (NPA), the cloud delivered Netskope Zero Trust solution Zero Trust Network Access (ZTNA) to private applications. It secures data and resources through application-level access control based on user identity and device security posture, in alignment with the CCHCS Security Operations team.

7. Support and Training:

The integration of the new eFax software solution for the CCHCS Enterprise will be completed by the CCHCS IT Staff (Infrastructure Team and Security Operations

Team). The Contractor will provide the necessary technical support needed by the

Infrastructure Team and Security Operations Team to integrate the new eFax software into existing CCHCS infrastructure, which includes Microsoft Azure AD with

Microsoft Entra ID integration with SSO option.

a) Professional Services - the eFax software solution Support engineer will setup an interactive session to walk CCHCS Infrastructure Team and Security

Operations Team through the setup process and SSO Azure AD, and SCIM integrations) and discuss how the system should be set up to best meet the

CCHCS Enterprise needs. The eFax software solution Support vendor will provide any necessary training to the users.

b) Service Level Agreement – The software solution shall provide access to phone and ticketing-based technical support during standard business hours.

8. Acceptance of Software Solution:

The software solution must meet all requirements contained in this Scope of Work – not including Section 5 – Proposed Software Solution Desirable Requirements -- as well as all other exhibits contained in this document to be considered for evaluation.

CCHCS shall be deemed to have accepted the software solution unless CCHCS, within 30 days from the implementation date, gives Contractor written notice to the effect that Software solution fails to conform to the requirements of the Contract.

The Contractor will, upon receipt of such notice, investigate the reported deficiencies. The rights of the parties are as follows:

a) If it is found that the Software solution fails to conform to the Contract requirements, the Contractor shall have 30 days to remedy all deficiencies. If the Contractor does not remedy all deficiencies within that timeframe, then CCHCS shall have the ability to terminate the contract in its entirety.

b) If it is found that the Software solution fails to conform to the Contract requirements, and Contractor, within 45 days of receipt of the above said notice corrects the deficiencies, the State will provide Contractor with a written acknowledgement of its acceptance of said Software solution.

9. Amendments:

CCHCS reserves the option to amend the Agreement to add additional quantities up to 20% maximum of the original agreement amount consistent with the rates submitted on Exhibit C – Cost Worksheet. The Agreement award is subject to availability of funds approved for this purpose. No amendment or variation of the terms of this Agreement shall be valid unless submitted in writing, and agreed upon by both parties and approved, as required. Products are price protected (fixed prices throughout the enrollment period) at the price identified in the Exhibit C - Cost Worksheet.

10. Terms and Conditions:

To submit an offer, you must comply with the instructions contained in this document as well as the requirements described in all Exhibits and attachments.

By responding to this offer, the Offeror agrees to the State’s Terms and Conditions. If the Offeror refuses to agree to the State’s Terms and Conditions after an award is made, then that refusal could be grounds to rescind the award and award the contract to another Offeror.

11. Notices:

All notices required by or relating to this Agreement shall be in writing and shall be sent to the parties of this Agreement at their address as set below unless changed from time to time, in which event each party shall notify the other in writing, and all such notices shall be deemed duly given if deposited, postage prepaid, in the United States mail and directed to the following addresses below:

12. Primary Contacts

The technical representative during the term of this Agreement will be:

State Agency

Contractor

California Correctional Health Care

Attn: Brian Lemley Attn:

Phone: (916) 204-9958 Phone:

Address: 8260 Longleaf Dr, Elk Grove, CA, 95758

Address:

E-mail: Brian.Lemley@cdcr.ca.gov E-mail:

Direct all contract related inquiries to:

State Agency

Contractor

California Correctional Health Care

Attn: Kamran Khalid Attn:

Phone: (916) 691-2369 Phone:

Address: 8260 Longleaf Dr, Elk Grove, CA, 95758

E-mail: Kamran.Khalid@cdcr.ca.gov E-mail:

13. Advertising of Data:

The Contractor and any service providers are not authorized to use, sell, resell, package, or repackage or publicly display any information or data without the express written approval of the State. This restriction includes keyword searching or data mining of state data. Advertising is not allowed in any of these services or to any of the contacts associated with these services.

14. Termination Provisions:

The State may exercise its option to terminate this Agreement at any time with 30 calendar days’ prior written notice. Termination Provisions are referenced in Section 16 of Exhibit D - Information Technology – General Provisions Cloud Computing

Services, of this Agreement.

III.

Exhibit B

Budget Detail and Payment Provisions

1. Invoicing and Payment

A. For services satisfactorily rendered and upon receipt and approval of invoices, CCHCS agrees to reimburse Contractor for said services, no more than annually, upon receipt and approval of itemized invoices, and in accordance with Exhibit C -

Cost Worksheet.

B. Payment for services performed under the Agreement shall be made in accordance with the State of California’s Prompt Payment Act (GC Section 927 et seq.).

C. Invoices shall include the Contract Number, sufficient scope and detail to define the actual work performed, including a description of the activities of the Contractor and Subcontractor, the hours allocated to those activities, the locations where work was performed, the expenses claimed, any required reports, and shall be submitted to:

California Department of Corrections and Rehabilitation Sacramento Accounting

Office Attention: Accounts

Payable A PO Box 187015

Sacramento, CA 95818-7015

D. The Contractor also has the option to submit invoices electronically to the appropriate email address listed below. The Contractor must use the name on the

Agreement and the Agreement on the subject line of the email. The email must include an attached PDF file of the invoices, in accordance with the information above, and must reference the institution acronym and the invoice number. For electronic submission, send invoices to:

medicalcontractinvoices@cdcr.ca.gov

2. Payment Structure

The payment structure for software and maintenance for 12 months or longer will be paid for the first year only and must be invoiced on an annual basis for the remaining period. Progress payments shall occur monthly upon approval of work completed for said services in accordance with Exhibit C - Cost Worksheet. All invoices shall be submitted to the Contract Manager for review/approval.

mailto:medicalcontractinvoices@cdcr.ca.gov

3. Budget Contingency Clause

A. It is mutually agreed that if the Budget Act of the current year and/or any subsequent years covered under this Agreement does not appropriate sufficient funds for the program, this Agreement shall be of no further force and effect. In this event, the State shall have no liability to pay any funds whatsoever to

Contractor or to furnish any other considerations under this Agreement and

Contractor shall not be obligated to perform any provisions of this Agreement.

B. If funding for any fiscal year is reduced or deleted by the Budget Act for purposes of this program, the State shall have the option to either cancel this Agreement with no liability occurring to the State or offer an agreement amendment to

Contractor to reflect the reduced amount.

4. Prompt Payment Clause

A. Payment will be made in accordance with, and within the time specified in, Government Code Chapter 4.5, commencing with Section 927.

5. Travel Reimbursement

[ X ] The following does not apply to this Agreement

A. Pursuant to the terms established in this agreement, travel reimbursement may not exceed the rates, terms, and conditions that apply to comparable State employees, in accordance with travel rules and regulations, as specified in

California Code of Regulations, Title 2, Division 1, Chapter 3, and/or regulations of the California Department of Personnel Administration (DPA), specifically

Sections 599.619 through 599.631.

6. Subcontractor

For all Agreements, with the exception of Interagency Agreements and other governmental entities/auxiliaries that are exempt from bidding, nothing contained in the Agreement, or otherwise, shall create any contractual relation between the State and any subcontractors, and no subcontract shall relieve Contractor of contractor’s responsibilities and obligations hereunder. Contractor agrees to be as fully responsible to the State for the acts and omissions of its subcontractors and of persons either directly or indirectly employed by any of them as it is for the acts and omissions of persons directly employed by the Contractor. The Contractor’s obligation to pay its subcontractors is an independent obligation from the State’s obligation to make payments to the Contractor. As a result, the State shall have no obligation to pay or to enforce the payment of any moneys to any subcontractor.

IV.

Exhibit C

Cost Worksheet

Offeror’s must submit a cost quote for each item(s) in the following list and clearly state unit and extended price. Additional line items can be added at Offeror’s discretion.

Term: Upon approval, not to exceed 12 months

Description Part # Qty Unit Price Total Cost

1 eFax lines (600) 600 $ $

2 Pages faxed (550,000) 550,000 $ $

3 $ $

4 $ $

5 $ $

Grand Total $

Amendment Option (20% of Grand Total) $

V.

Exhibit D

Information Technology - General Provisions Cloud Computing Services

The following Provisions referenced herein are incorporated into this agreement:

Information Technology – General Provisions Cloud Computing Services

(REV. 2/20/2025)

https://www.dgs.ca.gov/-/media/Divisions/PD/Acquisitions/Solicitation-Document-Attachments/IT-General-Provisions-Cloud-DGS-PD-402ITGP-Revised-02202025.pdf https://www.dgs.ca.gov/-/media/Divisions/PD/Acquisitions/Solicitation-Document-Attachments/IT-General-Provisions-Cloud-DGS-PD-402ITGP-Revised-02202025.pdf

VI.

Exhibit D

HIPAA Business Associate Agreement

Recitals – STANDARD RISK

A. This Contract (Agreement) constitutes a business associate relationship under the

Health Insurance Portability and Accountability Act (HIPAA) and its implementing privacy and security regulations at 45 C.F.R. Parts 160 and 164 (collectively, the

HIPAA regulations).

B. The California Department of Corrections and Rehabilitation, California

Correctional Health Care Services (CCHCS) wishes to disclose to Business

Associate certain information pursuant to the terms of this Agreement, some of which may constitute Protected Health Information (PHI) and confidential information protected by Federal and/or state laws.

C. Protected Health Information or PHI means any information, whether oral or recorded in any form or medium that relates to the past, present, or future physical or mental condition of an individual, the provision of health and dental care to an individual, or the past, present, or future payment for the provision of health and dental care to an individual; and that identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. PHI shall have the meaning given to such term under HIPAA and

HIPAA regulations, as the same may be amended from time to time. Confidential

Information means information protected by Federal and/or state laws identified in this Agreement.

D. Unsecured Protected Health Information means protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified in guidance from the Secretary of the U.S. Department of Health and Human Services

(Secretary).

E. Security Incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of CCHCS PHI or interference with system operations in Business Associate’s information system.

F. As set forth in this Agreement, the Contractor is the Business Associate of CCHCS that provides services, medical items for identified patients, arranges, performs or assists in the performance of functions or activities on behalf of CCHCS and creates, receives, maintains, transmits, uses or discloses PHI.

G. CCHCS and Business Associate desire to protect the privacy and provide for the security of PHI and confidential information created, received, maintained, transmitted, used or disclosed pursuant to this Agreement, in compliance with

HIPAA, HIPAA regulations, and other applicable laws.

H. The purpose of the Business Associate Agreement (BAA) is to satisfy certain standards and requirements of HIPAA and the HIPAA regulations.

I. The terms used in this Agreement, but not otherwise defined, shall have the same meanings as those terms in the HIPAA regulations.

In exchanging information pursuant to this Agreement, the parties agree as follows:

1. Permitted Uses and Disclosures of PHI by Business Associate

A. Permitted Uses and Disclosures. Except as otherwise indicated in this

Agreement, Business Associate may use or disclose PHI only to perform functions, activities or services specified in this Agreement or as necessary to perform

Business Associates obligation’s under the Agreement to which this Business

Associate Agreement is attached, for, or on behalf of CCHCS, provided that such use or disclosure would not violate the HIPAA regulations, if done by CCHCS.

B. Specific Use and Disclosure Provisions. Except as otherwise indicated in this

Agreement, Business Associate may:

1. Use and disclose for management and administration. Use and disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and will be used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware that the confidentiality of the information has been breached.

2. Provision of Data Aggregation Services. Use PHI to provide data aggregation services to CCHCS. Data aggregation means the combining of PHI created or received by the Business Associate on behalf of CCHCS with PHI received by the

Business Associate in its capacity as the Business Associate of another covered entity, to permit data analyses that relate to the health care operations of

CCHCS.

3. De-identify any and all PHI received by Business Associate under this Business

Associate Agreement, provided that the de-identification conforms to the requirements of the Privacy Rule.

2. Responsibilities of Business Associate

Business Associate agrees:

A. Nondisclosure. Not to use or disclose PHI other than as permitted or required by this Agreement or as required by law. Business Associate acknowledges that in some circumstances, Business Associate’s (BA) staff or contractors working on certain confidential or sensitive CCHCS projects relating to correctional security may be requested to execute a non-redisclosure agreement with respect to such confidential or sensitive information which may not be redisclosed. If a non-redisclosure statement is signed by any BA staff or contractor, such document shall be retained by the BA for 6 (six) years following termination of the contract timeframe to which this BAA is attached.

B. Safeguards. To implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI, including electronic PHI, that it creates, receives, maintains, uses or transmits on behalf of CCHCS; and to prevent use or disclosure of PHI other than as provided for by this Agreement. Business Associate shall develop and maintain a written information privacy and security program that includes administrative, technical and physical safeguards appropriate to the size and complexity of the

Business Associate’s operations and the nature and scope of its activities, and which incorporates the requirements of section C, Security, below. Upon written request, Business Associate will provide CCHCS with an attestation that its current and regularly updated internal privacy and information security policies comply with this requirement. And, if applicable, to the extent Business Associate stores

CCHCS PHI, CCHCS retains the right to inspect Business Associate’s information privacy and security program if Business Associate does not provide an attestation within a reasonable timeframe to respond to the attestation request.

C. Security. To take the reasonably necessary steps to ensure the continuous security of all computerized data systems containing Covered Entity’s PHI, and provide data security procedures for the use of CCHCS at the end of the contract period. These steps shall include, at a minimum:

1) Complying with all of the data system security precautions listed in this

Agreement or in an Exhibit incorporated into this Agreement; and

2) To the extent applicable, achieve and maintain compliance with the HIPAA

Security Rule (45 CFR Parts 160 and 164), in conducting operations on behalf of CCHCS under this agreement.

3) If Business Associate stores CCHCS PHI, Business Associate will comply with the safeguard provisions provided at https://www.dgs.ca.gov/Resources/SAM/TOC/5300/5300-5 as provided in the

Department’s Information Security Policy, embodied in the Security and Risk

Management Policy in the Information Technology Section of the State

Administrative Manual (SAM), § 4840 et seq., Information Security Policy in

SAM § 5300, et. seq. and State Information Management Manual (SIMM) §

5300 et. seq. If the above safeguard standards change, and after Business

Associate receives notice of any changes, Business Associate agree to work in good faith to determine if Business Associate can comply with the changes, and if Business Associate determines that it cannot comply with the changes, CCHCS and Business Associate agree that this Business Associate agreement and underlying agreements with CCHCS may be immediately terminated by either party.

4) Background Check. Before a member of the workforce may access CCHCS PHI and depending on the nature of the scope of work, a thorough background check of that workforce member may be conducted (i.e. LiveScan), with evaluation of the results to assure that there is no indication that the workforce member may present a risk to the security or integrity of confidential data or a risk for theft or misuse of confidential data. The Contractor shall retain each workforce member's background check documentation for a period of three (3) years following contract termination.

5) Business Associate shall designate an Information Security Officer to oversee its data security program who shall be responsible for carrying out the requirements of this section and for communicating on security matters with

D. Mitigation of Harmful Effects. To mitigate, to the extent practicable, any harmful effects known to Business Associate of a use or disclosure of PHI by Business

Associate or its subcontractors in violation of the requirements of this Agreement.

E. Business Associate’s Agents. If Business Associate subcontracts the services under the agreement to which this Business Associate Agreement is attached, ensure that any agents, including subcontractors, to whom Business Associate provides PHI received from or created or received by Business Associate on behalf of CCHCS, agree to the same restrictions and conditions that apply to Business Associate with respect to such PHI, including implementation of reasonable and appropriate administrative, physical, and technical safeguards to protect such PHI; and to incorporate, when applicable, the relevant provisions of this Agreement into each subcontract or with agents or subcontractors.

F. Availability of Information to CCHCS and Individuals. To provide access as

CCHCS may require, and in the time and manner designated by CCHCS (upon reasonable notice and during Business Associate’s normal business hours) to PHI in a

Designated Record Set, to CCHCS (or, as directed by CCHCS), to an Individual, in accordance with 45 C.F.R. § 164.524. Designated Record Set means the group of records maintained for CCHCS that includes medical, dental and billing records about individuals; enrollment, payment, claims adjudication, and case or medical management systems maintained for CCHCS health plans; or those records used to make decisions about individuals on behalf of CCHCS. Business Associate shall use the forms and processes developed by CCHCS for this purpose and shall respond to requests for access to records transmitted by CCHCS within fifteen (15) calendar days of receipt of the request by producing the records or verifying that there are none.

G. Amendment of PHI. To make any amendment(s) to PHI that CCHCS directs or agrees to pursuant to 45 C.F.R. § 164.526, in the time and manner designated by

H. Internal Practices. To make Business Associate’s internal practices, books and records relating to the use and disclosure of PHI received from CCHCS, or created or received by Business Associate on behalf of CCHCS, available to CCHCS or to the

Secretary in a time and manner designated by CCHCS or by the Secretary, for purposes of determining CCHCS compliance with the HIPAA regulations.

I. Documentation of Disclosures. To document and make available to CCHCS (within

14 calendar days) or (at the direction of CCHCS) to an Individual such disclosures of

PHI, and information related to such disclosures, necessary to respond to a proper request by the subject Individual for an accounting of disclosures of PHI, in accordance with 45 C.F.R. § 164.528.

J. Notification of Patient Confidential Communications. Notify CCHCS within two (2) business days of any patient (or patient’s representative) preferences (or changes to) regarding method of or how to communicate with the patient.

K. Notification of Information Security Incidents, Investigation, and Written

Reporting.

1. Discovery of Information Security Incident. To notify CCHCS immediately by telephone call plus email/electronic communication upon the discovery of an information security incident involving the privacy of or security of PHI in computerized form if the PHI was, or is reasonably believed to have been, acquired by an unauthorized person, or within 24 hours by email/electronic communication of any suspected security incident, intrusion or unauthorized use or disclosure of PHI in violation of this Agreement, or potential loss of confidential data affecting this Agreement. Notification shall be provided to the CCHCS contract manager, the CCHCS Privacy Officer, and the CCHCS Information Security Officer.

If the incident occurs after business hours or on a weekend or holiday and involves electronic PHI, notification shall be provided by calling the CCHCS ITSD Solution

Center at 1-888-735-3470. Business Associate shall take:

i. Prompt corrective action to mitigate any risks or damages involved with the breach and to protect the operating environment, including potential claims or exemptions or exceptions following mitigation; and

ii. Any and all actions pertaining to such unauthorized disclosures required by applicable Federal and State laws and regulations.

2. Investigation of Information Security Incident and Status Reporting to CCHCS.

To immediately investigate such information security incident, breach, or unauthorized use or disclosure of PHI. Within 72 hours of the discovery, to notify and provide the status of the investigation to the CCHCS contract manager(s), the

CCHCS Privacy Officer, and the CCHCS Information Security Officer of:

i. What data elements were involved and the extent of the data involved in the breach,

ii. A description of the unauthorized persons known or reasonably believed to have improperly used, disclosed, or received PHI,

iii. A description of where the PHI is believed to have been improperly transmitted, sent, or utilized,

iv. A description of the probable causes of the improper use or disclosure; and

v. Whether Civil Code § 1798.29 or § 1798.82 or any other federal or state laws requiring individual notifications of breaches are triggered.

Notwithstanding the above, Business Associate shall not be obligated to report unsuccessful attempts to penetrate computer networks or servers that do not result in loss of data or degradation of computer networks or services, unless, if applicable, Business associate stores CCHCS PHI and the unsuccessful attempts involves CCHCS

PHI.

3. Written Report. To provide an initial written report of the investigation to the CCHCS contract managers, the CCHCS Privacy Officer, and the CCHCS Information

Security Officer within ten (10) calendar days of the information security incident, discovery of the breach, or discovery of unauthorized use, disclosure, or receipt. The report shall be in the form and manner required by CCHCS and includes, but is not limited to, the information specified above, as well as a full, detailed corrective action plan, including information on measures that were taken to halt and/or contain the improper use or disclosure. The initial report shall be submitted using the CCHCS

Information Security Incident Report for external entities (ISIR) available at https://cchcs.ca.gov/wp- content/uploads/sites/60/ITSD/CCHCS-ISIR.pdf.

The ISIR shall be emailed to the CCHCS Information Security Office at CCHCS-ISO@cdcr.ca.gov. Business Associate shall provide reasonable cooperation and work with CCHCS in good faith as the investigation progresses, and at the request of CCHCS. CCHCS retains all rights as the Covered Entity to review the sufficiency of the BA’s proposed notice, investigation activities regarding CCHCS PHI incidents, or reporting of information security incidents involving CCHCS PHI.

4. Notification of Individuals. To the extent a determination has been made that patient notification is required in a breach involving Business Associate, the parties https://cchcs.ca.gov/wp-%20content/uploads/sites/60/ITSD/CCHCS-ISIR.pdf agree to work together in good faith to determine the responsible party and any cost associated with such notification. Provided however, nothing shall excuse the obligations on the Business Associated as required under law. Business Associate shall pay any such costs of notifications or the costs associated with the breach if the breach is determined to be solely the responsibility of the Business Associate or their subcontractor. The CCHCS contract managers, the CCHCS Privacy Officer, and the

CCHCS Information Security Officer shall approve the time, manner and content of any such notifications prior to release of the notification. When a determination is made that patient notification is required in a breach involving Business Associate, both parties agree to cooperate on the notification language.

5. CCHCS Contact Information. To direct communications to the above referenced

CCHCS staff, the Contractor shall initiate contact as indicated herein CCHCS reserves the right to make changes to the contact information below by giving written notice to the Contractor. Said changes shall not require an amendment to this

Agreement.

L. Employee Training and Discipline. If Business Associate requires access to

CCHCS’s systems, then Business Associate agrees to train and use reasonable measures to ensure compliance with the requirements of this Agreement by employees

CCHCS CCHCS CCHCS

Contract Manager Privacy Officer Information Security Officer

See Exhibit A for Contract Manager information See the Scope of Work exhibit for Program Contract Manager Information

Privacy Officer

California

Correctional

Health Care

Services

P.O. Box

588500, Bldg. D3, Elk Grove, CA 95758 Email:

Privacy@cdcr.ca.gov Telephone: 1-877-974-

Information Security Officer Information Security Officer

CCHCS

Information

Technology

Services

Division

P.O. Box 588500, Bldg. C3, Elk Grove, CA 95758 Email:

CCHCS-ISO@cdcr.ca.gov Telephone: 916-691-3243 mailto:Privacy@cdcr.ca.gov mailto:CCHCS-ISO@cdcr.ca.gov who assist in the performance of functions or activities on behalf of CCHCS under this

Agreement and use or disclose PHI and discipline such employees who intentionally violate any provisions of this Agreement, including additional training, progressive discipline, removal, or up to and including termination if warranted by the facts. In complying with the provisions of this section L, Business Associate shall observe the following requirements:

1) Business Associate shall provide information privacy and security training, at least every twelve (12) calendar months, at its own expense, to all its employees who assist in the performance of functions or activities on behalf of CCHCS under this

Agreement and use or disclose PHI.

2) Business Associate shall document the employee’s name and the date on which the training was completed and retain such documentation. Upon written request of CCHCS, Business Associate shall certify to CCHCS that such employees that provide services under the Agreement to which this Business Associate

Agreement is attached have completed the training indicated above for CCHCS inspection for a period of three years following contract termination, and shall provide copies of training certifications to CCHCS on request.

3. Obligations of CCHCS

CCHCS agrees to:

A. Notice of Privacy Practices. Provide Business Associate with the Notice of

Privacy Practices that CCHCS produces in accordance with 45 C.F.R. § 164.520, as well as any changes to such notice. To ensure Notice of Privacy Practices to patients allows for the provisions of PHI to Business Associate.

B. Permission by Individuals for Use and Disclosure of PHI. Provide the Business

Associate with any changes in, or revocation of, permission by an Individual to use or disclose PHI, if such changes affect the Business Associate’s permitted or required uses and disclosures. If Business Associate staff or contractors execute a non-redisclosure agreement pursuant to section 2A above, CCHCS shall review those agreements on an annual basis to determine whether such access remains appropriate.\

C. Notification of Restrictions. Notify the Business Associate of any restriction to the use or disclosure of PHI that CCHCS has agreed to in accordance with 45

C.F.R. § 164.522, to the extent that such restriction may affect the Business

Associate’s use or disclosure of PHI.

D. Notification of Patient Confidential Communications. Notify the Business

Associate (within 2 calendar days of request) of any patient (or patient’s representative) preferences (or changes to) regarding the method of or how to communicate with the patient.

E. Requests Conflicting with HIPAA Rules. Not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA regulations.

4. Audits, Inspection and Enforcement

If Business Associate saves or stores CCHCS PHI on Business Associate’s systems, then from time to time, CCHCS may request, and Business Associate shall provide, the necessary information, books, and records of Business Associate pertaining to CCHCS PHI to enable CCHCS to monitor compliance with this Agreement. Business Associate shall promptly remedy any violation of any provision of this Agreement and shall certify the same to the CCHCS Privacy Officer in writing. The fact that CCHCS, or its state oversight agency or federal oversight agency inspects, or fails to inspect, or has the right to inspect Business Associate does not relieve Business Associate of its responsibility to comply with this Agreement, nor does CCHCS’:

A. Failure to detect; or

B. Detection, but failure to notify Business Associate or require Business Associate’s remediation of any unsatisfactory practices does not constitute acceptance of such practice or a waiver by CCHCS of any of its inspection and/or enforcement rights under this Agreement.

Business Associate may meet this requirement by providing a SOC2 certificate of compliance or other certificate of compliance to nationally recognized information security standards and procedures by an accreditation body acceptable to CCHCS. Business Associate shall ensure SOC2 or other compliance certificates are valid and in effect for the duration of any contract to which this BAA attaches.

5. Termination

A. Termination for Cause. Upon CCHCS knowledge of a material breach of this

Agreement by Business Associate, CCHCS shall:

1) Provide an opportunity for Business Associate tocure the breach or end the violation and terminate this Agreement if Business Associate does not cure the breach or end the violation within the time specified by CCHCS;

2) Immediately terminate this Agreement if Business Associate has breached a material term and cure is not possible; or

3) If neither cure nor termination is feasible, report the violation to the Secretary.

B. Judicial or Administrative Proceedings. Business Associate will notify CCHCS if it is named as a defendant in a criminal proceeding for a violation of HIPAA. CCHCS may terminate this Agreement if Business Associate is found guilty of a criminal violation of HIPAA. CCHCS may terminate this Agreement if a finding or stipulation that the Business Associate has violated any standard or requirement of HIPAA, or other security or privacy laws is made in any administrative or civil proceeding in which the Business Associate is a party or has been joined.

C. Effect of Termination. Upon termination or expiration of this Agreement for any reason, Business Associate shall return or destroy all PHI received from CCHCS (or created or received by Business Associate on behalf of CCHCS) that Business

Associate still maintains in any form, and shall retain no copies of such PHI or, if return or destruction is not feasible, shall continue to extend the protections of this

Agreement to such information, and shall limit further use of such PHI to those purposes that make the return or destruction of such PHI infeasible. This provision shall apply to PHI that is in the possession of subcontractors or agents of Business

Associate.

6. Miscellaneous Provisions

A. Disclaimer. CCHCS makes no warranty or representation that compliance by

Business Associate with this Agreement, HIPAA or the HIPAA regulations will be adequate or satisfactory for Business Associate’s own purposes or that any information in Business Associate’s possession or control, or transmitted or received by Business Associate, is or will be secure from unauthorized use or disclosure.

Business Associate is solely responsible for the safeguarding of PHI solely transferred to it under applicable federal or state law.

B. Amendment. The parties acknowledge that federal and state laws relating to electronic data security and privacy are rapidly evolving and that amendment of this

Agreement may be required to provide for procedures to ensure compliance with such developments. The parties specifically agree to take such action as necessary to implement the standards and requirements of HIPAA, the HIPAA regulations and other applicable laws relating to the security or privacy of PHI. Upon CCHCS request, Business Associate agrees to promptly enter into negotiations with CCHCS concerning an amendment to this Agreement confirming written assurances consistent with the standards and requirements of HIPAA, the HIPAA regulations or other applicable laws. CCHCS may terminate this Agreement upon thirty (30) days written notice in the event:

1) Business Associate does not promptly enter into negotiations to amend this

Agreement when requested by CCHCS pursuant to this Section, or

2) Business Associate does not enter into an amendment providing assurances regarding the safeguarding of PHI that CCHCS in…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .