J-1_CCW_Re-Compete_2014_STATEMENT_OF_WORK_7-7-14.pdf

PDF 329 KB Posted

Attached to
CHRONIC CONDITION WAREHOUSE Federal contract opportunity
Solicitation number
RFP-CMS-2014-8A-00092
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

ATTACHMENT A SCHEDULE OF DELIVERABLES

View the file

Other files for this federal contract opportunity

Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment J-1

CHRONIC CONDITION WAREHOUSE (CCW) and VIRTUAL

RESEARCH DATA CENTER (VRDC) STATEMENT OF WORK

I. PURPOSE:

The purpose of this Statement of Work is to continue operations and maintenance of the Chronic Condition Warehouse (CCW) and Virtual Research Data Center (VRDC) and associated research tasks within the Office of Information Products and Data Analytics (OIPDA), other CMS components and the Center for Medicare & Medicaid Innovation (CMMI). The CCW was implemented in 2005 to comply with Section 723 of the Medicare Prescription Drug, Improvement, and Modernization Act of 2003. This legislation mandated CMS to develop a method of disseminating data to health services researchers studying ways to improve the quality and reduce the cost of care provided to chronically ill Medicare beneficiaries. The VRDC was recently developed to provide a more secure, efficient access method to approved users of CMS data.

The prior contract was an Indefinite Delivery/Indefinite Quantity (IDIQ) vehicle and contained many task orders covering various components in CMS and CMMI. This contract consolidates all of the work that was being performed under the IDIQ task order contracts into one large contract. General tasks have been merged together but tasks pertaining to individual components such as the Policy & Data Analysis Group (PDAG) and CMMI work are identified separately for ease of operations, management and tracking. The CCW/VRDC contractor will be required to establish a data warehouse and acquire the equipment, connectivity, software and licenses, etc.

necessary to perform all of the tasks in this SOW. The contractor is required to perform an assessment to ensure the infrastructure is set-up in a successful manner and does not pose any security or performance issues for CMS/CMMI or the external users accessing or receiving data files. The current equipment, documentation, algorithms, etc. will be transitioned from the incumbent contractor to the new contractor. The contractor will be required to work with the incumbent contractor to develop and implement a successful transition plan with minimal interruptions and/or down-time. The existing inventory of equipment is listed in Attachment B.

Since the CCW will continue to grow, the contractor shall include the acquisition of new/replacement equipment needed beyond the current equipment listed in Attachment B. Some of the key features of this SOW are to:

• Develop a secure infrastructure located at the contractor’s site, meeting the required CMS security requirements, to house, process, provide access to, analyze and perform extractions of the data covered under the CCW/VRDC SOW (approximately 315 billion records utilizing 800 terabytes of storage with overall storage capacity of 3 petabytes);

• Transition the current data files and load and maintain future Medicare and Medicaid data including but not limited to enrollment, claims, assessment, quality provider, etc. Future data files will be downloaded from CMS so the contractor is required to have connectivity to CMS;

• Have the capability of extracting custom research identifiable data files based on the extract specifications provided by the researcher;

• Have the capability of copying and shipping standard research identifiable extracts as well as Limited Data Set files and public use files, upon approval;

• Maintain the current chronic condition flags and work with CMS/other CMS contractors to develop new chronic condition algorithms and apply them to the data;

• Transition and set-up the VRDC environment and continue supporting access for up to 900 users, 475 being concurrent users, via virtual desktops. Have the capability to grant access to new users and be able to conduct statistical output reviews for those users that are required to only download statistical data outside of the environment;

• Transition and operate the current CCW Access Request System (CARS) to initiate and track VRDC users;

• Provide support to epidemiologic researchers by assisting with their proposed research methods;

• Provide analytic and research support to CMS/CMMI and other contractor staff for the purpose of conducting research, data storage, and evaluation of CMMI demonstration/model data;

• Develop, maintain and operate the existing CMMI business and enclave workspace in the

VDRC;

• Operate an analytic and technical help desk to support users with research analysis as well as technical questions.

II. BACKGROUND AND HISTORY:

The CCW has grown over time from a small data warehouse containing 5% Medicare files to a very large data warehouse containing 100% Medicare and Medicaid data files for the years 1991-current. The list of data files covered under this contract are listed in Attachment C. The data are housed in a relational database and pre-extracted SAS files are made available to users that are approved to receive them via the VRDC. Each beneficiary in the Medicare and Medicaid data files are assigned a unique CCW beneficiary identifier allowing researchers to easily track individuals over various data file types and over various years. The CCW data initially incorporated 21 pre-determined chronic conditions. Beneficiaries that were identified as being diagnosed with 1 or more of the 21 chronic conditions, based on very detailed algorithms, were flagged in the CCW database. Over time, new chronic condition algorithms were added and expanded to include Medicaid and Medicare/Medicaid (those dually eligible under both programs). There are currently 27 pre-determined Medicare chronic condition flags and 24 pre-determined Medicaid chronic condition flags that researchers can use when studying Medicare only, Medicaid only or the duals population in their analysis. Researchers also have the option of developing their own specifications so the contractor shall be capable of developing these custom extracts. For researchers opting to purchase a VRDC seat, the contractor shall have the capability of establishing a user account within the VRDC for that researcher and assigning the researcher with access to the approved data files for their project. The contractor is required to comply with CMS’ minimum necessary requirements and have the capability of encrypting sensitive fields such as social security number, Medicare claim number, etc. This encryption feature is key to protecting the confidentiality of the data but also permits a researcher to link and track individuals over time and associate multiple providers claims to unique individuals. Some researchers and internal CMS staff may be approved to get sensitive fields so there is a need to be capable of providing the actual data fields upon approval. Due to the development of this user, research-friendly data warehouse, the number and types of CCW users have increased significantly since the initial CCW implementation. Initially the users were limited to academic researchers that received physical shipment of the data files for their approved use. The CCW now provides data to various types of users, including but not limited to: researchers, internal CMS staff and contractors, other Federal agencies and their contractors, State agencies, etc.

CMMI has various demonstrations and models that require the use of Medicare, Medicaid, and CHIP data. The VDRC enables users to access CCW data and upload demonstration and model data, as well as utilize the same resources within the CCW environment instead of having data disseminated to each contractor or organization.

Approximately 15,000 data files are disseminated annually and an estimated 600 users access the CCW directly via the VRDC (current capability under the incumbent contractor support up to 900 users). The VRDC access is expected to increase over the life of the contract.

III. TECHNICALASSUMPTIONS:

1. The contractor must be knowledgeable about CMS data, CMS data dissemination and CMS privacy policies/practices, including minimum necessary requirements, and that they will be capable of providing the VRDC access, data extraction, technical assistance, and overall support and services within the SOW.

2. The contractor must have a FISMA compliant location, upon award, to house and maintain the equipment necessary to support the data warehouse. The data center shall meet the security requirements stated in this SOW and the meet all necessary equipment storage requirements as indicated by the equipment manufacturer. The facility will be required to have connectivity to CMS as well as to any other sites (e.g., the training facility identified in #3).

3. The contractor must have a secure location to conduct on-site training within 20 miles of the CMS Baltimore complex. The location will require connectivity to the CCW data center at the location specified in #2 above and to CMS. Establishing the connectivity can take some time so the contractor shall have the facility in place within 10 days of award. The training location must provide individual workstations and virtual desktop computers to support 10-20 trainees and be large enough to accommodate the students and an additional 5 trainers/observers.

4. The infrastructure to support the CCW, including software, hardware and extraction tools is owned by the Government. The system shall be scalable, extensible, and portable to enable integrating future enhancements and potentially transitioning to another organization, if CMS chooses to do so in the future.

5. The contractor shall obtain from CMS, and the incumbent, all of the data files necessary to complete the tasks specified in this SOW. The contractor shall be prepared to access and/or receive newly available identifiable data files, limited data sets and public use files from CMS using a secure network connection (e.g., DS3 line). All files containing identifiable data, including limited data sets, shall only be transmitted across a secure network connection. The contractor shall be prepared to receive data on physical media (tape, cartridge, CD/DVD, etc.) if required.

6. The contractor must be capable of transitioning the CCW/VRDC infrastructure and all operational components within a 120-day period with downtime of no more than 48-72 hours.

7. Upon completion of the transition-in phase, the contractor must be capable of performing all operational and maintenance tasks identified in the SOW, including but not limited to, the ability to create data extracts to fulfill approved data requests in timely manner, grant access to VRDC users in a secure and timely manner and load their workspace with the approved data files, and conduct informative training sessions on the CCW and VRDC.

8. The contract Period of Performance is as follows:

a. 12 Month Base year (includes 6 month transition period) – March 30, 2015 – March 29, 2015

9. Option years (up to 9, 1 year extensions—last year will include optional transition task)

IV.A. TRANSITION-IN TASKS:

Task A1 – Kick off and Transition Discussion:

The contractor shall attend a 1-day kick-off meeting at CMS’ Baltimore office with the COR, Government Task Leads (GTL), component points of contact, appropriate CMS staff and incumbent contractor staff within 10 days after the date of award. The purpose of the kick-off meeting is to discuss the transition, the transition tasks, and transition deliverables. The contractor will have the opportunity to address any issues or clarify any questions they may have regarding the tasks in the SOW. The contractor shall prepare an agenda for the meeting and a draft work plan identifying the specific activities that should be performed to establish the CCW/VRDC environment and all other tasks defined in the SOW. The contractor shall identify the location of the data center and the location of the training facility. The contractor shall provide a summary of the meeting, action items/next steps and an updated work plan including all of the items discussed.

Task A2 – Information Gathering and Transition Planning:

The contractor shall work with CMS and the incumbent contractor to understand the current CCW/VRDC infrastructure, processing and workload associated with the CCW IDIQ task orders. An inventory of all existing equipment and data files covered under the current CCW IDIQ task orders are contained in Attachments B and Attachment C. Based on the requirement to combine all CCW IDIQ task orders, the contractor shall develop a comprehensive list of questions, issues, and/or risks that need to be resolved prior to the transition. The contractor shall participate in meetings, via conference call, with the incumbent contractor and the COR/GTL to ensure all questions, issues and/or risks are identified. For all risks identified, the contractor shall develop recommendations for eliminating or reducing the risk. The contractor shall provide the COR/GTL with a report containing all questions, issues and/or risks they have identified and the associated responses or recommendations for resolution. The contractor shall work with the COR/GTL and the incumbent contractor to update the list. The list shall be updated and provided to the COR/GTL throughout the transition and into the operation phase.

The frequency of the updates will be defined by the COR/GTL.

The contractor shall develop a concept of operations plan for detailing support for all users covered in this SOW. The contractor shall develop a separate concept of operations plan specifically for CMMI related tasks/services provided in this SOW. The details of the plan will be defined by the CMMI GTL. The contractor shall develop an organizational chart identifying the support for all business operations within the CCW/VRDC. The organization chart shall identify the business operations by functional area for ease of reporting to appropriate GTL’s (CMMI, OIPDA, other CMS users, external users, etc.).

Task A3 – Develop Data and Infrastructure Acquisition Plan for Equipment Refresh:

Upon award, the contractor shall have a facility large enough to house the CCW/VRDC data center and associated equipment and data, identified in the SOW Attachments, and have additional space to expand in the future. Within 10 days of award, the contractor shall have a facility, within 20 miles of the CMS Baltimore location, to host training sessions for CCW/VRDC users. The facility shall be large enough to comfortably host 20 students and up to 5 trainers/observers. Additional hardware and software will be needed to support the volume of data, data access and data extract processing taking into account the increase in users accessing the CCW/VRDC and workspace needed to support those users. The contractor shall prepare a list identifying all recommended hardware for the transition and future hardware for replacement of the current equipment, software, storage space, archival space, etc. that are needed to support the current and scalable environment. The contractor shall include media (CDs, DVDs and external hard drives) that will be required to fulfill external data requests.

The contractor shall work with CMS and the incumbent contractor to establish a schedule to receive, load and validate all data files needed to support the CCW and user workspace for all VRDC users. The contractor shall work with the incumbent and the COR/GTL to develop an acquisition schedule for transitioning the current equipment and purchasing additional equipment (hardware, software, storage space, archival space, media, etc.) identified from the recommended listing identified above. The contractor shall procure the items upon approval from the COR/GTL. The contractor shall address the following in the Data and Infrastructure Acquisition Plan/Schedule and include completion dates:

Hardware:

1. Identify scalability of current equipment and recommendation for replacement equipment;

2. Develop storage projections and communicate the information and assumptions that support these projections;

3. Attain quotes for moving and insuring the current hardware during shipping;

4. Build comprehensive hardware migration plan;

a. Factor in all existing hardware, vendor assistance, and contractor personnel on both ends of the move

b. Account for all media on-site and off-site that will need to be shipped

c. Proposed set-up date should incorporate the time needed by the incumbent to prepare the equipment for shipment, shipping time and arrival time. Contractor shall identify the amount of time needed to set-up and operationalize the CCW/VRDC data center upon receipt of equipment

5. Develop and apply measures to the database before and after migration/transition to assure accuracy.

Source Code and Documentation:

1. Identify all source code, documentation, algorithms and SAS programs for:

a. Attaining data to support CCW operations (see Task B3 – CCW Data Loads);

b. Processing and assigning the CCW beneficiary identifier to the CCW data;

c. Loading the CCW data;

d. Validating the CCW data;

e. Extracting the CCW data;

f. Maintaining the CCW workbench;

g. Providing direct user access via the VRDC (using virtual desktops);

h. Providing users with access to the CCW workbench;

i. Producing CCW Master Beneficiary Summary Files;

j. Producing the CCW Part D supplemental files;

k. Producing the CCW standard analytical files (claims files);

l. Producing the Geographic Variation Database (GVDB);

m. Producing the Medicare-Medicaid Linked Enrollee Analytic Data Source

(MMLEADS) file;

n. CCW Business Intelligence Reports;

o. CCW website;

p. Data request tracking system;

q. CCW Access Request System (for user access);

r. Change request history logs;

s. Extracting research identifiable files and data request process;

t. Limited Data Set files and processing/fulfilling data requests;

u. Public Use files and processing/fulfilling data requests.

Direct Connectivity to users of the CCW and VRDC:

1. Identify hardware and software needs for supporting direct connectivity to support up to 900 users, 475 concurrent, plus additional users in the future (taking into account user workspace and archival space needed for each user). This total does not include the number of CCW/VRDC contractor users that are needed for management and operations of the CCW/VRDC. The contractor shall determine the number of licenses needed for internal use and include this in the projections.

2. Identify the required connectivity and telecom components to support the existing users and future users.

The contractor shall work with the COR/GTL and the Office of Information Services to establish connectivity to the data warehouse and training locations.

Task A4 – Review and Comment on Transition Plan:

The incumbent contractor will provide CMS with a transition plan for transferring the existing data and equipment to the contractor. The contractor shall review the transition plan and be prepared to discuss any issues, questions or concerns regarding the proposed transition. The contractor shall participate in a workgroup comprised of CMS and incumbent contractor staff.

The purpose of this workgroup is to ensure the transition plan identifies all of the appropriate steps that need to occur to ensure that the CCW tasks and mission are transitioned in an orderly and timely manner by the new contractor. The contractor shall provide recommendations on improvements, if any, which could be made to ensure the transition occurs in a successful and timely manner.

Task A5 – Develop Data Preparation Plan:

The contractor shall develop a plan to:

1. Manage (after the initial load and validation) all necessary data needed to satisfy customer data extract requests and VRDC access;

2. Identify how the current identifiable data field encryption will be applied to future data requests;

3. Identify how data will be encrypted for transport to requestors. The contractor shall use encryption software which is compliant with CMS’ media transport encryption standards which are:

a. Encryption software must be FIPS 140-2 compliant

b. Encryption software must be a NIST validated encryption module

c. Encryption software must employ key management

d. Media must be encrypted prior to shipment

e. Media must be in tamper-proof packaging; trackable with receipt

4. Identify how the data extraction process will satisfy minimum necessary requirements. The contractor’s data extraction tool shall have the capability of excluding:

a. Individual data elements from Part D drug event data

b. Individual data elements from Patient Assessment data

c. Field level elements for the Part A and B claims data

5. Provide technical assistance to researchers to determine the appropriate source(s) of data needed and how to obtain the data to conduct their research analysis. This plan shall include provisions for coordinating with the Research Data Assistance Center (ResDAC). ResDAC is a CMS contractor that provides assistance to researchers in understanding how to use CMS data and how to request CMS data. They are the initial point of contact for researchers and provide them with information on what data are available and how they can obtain the data.

The contractor will work closely with ResDAC to ensure the data availability and data processing methods are clear so information relayed to researchers via ResDAC is accurate and consistent. The contractor shall use the existing specification worksheet which identifies the data files and data selection criteria. Modifications to the specification worksheet will require input from the contractor, ResDAC and approval from the COR/GTL.

6. Document the proposed steps involved with processing and fulfilling requests for CMS data starting with the receipt of the approved request from CMS to the shipment of data to the requestor. The document shall break down the proposed steps involved for each type of data request: VRDC access, custom research identifiable file data extract, standard research identifiable file extract, limited data set file extract and public use file extract.

Task A6 – Management Plan:

Develop a comprehensive management plan highlighting the steps that need to be accomplished in order to accomplish the CCW/VRDC tasks involved with, but not limited to, moving/testing/operating the CCW data center and operations, loading all current data files and transferring all user workspace into the new environment, processing pending data requests and storing/tracking historical data request documentation and archival files from the incumbent contractor to the newly awarded contractor facility. This management plan shall include:

• Staffing (key person/hours)

• Budget

• Schedule for moving/testing/operating the CCW/VRDC infrastructure (including all tasks and subtasks involved from receipt through implementation)

• Schedule for loading and having data and user workspace available to fulfill extracts/provide access to users (including all tasks and subtasks involved from receipt of data through implementation)

• Schedule and method of processing pending data requests and management of historical data requests and archived files

• Recommendation regarding the need to install additional telecommunication components.

Task A7 – Implement the Transition:

The contractor shall implement the transition according to the schedule and management plan prepared in prior tasks and provide daily updates to the COR/GTL via an updated project schedule document as well as conference calls. The total amount of downtime for users shall not exceed 72 hours. The contractor shall notify the COR/GTL of all risks that could impact the transition schedule and how those risks can be mitigated, as specified in Task A2. The contractor shall notify the COR/GTL of any issues or problems impacting the transition and provide corrective action plans for timely and efficient resolution. The contractor shall work with the incumbent contractor to clarify any questions, issues or problems that require resolution prior to moving to the operation and maintenance tasks.

Task A8 – Infrastructure Assessment Document:

The contractor shall perform an assessment of the overall infrastructure to ensure that the environment has been successfully transitioned and is operating without security and/or performance issues. The contractor shall use the measures defined in Task A3. The contractor shall provide the COR/GTL with a report containing, but not limited to, details of the following:

connectivity, bandwidth, processing capacity of the users, etc. The contractor shall track all help desk calls and issues reported by users and provide a detailed description to the COR/GTL. The COR/GTL reserves the right to modify the contents of this document if additional details are identified during the transition period.

IV.B. OPERATION AND MAINTENANCE TASKS:

Task B1 – Information Security:

The central tenet of the CMS Information Security (IS) Program is that all CMS information and information systems shall be protected from unauthorized access, disclosure, duplication, modification, diversion, destruction, loss, misuse, or theft—whether accidental or intentional.

The security safeguards to provide this protection shall be risk-based and business-driven with implementation achieved through a multi-layered security structure. All information access shall be limited based on a least-privilege approach and a need-to-know basis, i.e., authorized user access is only to information necessary in the performance of required tasks. Most of CMS' information relates to the health care provided to the nation’s Medicare and Medicaid beneficiaries, and as such, has access restrictions as required under legislative and regulatory mandates.

The CMS IS Program has a two-fold purpose:

(1) To enable CMS’ business processes to function in an environment with commensurate security protections, and

(2) To meet the security requirements of federal laws, regulations, and directives.

The principal legislation for the CMS IS Program is Public Law (P.L.) 107-347, Title III, Federal Information Security Management Act of 2002 (FISMA), http://csrc.nist.gov/drivers/documents/FISMA-final.pdf. FISMA places responsibility and accountability for IS at all levels within federal agencies as well as those entities acting on their behalf. FISMA directs Office of Management and Budget (OMB) through the Department of Commerce, National Institute of Standards and Technology (NIST), to establish the standards and guidelines for federal agencies in implementing FISMA and managing cost-effective programs to protect their information and information systems. As a contractor acting on behalf of CMS, this legislation requires that the Contractor shall:

• Establish senior management level responsibility for IS,

• Define key IS roles and responsibilities within their organization,

• Comply with a minimum set of controls established for protecting all Federal information, and

• Act in accordance with CMS reporting rules and procedures for IS.

Additionally, the following laws, regulations and directives and any revisions or replacements of same have IS implications and are applicable to all CMS contractors.

• P.L. 93-579, The Privacy Act of 1974P.L. 99-474, Computer Fraud & Abuse Act of 1986,

• P.L. 104-13, Paperwork Reduction Act of 1978, as amended in 1995, U.S. Code 44

Chapter 35,

• P.L. 104-208, Clinger-Cohen Act of 1996 (formerly known as the Information

Technology Management Reform Act),

• P.L. 104-191, Health Insurance Portability and Accountability Act of 1996 (formerly known as the Kennedy-Kassenbaum Act) http://aspe.hhs.gov/admnsimp/pl104191.htm;

• OMB Circular No. A-123, Management’s Responsibility for Internal Control, December

21, 2004, http://www.whitehouse.gov/omb/circulars/a123/a123_rev.html;

• OMB Circular A-130, Management of Federal Information Resources, Transmittal 4, November 30, 2000, http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html;

• NIST standards and guidance, http://csrc.nist.gov/; and,

• Department of Health and Human Services (DHHS) regulations, policies, standards and guidance http://www.hhs.gov/policies/index.html

These laws and regulations provide the structure for CMS to implement and manage a cost-effective IS program to protect its information and information systems. Therefore, the Contractor shall monitor and adhere to all IT policies, standards, procedures, directives, http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://aspe.hhs.gov/admnsimp/pl104191.htm http://www.whitehouse.gov/omb/circulars/a123/a123_rev.html http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html http://csrc.nist.gov/ http://www.hhs.gov/policies/index.html templates, and guidelines that govern the CMS IS Program, http://www.cms.hhs.gov/informationsecurity and the CMS System Lifecycle Framework, https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/XLC/index.html.

The Contractor shall comply with the CMS IS Program requirements by performing, but not limited to, the following:

• Implement their own IS program that adheres to CMS IS policies, standards, procedures, and guidelines, as well as industry best practices;

• Participate and fully cooperate with CMS IS audits, reviews, evaluations, tests, and assessments of contractor systems, processes, and facilities;

• Provide upon request results from any other audits, reviews, evaluations, tests and/or assessments that involve CMS information or information systems;

• Report and process corrective actions for all findings, regardless of the source, in accordance with CMS procedures;

• Document its compliance with CMS security requirements and maintain such documentation in the systems security profile;

• Prepare and submit in accordance with CMS procedures, an incident report to CMS of any suspected or confirmed incidents that may impact CMS information or information systems; and

• Participate in CMS IT information conferences as directed by CMS.

If the contractor believes that an updated IS-related requirement posted to the CMS website may result in a significant cost impact (e.g., over 3 percent of annual contract cost), the contractor may submit a request for equitable cost adjustment before implementing change.

The CCW/VRDC data warehouse will contain a large volume of Medicare and Medicaid enrollment, claims, assessment, quality, and provider data. The warehouse currently houses 315 billion records utilizing 800TB of space with the capability of expanding to 3 petabytes. The size of the data warehouse will continue to grow as additional data sources and years of data are loaded. Due to the size and sensitivity of the data, the contract needs to meet all CMS information security requirements. Within 60 days from contract award, the contractor shall be subject to an independent evaluation that they have fulfilled the necessary information security requirements listed below.

Task B1.1 – System Security Plan and Disaster Recovery Plan:

Security and the reliability of a secure CCW/VRDC IT system environment are of paramount importance to CMS. The CCW/VRDC Contractor will create and maintain a highly integrated development environment to support a unified security approach. The CCW/VRDC Contractor will provide CMS visibility into CCW/VRDC task operations and management to ensure close coordination and management of enterprise-level security threats. The CCW/VRDC Contractor will ensure the protection of private and confidential data on beneficiaries, providers, etc. as well as information and information systems categorized as National Critical Infrastructure, Health http://www.cms.hhs.gov/informationsecurity https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/XLC/index.html and Human Services Mission-Critical, and all other sensitive assets. The CCW/VRDC Contractor is obligated to meet federal and DHHS security and privacy requirements and standards. The CCW/VRDC Contractor shall meet CMS requirements for Certification and Accreditation (C&A). These C&A requirements include developing and maintaining a System Security Plan (SSP), Risk Assessment (RA) and Contingency Plan (CP) in accordance with CMS standards and guidelines. As part of the C&A process, the CCW/VRDC Contractor shall establish, maintain, and test a Disaster Recovery (DR) Plan where required based upon CMS’ business continuity guidelines.

The contractor shall establish appropriate administrative, technical, and physical safeguards to protect the confidentiality of the data and to prevent unauthorized use or access to the data. The safeguards shall provide a level and scope of security controls that conforms to the Office of Budget and Management Circular No. A-130, Appendix III—Security of Federal Automated information Systems (http://www.whitehouse.gov/omb/circulars/a130/a130.html), which sets forth guidelines for security plans for automated information systems in Federal agencies.”

The contractor shall draft and submit a SSP and DRP to the COR no later than 60 days from the start date of the Operation and Maintenance Base period of the contract. The SSP shall meet the requirements specified by CMS (identified above).

The contractor shall:

Permit CMS access to the CCW/VRDC facility, upon request, for review and inspection;

Report any loss or inappropriate disclosures of data to CMS immediately following the incident and cooperate fully with the federal security incident process;

Not use the CCW/VRDC data to gain a competitive advantage to bid on contracts or grants within CMS or any other Federal Agencies. The data cannot be used outside the CCW/VRDC scope without meeting all of CMS’ policies and data use requirements.

Additionally, the CMS COR/GTL must approve all uses of the data outside this project. The CCW/VRDC cannot advertise or market that they have CMS data available for use to other Federal Agencies, States, Universities or any other organization interested in obtaining CMS data.

Task B1.2 – FISMA (Risk Assessment and Independent Testing):

Due to the large volume of personally identifiable data that the CCW/VRDC will possess, the contractor must be FISMA compliant within 2 months of beginning the Operations and Maintenance tasks of the contract. The contractor shall provide an assurance that its security controls will conform to the Minimum Security Controls for Moderate – Impact Systems described in Appendix D and Appendix F of NIST Special Publication 800-53, Recommended Information Security Controls for Federal Information Systems. The contractor shall have its compliance with these controls (see Table A) independently tested and any findings identified as a result of the testing must be corrected before Medicare data are provided to the contractor.

Additionally, the contractor shall annually test its security controls to ensure ongoing compliance, and every three years, independently test the controls. An annual attestation of its compliance with these requirements shall be submitted. Documentation to support its compliance with the NIST/FISMA requirements shall be maintained along with the results of all http://www.whitehouse.gov/omb/circulars/a130/a130.html testing and corrective actions for vulnerabilities identified in the testing. Required documentation includes but is not limited to a system security plan (identified above), information security risk assessment and contingency plan.

Table A -- ST&E Services Task Controls

• ST&E Services Task Controls

Guidelines, Standards, and Templates

• CMS Framework https://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information-Technology/XLC/index.html

• DHHS EVM Procedures

• Federal Enterprise Architecture Consolidated Reference Model Version 2.0, June 2006,

• CMS Certification and Accreditation (C&A) Procedure

• CMS Business Partner System Security Manual http://www.cms.gov/Research-

Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library- Items/CMS1223332.html

• NIST Special Publication (SP) 800-55, Security Metrics Guide for Information Technology Systems

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems

• NIST SP 800-51, Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme

• NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems

• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems

• NIST SP 800-18, Guide for Developing Security Plans for Information Technology Systems

• Health Insurance Portability and Accountability Act (HIPAA) of 1996

• FIPS 200, Minimum Security Requirements for Federal Information and

Information Systems

• FIPS 199, Standards for Security Categorization of Federal Information and

Information Systems

• FIPS 191, Guideline for the Analysis of Local Area Network Security

• IEEE Std 829-1998, IEEE Standard for Software Test Documentation

Task B1.3 – Privacy Compliance:

All Contractors who access CMS data that are subject to the Privacy Act of 1974, as amended, 5 U.S.C. 552a (P.L. 93-579) shall sign and adhere to a CMS Data Use Agreement (DUA), which is available for downloading from the CMS website at: http://www.cms.hhs.gov/cmsforms/downloads/cms-r-0235.pdf. An executed DUA is a https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/XLC/index.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/XLC/index.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS1223332.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS1223332.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS1223332.html http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS1223332.html http://www.cms.hhs.gov/cmsforms/downloads/cms-r-0235.pdf prerequisite for any contractors that require access to such data. The CCW/VRDC Contractor shall be required to sign and adhere to a CMS DUA before any data are transmitted to the CCW/VRDC Contractor Site.

Task B2 – Infrastructure:

The contractor shall utilize the transitioned equipment and acquire additional equipment as stated in tasks A3, for the use and benefit of the government, to support the CCW/VRDC operations and maintenance. The infrastructure shall support the following:

a. Have sufficient capacity to house the current CCW/VRDC software and data files including pre-extracted SAS files;

b. Have a direct telecommunications connection from the CCW/VRDC environment to the CMS Data Center to access data files;

c. Have a direct telecommunications connection from the CCW/VRDC to allow CMS/CMMI users access to the CCW/VRDC data files;

d. Have a direct telecommunications connection from the CCW/VRDC environment to the training center(s);

e. Have the capability of saving data outputs on multiple media, including at a minimum, external hard drives, compact disks, and Digital Versatile Disks (DVDs);

f. Have the capability of selecting specific data elements from a file to comply with minimum necessary requirements. This will be required immediately to ensure data requestors only receive the data elements necessary to perform their analysis;

g. Have the capability of encrypting identifiable data using a software package that meets the following CMS standards:

i. Encryption software must be FIPS 140-2 compliant

ii. Encryption software must be a NIST validated encryption module

iii. Encryption software must employ key management

h. Enable queries of claims data based on the following:

i. Health Insurance Claim (HIC) account number and social security number finder files

ii. Health Care Common Procedure Codes (HCPCS), Diagnostic Related Groups (DRGs), and International Classification of Diseases-9 and 10 (ICD-9 and ICD-10) codes

iii. Beneficiary State and/or county of residence

iv. Health care provider and/or supplier number

i. Enable queries of enrollment data based on the following:

i. HIC and/or SSN finder files

ii. Beneficiary State and/or county of residence

iii. Enrollment date

iv. Medicare status code (Part A, Part B, Part D, End Stage Renal Disease, Hospice)

v. Beneficiary age

j. Be able to produce analytical files in SAS formats using CMS-approved conversion programs; and

k. Enable geo-coding for spatial mapping capability.

The COR/GTL reserve the right to make changes to these requirements, as needed, to support the activities of the CCW/VRDC users.

Task B2.1 – Ancillary Asset Management:

As an ancillary service to the procurement of equipment for the Government’s use and benefit, the Contractor will be responsible for the support, management, control and maintenance of systems software and hardware platforms. The contractor shall procure and maintain software licenses, including operating systems, subsystems, and system tools, to operate within its environment, and will manage any Government Furnished Property (GFP) software licenses.

The contractor shall procure, maintain and operate all hardware consistent with current recommendations from the Original Equipment Manufacturers (OEM).

Task B2.2 – Database Services:

The Database Services activities focus on the development of detailed logical and physical data models, database design, design of extraction, transformation and load design, data preparation design, and data interface design. Data models developed in this phase are very detailed and fully attributed; these data models define business rules, adhere to CMS data administration standards, and align with CMS EA data models.

Database Services also cover the physical implementation activities necessary to deploying a database on a specific database platform in the targeted environment. The activities include, but are not limited to, creation of the database; initial performance parameters and object allocation;

access control mechanisms (e.g., scripts implementing roles, privileges, and permissions);

database interfaces, input and output data feeds, and data preparation (e.g., data cleansing and data conversion); data extraction, transformation and load (ETL); and operational scripts and code supporting archival and backup.

The requirements are as follows:

1. The Contractor shall ensure that its products and artifacts are approved by the CMS COR/GTL. The Contractor shall be responsible for ensuring that the artifacts and products can be incorporated automatically and integrated into CMS processes and tools.

2. The Contractor shall adhere to guidance, standards, and templates as delineated in Table B. The Contractor shall reference the CMS Framework for the latest standards, guidance, and templates provided by CMS.

3. The Contractor shall produce the deliverables (artifacts) as defined in Table B unless otherwise directed. The list of deliverables may change due to one or more of the following:

A. CMS modifies the list of artifacts in the CMS Framework

B. Some artifacts may be deemed unnecessary or redundant with other controls in the context of a specific task order

C. Additional artifacts may be deemed necessary in the context of a specific task order

4. The Contractor shall ensure the quality of database products through formalized internal reviews and audits. The Contractor shall communicate the plan and schedule of these quality measures at project startup. Subsequently, the Contractor shall report to CMS as specified by the CMS Contracting Officer results of reviews and audits, including risks, issues, and plans to mitigate and/or rectify contributing factors.

5. The Contractor shall provide updates to existing documentation as changes are identified that affect the consistency and accuracy of existing documentation. This applies to, but is not limited to, the Business Process Model (BPM), Data Models, Data Dictionaries, Interface Control Documents (ICDs), Business Requirements, System Development Lifecycle (SDLC) artifacts, test artifacts, and operations and maintenance artifacts, as appropriate.

6. The Contractor is responsible for ensuring the quality of the database products, and is responsible for correcting defects in performance or function identified during development, test, and maintenance. The contractor shall provide replacement files, at no cost to users, when file errors have been identified.

Table B -- Database Services Task Controls

• Database Services Task Controls

Guidelines, Standards, and Templates

• CMS Framework (https://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information-Technology/XLC/index.html)

• Federal Enterprise Architecture Consolidated Reference Model Version 2.0, June 2006,

• CMS Data Administration: http://www.cms.hhs.gov/DataAdmin/

The Contractor shall define and create database views for common CMMI/contractor user queries run in the CCW/VRDC CMMI workspace.

Task B2.3 – Performance and Stress Testing:

1. The Contractor shall perform comprehensive performance and stress testing as specified in Table C. Comprehensive performance testing may vary given the type, size, and scope of the software/system product. Performance and stress testing shall include, as appropriate and directed, by the following:

A. Database volumes B. Transaction volumes C. Concurrent user logons D. Concurrent activities and load balancing E. Batch transaction volumes (daily and other cycles) F. Batch processing windows and dependencies (daily and other cycles) https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/XLC/index.html http://www.cms.hhs.gov/DataAdmin/

G. Response time expectations H. Network (public and private) load considerations I. System interfaces and printing J. Other performance tests appropriate to the type, scope, and size of the software/system product.

2. The Contractor shall modify system and software products to rectify performance deficiencies identified during testing new development or major enhancements.

3. The Contractor shall perform security self-assessments, fix code, and correct procedures based upon defects found.

4. The Contractor shall coordinate updates to existing work products and work products created within this Performance and Stress Test Services task with CMS.

Table C -- Performance and Stress Test Services Task Controls.

Task B2.4 – Software Management and Maintenance:

The contractor will be responsible for the management and maintenance of all CCW/VRDC software. The software shall be compatible with and support CMS required processing. The contractor will obtain and manage software licenses and will monitor and audit all software licenses to determine license expiration. The contractor shall renew said licenses to avoid service impacts or unavailability.

The contractor will manage all software license maintenance agreements to ensure concurrency of required software and installation of new versions, releases, fixes or enhancements. The contractor will determine any impacts or risks (e.g., the impact that one software product’s version level or release may have on any other software products residing on the system). The contractor will also document these impacts and risks and present them to the Government with recommendations and proposed actions (with timelines for completion of the approved actions).

The contractor will establish a standard window for scheduled downtime to perform software maintenance. When maintenance is required, the contractor will coordinate with the Government to evaluate the requirement and its impact on the business and mutually agree on the best schedule to perform those activities.

The contractor will maintain all system and subsystem software, database, system tools and third-party software at one release version less than the most current release level (no greater than N-1) unless authorized by the Government. System software and all COTS software will be maintained at levels supported by the software vendor. If maintenance service is withdrawn

• Performance and Stress Test Services Task Controls Guidelines, Standards, and Templates

• CMS Framework ( https://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information-Technology/XLC/index.html)

• Federal Enterprise Architecture Consolidated Reference Model Version 2.0, June 2006 from a product by the software vendor, the contractor will assess and recommend a suitable upgrade or replacement for consideration in advance of the service end-of-life date. The contractor will work with the Government to communicate the effect and impact of the system software changes.

Core software to be provided within the VRDC environment shall contain but are not limited to the following:

• MS Office Suite

• Juniper SSL VPN

• VMware View

• Universal Content Management

• OBIEE

• SAS 9.3, SAS Enterprise Guide, Enterprise Miner and Base

• TIBCO MFT

• WinZip

• Adobe Reader

• STATA

The COR/GTL reserve the right to include additional software to support future needs of the VRDC users.

Task B2.5 – Hardware Management and Maintenance:

The contractor shall procure, manage, maintain and operate all hardware in the CCW/VRDC environment, consistent with current recommendations from OEMs.

The contractor will replace or upgrade the hardware if there is a business need for additional capacity or improved performance. The contractor will provide hardware installation and implementation services, including all required facility infrastructure changes to support these activities within a timeframe agreed to by both the contractor and the COR.

The contractor will identify hardware operation issues and provide effective hardware maintenance, including routine, preventative and corrective maintenance as recommended by the OEM. The contractor will prevent or minimize failures or risk of failure of the hardware and peripheral devices, including computer equipment, peripheral devices, front-end processors, communication controllers, and any related system or network equipment.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .