RFP 75D30123-R-72520_12.14.22 MSWord Format.doc
DOC document 1 MB Posted
- Attached to
- Mathematical Modeling and Economic Evaluation Federal contract opportunity
- Solicitation number
- 75D30123-R-72520
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| REV 75D30123-R-72520_CLEAN_01.10.23.doc | DOC document | |
| Questions and Answers_01.10.23.pdf | ||
| REV 75D30123-R-72520_Tracked Changes_01.10.23.doc | DOC document | |
| Amendment_00001_RFP_75D30123-R-72520.pdf | ||
| RFP 75D30123-R-72520_12.14.22 PDF Format.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION, OFFER AND AWARD
1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 700)
RATING
PAGE OF
2. CONTRACT NO.
3. SOLICITATION NO.
75D301-23-R-72520
4. TYPE OF SOLICITATION
X
NEGOTIATED (RFP)
5. DATE ISSUED
12/14/2022
6. REQUISITION/PURCHASE NO.
00HCVJCD-2023-69732
| 7. ISSUED BY |
| CODE |
| 8219 |
| 8. ADDRESS OFFER TO (If other than Item 7) |
Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS)
2900 Woodcock Blvd, MS TCU-4
Atlanta, GA 30341-4004
Liubov Kriel, Contracting Officer
Approved as to Form and Legality: _____________________________
NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”
SOLICITATION
9. Sealed offers in original and 1 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in See Section L until 2:00pm EST local time 1/28/2023 CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR INFORMATION
CALL:
A. NAME
Liubov Kriel
B. TELEPHONE (NO COLLECT CALLS)
AREA CODE NUMBER: EXT:
(770) 488-2856
C. E-MAIL ADDRESS
vyh1@cdc.gov
11. TABLE OF CONTENTS
(x)
DESCRIPTION
(x)
DESCRIPTION
| PART I – THE SCHEDULE |
| PART II – CONTRACT CLAUSES |
| X |
| A |
| SOLICITATION/CONTRACT FORM |
| 1 |
| X |
| I |
| CONTRACT CLAUSES |
| 48 |
| X |
| B |
| SUPPLIES OR SERVICES AND PRICES/COSTS |
| 2 |
| PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH. |
| X |
| C |
| DESCRIPTION/SPECS./WORK STATEMENT |
| 4 |
| X |
| J |
| LIST OF ATTACHMENTS |
| 57 |
| X |
| D |
| PACKAGING AND MARKING |
| 29 |
| PART IV – REPRESENTATIONS AND INSTRUCTIONS |
X
| E |
| INSPECTION AND ACCEPTANCE |
| 30 |
REPRESENTATIONS, CERTIFICATIONS, AND
| X |
| F |
| DELIVERIES OR PERFORMANCE |
| 31 |
| X |
| K |
| OTHER STATEMENTS OF OFFERORS |
| 58 |
| X |
| G |
| CONTRACT ADMINISTRATION DATA |
| 32 |
| X |
| L |
| INSTRS., CONDS., AND NOTICES TO OFFERORS |
| 66 |
| X |
| H |
| SPECIAL CONTRACT REQUIREMENTS |
| 35 |
| X |
| M |
| EVALUATION FACTORS FOR AWARD |
| 75 |
OFFER (Must be fully completed by offeror)
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52-232-8)
10 CALENDAR DAYS
20 CALENDAR DAYS
30 CALENDAR DAYS
| AMENDMENT NO. |
| DATE |
| AMENDMENT NO. |
| DATE |
CODE
FACILITY
16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER
15B. TELEPHONE NO.
AREA CODE NUMBER EXT.
15C. CHECK IF REMITTANCE ADDRESS
SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE
18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED
20. AMOUNT
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
21. ACCOUNTING AND APPROPRIATION
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
| 24. ADMINISTERED BY (If other than Item 7) |
| CODE |
| 8219 |
| 25. PAYMENT WILL BE MADE BY |
| CODE |
| 434 |
Centers for Disease Control and Prevention (CDC)
Office of Acquisition Services (OAS)
2900 Woodcock Blvd, MS TCU-4
Atlanta, GA 30341-4004
Centers for Disease Control and Prevention (FMO)
PO Box 15580 404-718-8100
Atlanta, GA 30333-0080
26. NAME OF CONTRACTING OFFICER (Type or print)
27. UNITED STATES OF AMERICA
(Signature of Contracting Officer)
28. AWARD DATE
IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.
AUTHORIZED FOR LOCAL REPRODUCTION
STANDARD FORM 33 (REV. 9-97)
PREVIOUS EDITION IS UNUSABLE
Prescribed by GSA
FAR (48 CFR) 53.214©
Section B - Supplies Or Services And Prices/Costs
| ITEM |
| SUPPLIES / SERVICES |
| QTY / UNIT |
| UNIT PRICE |
| EXTENDED PRICE |
| 0001 |
| Mathematical Modeling and Economic Evaluation Support Services as described in Section C of the contract. |
Task Orders to be issued as needed and funds to be obligated separately.
Period of Performance (POP)/ Ordering Period:
April 1, 2023 – March 31, 2028
| Maximum Value see B.6 |
| TBD per Task Order |
| NTE $3,918,536.40 |
| 0002 |
| Travel |
· All travel shall be reimbursed at cost in accordance with section B.8 of the contract.
Period of Performance (POP)/ Ordering Period:
April 1, 2023 – March 31, 2028
| 1 Lot |
| TBD per Task Order |
| TBD per Task Order |
B.1 Purpose
The purpose of this contract is to provide services that fall within the scope of the work specified in Section C for the project entitled, “Mathematical Modeling and Economic Evaluation.” The Contracting Officer (CO) will request the work through the issuance of task orders during the ordering period as specified in Section I of the contract.
B.2 Contract Type and Services This is a competitive procurement providing for full and open competition.
This acquisition is being competed in accordance with FAR Part 15 - Contracting by Negotiation. The NAICS Code is 541715 "Research and Development in the Physical, Engineering, and Life Sciences (except Nanotechnology and Biotechnology)," with a small business size standard of 1,000 employees.
This is single award Indefinite- Delivery Indefinite- Quantity contract (IDIQ) utilizing individual task orders to provide Mathematical Modeling and Economic Evaluation support services. The Government will issue task orders that are firm-fixed-price (FFP).
Obligation of funds will be done by the issuance of individual task orders by the Contracting Officer in accordance with the clause titled “Award of Task Orders” in Section H and FAR clause 52.216-18 titled “Ordering” in Section I. The Contractor shall not exceed the amount negotiated for each individual task order without prior written approval of the Contracting Officer.
In addition, the Contractor shall not commence work until a task order or other written notification for a specific assignment is issued by the Contracting Officer. Only a CDC Contracting Officer is authorized to issue a task order request to the Contractor or issue finalized task orders under this contract. The government is not obligated to reimburse the Contractor for any costs that it incurs before issuance of a task order or other written notification by the Contracting Officer.
The government intends to issue one basic contract award for this IDIQ contract.
The intent is to issue one Task Order 0001 (see Attachment J5 and Section L herein) upon award of this IDIQ. Task Order 0001 will be issued with specific performance period.
B.3 Performance-Based Preference
Pursuant to FAR 37.102(a)(1), the Contracting Officer will use performance-based acquisition methods to the maximum extent practicable.
B.4 Minimum and Maximum Ordering Amounts
Minimum Order Amount: $1,000.00 Maximum Order Amount: $750,000.00 B.5 Minimum Guarantee
This contract guarantees a minimum of $1,000. Once a contractor has received task order obligation awards that exceed $1,000, the minimum guarantee will be considered met.
B.6 Maximum Contract Value
The aggregate maximum value of all orders issues and awarded under the contract over the five (5) year ordering period shall not exceed $3,918,536.40.
B.7 Task Order Pricing
The Government will issue task orders that are firm-fixed-price (FFP). Pursuant to FAR 15.4, Pricing, and FAR 16.2, Fixed-Price Contracts, the firm-fixed-price type for each task order will be negotiated based on the price to complete the work. After acceptance of a fixed-price task order by the Contractor, the task order price will only be adjusted to reflect changes in scope or conditions.
B.8 Travel Pricing
Travel will be reimbursed at actual cost in accordance with the limitations set forth in FAR 31.205-46. Fee/ profit shall not be applied to travel costs. Contractors may apply G&A to travel in accordance with the Contractor’s usual accounting practices consistent with FAR 31.2. Travel expenses may be identified under a separate CLIN which will be a direct reimbursable in accordance with Federal Travel Regulations on the specific task order.
B.9 Place of Work and Government-Furnished Equipment
Work under this contract will be performed primarily off-site at the Contractor location(s) but it may be performed on-site at CDC locations in Atlanta, Georgia. On-site meetings with CDC staff may be required. Each task order will specify the location requirements.
If the work is to be performed primarily on-site at a CDC location, due to the nature of the work, CDC will provide IT equipment (i.e., desktop computer), telephone, and other office equipment and supplies as needed for the Contractor to perform required tasks.
If the work is to be performed primarily off-site at the Contractor’s locations, where the Contractor needs to access CDC’s network, the CDC will not provide IT equipment. The computers used by Contractor personnel shall meet CDC’s standard software and security configuration before logging onto CDC’s network.
Each task order will stipulate whether on-site or off-site performance, or both, is required.
B.10 Non-Personal Services Contract Statement
This is a non-personal services contract as defined in Federal Acquisition Regulation (FAR) 37.101. The Government will evaluate the quality of support services provided but the Contractor retains control over its employees or agents. The Contractor is solely responsible and liable for and expressly agrees to indemnify the Government with respect to any liability producing acts or omissions by it or by its employees.
B.11 Service Contract Act
The contract labor categories are considered bona fide professional labor and generally exempt from the Service Contract Act. However, each task order will be reviewed for applicability.
B.12. Contract Structure The basic contract will establish the general scope and ordering period for task orders to be issued against this contract. The term of this IDIQ contract is 60 months. It is anticipated that multiple task orders will be issued to the contractor to work in areas identified in this Scope of Work. Each task order shall have a discrete period of performance independent of the basic contract and no task order shall extend more than twelve (12) months beyond the expiration date of the basic contract.
Section C - Description/Specification/Work Statement
STATEMENT OF WORK
Mathematical Modeling and Economic Evaluation
SECTION 1 – BACKGROUND
Mathematical models of HIV transmission and disease progression in the United States can help predict the future of the disease, the impact of prevention and care strategies, and how best to allocate resources to optimize impact on health and disease outcomes. Under previous contracts, the Department of Health and Human Services’ (DHHS) Centers for Disease Control and Prevention (CDC) developed a dynamic, compartmental model of HIV in the United States. The purpose of this HIV Optimization and Prevention Effectiveness (HOPE) model is to assess the impact of prevention and care strategies on the reduction of HIV incidence in the total population and by race/ethnicity, among other types of evaluations.
Given limited resources and a mandate to protect public health, it is important for CDC to have the tools to assess the costs and effectiveness of, and optimal allocation of resources for, a wide array of strategies and policies to prevent the transmission and acquisition of HIV and to extend the survival and quality of life for those who are infected.
Complex mathematical models often are required to predict future trends in HIV disease and potential impact of public health interventions because they need to account for many continually changing dynamics over time, including the estimated costs and effectiveness of interventions to prevent the spread of HIV and extend the life of those infected, various behaviors either increasing or decreasing risk of HIV acquisition or transmission, the variations in HIV disease progression and transmission risk based on care, treatment, and viral suppression status, while accounting for differences across key demographic subpopulations. New mathematical approaches (using models for simulations and projections) to assess infectious disease transmission and effects of treatment and care on survival are constantly being developed and extended.
Mathematical modelers can be difficult to recruit and retain. Even with extensive hiring efforts, hiring efforts over the past 5 years have resulted in very few qualified candidates to fill vacancies. Candidates who do qualify possess skills are in wide demand; over a dozen modelers over the last few years have departed government service. To sustain modeling capacity within CDC’s Division of HIV Prevention (DHP), CDC has contracted for mathematical modeling and economic evaluation since 2012—one research IDIQ from FY 2012 to FY 2016, and a second research IDIQ from FY 2017 to FY 2022.
For FY 2023 through FY 2028, DHP requires an indefinite delivery, indefinite quantity (IDIQ) research contract to acquire support in the following areas.
1. Expand and refine in MATLAB® a dynamic, compartmental model of HIV transmission and disease progression in the U.S. population. CDC’s HIV Optimization and Prevention Economics model—the HOPE model—is a dynamic, compartmental model that shows how persons with HIV progress through disease stages and within the HIV care “continuum.”
2. Conduct analyses of HIV transmission and disease progression using the HOPE model.
3. Conduct HIV resource allocation analyses using the HOPE and other models.
4. Build, refine, and conduct analyses using agent-based and network models of HIV transmission and disease progression.
5. Conduct economic analyses of HIV prevention interventions.
6. Maintain a database of relevant literature related to HIV prevention interventions.
SECTION 2 – PURPOSE
The purpose is to provide to the Centers for Disease Control and Prevention (CDC), Division of
HIV Prevention (DHP), an 'as needed' mechanism to obtain required services related to the mathematical modeling of HIV transmission and disease progression in the U.S., economic evaluation of HIV prevention, care, and treatment interventions, and resource allocation modeling.
Located within the National Center for HIV, Viral Hepatitis, STD, and TB Prevention (NCHHSTP), the Division of HIV Prevention (DHP) is responsible for providing national leadership and support for HIV epidemiologic research and surveillance of the behaviors and determinants of HIV transmission and disease progression, and for prevention and intervention research and the development, implementation, monitoring, and evaluation of evidence-based HIV prevention programs serving persons affected by or at risk for HIV infection. These programs are authorized under the Public Health Service Act sections: 317 (42 U.S.C. 241 (a) and 247b); 301 (42 U.S.C. 241); 311 (42 U.S.C. 243), as amended.
Some general objectives of this effort will include,
1. Build on and expand existing national-level models of HIV transmission and disease progress to evaluate the effects of HIV prevention strategies.
2. Develop new types of models as needed to better understand the effects of transmission networks.
3. Evaluate the optimal allocation of limited HIV prevention funds to prevent the most new cases at least cost.
4. Construct cost-effectiveness analyses that meet changing methodological standards and guide HIV prevention policy.
5. Provide technical support on models to ensure PMET staff are trained to program, refine, and restructure any models originally programmed by the contractor.
6. Update and maintain a database on relevant literature related to HIV prevention strategies and assist in the preparation of manuscripts for CDC clearance and submission to peer-reviewed journals.
Each Task Order is expected to produce a technical report suitable for use by DHP decision-makers and a manuscript suitable for publication in a peer-reviewed scientific journal unless the specific Task Order indicates otherwise.
All work must be of sufficient quality for presentation at national conferences with peer-reviewed abstracts and for publication in high-impact, peer-reviewed scientific journals. Modified, expanded, or newly created models shall become the property of the CDC.
This approach will allow DHP to sustain the mathematical modeling and economic analytic capacity needed to meaningfully inform HIV prevention program and policy. The contract mechanism will allow for assurance of appropriate responsiveness to input from the division, assignment of specific model-related projects of high interest to the division, and completion of those assignments within meaningful timeframes.
SECTION 3 – SCOPE OF WORK
Independently, and not as an agent of the Government the Contractor shall furnish all necessary personnel, facilities, supplies, scientific software (such as MATLAB®, NetLogo, and R), a reliable video platform for communication such as Zoom or Microsoft Teams, and equipment to produce reports, papers, or other deliverables as specified by each Task Order issued.
SECTION 4 – TECHNICAL REQUIREMENTS
The specific scope, technical requirements, deliverables, and due dates shall be described in each request for Task Order proposal issued. All tasks shall fall within one or more of the following task areas.
Task Area 1: HIV Epidemic Modeling
1.1. The contractor shall expand and continually refine the HOPE model, a dynamic, compartmental model of HIV transmission and disease progression in the U.S. population, within MATLAB. This model shall be representative of the U.S. population in terms of HIV prevalence and incidence by transmission groups, race/ethnicity, gender, age and circumcision and PrEP status. Transmission dynamics shall reflect risk behaviors, disease stage, and steps in the HIV care continuum and associated transmission risks.
1.2. The Contractor shall provide the most up-to-date and scientifically proven model inputs, including consideration of Grading of Recommendations Assessment, Development and Evaluation (GRADE) in evaluating inputs related to intervention efficacy.
1.3. The Contractor shall efficiently calibrate the model, by population and subpopulation, to a variety of outcomes including HIV incidence, prevalence, and HIV-related deaths, as well as by population and subpopulation distributions along the HIV care continuum.
1.4. The Contractor shall recalibrate frequently changing HIV outcomes as reported in HIV surveillance reports.
1.5. The Contractor shall produce ranges around outcome point estimates based on uncertain model inputs.
1.6. The Contractor shall conduct analyses assessing the impact of various combinations of behavioral and biomedical interventions on HIV transmission and disease progression using the HOPE model. These analyses shall consider a variety of prevention, treatment, and care interventions and implementation strategies, notably those related to HIV screening and testing, the HIV care continuum, pre-exposure prophylaxis (PrEP), and syringe services programs (SSPs), and consider their impact across demographic and transmission group subpopulations.
1.7. The Contractor shall conduct sensitivity analyses on model inputs, including the use of elementary effects methods, and show outcome sensitivities and uncertainties graphically and in text and tables.
1.8. The Contractor shall ensure that methodological approaches include consideration for reducing racial/ethnic disparities in HIV diagnoses, viral suppression, and incidence.
1.9. The Contractor shall ensure that methodological approaches allow for innovative prevention tools including new biomedical tools, innovative delivery modalities, new implementation strategies, select structural-level interventions, and other innovations based on scientific updates.
1.10. The Contractor shall develop the methodology for including comprehensive prevention approaches, such as cluster detection and response, syndemics, status neutral, and social determinants of health (SDoH).
1.11. The Contractor shall prepare articles for peer-reviewed scientific journals related to methods and analyses related HIV epidemic modeling.
Task Area 2: HIV Resource Allocation Modeling
2.1. The Contractor shall build and assess models for the optimal HIV prevention resource allocation across a variety of prevention, treatment, and care interventions and implementation strategies, notably those related to HIV screening and testing, the HIV care continuum, pre-exposure prophylaxis (PrEP), and syringe services programs (SSPs), and distributed across subpopulations, particularly by key demographics and transmission group, at the national, state, and local levels.
2.2. The Contractor shall link optimization methods described in 2.1 (above) to the HOPE model.
2.3. The Contractor shall also use the HOPE model to estimate the total costs needed to reach national HIV goals under various scenarios and be able to break down the total costs by intervention strategy, subpopulations, transmission groups, or federal agencies, as needed.
2.4. The Contractor shall develop the methodology for including comprehensive prevention approaches, such as cluster detection and response, syndemics, status neutral, select structural-level interventions, and social determinants of health (SDoH), in resource allocation analyses.
2.5. The Contractor shall prepare articles for peer-reviewed scientific journals related to the optimization of HIV prevention and treatment resources.
Task Area 3: Other Types of HIV Models
3.1. The Contractor shall construct new and modify existing agent-based and network models of HIV transmission and disease progression. These models shall include more detailed characteristics, compared with a compartmental model, of individual sexual and drug-using behaviors, such as serosorting and concurrency, and/or specific networks of partners are needed for the evaluation of HIV prevention policies.
3.2. The Contractor shall prepare articles for peer-reviewed scientific journals using these models.
Task Area 4: Economic Analyses
4.1. The Contractor shall conduct economic analyses, including cost-effectiveness, cost-utility, and cost-benefit analyses.
4.2. The Contractor shall conduct cost-effectiveness analyses using the HOPE model.
4.3. The Contractor shall demonstrate knowledge of current guidelines and standard practices in economic evaluation, including reference case requirements, analysis perspective (societal, provider), timeframe, and discounting.
4.5. The Contractor shall conduct return on investment analysis and budget impact analysis.
4.6. The Contractor shall demonstrate experience and expertise in the use of HIV-related utility weights.
4.7. The Contractor shall develop appropriate intervention and treatment cost inputs for use in models and expertise in various approaches to costing.
4.8. The Contractor shall prepare articles for peer-reviewed scientific journals using these analyses.
Task Area 5: Repository of information from published HIV-related prevention literature
5.1. The Contractor shall update and maintain a repository of the publication citation information and key findings from published works through reviewing the scientific literature. Information gathered should be related to effectiveness analyses, economic analyses, and cost-effectiveness analyses of U.S.-based HIV prevention and care interventions implementation strategies, and comprehensive prevention approaches (such as cluster detection and response, syndemics, status neutral, and social determinants of health approaches).
Task Area 6: The Effects of Emerging and Other Infectious Diseases on HIV Prevention
6.1. The contractor shall conduct mathematical modeling and economic analyses on how other infectious diseases or other emerging epidemics, such as COVID-19 and monkeypox, affect the HIV epidemic and efforts towards meeting the goals of the Department of Health and Human Service’s Initiative Ending the HIV Epidemic (EHE).
6.2. This work shall also include analyses to identify enhanced HIV prevention efforts, allocate existing resources, or identify additional resources needed to offset any negative effects of these other diseases.
Task Area 7: Model Inputs
7.1. The contract shall examine and update key aspects of the HOPE model to ensure that CDC is using the most up-to-date and accurate scientific data available. Key aspects include: the model structure, inputs, calibration targets (e.g., updated HIV surveillance data), and validation of the inputs. If key aspects change, then update and recalibrate the model as needed.
SECTION 5 – TRANSITION PLANS
The continuity of the services without interruption is critical to the success of the program. Therefore, the contractor shall be required to provide and execute an approved transition plan that will provide a smooth transition (in the beginning and at the end of the full Period of Performance, including all Task Orders, of the contract) to ensure continuous service.
1. Responsibilities of Contractor, as they are Incoming:
The Contractor shall provide, within 10 days of the start of the Period of Performance, a final written transition plan (called the Incoming Transition Plan). This plan shall include detailed process for transition of products and materials from CDC to the Contractor, including delivery method and address for file/product/material delivery, responsible parties for each step, deadlines, and acceptable or preferred formats of files/products/materials.
Within three weeks of the start of the of the Period of Performance, CDC will provide to the Contractor: list of materials to be transferred, all data files, programming files, draft articles, and all other relevant products and materials associated with this mathematical modeling and economic evaluation effort. Examples of products/materials include: technical documentation describing the model structure (in Microsoft® Word and Excel), coding files (in MATLAB) and data related to the model, journal/abstract drafts, and other related documents.
Within one week after data transfer, the Contractor shall:
a. Confirm receipt of all related files/materials transferred from CDC,
b. Confirm the Contractor is able to access/open all files and materials,
c. Review all transferred files and documentation,
d. Establish a maintenance and storage process for all materials, and
e. Identify gaps in expected materials and report to CDC missing products/materials such that CDC can support the transition with minimal delay.
2. Outgoing Transition Plan: Responsibilities of Contractor, as they are Outgoing
The Contractor shall provide a Transition Plan (called the Outgoing Transition Plan) at least 90 days before the end of the Period of Performance of the contract. This plan shall include a detailed process for transitioning all relevant products and materials from the Contractor to CDC, including the delivery method (e.g., thumb drive sent via USPS mail, electronic transfer over the internet) for each file or product, responsible parties for each action item, timeline (including deadlines), and preferred formats of files/products/materials. Examples of materials to be transferred and included in the plan include: technical documentation describing the model structure (in Microsoft® Word and Excel), coding files (in MATLAB) and data related to the model, journal/abstract drafts, and other related documents.
This phase-out transition plan shall be sent to the COR at least 90 days before the end of the period of performance of the contract. CDC shall review and approve this plan at least 60 days before the end of the period of performance of the contract.
Once the contract ends, the contractor shall not use the model or model outputs for any presentations or publications, unless CDC has provided written authorization to do so.
SECTION 6 – IDIQ MANAGEMENT
The Contractor shall develop agendas for meetings, notes, and monthly progress reports, final task order reports, and a final contract report (covering the full period of performance).
The Monthly Progress Reports (at the Task Order level only): The specific scope, technical requirement, deliverable, and due date shall be described in each request for Task Order proposal issued. The reports shall include for the previous month:
1. A summary of progress toward completion of each task and any problems encountered, including the Contractor’s assessment of the specific impact of such problems on scheduled date of completion of deliverables,
2. A summary of fiscal expenditures, overall and by task,
3. The cumulative fiscal expenditures from start of the Period of Performance of the Task Order through the end of the previous month.
Each Task Order Report (produced at the end of each Task Order/ at the Task Order level only): The specific scope, technical requirement, deliverable, and due date shall be described in each request for Task Order proposal issued. The reports shall include for the life of the Task Order:
1. High-level accomplishments of the Task Order;
2. Impact of problems on costs and/or date of completion;
3. Status of deliverables (task number, description, due date, status update, expected delivery date); and
4. A list of publications (manuscripts, presentations, and posters) and papers in progress/completed, status, and target journal.
The Final Contract Report (at the basic IDIQ contract level): The report shall include for the life of the Contract:
1. A narrative summary of the high-level accomplishments across the full Period of Performance of the contract;
2. Impact of problems on costs and/or date of completion;
3. Recommendations (if any) for improvement in the management of this contract or the work performed under this contract;
4. A list of publications (manuscripts, presentations, and posters) and papers in progress/completed, status, and target journal.
The Contractor shall store and maintain files and materials produced as a part of this IDIQ effort in an organized manner that will allow for easy transition to CDC at the end of the contract’s Period of Performance.
SECTION 7 – GOVERNMENT FURNISHED MATERIALS
In Task Orders where the place of performance is specified to be at the Government's facility, the government will provide required workspace and equipment. Any additional government property to be furnished will be specified in each Task Order.
SECTION 8 – DELIVERABLES/REPORTING SCHEDULE
The Contractor shall furnish the COR the following items in the quantities and during the time periods indicated. All documents to be in Microsoft Word© or Excel© format unless alternative formats are approved in advance by CDC.
The specific deliverables/reporting schedules for Task Orders will be described in the Statement of Work for each Task Order issued.
| Task Number |
| Deliverable |
| Quantity/ Format |
| Recipient |
| Frequency/Due Date |
| Section 5 |
| Final Incoming Transition Plan |
| 1 electronic copy |
| COR |
| Plan due within 10 days of award date; activities due as outlined in plan. |
| Section 5 |
| Outgoing Transition Plan |
| 1 electronic copy |
| COR |
| 90 days before the end of the Period of Performance of the IDIQ contract |
| Section 6 |
| Final IDIQ Contract Report |
| 1 electronic copy |
| COR |
| Three (3) days before the end of the Period of Performance of the IDIQ Contract |
SECTION 9 – REFERENCE MATERIALS
SECTION 10- SPECIAL CONSIDERATIONS
Offeror shall maintain current representations and certifications at https://www.sam.gov. Rights of data: All material developed from work being performed under this contract shall be submitted to the Project Officer and COR. Any publications resulting from this work must occur with approval from CDC, and through clearance processes at CDC.
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee shall operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
2) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network, or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality:
[ x ] Low [ ] Moderate [ ] High
Integrity:
Availability:
Overall Risk Level:
[ x ] Low [ ] Moderate [ ] High
Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:
[ x ] No PII [ ] Yes PII
Complete this section using the information obtained from the Security and Privacy Checklist in Appendix A, parts A and B.
4) Personally Identifiable Information (PII). Per the Office of Management and Budget (OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother’s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [ X ] Low [ ] Moderate [ ] High
5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
b. disclosed to authorized personnel on a need-to-know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization.
6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
10) Contract Documentation. The Contractor shall use provided templates, policies, forms, and other agency documents to comply with contract deliverables as appropriate.
See SECTION 8 – DELIVERABLES/REPORTING SCHEDULE for baseline deliverables.
11) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use have been validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
e. Use the Key Management system on the HHS personal identification verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys shall be provided to CDC Office of Chief Information Security Officer (OCISO).
12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO Representative (COR) prior to performing any work under this acquisition.
See Appendix C for the Contractor Non-Disclosure Agreement.
13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.
a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle (SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT)within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.
All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.
D. Incident Response
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by Federal Information Security Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for other than authorized purpose.
OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information” (03 January 2017) states:
Definition of an Incident:
An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Definition of a Breach:
The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for other than authorized purpose.
It further adds:
A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for other than authorized purpose.
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII.”
Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:
1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.
2) All contractors and subcontractors shall properly encrypt PII in accordance with OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.
4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC) or CDC Computer Incident Response Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-2245, whether the response is positive or negative.
5) All contractors and subcontractors shall be able to determine what Federal information was or could…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .