SECTION_H_Amend_01.pdf

PDF 116 KB Posted

Attached to
Research, Measurement, Assessment, Design, and Analysis (RMADA) IDIQ Federal contract opportunity
Solicitation number
RFP-CMS-RMADA-2014
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

Section H- Amendment

View the file

Other files for this federal contract opportunity

Other files attached to Research, Measurement, Assessment, Design, and Analysis (RMADA) IDIQ, newest first.
File Type Posted
Contractor_ _Contract__s.xlsx XLSX spreadsheet
Amendment_05.pdf PDF
SECTION_M_Amend_05.pdf PDF
SECTION_L_Amend_05.pdf PDF
SECTION_M_Amend_04.pdf PDF
Amendment_04.pdf PDF
SECTION_L_Amend_04.pdf PDF
SECTION_L_Amend_03.pdf PDF
RFP-CMS-RMADA-2014-_Questions_ _Answers_Amend_03.pdf PDF
RFP-CMS-RMADA-2014-_Questions_ _Answers_Amend_02.pdf PDF
SECTION_L_Amend_01.pdf PDF
SECTION_B_Amend_01.pdf PDF
SECTION_G_Amend_01.pdf PDF
RFP-CMS-RMADA-2014-Question_ _Answers.pdf PDF
SECTION_I_Amend_01.pdf PDF
SECTION_J_Amend_01.pdf PDF
SECTION_M_Amend_01.pdf PDF
Attachment_J.8_-_Priority_Measures.pdf PDF
RFP-CMS-RMADA-2014.pdf PDF
SECTION_J.pdf PDF
SECTION_L.pdf PDF
SECTION_H.pdf PDF
SECTION_I.pdf PDF
SECTION_K.pdf PDF
Attachment_J.5-Consent_to_Subcontract.pdf PDF
Attachment_J.4-Question_Submission_Template.pdf PDF
Attachment_J.3-Past_Performance_Questionnaire.pdf PDF
SECTION_G.pdf PDF
Attachment_J.2-Sample_Task_Order-SOW_ _SOD.pdf PDF
SECTION_E.pdf PDF
SECTION_M.pdf PDF
SECTION_D.pdf PDF
SECTION_C.pdf PDF
Attachment_J.1-_Incident_Reporting_Guide.pdf PDF
Attachment_J.6-_Small_Business_Subcontracting_Plan.pdf PDF
SECTION_B.pdf PDF
SECTION_F.pdf PDF
Attachment_J.7-_General_Questions_Draft_RFP.pdf PDF
Draft_RFP_081413.docx DOCX document
Ltr_081413.docx DOCX document
Show all 40

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP-CMS-RMADA-2014

Amendment_01

SECTION H – SPECIAL CONTRACT REQUIREMENTS

H.1 FAR 52.252-1 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:

http://www.arnet.gov/far/

H.2 CMS CODE OF CONDUCT

A. Smoking

Effective June 9, 2004, smoking is not permitted anywhere on the CMS single site campus. This includes all areas outside the building, such as off-site facility, entranceways, sidewalks and parking areas. Smoking will not be permitted anywhere in Regional Offices or Washington, D.C. Office locations unless permitted by GSA guidelines or local landlord requirements. Contractor employees are subject to the same restrictions as government personnel. Fines up to $50 per occurrence will be issued and enforced by the Federal Protective Service.

B. Dress

The preferred dress codes at CMS facilities are professional attire, business attire or business casual attire.

C. EEO Agency Policies

The contractor shall be held accountable to all standards of conduct defined in the Agency’s EEO policies as made available on the CMS website http://www.cms.gov/About-CMS/Agency-Information/EEOInfo/index.html.

D. Social Media

The following guidance refers to Facebook, Twitter, LinkedIn, Tumblr, MySpace, or any other form of social media or blogs.

As a representative of the Government while performing the work described within the stated contract or any task order as a result of the contract, the contractor, using his or her official contracted title or acting within the scope of the stated contracted title shall not participate in any aspects of the identified contracted work or results that this work created/posted on any social media platform unless directed by the Government.

Violating this directive will result in removal of that individual from the contract or task order.

http://www.arnet.gov/far/ http://www.cms.gov/About-CMS/Agency-Information/EEOInfo/index.html

H.3 RESTRICTIONS AGAINST DISCLOSURE

(a) The Contractor agrees to keep all information it gathers or analyzes or information the Government in the course of this contract/task order/delivery order furnishes in the strictest confidence. The Contractor also agrees that Government-provided information marked "For Official Use Only," "Confidential", or "Proprietary" must also be similarly protected and shall take all reasonable measures necessary to prohibit access to such information by any such person other than those Contractor employees needing such information to perform the work, i.e., on a need-to-know basis.

(b) The Contractor shall immediately notify the Contracting Officer in writing in the event it has been determined or the Contractor has reason to suspect a breach of this requirement.

(c) The Contractor shall require that all employees and consultants who are given access to such information sign a confidentiality and nondisclosure statement agreeing to safeguard the confidentiality of all such information gathered or provided to them hereunder as an integral condition of their employment.

(d) Upon the Government's written request, the Contractor shall provide the Contracting Officer with plans and procedures to ensure the confidentiality and physical security of information gathered or provided hereunder.

(e) The Contractor may "gather and analyze" information that is not furnished or owned by the Government. Such information shall not be subject to the restrictions in this clause.

H.4 ORGANIZATIONAL CONFLICTS OF INTEREST (OCI)

The information and direction provided in this section apply to the RMADA Prime and all-tier subcontractors. Information contained in this section complies with FAR 9.5 and may be considered in both pre-and post award Contracting Officer determinations.

The primary purpose of this is to aid in ensuring that the Contractor (1) does not have any unfair competitive advantage over other parties in the competition for this contract, and (2) is not biased because of its current or planned interest (financial, organizational, or otherwise) which relate to the work under this contract.

The restrictions described herein shall apply to performance or participation by the Contractor and any of its affiliate organizations or their successors in interest (hereinafter collectively referred to as the "Contractor") in the activities covered by this clause as a prime Contractor, subcontractor, co-sponsor, joint venture, consultant, or in any similar capacity.

Advisory, consulting, analytical, evaluation, or study work, including the preparation of statements of work and specifications:

(i) If the Contractor performs advisory, consulting, analytical, evaluation, study, or similar work under this contract, it shall be ineligible thereafter to participate in any capacity in Government contractual efforts (solicited or unsolicited) which stem directly from such work, and the Contractor agrees not to perform similar work for prospective offerors with respect to any such contractual efforts.

Furthermore, unless so directed in writing by the Contracting Officer, the Contractor shall not perform any such work under this contract on any of its products or services, or the products or services of another firm for which the Contractor performs similar work.

Nothing in this subparagraph shall preclude the Contractor from competing for HHS management and technical support services follow-on contracts.

(ii) If the Contractor under this contract assists substantially in the preparation of a Statement of Objectives or specifications, the Contractor shall be ineligible to perform or participate in any capacity in any contractual effort which is based on such Statement of Objectives or specifications. The Contractor shall not incorporate its products or services in such Statement of Objectives or specifications unless so directed in writing by the Contracting Officer, in which case the restriction in this subparagraph shall not apply.

Access to the use of information:

(i) If the Contractor in the performance of this contract obtains access to information, such as HHS plans, policies, reports, studies, financial plans, or data which has not been released to the public, the Contractor agrees not to (a) use such information for any private purpose unless the information has been released to the public; (b) disclose such information for a period of six (6) months after the completion of this contract, or the release of such information to the public, whichever is first; (c) submit an unsolicited proposal to the Government which is based on such information until one (1) year after the release of such information to the public; or (d) release such information without prior written approval by the Contracting Officer.

(ii) In addition, the Contractor agrees that to the extent it receives or is given access to proprietary data or other confidential technical, business or financial information under this contract, it shall treat such information in accordance with any restrictions imposed on such information.

(iii) The Contractor shall have, subject to patent and security provisions of this contract, the right to use technical data it first produces under this contract for its private purposes provided that, as of the date of such use, all data requirements of this contract have been met.

Subcontracts. The Contractor shall include this clause, including this paragraph, in subcontracts of any tier. The use of this clause in such subcontracts shall be read by substituting the word "Subcontractor" for the word "Contractor" whenever the word "Contractor" appears.

Remedies: For breach of the above restrictions or for non-disclosure or misrepresentation of any relevant interest required to be disclosed concerning this contract, the Government may, at no cost, terminate the contract, disqualify the Contractor for subsequent related contractual efforts, and pursue other remedies as may be permitted by law or this contract.

Waiver. Any request for waiver under this clause shall be directed in writing to the Contracting Officer and shall include a full description of the requested waiver and the reasons in support thereof. If it is determined to be in the best interest of the

Government, the government shall grant such waiver in writing.

Definitions. The term "management and technical support services" includes any advice, assistance, analysis, consultation, evaluation, examination, report, review, study, survey, or similar assistance, including providing assistance in procurement and related activities, to support any program or their operations of CMS.

It is the responsibility of the RMADA contractor, at any time during the life of the contract, to identify if there is a perceived or real conflict of interest based upon the work under a particular task order, the umbrella contract and other work of the prime or subcontractors outside of this contract. With the reporting, the RMADA contractor must provide a mitigation plan subject to the Contracting Officer’s approval.

H.5 CONTRACTOR TERMINATION CMS BUILDING PASS

In the event that the contractor terminates an employee working on this contract, or an employee working on this contract voluntarily leaves the employment of the contractor and that employee has been issued a contractor’s badge by CMS for access to CMS Buildings; The contractor shall immediately take the following actions:

- Secure the CMS contractor’s badge from the employee;

- Formally advise the contracting officer that the individual is no longer an employee of the contractor, and;

- Return the badge with the notification to the contracting officer.

H.6 SECURITY CLAUSE-BACKGROUND-INVESTIGATIONS FOR CONTRACTOR

PERSONNEL

A. If applicable, Contractor personnel performing services for CMS under this contract, task order or delivery order shall be required to undergo a background investigation. CMS will pay for the background investigations.

B. After contract award, the CMS COR and the Emergency Management &

Response Group (EMRG), with the assistance of the Contractor, shall perform a position-sensitivity analysis based on the duties contractor personnel shall perform on the contract, task order or delivery order. The results of the position-sensitivity analysis will determine first, whether the provisions of this clause are applicable to the contract and second, if applicable, determine each position’s sensitivity level (i.e., high risk, moderate risk or low risk) and dictate the appropriate level of background investigation to be processed. Investigative packages may contain the following forms:

1. SF-85, Questionnaire for Non-Sensitive Positions, 09/1995

2. SF-85P, Questionnaire for Public Trust Positions, 09/1995

3. OF-612, Optional Application for Federal Employment, 12/2002

4. OF-306, Declaration for Federal Employment, 01/2001

5. Credit Report Release Form

6. FD-258, Fingerprint Card, 5/99, and http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=FC83C171AE71F90585256A730051C8AB http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=25292D2D26D8B5EC85256A730051F924 http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=41A93F1A1771761B85256A720061344C http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=047C39FC0226D01E85256AAB005DF2AD http://www.opm.gov/extra/investigate/Fin-1998/fin9802.asp http://www.fbi.gov/hq/cjisd/PDF/fpcardb.pdf

7. CMS-730A, Request for Physical Access to CMS Facilities (NON-CMS

ONLY), 11/2003.

C. The Contractor personnel shall be required to undergo a background investigation commensurate with one of these position-sensitivity levels:

(i) High Risk (Level 6)

Public Trust positions that would have a potential for exceptionally serious impact on the integrity and efficiency of the service. This would include computer security of a major automated information system (AIS). This includes positions in which the incumbent’s actions or inaction could diminish public confidence in the integrity, efficiency, or effectiveness of assigned government activities, whether or not actual damage occurs, particularly if duties are especially critical to the agency or program mission with a broad scope of responsibility and authority.

Major responsibilities that would require this level include:

a. development and administration of CMS computer security programs, including direction and control of risk analysis and/or threat assessment;

b. significant involvement in mission-critical systems;

c. preparation or approval of data for input into a system which does not necessarily involve personal access to the system but with relatively high risk of causing grave damage or realizing significant personal gain;

d. other responsibilities that involve relatively high risk of causing damage or realizing personal gain;

e. policy implementation;

f. higher level management duties/assignments or major program responsibility;

or

g. independent spokespersons or non-management position with authority for independent action.

Approximate cost of each investigation: $3,500

(ii) Moderate Risk (Level 5)

Public Trust positions that have potential for moderate to serious impact on the integrity and efficiency of the service, including computer security. These positions involve duties of considerable importance to the CMS mission with significant program responsibilities that could cause damage to large portions of AIS. Duties involved are considerably important to the agency or program mission with significant program responsibility, or delivery of service.

Responsibilities that would require this level include:

a. the direction, planning, design, operation, or maintenance of a computer system and whose work is technically reviewed by a higher authority at the High Risk level to ensure the integrity of the system;

b. systems design, operation, testing, maintenance, and/or monitoring that are carried out under the technical review of a higher authority at the High Risk level;

http://cmsnet.cms.hhs.gov/hpages/oics/formsloc/cms730af.pdf

c. access to and/or processing of information requiring protection under the Privacy Act of 1974;

d. assists in policy development and implementation;

e. mid-level management duties/assignments;

f. any position with responsibility for independent or semi-independent action;

or

g. delivery of service positions that demand public confidence or trust.

Approximate cost range of each investigation: $150 - $2,600

(iii) Low Risk (Level 1)

Positions having the potential for limited interaction with the agency or program mission, so the potential for impact on the integrity and efficiency of the service is small. This includes computer security impact on AIS.

Approximate cost of each investigation: $100

D. The Contractor shall submit the investigative package(s) to the EMRG within three (3) days after being advised by the EMRG of the need to submit packages.

Investigative packages shall be submitted to the following address:

Centers for Medicare & Medicaid Services Office of Operations Management Emergency Management & Response Group Mail Stop SL-13-15 7500 Security Boulevard Baltimore, Maryland 21244-1850

E. The Contractor shall submit a copy of the transmittal letter to the Contracting

Officer (CO).

F. Contractor personnel shall submit a CMS-730A (Request for Badge) to the

EMRG. The Contractor and the COR shall obtain all necessary signatures on the CMS-730A prior to any Contractor employee arriving for fingerprinting and badge processing.

G. The Contractor must appoint a Security Investigation Liaison as a point of contact to resolve any issues of inaccurate or incomplete form(s). Where personal information is involved, EMRG may need to contact the contractor employee directly. The Security Investigation Liaison may be required to facilitate such contact.

H. After EMRG fingerprints contractor personnel and issues them a temporary CMS identification badge, the EMRG will send their completed investigative package to the Office of Personnel Management (OPM). OPM will conduct the background investigation. Badges will be provided by EMRG while contractor personnel investigative forms are being processed. The Contractor remains fully responsible for ensuring contract, task order or delivery order performance pending completion of background investigations of contractor personnel.

I. EMRG shall provide written notification to the CO with a copy to the COR of all suitability decisions. The shall then notify the Contractor in writing of the approval of the Contractor’s employee(s), at that time the Contractor’s employee(s) will receive a permanent identification badge. Contractor personnel who the EMRG determines to be ineligible may be required to cease working on the contract immediately.

J. The Contractor shall report immediately in writing to EMRG with copies to the CO and the COR, any adverse information regarding any of its employees that may impact their ability to perform under this contract, task order or delivery order.

Reports should be based on reliable and substantiated information, not on rumor or innuendo. The report shall include the contractor employee’s name and social security number, along with the adverse information being reported.

K. Contractor personnel shall be provided an opportunity to explain or refute unfavorable information found in an investigation to EMRG before an adverse adjudication is made. Contractor personnel may request, in writing, a copy of their own investigative results by contacting:

Office of Personnel Management Freedom of Information Federal Investigations Processing Center PO Box 618 Boyers, PA 16018-0618.

L. At the Agency’s discretion, if an investigated contractor employee leaves the employment of the contractor, or otherwise is no longer associated with the contract, task order, or delivery order within one (1) year from the date the background investigation was completed, then the Contractor may be required to reimburse CMS for the full cost of the investigation. Depending upon the type of background investigation conducted, the cost could be approximately $100 to $3,500. The amount to be paid by the Contractor shall be due and payable when the CO submits a written letter notifying the Contractor as to the cost of the investigation. The Contractor shall pay the amount due within thirty (30) days of the date of the CO’s letter by check made payable to the “United States Treasury.” The Contractor shall provide a copy of the CO’s letter as an attachment to the check and submit both to the Office of Financial Management at the following address:

PO Box 7520 Baltimore, Maryland 21207

M. The Contractor must immediately provide written notification to EMRG (with copies to the CO and the COR) of all terminations or resignations of Contractor personnel working on this contract, task order or delivery order. The Contractor must also notify EMRG (with copies to the CO and the COR) when a Contractor’s employee is no longer working on this contract, task order or delivery order.

N. At the conclusion of the contract, task order or delivery order and at the time when a contractor employee is no longer working on the contract, task order or delivery order due to termination or resignation, all CMS-issued parking permits, identification badges, access cards, and/or keys must be promptly returned to EMRG. Contractor personnel who do not return their government-issued parking permits, identification badges, access cards, and/or keys within 48 hours of the last day of authorized access shall be permanently barred from the CMS complex and subject to fines and penalties authorized by applicable federal and State laws.

H.7 WORK PERFORMED OUTSIDE THE CONTINENTAL UNITED STATES AND ITS

TERRITORIES (OCONUS)

The contractor, and its subcontractors, shall not perform any activities under this contract at a location OCONUS (outside the continental United States), including the transmission of data or other information OCONUS, without the prior written approval of the Contracting Officer. The factors that the Contracting Officer will consider in making a decision to authorize the performance of work OCONUS include, but are not limited to the following:

- All contract terms regarding system security;

- All contract terms regarding the confidentiality and privacy requirements for information and data protection;

- All contract terms that are otherwise relevant, including the provisions of the Statement of Objectives and what is defined in the technical requirements of a particular task order;

- All laws and regulations applicable to the performance of work OCONUS;

- Concurrence from the CMS SEMG Director or designee; and,

- The best interest of the Government.

In requesting the Contracting Officer’s authorization to perform work OCONUS, the contractor must demonstrate that the performance of the work satisfies all of the above factors. If, in the Contracting Officer’s judgment, the above factors are not fully satisfied, the performance of work OCONUS will not be authorized.

H.8 ADP SYSTEMS SECURITY REQUIREMENTS

In the performance of this contract, the Contractor agrees to comply with the ADP systems security requirements of the Office of Management and Budget (OMB) Circular A-130, "Management of Federal Information Resources", and with the ADP systems security policy of DHHS as outlined in Part 6 of the HHS ADP Systems Manual and in CMS's AIS Guide. The Contractor shall include this requirement in any subcontract awarded under this prime contract

H.9 352.201-70 Paperwork Reduction Act (January 2006)

In the event that it becomes a requirement to collect information under this order, OMB

Forms clearance shall be required pursuant to the Paperwork Reduction Act (see 5 CTR, Part 1320). The Contractor is hereby advised not to expend any funds or take any other action to solicit information until the Contracting Officer has notified the Contractor in writing that the required OMB clearance has been obtained. The Contractor shall provide to the COR such information as will facilitate obtaining such clearance.

H.10 HHSAR 352.224-70 PRIVACY ACT (JAN 2006)

This contract requires the Contractor to perform one or more of the following:

(a) design; (b) develop; or (c) operate a federal agency system of records to accomplish an agency function in accordance with the Privacy Act of 1974 (Act) [5 U.S.C. 552a(m)(1)] and applicable agency regulations. The term “system of records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual. Violations of the Act by the Contractor and/or its employees may result in the imposition of criminal penalties [5 U.S.C. 552a(i)]. The Contractor shall ensure that each of its employees knows the prescribed rules of conduct and that each employee is aware that he/she is subject to criminal penalties for violation of the Act to the same extent as Department of Health and Human Services employees. These provisions also apply to all subcontracts the Contractor awards under this contract which require the design, development or operation of the designated system(s) of records [5 U.S.C. 552a(m)(1)]. The contract work statement: (a) identifies the system(s) of records and the design, development, or operation work the Contractor is to perform; and (b) specifies the disposition to be made of such records upon completion of contract performance.

H.11 HIPPA BUSINESS ASSOCIATE CLAUSE (SEPT 2013)

All Protected Health Information (PHI), as defined in 45 C.F.R. §160.103, that is relevant to this Contract, shall be administered in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA," 42 U.S.C. § 1320d), as amended, as well as the corresponding implementing regulations and this HIPAA Business Associate Clause.

A. Definitions:

All terms used herein and not otherwise defined, shall have the same meaning as in HIPAA, as amended, and the corresponding implementing regulations. Non-HIPAA related provisions governing the Contractor's duties and obligations, such as those under the Privacy Act and any applicable data use agreements, are generally covered elsewhere in the Contract.

The following definitions apply to this Contract Clause:

"Business Associate'' shall mean the Contractor (and/or the Contractor’s subcontractors or agents) if/when it uses individually identifiable health information on behalf of CMS, i.e. PHI, to carry out CMS’ HIPAA-covered functions.

"Covered Entity" shall mean the portions of CMS that are subject to the HIPAA Privacy Rule.

http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a

"Secretary" shall mean the Secretary of the Department of Health & Human Services or the Secretary's designee.

B. Obligations and Activities of Business Associate:

Except as otherwise provided in this Contract, Business Associate, as defined above, shall only use or disclose PHI on behalf of, or to provide services to, Covered Entity in accordance with this Contract and the HIPAA Privacy and Security Rules.

Business Associate shall document in writing the policies and procedures that will be used to meet HIPAA requirements. The policies and procedures shall include the following, at a minimum:

1. Business Associate shall not:

a. Use or disclose PHI that is created, received, maintained or transmitted by Business Associate from, or on behalf of, Covered Entity other than as permitted or required by this Contract or as required by law;

b. Sell PHI; or,

c. Threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual for:

i. Filing a complaint under 45 CFR § 160.306;

ii. Testifying, assisting or participating in an investigation, compliance review, proceeding or hearing under 45 CFR Part 160;

or

iii. Opposing any act or practice that is unlawful under HIPAA, provided there is a good faith belief that the practice is unlawful, the manner of opposition is reasonable, and the opposition does not involve the disclosure of PHI in violation of subpart E of Part 164.

2. Business Associate shall:

a. Have a security official who will be responsible for development and implementation of its security policies and procedures, including workforce security measures, to ensure proper security awareness and training (including security incident response and reporting), and security incident procedures, in accordance with this Contract, including this HIPAA Business Associate Clause and the Contract’s clause entitled “CMS Information Security.”

b. Use administrative, physical and technical safeguards to prevent use or disclosure of PHI created, received, maintained or transmitted by Business Associate from, or on behalf of Covered Entity only as provided for by this Contract. In doing so, it shall implement policies and procedures to address the following and, where applicable, ensure that such policies and procedures are also in conformance with this Contract’s clause entitled “CMS Information Security:”

i. Prevent, detect, contain and correct security violations through the use of:

1. Risk analyses (including periodic technical and nontechnical evaluations);

2. Appropriate risk management strategies, including system activity review;

3. Information access procedures for approving individual’s access rights to PHI (including the implementation of workforce security measures to ensure continued appropriate role-based access to PHI), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and tracking of users) and;

4. The imposition of sanctions for violations.

ii. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.

iii. Implement policies, procedures and physical security measures that will limit access to PHI through workstations and other devices, including access through mobile devices.

Implement media controls covering the movement of devices containing PHI within or outside of the Business Associate’s facility as well as the disposal and reuse of media containing PHI.

iv. Implement appropriate administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability (including the use of contingency plans) of any electronic protected health information ("EPHI") it creates, receives, maintains or transmits from, or on behalf of the Covered Entity to prevent impermissible use, disclosure, maintenance or transmission of such EPHI. In the establishment of such safeguards, Business Associate shall consider its size, complexity and capabilities, as well as its technical infrastructure, and its hardware and software security capabilities.

c. Assess, and implement, where appropriate, any addressable implementation specifications associated with applicable PHI security standards.

d. Mitigate, to the extent practicable, any harmful effect that is known to

Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Contract.

e. Comply with the following Incident Reporting:

(a) Report to Covered Entity any security incident/breach involving unsecured PHI, of which it becomes aware, including those of its agents and subcontractors. The Business Associate shall report any violation of the terms of this contract involving PHI and any security incidents/breaches involving unsecured PHI to CMS within one (1) hour of discovery in accordance with the CMS Information Security Requirements, Section 1.2.2.3, Incident Response, which can be found at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS- Information-Technology/InformationSecurity/Info-Security-Library- Items/CMS-Information-Security-Contract-Clause-Provision.html. In addition, the Business Associate will also notify the CMS Contracting Officer and the Contracting Officer’s Representative (COR) by email within one (1) hour of identifying such violation or incident.

(b) Upon Covered Entity's knowledge of any material security incident/breach by Business Associate, Covered Entity will provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination clause of this Contract. See also paragraph D. Term of Clause below.

f. Ensure that any agent or subcontractor agrees through a written contract, or other legally enforceable arrangement, to the same restrictions and conditions that apply through this HIPAA Contract Clause, when creating, receiving, maintaining or transmitting PHI from, or on behalf of, Covered Entity.

g. Upon Covered Entity’s request:

i. Provide the Covered Entity or its designee with access to the PHI created, received, maintained or transmitted by Business Associate from or on behalf of the Covered Entity in the course of contract performance in order to ensure Covered Entity’s ability to meet the requirements under 45 CFR § 164.524.

ii. Amend PHI as Covered Entity directs or agrees to pursuant to 45

CFR §

164.526.

h. Make its facilities and any books, records, accounts, and any sources of

PHI, including any policies and procedures, that are pertinent to ascertaining its own compliance with this contract or the Covered Entity’s compliance with the applicable HIPAA requirements, available to Covered Entity, or, in the context of an investigation or compliance review, to the Secretary for purposes of the Secretary determining Covered Entity's compliance with the various rules implementing the HIPAA.

i. Document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html

CFR § 164.528.

j. Provide to Covered Entity, or an individual identified by the Covered Entity, information collected under this Contract, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

k. Make reasonable efforts to limit the PHI it uses, discloses or requests to the minimum necessary to accomplish the intended purpose of the permitted use, disclosure or request.

C. Obligations of Covered Entity

Covered Entity shall notify Business Associate of any:

1. Limitation(s) in its Notice of Privacy Practices in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI;

2. Changes in, or revocation of, permission by an Individual to use or disclose their PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI; and,

3. Restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

D. Term of Clause

1. The term of this Clause shall be effective as of date of Contract award, and shall terminate when all of the PHI provided to Business Associate by the Covered Entity or a Business Associate of the Covered Entity, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity in accordance with “CMS Information Security” procedures. Business Associate shall not retain any PHI.

2. Security Incident/Breach:

Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall take action consistent with the terms of this Contract, and, as appropriate, the following:

a) Federal Acquisition Regulation (FAR) Contracts – Covered Entity may:

i. Terminate this Contract in accordance with FAR Part 49, Termination of Contracts, if the Business Associate does not cure the security incident/breach within the time specified by Covered Entity and/or cure is not possible; or,

ii. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

b) Other Agreements –Covered Entity shall either:

i. Provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination terms of this Contract.

Covered Entity may terminate this Contract for default if the Business Associate does not cure the breach or end the violation within the time specified by Covered Entity; or,

ii. Consistent with the terms of this Contract, terminate this Contract for default if Business Associate has breached a material term of this Contract and cure is not possible; or,

iii. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

3. Returning or Destroying PHI:

Business Associate, as defined above, which includes subcontractors or agents of the Contractor, shall:

a) Upon expiration or termination of this Contract, for any reason, return or destroy all PHI received from Covered Entity or another Business Associate of the Covered Entity, as well as any PHI created, received, maintained or transmitted from or on behalf of Covered Entity, or another Business Associate of the Covered Entity, in accordance with this contract, including the “CMS Information Security” clause.

b) In the event that Business Associate determines that returning or destroying the PHI is infeasible, provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon such notice that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.

E. Miscellaneous

1. A reference in this Contract to a section in the Rules issued under HIPAA means the section as in effect or as amended.

2. The respective rights and obligations of Business Associate under paragraph D.3.b of the section entitled "Term of Clause" shall survive the termination of this Contract.

3. Any ambiguity in this Contract clause shall be resolved to permit Covered Entity to comply with the Rules implemented under HIPAA.

H.12 CMS INFORMATION SECURITY (APR 2013)

All CMS information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, in order to maintain the security, confidentiality, integrity, and availability of such information. Therefore, if this contract requires the Contractor to provide services (both commercial and non-commercial) for Federal Information/Data, to include any of the following requirements:

• Process any Information/Data; or

• Store any Information/Data (includes “Cloud” computing services); or

• Facilitate the transport of Information/Data; or

• Host/maintain Information/Data (including software and/or infrastructure developer/maintainers); or

• Have access to, or use of, Personally Identifiable Information (PII), including instances of remote access to, or physical removal of, such information beyond agency premises or control, the Contractor shall become and remain compliant with the requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics- Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS- Information-Security-Contract-Clause-Provision.html. The requirements cover all CMS contracts and associated deliverables, which are required on a “per Contractor” basis.

The Contractor shall ensure that the following Federal information security standards are met for all of its CMS contracts:

• Federal Information Security Management Act (FISMA) – FISMA information can be found at http://csrc.nist.gov/groups/SMA/fisma/index.html. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source; and,

• Federal Risk and Authorization Management Program (FedRAMP) – FedRAMP information can be found at http://www.gsa.gov/portal/category/102371. The FedRAMP is a Government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

The Contractor shall include in all awarded subcontracts the FISMA/FedRAMP compliance requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security- Contract-Clause-Provision.html.

https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html

H.13 OPEN GOVERNMENT PROACTIVE PRE-DISCLOSURE NOTIFICATION

In order to reduce the administrative burden of responding to FOIA requests for high visibility/high public interest contracts throughout contract administration, the Contractor shall submit its review of the awarded contract (and contract modifications, if requested) for FOIA disclosure exemptions within 30 days of contract award. The review will substantiate “…Trade secrets and commercial or financial information obtained from a person and privileged or confidential…” information in accordance with 5 U.S.C. §552 FOIA, Exemption (b)(4), which could reasonably be expected to cause substantial competitive harm.

Submissions: The Contractor shall submit one (1) Compact Disc (CD) or Digital Video Disc (DVD) with all 5 U.S.C. §552 FOIA, Exemption (b)(4), “…Trade Secrets, Commercial or Financial Information Which is Privileged or Confidential…,” otherwise known as public release/non-Confidential Business Information (non-CBI), with the information identified as follows:

a) CBI Highlighted Copy of Contract: One copy of the contract with all CBI highlighted for CMS FOIA review.

b) Contractor Proposed Redacted Public Release Copy of Contract: An additional copy of the contract will be provided for public release with all the identified information redacted. Redactions shall be made using “black” boxes, which cannot be removed or uncovered by a reader.

c) Pre-Disclosure Concerns - Comments/Rationale for Non-Disclosure of Trade

Secrets, Commercial or Financial Information Which is Privileged or Confidential:

The Contractor shall provide, in a separate file, rationale for why disclosure of “…Trade Secrets, Commercial or Financial Information Which is Privileged or Confidential…” would cause the Contractor organization substantial competitive harm if disclosed to other entities. Rationale shall be provided for each individual recommended redaction. Generalized conclusions of competitive harm are not a sufficient basis for the CMS FOIA office to invoke the exemption and thereby protect the Contractor’s interest.

All CD/DVDs shall be mailed to the CMS FOIA Officer (address below) within thirty (30) calendar days of contract award and within thirty (30) calendar days of a CMS request, i.e. existing or modified contracts. All CD/DVD files shall be submitted as Portable Document Format (.pdf) files.

CD/DVD and File Naming Conventions: The Contractor shall name the CD/DVD with the

Contract Number and utilize the following CD/DVD file naming conventions:

o HHSM-500-2013-xxxxxx – Highlighted o HHSM-500-2013-xxxxxx – Redacted o HHSM-500-2013-xxxxxx – Pre-Disclosure Concerns

CD/DVD shall be mailed to the CMS FOIA Officer at:

Freedom of Information Act Office ATTN: CMS FOIA Officer

Mailstop: N2-20-16 7500 Security Boulevard Baltimore, MD 21244-1850 Copy– Correspondence Only (No CD/DVD):

o Contracting Officer o Contracting Officer’s Representative (COR)

The CMS FOIA Office makes the final determination as to what information is released to the public, after considering any feedback from OAGM and/or the Contractor.

H.14 SECTION 508, ACCESSIBILITY OF ELECTRONIC AND INFORMATION

TECHNOLOGY (EIT)

A. This contract is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C.

794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220).

Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow all Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.

B. The EIT accessibility standards at 36 CFR Part 1194 were developed by the

Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001.

C. Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CRF 1194), as specified in the contract, as a minimum.

If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:

1. Cancellation of the contract, delivery or task order, purchase order, or line item without termination liabilities; or

2. In the case of custom EIT being developed by a Contractor for the

Government, the Government shall have the right to have any necessary changes made or repairs performed, by itself, or by another firm for the non-compliant EIT, with the Contractor liable for reimbursement to the Government for any expenses incurred thereby.

D. The contractor must ensure that all EIT products that are less tan fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy this contract's requirements.

E. For every EIT product or service accepted under this contract by the Government that does not comply with 36 CRF 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either the planned refresh cycle of the product or service, or on the contract renewal/effective option date, whichever shall occur first.

F. The contractor shall comply with the Rehabilitation Action, Section 508, Accessibility

Standards as referenced below.

508 Standards: http://www.access-board.gov/sec508/standards.htm

Guide to Standards: http://www.access-board.gov/sec508/guide/index.htm

508 guide: http://cmsnet.cms.hhs.gov/hpages/cmm/dmsd/508Ref_Guide.doc http://www.access-board.gov/sec508/standards.htm http://www.access-board.gov/sec508/guide/index.htm http://cmsnet.cms.hhs.gov/hpages/cmm/dmsd/508Ref_Guide.doc

SECTION H – SPECIAL CONTRACT REQUIREMENTS
H.2 CMS CODE OF CONDUCT
H.6 SECURITY CLAUSE-BACKGROUND-INVESTIGATIONS FOR CONTRACTOR PERSONNEL
H.8 ADP SYSTEMS SECURITY REQUIREMENTS
H.10 HHSAR 352.224-70 PRIVACY ACT (JAN 2006)
H.11 HIPPA Business Associate CLAUSE (SEPT 2013)
H.12 CMS Information Security (APR 2013)

File details come from the government source that posted it. Updated .