About this file

Section H

View the file

Other files for this federal contract opportunity

Other files attached to Research, Measurement, Assessment, Design, and Analysis (RMADA) IDIQ, newest first.
File Type Posted
Contractor_ _Contract__s.xlsx XLSX spreadsheet
Amendment_05.pdf PDF
SECTION_M_Amend_05.pdf PDF
SECTION_L_Amend_05.pdf PDF
SECTION_M_Amend_04.pdf PDF
Amendment_04.pdf PDF
SECTION_L_Amend_04.pdf PDF
SECTION_L_Amend_03.pdf PDF
RFP-CMS-RMADA-2014-_Questions_ _Answers_Amend_03.pdf PDF
RFP-CMS-RMADA-2014-_Questions_ _Answers_Amend_02.pdf PDF
SECTION_L_Amend_01.pdf PDF
SECTION_H_Amend_01.pdf PDF
SECTION_B_Amend_01.pdf PDF
SECTION_I_Amend_01.pdf PDF
SECTION_G_Amend_01.pdf PDF
RFP-CMS-RMADA-2014-Question_ _Answers.pdf PDF
SECTION_J_Amend_01.pdf PDF
SECTION_M_Amend_01.pdf PDF
Attachment_J.8_-_Priority_Measures.pdf PDF
RFP-CMS-RMADA-2014.pdf PDF
SECTION_J.pdf PDF
Attachment_J.2-Sample_Task_Order-SOW_ _SOD.pdf PDF
SECTION_E.pdf PDF
SECTION_M.pdf PDF
SECTION_D.pdf PDF
SECTION_C.pdf PDF
Attachment_J.1-_Incident_Reporting_Guide.pdf PDF
SECTION_L.pdf PDF
SECTION_I.pdf PDF
SECTION_K.pdf PDF
Attachment_J.5-Consent_to_Subcontract.pdf PDF
Attachment_J.4-Question_Submission_Template.pdf PDF
Attachment_J.3-Past_Performance_Questionnaire.pdf PDF
SECTION_G.pdf PDF
Attachment_J.6-_Small_Business_Subcontracting_Plan.pdf PDF
SECTION_B.pdf PDF
SECTION_F.pdf PDF
Attachment_J.7-_General_Questions_Draft_RFP.pdf PDF
Draft_RFP_081413.docx DOCX document
Ltr_081413.docx DOCX document
Show all 40

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP-CMS-RMADA-2014

SECTION H – SPECIAL CONTRACT REQUIREMENTS

H.1 FAR 52.252-1 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses provisions by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:

http://www.arnet.gov/far/

H.2 CMS CODE OF CONDUCT

A. Smoking

Effective June 9, 2004, smoking is not permitted anywhere on the CMS single site campus. This includes all areas outside the building, such as off-site facility, entranceways, sidewalks and parking areas. Smoking will not be permitted anywhere in Regional Offices or Washington, D.C. Office locations unless permitted by GSA guidelines or local landlord requirements. Contractor employees are subject to the same restrictions as government personnel. Fines up to $50 per occurrence will be issued and enforced by the Federal Protective Service.

B. Dress

The preferred dress codes at CMS facilities are professional attire, business attire or business casual attire.

C. EEO Agency Policies

The contractor shall be held accountable to all standards of conduct defined in the Agency’s EEO policies as made available on the CMS website http://www.cms.gov/About-CMS/Agency-Information/EEOInfo/index.html.

D. Social Media

The following guidance refers to Facebook, Twitter, LinkedIn, Tumblr, MySpace, or any other form of social media or blogs.

As a representative of the Government while performing the work described within the stated contract or any task order as a result of the contract, the contractor, using his or her official contracted title or acting within the scope of the stated contracted title shall not participate in any aspects of the identified contracted work or results that this work created/posted on any social media platform unless directed by the Government.

Violating this directive will result in removal of that individual from the contract or task order.

http://www.arnet.gov/far/ http://www.cms.gov/About-CMS/Agency-Information/EEOInfo/index.html

H.3 RESTRICTIONS AGAINST DISCLOSURE

(a) The Contractor agrees to keep all information it gathers or analyzes or information the Government in the course of this contract/task order/delivery order furnishes in the strictest confidence. The Contractor also agrees that Government-provided information marked "For Official Use Only," "Confidential", or "Proprietary" must also be similarly protected and shall take all reasonable measures necessary to prohibit access to such information by any such person other than those Contractor employees needing such information to perform the work, i.e., on a need-to-know basis.

(b) The Contractor shall immediately notify the Contracting Officer in writing in the event it has been determined or the Contractor has reason to suspect a breach of this requirement.

(c) The Contractor shall require that all employees and consultants who are given access to such information sign a confidentiality and nondisclosure statement agreeing to safeguard the confidentiality of all such information gathered or provided to them hereunder as an integral condition of their employment.

(d) Upon the Government's written request, the Contractor shall provide the Contracting Officer with plans and procedures to ensure the confidentiality and physical security of information gathered or provided hereunder.

(e) The Contractor may "gather and analyze" information that is not furnished or owned by the Government. Such information shall not be subject to the restrictions in this clause.

H.4 ORGANIZATIONAL CONFLICTS OF INTEREST (OCI)

The information and direction provided in this section apply to the RMADA Prime and all-tier subcontractors. Information contained in this section complies with FAR 9.5 and may be considered in both pre-and post award Contracting Officer determinations.

The primary purpose of this is to aid in ensuring that the Contractor (1) does not have any unfair competitive advantage over other parties in the competition for this contract, and (2) is not biased because of its current or planned interest (financial, organizational, or otherwise) which relate to the work under this contract.

The restrictions described herein shall apply to performance or participation by the Contractor and any of its affiliate organizations or their successors in interest (hereinafter collectively referred to as the "Contractor") in the activities covered by this clause as a prime Contractor, subcontractor, co-sponsor, joint venture, consultant, or in any similar capacity.

Advisory, consulting, analytical, evaluation, or study work, including the preparation of statements of work and specifications:

(i) If the Contractor performs advisory, consulting, analytical, evaluation, study, or similar work under this contract, it shall be ineligible thereafter to participate in any capacity in Government contractual efforts (solicited or unsolicited) which stem directly from such work, and the Contractor agrees not to perform similar work for prospective offerors with respect to any such contractual efforts.

Furthermore, unless so directed in writing by the Contracting Officer, the Contractor shall not perform any such work under this contract on any of its products or services, or the products or services of another firm for which the Contractor performs similar work.

Nothing in this subparagraph shall preclude the Contractor from competing for HHS management and technical support services follow-on contracts.

(ii) If the Contractor under this contract assists substantially in the preparation of a Statement of Objectives or specifications, the Contractor shall be ineligible to perform or participate in any capacity in any contractual effort which is based on such Statement of Objectives or specifications. The Contractor shall not incorporate its products or services in such Statement of Objectives or specifications unless so directed in writing by the Contracting Officer, in which case the restriction in this subparagraph shall not apply.

Access to the use of information:

(i) If the Contractor in the performance of this contract obtains access to information, such as HHS plans, policies, reports, studies, financial plans, or data which has not been released to the public, the Contractor agrees not to (a) use such information for any private purpose unless the information has been released to the public; (b) disclose such information for a period of six (6) months after the completion of this contract, or the release of such information to the public, whichever is first; (c) submit an unsolicited proposal to the Government which is based on such information until one (1) year after the release of such information to the public; or (d) release such information without prior written approval by the Contracting Officer.

(ii) In addition, the Contractor agrees that to the extent it receives or is given access to proprietary data or other confidential technical, business or financial information under this contract, it shall treat such information in accordance with any restrictions imposed on such information.

(iii) The Contractor shall have, subject to patent and security provisions of this contract, the right to use technical data it first produces under this contract for its private purposes provided that, as of the date of such use, all data requirements of this contract have been met.

Subcontracts. The Contractor shall include this clause, including this paragraph, in subcontracts of any tier. The use of this clause in such subcontracts shall be read by substituting the word "Subcontractor" for the word "Contractor" whenever the word "Contractor" appears.

Remedies: For breach of the above restrictions or for non-disclosure or misrepresentation of any relevant interest required to be disclosed concerning this contract, the Government may, at no cost, terminate the contract, disqualify the Contractor for subsequent related contractual efforts, and pursue other remedies as may be permitted by law or this contract.

Waiver. Any request for waiver under this clause shall be directed in writing to the Contracting Officer and shall include a full description of the requested waiver and the reasons in support thereof. If it is determined to be in the best interest of the

Government, the government shall grant such waiver in writing.

Definitions. The term "management and technical support services" includes any advice, assistance, analysis, consultation, evaluation, examination, report, review, study, survey, or similar assistance, including providing assistance in procurement and related activities, to support any program or their operations of CMS.

It is the responsibility of the RMADA contractor, at any time during the life of the contract, to identify if there is a perceived or real conflict of interest based upon the work under a particular task order, the umbrella contract and other work of the prime or subcontractors outside of this contract. With the reporting, the RMADA contractor must provide a mitigation plan subject to the Contracting Officer’s approval.

H.5 CONTRACTOR TERMINATION CMS BUILDING PASS

In the event that the contractor terminates an employee working on this contract, or an employee working on this contract voluntarily leaves the employment of the contractor and that employee has been issued a contractor’s badge by CMS for access to CMS Buildings; The contractor shall immediately take the following actions:

- Secure the CMS contractor’s badge from the employee;

- Formally advise the contracting officer that the individual is no longer an employee of the contractor, and;

- Return the badge with the notification to the contracting officer.

H.6 SECURITY CLAUSE-BACKGROUND-INVESTIGATIONS FOR CONTRACTOR

PERSONNEL

A. If applicable, Contractor personnel performing services for CMS under this contract, task order or delivery order shall be required to undergo a background investigation. CMS will pay for the background investigations.

B. After contract award, the CMS COR and the Emergency Management &

Response Group (EMRG), with the assistance of the Contractor, shall perform a position-sensitivity analysis based on the duties contractor personnel shall perform on the contract, task order or delivery order. The results of the position-sensitivity analysis will determine first, whether the provisions of this clause are applicable to the contract and second, if applicable, determine each position’s sensitivity level (i.e., high risk, moderate risk or low risk) and dictate the appropriate level of background investigation to be processed. Investigative packages may contain the following forms:

1. SF-85, Questionnaire for Non-Sensitive Positions, 09/1995

2. SF-85P, Questionnaire for Public Trust Positions, 09/1995

3. OF-612, Optional Application for Federal Employment, 12/2002

4. OF-306, Declaration for Federal Employment, 01/2001

5. Credit Report Release Form

6. FD-258, Fingerprint Card, 5/99, and

7. CMS-730A, Request for Physical Access to CMS Facilities (NON-CMS http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=FC83C171AE71F90585256A730051C8AB http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=25292D2D26D8B5EC85256A730051F924 http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=41A93F1A1771761B85256A720061344C http://www.gsa.gov/Portal/gsa/ep/formslibrary.do?viewType=DETAIL&formId=047C39FC0226D01E85256AAB005DF2AD http://www.opm.gov/extra/investigate/Fin-1998/fin9802.asp http://www.fbi.gov/hq/cjisd/PDF/fpcardb.pdf http://cmsnet.cms.hhs.gov/hpages/oics/formsloc/cms730af.pdf

ONLY), 11/2003.

C. The Contractor personnel shall be required to undergo a background investigation commensurate with one of these position-sensitivity levels:

(i) High Risk (Level 6)

Public Trust positions that would have a potential for exceptionally serious impact on the integrity and efficiency of the service. This would include computer security of a major automated information system (AIS). This includes positions in which the incumbent’s actions or inaction could diminish public confidence in the integrity, efficiency, or effectiveness of assigned government activities, whether or not actual damage occurs, particularly if duties are especially critical to the agency or program mission with a broad scope of responsibility and authority.

Major responsibilities that would require this level include:

a. development and administration of CMS computer security programs, including direction and control of risk analysis and/or threat assessment;

b. significant involvement in mission-critical systems;

c. preparation or approval of data for input into a system which does not necessarily involve personal access to the system but with relatively high risk of causing grave damage or realizing significant personal gain;

d. other responsibilities that involve relatively high risk of causing damage or realizing personal gain;

e. policy implementation;

f. higher level management duties/assignments or major program responsibility;

or

g. independent spokespersons or non-management position with authority for independent action.

Approximate cost of each investigation: $3,500

(ii) Moderate Risk (Level 5)

Public Trust positions that have potential for moderate to serious impact on the integrity and efficiency of the service, including computer security. These positions involve duties of considerable importance to the CMS mission with significant program responsibilities that could cause damage to large portions of AIS. Duties involved are considerably important to the agency or program mission with significant program responsibility, or delivery of service.

Responsibilities that would require this level include:

a. the direction, planning, design, operation, or maintenance of a computer system and whose work is technically reviewed by a higher authority at the High Risk level to ensure the integrity of the system;

b. systems design, operation, testing, maintenance, and/or monitoring that are carried out under the technical review of a higher authority at the High Risk level;

c. access to and/or processing of information requiring protection under the

Privacy Act of 1974;

d. assists in policy development and implementation;

e. mid-level management duties/assignments;

f. any position with responsibility for independent or semi-independent action;

or

g. delivery of service positions that demand public confidence or trust.

Approximate cost range of each investigation: $150 - $2,600

(iii) Low Risk (Level 1)

Positions having the potential for limited interaction with the agency or program mission, so the potential for impact on the integrity and efficiency of the service is small. This includes computer security impact on AIS.

Approximate cost of each investigation: $100

D. The Contractor shall submit the investigative package(s) to the EMRG within three (3) days after being advised by the EMRG of the need to submit packages.

Investigative packages shall be submitted to the following address:

Centers for Medicare & Medicaid Services Office of Operations Management Emergency Management & Response Group Mail Stop SL-13-15 7500 Security Boulevard Baltimore, Maryland 21244-1850

E. The Contractor shall submit a copy of the transmittal letter to the Contracting

Officer (CO).

F. Contractor personnel shall submit a CMS-730A (Request for Badge) to the

EMRG. The Contractor and the COR shall obtain all necessary signatures on the CMS-730A prior to any Contractor employee arriving for fingerprinting and badge processing.

G. The Contractor must appoint a Security Investigation Liaison as a point of contact to resolve any issues of inaccurate or incomplete form(s). Where personal information is involved, EMRG may need to contact the contractor employee directly. The Security Investigation Liaison may be required to facilitate such contact.

H. After EMRG fingerprints contractor personnel and issues them a temporary CMS identification badge, the EMRG will send their completed investigative package to the Office of Personnel Management (OPM). OPM will conduct the background investigation. Badges will be provided by EMRG while contractor personnel investigative forms are being processed. The Contractor remains fully responsible for ensuring contract, task order or delivery order performance pending completion of background investigations of contractor personnel.

I. EMRG shall provide written notification to the CO with a copy to the COR of all suitability decisions. The shall then notify the Contractor in writing of the approval of the Contractor’s employee(s), at that time the Contractor’s employee(s) will receive a permanent identification badge. Contractor personnel who the EMRG determines to be ineligible may be required to cease working on the contract immediately.

J. The Contractor shall report immediately in writing to EMRG with copies to the CO and the COR, any adverse information regarding any of its employees that may impact their ability to perform under this contract, task order or delivery order.

Reports should be based on reliable and substantiated information, not on rumor or innuendo. The report shall include the contractor employee’s name and social security number, along with the adverse information being reported.

K. Contractor personnel shall be provided an opportunity to explain or refute unfavorable information found in an investigation to EMRG before an adverse adjudication is made. Contractor personnel may request, in writing, a copy of their own investigative results by contacting:

Office of Personnel Management Freedom of Information Federal Investigations Processing Center PO Box 618 Boyers, PA 16018-0618.

L. At the Agency’s discretion, if an investigated contractor employee leaves the employment of the contractor, or otherwise is no longer associated with the contract, task order, or delivery order within one (1) year from the date the background investigation was completed, then the Contractor may be required to reimburse CMS for the full cost of the investigation. Depending upon the type of background investigation conducted, the cost could be approximately $100 to $3,500. The amount to be paid by the Contractor shall be due and payable when the CO submits a written letter notifying the Contractor as to the cost of the investigation. The Contractor shall pay the amount due within thirty (30) days of the date of the CO’s letter by check made payable to the “United States Treasury.” The Contractor shall provide a copy of the CO’s letter as an attachment to the check and submit both to the Office of Financial Management at the following address:

Centers for Medicare & Medicaid Services PO Box 7520 Baltimore, Maryland 21207

M. The Contractor must immediately provide written notification to EMRG (with copies to the CO and the COR) of all terminations or resignations of Contractor personnel working on this contract, task order or delivery order. The Contractor must also notify EMRG (with copies to the CO and the COR) when a Contractor’s employee is no longer working on this contract, task order or delivery order.

N. At the conclusion of the contract, task order or delivery order and at the time when a contractor employee is no longer working on the contract, task order or delivery order due to termination or resignation, all CMS-issued parking permits, identification badges, access cards, and/or keys must be promptly returned to EMRG. Contractor personnel who do not return their government-issued parking permits, identification badges, access cards, and/or keys within 48 hours of the last day of authorized access shall be permanently barred from the CMS complex and subject to fines and penalties authorized by applicable federal and State laws.

H.7 WORK PERFORMED OUTSIDE THE CONTINENTAL UNITED STATES AND ITS

TERRITORIES (OCONUS)

The contractor, and its subcontractors, shall not perform any activities under this contract at a location OCONUS (outside the continental United States), including the transmission of data or other information OCONUS, without the prior written approval of the Contracting Officer. The factors that the Contracting Officer will consider in making a decision to authorize the performance of work OCONUS include, but are not limited to the following:

- All contract terms regarding system security;

- All contract terms regarding the confidentiality and privacy requirements for information and data protection;

- All contract terms that are otherwise relevant, including the provisions of the Statement of Objectives and what is defined in the technical requirements of a particular task order;

- All laws and regulations applicable to the performance of work OCONUS;

- Concurrence from the CMS SEMG Director or designee; and,

- The best interest of the Government.

In requesting the Contracting Officer’s authorization to perform work OCONUS, the contractor must demonstrate that the performance of the work satisfies all of the above factors. If, in the Contracting Officer’s judgment, the above factors are not fully satisfied, the performance of work OCONUS will not be authorized.

H.8 ADP SYSTEMS SECURITY REQUIREMENTS

In the performance of this contract, the Contractor agrees to comply with the ADP systems security requirements of the Office of Management and Budget (OMB) Circular A-130, "Management of Federal Information Resources", and with the ADP systems security policy of DHHS as outlined in Part 6 of the HHS ADP Systems Manual and in CMS's AIS Guide. The Contractor shall include this requirement in any subcontract awarded under this prime contract

H.9 352.201-70 Paperwork Reduction Act (January 2006)

In the event that it becomes a requirement to collect information under this order, OMB Forms clearance shall be required pursuant to the Paperwork Reduction Act (see 5 CTR, Part 1320). The Contractor is hereby advised not to expend any funds or take any other action to solicit information until the Contracting Officer has notified the Contractor in writing that the required OMB clearance has been obtained. The Contractor shall provide to the COR such information as will facilitate obtaining such clearance.

H.10 HHSAR 352.224-70 PRIVACY ACT (JAN 2006)

This contract requires the Contractor to perform one or more of the following:

(a) design; (b) develop; or (c) operate a federal agency system of records to accomplish an agency function in accordance with the Privacy Act of 1974 (Act) [5 U.S.C. 552a(m)(1)] and applicable agency regulations. The term “system of records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual. Violations of the Act by the Contractor and/or its employees may result in the imposition of criminal penalties [5 U.S.C. 552a(i)]. The Contractor shall ensure that each of its employees knows the prescribed rules of conduct and that each employee is aware that he/she is subject to criminal penalties for violation of the Act to the same extent as Department of Health and Human Services employees. These provisions also apply to all subcontracts the Contractor awards under this contract which require the design, development or operation of the designated system(s) of records [5 U.S.C. 552a(m)(1)]. The contract work statement: (a) identifies the system(s) of records and the design, development, or operation work the Contractor is to perform; and (b) specifies the disposition to be made of such records upon completion of contract performance.

H.11 HIPPA BUSINESS ASSOCIATE PROVISION (MAY 2012)

a. Definitions:

All terms used herein and not otherwise defined shall have the same meaning as in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA," 42 U.S.C. sec.

1320d) and the corresponding implementing regulations. Provisions governing the Contractor's duties and obligations under the Privacy Act (including CMS’ data use agreements) are covered elsewhere in the contract.

"Business Associate'' shall mean the Contractor.

"Covered Entity" shall mean CMS' Medicare Fee for Service program and/or Pre- Existing Condition Insurance Plan.

"Secretary" shall mean the Secretary of the Department of Health and Human Services or the Secretary's designee.

b. Obligations and Activities of Business Associate

1. Business Associate agrees to not use or disclose Protected Health Information ("PHI"), as defined in 45 C.F.R. § 160.103, created or received by Business Associate from or on behalf of Covered Entity other than as permitted or required by this Contract or as required by law.

2. Business Associate agrees to use safeguards to prevent use or disclosure of PHI created or received by Business Associate from or on behalf of Covered Entity http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=browse_usc&docid=Cite%3A%2B5USC552a other than as provided for by this Contract. Furthermore, Business Associate agrees to use appropriate administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the electronic protected health information ("EPHI"), as defined in 45 C.F.R.

160.103, it creates, receives, maintains or transmits on behalf of the Covered Entity to prevent use or disclosure of such EPHI.

3. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Contract.

4. Business Associate agrees to report to Covered Entity any use or disclosure involving PHI it receives/maintains from/on behalf of the Covered Entity that is not provided for by this Contract of which it becomes aware. Furthermore, Business Associate agrees to report to Covered Entity any security incident involving EPHI of which it becomes aware. The Business Associate shall report any violation in use or disclosure involving PHI or any security incident to CMS within one (1) hour of discovery in accordance with the “CMS Guide for the Incident Reporting Process” (See Attachment). In addition, the Business Associate will also notify the CMS Contracting Officer and Contracting Officer’s Representative (COR) by email within one (1) hour of identifying such violation or incident.

5. Business Associate agrees to ensure that any agent, including a subcontractor, to whom it provides PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, agrees to the same restrictions and conditions that apply through this Contract to Business Associate with respect to such information. Furthermore, Business Associate agrees to ensure that its agents and subcontractors implement reasonable and appropriate safeguards for the PHI received from or on behalf of the Business Associate.

6. Business Associate agrees to provide access, at the request of Covered Entity, to PHI received by Business Associate in the course of contract performance, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 CFR § 164.524.

7. Business Associate agrees to make any amendment(s) to PHI in a Designated

Record Set that Covered Entity directs or agrees to pursuant to 45 CFR §

164.526 upon request of Covered Entity.

8. Business Associate agrees to make internal practices, books, and records, including policies and procedures and PHI, relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of Covered Entity, available to Covered Entity, or to the Secretary for purposes of the Secretary determining Covered Entity's compliance with the various rules implementing the HIPAA.

9. Business Associate agrees to document such disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

10. Business Associate agrees to provide to Covered Entity, or an individual identified by the Covered Entity, information collected under this Contract, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

c. Permitted Uses and Disclosures by Business Associate

Except as otherwise limited in this Contract, Business Associate may use or disclose PHI on behalf of, or to provide services to, Covered Entity for purposes of the performance of this Contract, if such use or disclosure of PHI would not violate the HIPAA Privacy or Security Rules if done by Covered Entity or the minimum necessary policies and procedures of Covered Entity.

d. Obligations of Covered Entity

1. Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices of Covered Entity in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.

2. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.

3. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

e. Permissible Requests by Covered Entity

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy or Security Rules.

f. Term of Provision

1. The term of this Provision shall be effective as of date of contract award, and shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions in this Section.

2. Upon Covered Entity's knowledge of a material breach by Business

Associate, Covered Entity shall either:

i. Provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination terms of this Contract.

Covered Entity may terminate this Contract for default if the Business

Associate does not cure the breach or end the violation within the time specified by Covered Entity; or,

ii. Consistent with the terms of this Contract, terminate this Contract for default if Business Associate has breached a material term of this Contract and cure is not possible; or,

iii. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

3. Effect of Termination.

i. Except as provided in paragraph f.2 of this section, upon termination of this Contract, for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. This provision shall apply to PHI that is in the possession of subcontractors or agents of Business Associate. Business Associate shall retain no copies of the PHI.

ii. In the event that Business Associate determines that returning or destroying the PHI is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon such notice that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.

g. Miscellaneous

i. A reference in this Contract to a section in the Rules issued under HIPAA means the section as in effect or as amended.

ii. The Parties agree to take such action as is necessary to amend this Contract from time to time as is necessary for Covered Entity to comply with the requirements of the Rules issued under HIPAA.

iii. The respective rights and obligations of Business Associate under paragraph f.3 of the section entitled "Term of Provision" shall survive the termination of this Contract.

iv. Any ambiguity in this Contract shall be resolved to permit Covered Entity to comply with the Rules implemented under HIPAA.

H.12 CMS INFORMATION SECURITY (APR 2013)

All CMS information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, in order to maintain the security, confidentiality, integrity, and availability of such information. Therefore, if this contract requires the Contractor to provide services (both commercial and non-commercial) for Federal Information/Data, to include any of the following requirements:

• Process any Information/Data; or

• Store any Information/Data (includes “Cloud” computing services); or

• Facilitate the transport of Information/Data; or

• Host/maintain Information/Data (including software and/or infrastructure developer/maintainers); or

• Have access to, or use of, Personally Identifiable Information (PII), including instances of remote access to, or physical removal of, such information beyond agency premises or control, the Contractor shall become and remain compliant with the requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics- Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS- Information-Security-Contract-Clause-Provision.html. The requirements cover all CMS contracts and associated deliverables, which are required on a “per Contractor” basis.

The Contractor shall ensure that the following Federal information security standards are met for all of its CMS contracts:

• Federal Information Security Management Act (FISMA) – FISMA information can be found at http://csrc.nist.gov/groups/SMA/fisma/index.html. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source; and,

• Federal Risk and Authorization Management Program (FedRAMP) – FedRAMP information can be found at http://www.gsa.gov/portal/category/102371. The FedRAMP is a Government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

The Contractor shall include in all awarded subcontracts the FISMA/FedRAMP compliance requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information- Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security- Contract-Clause-Provision.html.

H.13 SECTION 508, ACCESSIBILITY OF ELECTRONIC AND INFORMATION

TECHNOLOGY (EIT)

A. This contract is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C.

794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220).

Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow all Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.

https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html

B. The EIT accessibility standards at 36 CFR Part 1194 were developed by the

Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001.

C. Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CRF 1194), as specified in the contract, as a minimum.

If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:

1. Cancellation of the contract, delivery or task order, purchase order, or line item without termination liabilities; or

2. In the case of custom EIT being developed by a Contractor for the

Government, the Government shall have the right to have any necessary changes made or repairs performed, by itself, or by another firm for the non-compliant EIT, with the Contractor liable for reimbursement to the Government for any expenses incurred thereby.

D. The contractor must ensure that all EIT products that are less tan fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy this contract's requirements.

E. For every EIT product or service accepted under this contract by the Government that does not comply with 36 CRF 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either the planned refresh cycle of the product or service, or on the contract renewal/effective option date, whichever shall occur first.

F. The contractor shall comply with the Rehabilitation Action, Section 508, Accessibility

Standards as referenced below.

508 Standards: http://www.access-board.gov/sec508/standards.htm

Guide to Standards: http://www.access-board.gov/sec508/guide/index.htm

508 guide: http://cmsnet.cms.hhs.gov/hpages/cmm/dmsd/508Ref_Guide.doc http://www.access-board.gov/sec508/standards.htm http://www.access-board.gov/sec508/guide/index.htm http://cmsnet.cms.hhs.gov/hpages/cmm/dmsd/508Ref_Guide.doc

SECTION H – SPECIAL CONTRACT REQUIREMENTS
H.2 CMS CODE OF CONDUCT
H.6 SECURITY CLAUSE-BACKGROUND-INVESTIGATIONS FOR CONTRACTOR PERSONNEL
H.8 ADP SYSTEMS SECURITY REQUIREMENTS
H.10 HHSAR 352.224-70 PRIVACY ACT (JAN 2006)
H.11 HIPPA Business Associate Provision (May 2012)
H.12 CMS Information Security (APR 2013)

File details come from the government source that posted it. Updated .