About this file

RDIS Statement of Work

View the file

Other files for this federal contract opportunity

Other files attached to Research, Demonstration, & Information System (RDIS) Information Technology (IT) Development, newest first.
File Type Posted
CMS Technical Ref Arch_ v 2.0_11124009.pdf PDF
RDIS_RFP questions.xlsx XLSX spreadsheet
Acronym RDIS Master 05 24 2010.docx DOCX document
EHR_To Be BPM Diagrams_legal_11_18_2009_1.pdf PDF
SF33.pdf PDF
RFP-CMS-2010-8A-0014 RDIS.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Research, Demonstration, & Information System IT Development Statement of Work

Research, Demonstration, & Information System IT Development Statement of Work

STATEMENT OF WORK (SOW)

May 24, 2010

1BACKGROUND AND PURPOSE6
1.1General Background6
1.2ORDI Business Functions Overview7
1.3Demonstration & Evaluation IT Development & Operations9
1.4Data & Statistics Dissemination10
1.4.1Data Dissemination11
1.4.2Digital Journals11
1.5Purpose12
2TECHNICAL INSTRUCTION13
2.1Technical Direction14
2.1.1Contractor Security14
2.1.2CMS Data Center Connectivity15
2.1.3On Site Availability15
2.1.4Tour of Duty16
2.1.5Computer Hardware & Software16
2.1.6Task Order Management16
2.1.7Contract Kick-Off Meeting17
2.1.8Monthly Status Report17
2.1.9Earned Value Management17
2.1.10Project Status Review18
2.2Interfacing Contracting Entities18
2.2.1IT Technical & Requirements Management Contractor18
2.2.2IT Development, Operations, & Maintenance Contractor18
2.2.3Comparative Effectiveness Research (CER) IT Development, Operations, & Maintenance Contractor18
2.2.4CER Research Development Contractor18
2.2.5Office of Information Services (OIS) Support Contractors19
2.2.6Research Data Assistance Center Contractor (RESDAC)19
2.2.7Chronic Condition Warehouse (CCW)/Research Data Distribution Center (RDDC) Contractors19
2.3Key Assumptions & Constraints19
3STANDARDS, POLICIES, & PROCEDURES21
3.1Federal Standards, Policies, and Procedures21
3.2CMS Integrated IT Investment & System Life Cycle Framework21
3.3CMS IT Standards21
3.4CMS Information Security21
3.5HIPAA Privacy and Security Rules23
3.6Section 508 Accessibility of Electronic and Information Technology24
4SERVICES SCOPE26
4.1RDIS IT Project and System Management Services26
4.1.1Communications Plan27
4.1.2Project Schedule27
4.1.3Risk Management27
4.1.4Project Status & Technical Meetings27
4.1.5Meeting Agendas and Minutes28
4.2RDIS IT Requirements Development Services28
4.2.1Business Process Models (BPMs)28
4.2.2Concept of Operations (CONOPs)28
4.2.3Gather and Document Business, Functional, and Nonfunctional Requirements28
4.2.4Requirements Document29
4.2.5Requirements Review29
4.2.6Requirements in DOORS29
4.3RDIS IT Development Services30
4.3.1System Engineering/System Integration30
4.3.2Design Reviews30
4.3.3System Certification and Accreditation31
4.3.4Closeout Certifications31
4.3.5Application Development31
4.3.6Quality Assurance and Testing33
4.3.7Operational Readiness Validation34
4.3.8User Manual34
4.3.9Installation34
4.4RDIS Database Development Services35
4.4.1General Database Support35
4.4.2Database Development35
4.4.3Database Test36
4.4.4Database Integration36
4.4.5Database Production36
4.4.6Database Logical Data Model36
4.4.7Database Design Document37
4.5RDIS Business Intelligence/Reporting Development Services37
4.6RDIS IT Security Services38
4.6.1Information Security Risk Assessment38
4.6.2System Security Plan38
4.6.3Security Assessment/System Test & Evaluation (ST&E)39
4.6.4Privacy Impact Assessment (PIA)40
4.6.5System Re-Certification and Re-Accreditation40
4.7RDIS IT Operations & Maintenance Services40
4.7.1Adaptive & Corrective Maintenance40
4.7.2Operations & Maintenance (O&M) Manual40
4.7.3Problem Reports41
4.7.4Changes Requests41
4.7.5Release Plan41
4.8RDIS Transition Planning & Execution Services41
5RDIS FUTURE PROJECT SCENARIOS42
5.1Electronic Health Record Demonstration System (EHRDS) Services42
5.1.1EHRDS IT Operations & Maintenance Services42
5.1.2EHRDS IT Development Services42
5.1.3EHRDS Database Development Services42
5.1.4EHRDS Business Intelligence/Reporting Development Services43
5.1.5EHRDS IT Security Services43
5.1.6EHRDS Transition Planning & Execution Services43
5.2Public Use File (PUF) Data & Statistics Dissemination System Services (PDSDS)43
5.2.1PDSDS IT Project & System Management Services43
5.2.2PDSDS IT Requirements Development Services43
5.2.3PDSDS IT Development Services43
5.2.4PDSDS Database Development Services44
5.2.5PDSDS Business Intelligence/Reporting Development Services44
5.2.6PDSDS IT Security Services44
5.2.7PDSDS IT Operations & Maintenance Services44
5.2.8PDSDS Transition Planning & Execution Services44
5.3North Dakota Statewide Quality Improvement Network (SQIN) Demonstration System (SQINDS) Services44
5.3.1SQINDS IT Project & System Management Services45
5.3.2SQINDS IT Requirements Development Services45
5.3.3SQINDS IT Development Services45
5.3.4SQINDS Database Development Services45
5.3.5SQINDS Business Intelligence/Reporting Development Services45
5.3.6SQINDS IT Security Services45
5.3.7SQINDS IT Operations & Maintenance Services45
5.3.8SQINDS Transition Planning & Execution Services45
5.4Multi Payer Advanced Primary Care Practice (MAPCP) Demonstration System (MAPCPDS) Services45
5.4.1MAPCP IT Project & System Management Services46
5.4.2MAPCP IT Requirements Development Services46
5.4.3MAPCP IT Development Services46
5.4.4MAPCP Database Development Services46
5.4.5MAPCP Business Intelligence/Reporting Development Services46
5.4.6MAPCP IT Security Services46
5.4.7MAPCP IT Operations & Maintenance Services46
5.4.8MAPCP Transition Planning & Execution Services46
5.5Federally Qualified Health Center (FQHC) Medical Home Demonstration System (FQHCDS) Services47
5.5.1FQHCDS IT Project & System Management Services47
5.5.2FQHCDS IT Requirements Development Services47
5.5.3FQHCDS IT Development Services47
5.5.4FQHCDS Database Development Services47
5.5.5FQHCDS Business Intelligence/Reporting Development Services47
5.5.6FQHCDS IT Security Services47
5.5.7FQHCDS IT Operations & Maintenance Services47
5.5.8FQHCDS Transition Planning & Execution Services48
5.6Digital Journal IT Services48
5.6.1Digital Journal IT Project & System Management Services48
5.6.2Digital Journal IT Requirements Development Services48
5.6.3Digital Journal IT Development Services48
5.6.4Digital Journal Database Development Services48
5.6.5Digital Journal Business Intelligence/Reporting Development Services48
5.6.6Digital Journal IT Security Services48
5.6.7Digital Journal IT Operations & Maintenance Services49
5.6.8Digital Journal Transition Planning & Execution Services49
5.7Comparative Effectiveness Research (CER) Services49
5.7.1CER IT Project & System Management Services49
5.7.2CER IT Requirements Development Services49
5.7.3CER IT Development Services50
5.7.4CER Database Development Services50
5.7.5CER Business Intelligence/Reporting Development Services50
5.7.6CER IT Security Services50
5.7.7CER IT Operations & Maintenance Services50
5.7.8CER Transition Planning & Execution Services50
5.8Decision Support, Performance Metrics, and Program Statistics (DSPMPS) Services50
5.8.1DSPMPS IT Project & System Management Services51
5.8.2DSPMPS IT Requirements Development Services51
5.8.3DSPMPS IT Development Services51
5.8.4DSPMPS Database Development Services51
5.8.5DSPMPS Business Intelligence/Reporting Development Services51
5.8.6DSPMPS IT Security Services51
5.8.7DSPMPS IT Operations & Maintenance Services51
5.8.8DSPMPS Transition Planning & Execution Services51
5.9Center for Medicare and Medicaid Innovation (CMI) Web Intake System (CMIWIS)52
5.9.1CMIWIS IT Requirements Development Services53
5.9.2CMIWIS IT Development Services53
5.9.3CMIWIS Database Development Services53
5.9.4CMIWIS Business Intelligence/Reporting Development Services53
6GOVERNMENT FURNISHED INFORMATION (GFI), EQUIPMENT, AND FACILITIES53
6.1Attachments53
6.2Web site References53
6.3Reference System Documentation54
7QUALITY ASSURANCE54
7.1Quality Control Requirements54
7.2Quality Assurance Requirements55
8CONTRACT-RELATED ROLES AND RESPONSIBILITIES55
8.1CMS Personnel55
8.2Key Contractor Personnel56
9DELIVERABLES57
9.1Format57
9.2Recipients57
9.3Review Cycle57
9.4Deliverables Schedule57
10DATA RIGHTS62
11CONTRACT TERM63
12Attachment A: Research, Demonstration, and Information System (RDIS) Acronyms64
13Attachment B: EHR Demonstration “As Is” Business Process Description64

BACKGROUND AND PURPOSE

General Background The Office of Research, Development, and Information (ORDI) provides leadership in producing information and analysis to help shape current and future directions of CMS programs and related policy decisions.

ORDI staff helps improve CMS programs through:

· Expert consultation

· Program data and statistics

· Policy analysis

· Survey data and analyses

· Health services research

· Medicare and dual-eligible demonstrations

· Program evaluation findings

· Publications and information dissemination

· Research budget and support services

· Privacy oversight for external researchers

· Development of analytic databases and monitoring systems

The primary users of our products are operational and policy staff within the Agency and the federal government. Other users of our products include the research community, states, providers, health plans, and beneficiaries and their families.

ORDI’s broad experience and expertise encompass all aspects of research, demonstrations, and policy analysis. We provide the organizational structure and systems to support the full range of research, demonstration, statistics, and dissemination activities. We turn research, concepts, and information into improved health care policy and practice.

Although ORDI’s primary business functions relate to research, Information Technology (IT) provides a key enabler of many of ORDI’s core activities. IT is not ORDI’s core business, but virtually every interaction between ORDI and our business partners and customers depends on applications, systems, and processes employing IT.

Previously, the Secretary of the Department of Health and Human Services directed the Centers for Medicare & Medicaid Services to develop a new demonstration initiative using Medicare waiver authority to reward the delivery of high-quality care supported by the adoption and use of electronic health records (EHR). The goal of the demonstration was to foster the implementation and adoption of EHRs and health information technology (HIT) more broadly as effective vehicles improve the quality of care provided and transform the way medicine is practiced and delivered.

ORDI directed the construction of an Internet enabled application/system to support the management, administration, data collection, data dissemination, reporting, and other critical activities required to implement and operate this demonstration. CMS’s decision to deploy the EHR Demonstration System (EHRDS) on the Internet was intended to facilitate data collection and validation, streamline the process for the Electronic Health Record Demonstration activities, and provide a framework to support the business processes of future research, demonstration, and information IT initiatives. The EHRDS was constructed to support typical research, demonstration, and information business processes and provide capabilities that enable external entities to apply for the demonstration, register to access the system, and sign on to a secure web site to either manually input additional, patient specific information needed to calculate the quality measures, import data, or generate reports. The system assigns specific data access roles to each external entity that ensures the entity only has access to the data specifically pertaining to the practice. Although constructed to support the EHR Demonstration, the system was also designed specifically to be scalable, extensible, portable, and provide a framework for constructing and integrating IT applications that enable future research, demonstration, and information business processing requirements. The system has the capability to assign specific data access roles to each entity that ensures the entity only has access to the data specifically pertaining to that entity.

The EHRDS resides at the CMS Baltimore Data Center in the CMS 3-zone environment and entities participating in the demonstration connect to the system through their Internet Service Providers. The EHRDS complies with the CMS Target Reference Architecture and the CMS Internet Architecture. See Section 6 Government Furnished Information for the CMS IT standards URL.

ORDI Business Functions Overview Many existing ORDI demonstrations, evaluations, surveys, information, and research activities follow similar business processes. Typically, these processes include the following functions:

1. Identification of Eligible Beneficiaries for Demonstrations Demonstrations have a select group of individuals who are eligible for participation. Specific inclusion criteria are established, such as those pertaining to coverage (Medicare fee-for-service vs. managed care), entitlement (Part A and Part B), age, where a person lives, health status (presence of chronic condition), etc. In some instances, specific inclusion criteria are used to identify certain individuals from the universe and a target sample is generated. In other instances, the sampling universe is provided to an implementation contractor so that it may apply its own sampling methodology to create the target sample for the demonstration.

2. Demonstration Enrollment Demonstrations require processes for enrolling beneficiaries and for monitoring enrollment over time. Demonstration providers usually have the responsibility for enrolling beneficiaries, and while they are often required to monitor enrollment over time, they are not always consistent and dependable. In some demonstrations, the implementation contractor or CMS is involved in demonstration enrollment and monitoring. ORDI requires the capacity to develop and maintain the enrollment data based on information from demonstration providers for demonstrations that require this type of technical assistance. Maintaining accurate information on enrollment is crucial for providing accurate payments for demonstration services and accurate data to the demonstration evaluator regarding participation. The process for receiving enrollment data from a demonstration provider, checking it for consistency (e.g., includes Medicare number, first name, last name, date of birth, etc.), and creating an enrollment database are typically done ad hoc and require quite a bit of manual intervention.

3. Eligibility Verification The eligibility of beneficiaries for demonstrations needs to be verified before payments can be processed to demonstration providers. This involves taking an enrollment file and running it against a series of edits in the enrollment database (or another database, such as the Chronic Condition Warehouse (CCW) or Medicare Beneficiary Database (MBD)) to ensure beneficiaries who have enrolled are eligible for payment (e.g., not in MA, have both Part A and B, alive, etc.). Eligibility verification occurs upon the beneficiary’s initial enrollment in a demonstration and monthly thereafter. Beneficiaries who lose eligibility need to be identified and removed from the enrollment file for the particular month. Demonstration providers need to be notified of beneficiaries who have lost eligibility and been disenrolled from the demonstration payment system so that they may disenroll the beneficiaries from the demonstration. The enrollment database needs to be updated monthly to reflect changes in eligibility as well as be able to maintain a history for each person who has ever been enrolled in the demonstration.

4. Data Collection CMS needs the capability to “acquire” clinical and other appropriate data necessary for program administration and improving health outcomes for beneficiaries at the point of service (provider setting). These systems shall include the capabilities for an entity to apply to access the system demonstration, register to access the system, and sign on to a secure web site to either manually input information or could use an “import” function to import the data. The system shall assign specific data access roles to each entity that ensures the entity only has access to the data specifically pertaining to the practice.

5. Payment Calculation Demonstration providers often have different payment rates. The payment process must include programming separate payment information for each provider and have the capacity to allow for updates or changes in payment rates. The process must also be able to calculate payment amounts for each eligible person each month and maintain a payment history for each participant in the demonstration, and for each demonstration provider.

6. Report Generation & Data Access Reports on enrollment, disenrollment, provider listings, and payment often help ORDI and demonstration providers monitor demonstration activities. These reports can be generated both on an ad hoc basis and recurring schedules for monitoring. Different entities frequently need to perform periodic data extracts for their analysis

7. Program Integrity Many demonstrations require periodic monitoring of spending under the demonstration, either in total or by sub-population or by subset of conditions and/or type of service, for the purpose of helping demonstration sites understand the impact of their interventions on their population or for the purpose of helping ORDI determine whether a demonstration should be terminated or extended. Most of this monitoring work has been done by customized applications, but it is preferred that such work be done in a more systematic fashion spanning the entire demonstration portfolio.

8. Surveys One of the core functions of ORDI is to develop, implement, and analyze surveys of the populations and entities affected by CMS Programs. ORDI serves as center of expertise in survey methodology in that we develop and test innovative methods of data collection, measurement, storage, aggregation, and dissemination. The Medicare Current Beneficiary Survey (MCBS) and the Medicare Health Outcomes Survey (HOS) are surveys sponsored by the Centers for Medicare and Medicaid Services (CMS) and directed by the Office of Research, Development and Information (ORDI).

Many of the demonstration functions also reflect survey functions conducted by CMS. The base tenets outlined above for the demonstration specific projects can also be applied to many of the surveys conducted by CMS.

9. Data Dissemination ORDI serves as a key resource for disseminating data to public and private researchers seeking to access CMS Medicare and Medicaid data. We help provide a point of contact for external entities seeking to obtain Medicare and Medicaid data.

Demonstration & Evaluation IT Development & Operations Historically, ORDI Research, Demonstration and Evaluation projects have independently sought their own IT solutions to meet the project’s needs. Oftentimes this was done due to the fact that the existing CMS IT environment could not assist in meeting ORDI’s demonstration requirements. IT had become more of an obstacle as opposed to an enabler. Systems were developed piecemeal to meet project specific requirements and little effort was devoted to integrating efforts to reuse common functionality. Oftentimes, very little consideration was given to whether or not the IT solution complied with Federal, HHS, or CMS standards, policies, and procedures.

The fundamental limitation of this approach to systems is that it can never result in a foundation for effective business processes. Every demonstration and evaluation business process is dependent on the instincts, judgments, and attention of the person completing it. Furthermore, if these research, demonstration and evaluation systems need to interface with existing CMS legacy systems, we need to spend more and more time trying to tie together systems and data that were designed independently. The eventual patchwork of systems makes the business processes more susceptible to system’s outages and we find it increasingly difficult to respond to changing business conditions. Additionally, this approach makes ORDI more susceptible to being out of compliance with various CMS and Federal mandates concerning security and privacy regulations (e.g. FISMA).

ORDI has begun establishing an integrated set of research, demonstration, and evaluation business processes and the appropriate capabilities to employ technologies, applications, and data to support these processes. Although each demonstration and evaluation has unique requirements, core business processes still transcend demonstration boundaries that do not change so they can be used to define a reliable set of reusable IT-supported data and processes. Business entities can apply different decision rules relating to specific demonstrations and evaluations, using the same business process other demonstrations and evaluations employ.

Many demonstrations, evaluations, and research projects share business processes that follow a similar life cycle. Report generation, monitoring and program integrity checks, evaluation analytics, eligibility identification, demonstration enrollment, eligibility verification, and payment calculation and reconciliation are business functions that apply to many demonstration projects. The ultimate goal is to construct integrated systems that apply different decision rules relating to specific demonstrations, evaluations, and research projects, while at the same time reusing the same business process. Because many of these systems should be Internet-based and will house sensitive and personally identifiable data, security is a crucial aspect of the system development. We need to be concerned about the authentication of users, many of whom may be dispersed throughout the Medicare provider community. We also need to be concerned about the transmission of sensitive financial (e.g. tax identification numbers) and health information over the Internet.

Data & Statistics Dissemination ORDI maintains the Chronic Condition Warehouse (CCW) that houses data that are easily linked, at the individual patient level, for all Medicare claims data, eligibility data, nursing home and home health assessments, and CMS beneficiary survey data. This data warehouse transforms and summarizes this administrative health insurance information into research data files. Part of this process involved transforming diagnostic information on a beneficiary’s Medicare claims into information about their chronic medical conditions. The data warehouse is designed to support research, policy analysis, quality improvement activities, and demonstrations that attempt to foster a better understanding of how to improve the quality of life and contain the health care costs of the chronically ill. The data warehouse has become a critical enabling technology for ORDI individuals that provide the following capabilities:

· Disseminating data to health services researchers studying ways to improve the quality and reduce the cost of care provided to chronically ill Medicare beneficiaries.

· Reduce program spending by making current Medicare data more readily available to researchers studying chronic illness in the Medicare population.

· Making data extraction from more efficient, allowing for data requests to be fulfilled in a timelier and more cost efficient manner.

· Eventually, providing the same capabilities for Medicaid and Children's Health Insurance Program (CHIP) data.

ORDI also oversees the Research Data Distribution Center (RDDC) that serves as a key resource for disseminating data to public and private researchers seeking to access CMS Medicare and Medicaid data. We provide a single point of contact for external entities seeking to obtain Medicare and Medicaid data.

In the last several years, CMS has seen an explosive demand for its data by internal and external customers. However, the demand is not only for raw data, but also for timely and readily available information. The White House and Office of Management and Budget have given direction that we should move forward aggressively with efforts to make program data and information much more available and readily accessible to internal and external users.

CMS maintains the most comprehensive health care data resource anywhere and we are in a unique position to help catalyze a data-driven health care industry that can encourage high quality and efficient performance. CMS is now moving in the direction of becoming an information-focused organization at the center of the federal health enterprise.

Data Dissemination In addition to overseeing and maintaining the CCW and RDDC, ORDI has also been tasked with assisting in the integration of Medicare public use data sets into www.Data.gov. This is a website developed by the Federal CIO Council as an interagency federal initiative to increase public access to high value, machine readable datasets generated by the executive branch of the federal government. Many of these products were developed and are maintained by ORDI. Recently, ORDI’s Statistical Supplement has been selected as one of the “Featured Tools” of the site. One of the main intents of the site is to enable the public to participate in government by providing downloadable federal datasets to build applications, conduct analyses, and perform research. CMS plans to contribute a variety of data files, tools and extracts to Data.gov. We will contribute data on a rolling basis as they are available. ORDI requires the capability to:

1. Design, develop, produce, and disseminate information products that will allow easy monitoring of program enrollment, utilization, payments, and performance of the Medicare, Medicaid, and CHIP programs.

2. Design, develop, produce, and disseminate a variety of statistical and analytical data repositories containing Medicare, Medicaid, and CHIP program information for use by the general public and research communities.

3. Design, develop, produce, and disseminate statistical tables, chart books and data tables of Medicare, Medicaid, and CHIP program information.

4. Expands our information products, including public use files (PUF) and data, limited data sets (LDS), research identifiable files (RIF), and enhanced information products produced through file linkages

5. Translate raw statistical data into files useful to technical researchers, website visitors, and the general public in understanding CMS programs, spending, and policies Digital Journals Previously, IMG created and published the Health Care Financing (HCF) Review, which provided a unique means for CMS to communicate with the health care provider, research, and policy communities on CMS initiatives, issues, and accomplishments. The Review helped provide government, academia, and industry information on health care expenditures, enrollment, and utilization, and a forum for the discussion and evaluation of research projects to assess alternative financing and delivery systems for health care. The Review also provided information on publications, studies, and conferences related to health care financing.

ORDI recently made a determination to end the 30-year run of the HCF Review. However, there is an opportunity to carry forward valuable functions of the hard copy HCF Review to a new (digital) medium. ORDI researchers and analysts have skills and data access opportunities that could allow the agency to be among the first out of the gate in identifying significant issues, not only for research, but to inform the policy and lawmaking processes at a time when it would still have an impact. ORDI shall play a lead role in the design, development, production, and publication of Internet-based digital journals that communicate Research and Development (R&D) findings to Congress, the Administration, state & local government officials, academia, researchers, analysts, and other stakeholders. ORDI shall be a key contributor in creating and operating a future peer-reviewed online journal reporting data and research that help shape current and future directions of the Medicare, Medicaid, and Children’s Health Insurance programs. The journal shall seek to examine and evaluate effective up-to-date health care coverage, quality and access to care for beneficiaries, and efficient payment for health services. These journals and associated IT systems shall also provide the following capabilities and features:

1. Communicate CMS R&D findings to Congress, the Administration, state & local government officials, academia, researchers, analysts, and myriad other stakeholders

2. Report data and research that help shape current and future directions of the Medicare, Medicaid, and Children’s Health Insurance programs

3. Provide analytical narratives to accompany program data

4. Provide an outlet for CMS staff research

5. Provide “provisional research” or other preliminary analysis on current policy issues

6. Examine and evaluate effective up-to-date health care coverage, quality and access to care for beneficiaries

7. Examine and evaluate effective efficient payment for health services

8. Provide support for the preparation, release and dissemination of ORDI products via electronic media and web publishing Purpose The purpose of this Indefinite Delivery/Indefinite Quantity (IDIQ) Cost Reimbursable contract is to assist the Centers for Medicare and Medicaid (CMS) in providing information technology services to develop secure and integrated Internet-based software and database systems to support research, demonstration, and information activities. The overarching system shall be referred to as the Research, Demonstration and Information System (RDIS) and shall be constructed and integrated into the architectural framework that currently supports the EHRDS. This IDIQ will encompass a variety of IT developmental and project management activities associated with web site development, database development, business intelligence development, data dissemination and analytics to support ORDI’s current and future portfolio of research projects.

Because many of the components of the RDIS shall be Internet-based and may house sensitive and personally identifiable data, security is a crucial aspect of the system development. CMS is concerned about the authentication of users, many of whom may be dispersed throughout the Medicare provider community. CMS is also concerned about the transmission of sensitive financial (e.g. tax identification numbers) and health information over the Internet.

CMS’s decision to deploy the RDIS on the Internet is intended to ensure security and privacy requirements, streamline business processes, and facilitate data collection, validation, dissemination, reporting, and analytics. The system will reside at the CMS Baltimore Data Center in the CMS 3-zone environment. The entities accessing system components will connect to the system through their Internet Service Providers. By maintaining the system on the web and establishing a secure, centralized system, security concerns and problems presented by so many external entities might largely be avoided.

The period of performance for this contract is five years; individual Task Orders will be issued during the five years from the effective date of award and may continue to be effective for five years after the Task Order’s effective date. The RDIS IDIQ will cover the Information Technology Requirements, Project Management, Design, Development, Implementation, Testing, and Operations tasks as they are determined.

TECHNICAL INSTRUCTION

All system components will comply with the CMS Target Reference Architecture and the CMS Internet Architecture. See Section 6 Government Furnished Information for the CMS IT standards URL. The Contractor will develop the system with standard (or future) CMS development software tools (ie: Java, Flex, etc.) and standard CMS Business Intelligence tools to use an Oracle and/or Teradata database.

Because of the complexity and breadth of this effort, it is anticipated that multiple contracts will be awarded under this IDIQ to assist with the Information Technology (IT) design, implementation and operational activities, including but not limited to:

1. IT Project Management

2. Requirements Analysis & Development

3. System Quality Assurance and Test

4. System Architecture

5. System Engineering

6. System Integration

7. System Design

8. IT Application Design

9. System Programming

10. Database Design

11. Extract, Transform, & Load Design and Integration

12. Operations & Maintenance

13. IT Security

14. IT Infrastructure

15. Enterprise Architecture

16. Business Intelligence

17. Data & Statistical Information Dissemination Technical Direction Independently and not as an agent of the Government, the Contractor shall furnish all the necessary services, qualified personnel, material, equipment, and facilities, not otherwise provided by the Government, as needed to perform the requirements of this SOW.

All work under this contract shall be performed under the general guidance and monitoring of CMS and is subject to CMS approval. The Contractor shall work closely with the CMS Contracting Officer Technical Representatives (COTRs), Government Task Leaders (GTLs) and Project Officer to accomplish all Government requirements described in this Statement of Work.

The Contractor shall serve in a consultative/collaborative capacity on an ongoing basis to address issues related to all IT aspects of the RDIS. This contract requires the Contractor to interact with CMS Federal personnel and contracting entities of multiple disciplines (contracting personnel, project management personnel, technical personnel, application development, etc.) that form a CMS team. Identification of the specific point-of-contact on the CMS team for specific situations has not been addressed in this document. This lack of a specific point-of-contact in no way affects any of the requirements the Contractor is required to perform. The Contractor shall be held accountable for positive and negative collaboration performance that advances or impedes the ability of CMS and CMS contractors to perform effectively. The Contractor is advised that specific use of the terms “CMS”, “Contracting Officer Technical Representative” (COTR), “Project Officer” (PO), “Contracting Officer” (CO), or “Government Task Lead” (GTL) in this document could denote one or more members of the CMS team. The CO is the only CMS official who can approve requests for additional funds or authorize work not specified under this statement of work in this contract. All contract changes must have the prior approval of the CO through the written contract modification.

Contractor Security The Contractor will be required to sign an Interconnection Security Agreement (ISA) that describes the security requirements between the CMS Data Center (CMSDC) and the Contractor. The security requirements documented in this agreement will be the result of a Risk Assessment performed by CMS at the Contractor site.

The policies, standards, and procedures that govern the CMS Information Security Program have a two-fold purpose: (1) to enable CMS’ business processes to function in an environment with adequate security protections; and (2) to meet the security requirements of Federal laws, regulations, and directives, including the Privacy Act of 1974 (as amended), HIPAA, and FISMA, as well as various rules, regulations, policies, and guidance developed by DHHS, OMB, Homeland Security and NIST. Although all the documents are important in applying information security for CMS systems, the key ones include:

The CMS Policy for the Information Security Program This policy aims to reduce the risk, and minimize the effect of security incidents and establishes the ground rules under which the CMS shall operate its information systems. All CMS employees, contractors, sub-contractors, and their respective facilities supporting CMS business missions shall observe the individual policy statements. Some policies are explicitly for persons with a specific job function, e.g. the System Administrator; otherwise, all personnel supporting CMS business functions shall comply with the policies. The CMS IS Program Policies address the reduction in risks to information resources through adoption of preventive measures and controls designed to detect any errors that occur.

CMS Information Security Acceptable Risk Safeguards (ARS) The ARS reflects the minimum thresholds for information security controls based on the NIST SP 800-53, Recommended Security Controls for Federal Information Systems and NISP SP 800-63, Electronic Authentication Guidelines. These controls must be implemented to ensure that all CMS systems meet a minimum level of information security.

CMS Information Security (IS) Risk Assessment (RA) Methodology This methodology presents a systematic approach for the Risk Assessment (RA) process of information systems within the CMS environment. The IS RA provides an evaluation of current security controls to safeguard against the identified threat/vulnerability pairs and the resulting risks levels; and the recommended safeguards to reduce the system’s risk exposure with a revised residual risk level once the recommended safeguards are implemented.

CMS System Security Plan Methodology This methodology is intended to serve as a tool for System Owners/Managers and System Maintainer/Managers in determining the SSP requirements of General Support Systems (GSS), Major Application (MA) systems and applications. The SSP documents the current level of security within the system and is evaluated by the CMS Chief Information Officer (CIO). Based on those controls currently implemented and documented in its SSP, the CIO determines whether or not the system will be granted authorization to process, i.e., accreditation. Similarly, the SSP forms the primary reference documentation for testing and evaluation, whether by CMS, the GAO, the IG, or other oversight bodies. The following web page should be referenced for more information regarding CMS’ Policy for the Information Security Program (PISP): www.cms.hhs.gov/InformationSecurity. The information on this web site is updated frequently to comply with the on-going directives of OMB, Homeland Security, the National Institute of Standards and Technology and the Department of Health and Human Services.

CMS Data Center Connectivity The Contractor shall be required to establish a network configuration within the Contractor site that enables establishing broadband connectivity between the Contractor site and the CMS Data Center within three months after contract award. The network configuration shall adhere to the security requirements established by CMS. CMS shall provide the funds for the actual broadband connection service costs. The Contractor has the responsibility for the costs associated with establishing the internal network at the Contractor site.

On Site Availability The Contractor shall be required to attend scheduled and impromptu meetings and conferences at the CMS facility on a regular basis. The Contractor shall also be required to perform tasks that require their physical presence within the CMS data center and satellite telecommunications rooms on a scheduled and impromptu basis. The Contractor must have the capability of arriving at the CMS facility for these types of activities within 60 minutes after being notified their presence is required on site. Due to the nature of the work, this could occur several times over the course of a normal business day and may also take place on Federal holidays, weekends, and non core weekday hours. It is estimated these types of activities could potentially consume 25% - 75% of their normal workday tour of duty for a business day.

Tour of Duty CMS Core business hours for covered tasks are defined as between 6:00 AM and 6:00 PM Eastern Standard Time, Monday through Friday, excluding Federal Holidays. The Contractor shall be required to provide coverage for production systems during this time frame. Due to the requirement to maintain system availability 24/7/365, it is expected that the contractor shall be able to provide service for this requirement when needed including on-call support. This may require duty tours during Federal holidays and weekends, particularly when there is a need to perform tests for operating system, hardware, COTS software, and other CMS infrastructure related upgrades in addition to RDIS application specific upgrades and maintenance releases. The Contractor is allowed to stagger shifts and provide flexible workplace options for contracting employees as long as the core hour coverage is maintained.

Computer Hardware & Software The nature of the work necessitates the Contractor provide portable-computing devices to individuals engaged in CMS related DBA and DA tasks. The Contractor must have the capability to access critical and sensitive data remotely outside of the CMS and Contractor physical facilities. Remote access to the CMS computing infrastructure is mandatory. The Contractor shall also be required at times to access the CMS computing infrastructure from within the CMS physical facilities. CMS may or may not provide the computing resources to perform these tasks.

The Contractor shall be required to provide employees working on CMS tasks the capability to meet the portable computing requirements. Dial-in remote access and on-site access to the CMS computing infrastructure shall only be granted to individuals possessing a Government approved Contractor-owned portable computing device. To ensure accountability and auditability, these computers may not be shared between individuals. The Contractor shall provide CMS an inventory detailing the computer identification numbers and individual assignments. Portable computing devices in support of the CMS contract shall have the CMS standard desktop configuration and abide by the CMS Desktop Features and Specifications, which shall be provided by CMS. The portable computing device must have the Microsoft Office Professional software suite installed, which shall be provided by the Contractor.

Personally owned computers are prohibited from connecting to the CMS network.

Task Order Management The contractor shall provide skilled personnel together with the supervisory, managerial, and administrative services necessary to successfully meet the requirements of this task order. Personnel assigned by the contractor to perform work on the contract shall be acceptable to the Government in terms of personal and professional conduct and technical knowledge. The contractor shall have a plan in place with the ability to retain and attract qualified personnel. Replacement personnel qualifications shall be equal or greater than those of the personnel being replaced and will result in no increase in Task Order price. Employment and staffing difficulties will not be a justification for the failure to meet established schedules.

Contract Kick-Off Meeting The Contractor shall participate in an initial kick-off meeting hosted by CMS to discuss expectations. The Kick-Off Meeting will be held at CMS’s Baltimore, MD Central Office location on a mutually agreed upon date and time. The Contractor shall develop and deliver a presentation for the Kick-Off Meeting that includes the following material:

· Technical Approach Overview

· Introduction of Key Personnel

· Other Topics as directed by CMS Monthly Status Report The Contractor shall submit monthly administrative progress reports outlining all work accomplished during the previous month. At a minimum, such reports shall cover the following items:

· Activities during the month (data collection activities, problems encountered and potential future problems, actual and possible delays in deliverables, etc.);

· Activities planned for the forthcoming month;

· Contractor expectations of the PO or other CMS staff during the forthcoming month (review of deliverables submitted, delivery of data or other items);

· A financial report, including past month expenditures, to-date expenditures, and significant deviations from planned expenditures. This is to include a discussion of planned versus actual resource consumption by major task area. Discrepancies of greater than 10 percent (i.e. cost overruns or underruns) shall be noted. To the extent actual expenses for the period are not yet available (e.g. for sub-contractors), an estimate of incurred expenses shall be provided in order to more closely manage total project costs; and

· A brief discussion of substantive findings during the previous month, if any.

Each monthly report shall be submitted electronically within 10 days following the end of the month and one copy shall accompany the Contractor's voucher that is sent to the CMS contract officer. Vouchers will not be processed without submission of a monthly progress report.

Earned Value Management At the Government’s discretion, the Contractor shall maintain an earned-value management system (EVMS) that uses criteria acceptable to the CMS GTL and Project Officer. The EVMS shall correlate cost and schedule performance with technical progress while performing all tasks and shall be capable of producing a project level (includes all project related contract costs) EVM status report both on demand and at predefined intervals using a format acceptable to the CMS GTL.

Project Status Review The Contractor may be required to lead or participate in ad hoc Project Status Reviews with CMS senior management. The Project Status Reviews may include:

1. An overview of the project status with a focus on outstanding issues and risks;

2. Identification of Critical Path Milestones;

3. Identification of issues needing resolution by CMS; and

4. Identification of decisions needed from CMS.

Interfacing Contracting Entities The Contractor shall serve in a consultative/collaborative capacity on an ongoing basis to address issues related to all IT aspects of the RDIS. This IDIQ contract requires the Contractor to interact with CMS Federal personnel and contracting entities of multiple disciplines (contracting personnel, project management personnel, technical personnel, application development, etc.) that form a CMS team, headed by the COTR. The contractors must work together and in collaboration with various components within CMS to support the requirements and goals of the RDIS. Representative interfacing entities are detailed below.

IT Technical & Requirements Management Contractor

The IT Technical & Requirements Management Contractor will provide IT project and technical management support services to assist in the planning, definition, design, testing, and quality assurance of IT related functionality.

IT Development, Operations, & Maintenance Contractor

The IT Development, Operations, & Maintenance Contractor shall be responsible for the development of an Internet-based systems that will facilitate data dissemination, statistical publications, demonstration enrollment, and demonstration application data collection activities.; Additionally, the Internet-based system will be responsible for incorporating demonstration payment, demonstration and evaluation reporting and analytics, and streamlining and improving data security for collection of clinical quality data.

Comparative Effectiveness Research (CER) IT Development, Operations, & Maintenance Contractor

The CER IT Development, Operations, & Maintenance Contractor shall be responsible for the development of Internet-based systems that facilitate data dissemination for comparative effectiveness research.

CER Research Development Contractor

The CER Research Development Contractor shall be responsible for conducting comprehensive research on re-identifying Health Insurance Portability and Accountability Act (HIPAA) de-identified datasets.

Office of Information Services (OIS) Support Contractors

The OIS Support Contractors shall be responsible for establishing the physical environment within the CMS data center, providing Business Process Modeling (BPM) support, identity management support, and a host of other critical IT infrastructure and IT support tasks.

Research Data Assistance Center Contractor (RESDAC)

ResDAC is a CMS contractor that provides assistance to researchers in understanding how to use CMS data and how to request CMS data.

Chronic Condition Warehouse (CCW)/Research Data Distribution Center (RDDC) Contractors

The CCW/RDDC contractors are currently employed by Buccaneer Computer Systems & Service, Inc. (BCSSI). The contractors will provide support for the Chronic Condition Warehouse Database and fulfill research requests using identifiable data, Limited Data Sets (LDS) which are partially de-identified data, and Public Use Files (PUF).

Key Assumptions & Constraints Some of the key assumptions and constraints for the RDIS components and for this contract are listed below.

1. ORDI is the Business Owner for the RDIS components.

2. All RDIS components will reuse current EHRDS and CMS systems and technology to the maximum extent possible.

3. CMS will develop the different RDIS components in incremental releases. Each major release will implement a defined set of functionality for the program.

4. Based on the gap analysis and high level implementation planning, CMS will define the scope of each release and provide direction to the Contractor.

5. To the extent applicable, all projects shall follow the CMS Lifecycle Framework. Additionally, all releases will follow the CMS Life Cycle Framework. Each release will build on prior releases’ life cycle documentation (i.e., the Contractor will not need to create completely new documentation for each release).

6. All RDIS components will either use CMS’ Enterprise Identity Management and Authentication Service, referred to as the Individuals Authorized Access to the CMS Computer Systems (IACS), or an alternative approach as designated by OIS.

7. The Identity Management and Authentication Services will store user identification information

8. All deliverables, reports, data, or information either generated as a result of performance under this contract or provided to the Contractor or to any…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .