RFQ 36C26225Q0594.docx
DOCX document 136 KB Posted
- Attached to
- 6515--DISPENSING CABINETS, IVX WORKFLOW, & SERVER UPGRADE Federal contract opportunity
- Solicitation number
- 36C26225Q0594
About this file
This is a Request for Quote (RFQ) 36C26225Q0594 issued by the Department of Veterans Affairs Network Contracting Office 22 for a brand name or equal procurement of Omnicell dispensing cabinets, IVX Workflow, and server upgrade for VA Southern Arizona Healthcare System. The solicitation is for a single-visit installation of hardware and software, including one IVX Workflow instance with scales, interfaces, cloud connection, NiceLabel software, IVX color label printer, and IVX Zebra barcode scanner. The procurement will upgrade end-of-life Omnicell servers and support compliance with USP 797 guidelines for sterile compounding.
Key procurement details include an unrestricted full and open competition with a quote submission deadline of March 13, 2025 at 7:00 am PST. The contract will be a firm-fixed-price type with total line items including XT Extend Console cabinets, remote access licenses, Windows Server, and support services. Vendor requirements include being an authorized OEM dealer, providing all necessary installation and configuration services, training inpatient pharmacy staff, and ensuring data storage and reporting capabilities. The solicitation emphasizes strict information security requirements, compliance with VA regulations, and the need for vendor personnel to adhere to facility-specific protocols during installation.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
36C26225Q0594
PAGE 1 OF
1. REQUISITION NO.
2. CONTRACT NO.
3. AWARD/EFFECTIVE DATE
4. ORDER NO.
5. SOLICITATION NUMBER
6. SOLICITATION ISSUE DATE
a. NAME
b. TELEPHONE NO. (No Collect Calls)
8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY
CODE
10. THIS ACQUISITION IS
UNRESTRICTED OR
SET ASIDE:
% FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ
IFB
RFP
15. DELIVER TO
CODE
16. ADMINISTERED BY
CODE
17a. CONTRACTOR/OFFEROR
CODE
FACILITY CODE
18a. PAYMENT WILL BE MADE BY
CODE
TELEPHONE NO.
UEI:
EFT:
PHONE:
FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER 18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19.
20.
21.
22.
23.
24.
ITEM NO.
SCHEDULE OF SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA
26. TOTAL AWARD AMOUNT (For Govt. Use Only) 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA
ARE
ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________
29. AWARD OF CONTRACT: REF. ___________________________________ OFFER
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
DATED ________________________________. YOUR OFFER ON SOLICITATION
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER) 30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION
(REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE
Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
678-25-2-071-0055 36C26225Q0594 03-06-2025 Anthony Dela Cruz 562-766-2284 03-13-2025 7:00 am
PDT
36C262 Department of Veterans Affairs Network Contracting Office 22 4811 Airport Plaza Drive Suite 600 Long Beach CA 90815 X 339112 1000 Employees
NET 30
N/A X 36C678 Department of Veterans Affairs Southern Arizona Healthcare System Tucson Medical Center 3601 South Sixth Avenue Tucson AZ 85723-0001 36C262 Department of Veterans Affairs Network Contracting Office 22 4811 Airport Plaza Drive Suite 600 Long Beach CA 90815
Department of Veterans Affairs Financial Services Center Submit invoices electronically to:
https://www.tungsten-network.com Tungsten support: 1-877-489-6135
See CONTINUATION Page This is a brand name or equal requirement for Omnicell dispensing cabinets, IVX Workflow, and server upgrade.
Reference B.2 and B.3 for details.
The contractor shall show clear, and compelling evidence they meet all requirements of this solicitation.
RFQ 36C26225Q0594 is unrestricted full and open competition in the open market in accordance with (IAW) FAR 12 Acquisition of Commercial Products and FAR 13 Simplified Acquisition Procedures.
Award will be made IAW ADDENDUM to FAR 52.212-1 INSTRUCTIONS
TO OFFERORS – COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
and FAR 52.212-2 EVALUATION-COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES.
All quotes must be received by Thursday March 13, 2025 7:00 am PST.
See CONTINUATION Page Anthony Dela Cruz
VA-VHA-RPOW-2024-0101
Table of Contents
| SECTION A | 1 |
| A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES | 1 |
| SECTION B - CONTINUATION OF SF 1449 BLOCKS | 4 |
| B.1 CONTRACT ADMINISTRATION DATA | 4 |
| B.2 STATEMENT OF WORK | 5 |
| B.3 PRICE/COST SCHEDULE | 17 |
| ITEM INFORMATION | 17 |
| SECTION C - CONTRACT CLAUSES | 20 |
| C.1 52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND SERVICES DEVELOPED OR PROVIDED BY KASPERSKY LAB COVERED ENTITIES (DEC 2023) | 20 |
| C.2 52.204-27 PROHIBITION ON A BYTEDANCE COVERED APPLICATION (JUN 2023) | 21 |
| C.3 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2023) | 22 |
| C.4 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (JAN 2025) | 28 |
| C.5 52.225-1 BUY AMERICAN—SUPPLIES (OCT 2022) | 36 |
| C.6 52.227-14 RIGHTS IN DATA—GENERAL (MAY 2014) | 38 |
| C.7 52.227-19 COMMERCIAL COMPUTER SOFTWARE LICENSE (DEC 2007) | 43 |
| C.8 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998) | 44 |
| C.9 VAAR 852.212-71 GRAY MARKET AND COUNTERFEIT ITEMS (FEB 2023) | 44 |
| C.10 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV 2018) | 45 |
| C.11 VAAR 852.246-71 REJECTED GOODS (OCT 2018) | 46 |
| C.12 VAAR 852.247-71 DELIVERY LOCATION (OCT 2018) | 46 |
| C.13 VAAR 852.247-73 PACKING FOR DOMESTIC SHIPMENT (OCT 2018) | 47 |
| SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS | 48 |
| SECTION E - SOLICITATION PROVISIONS | 49 |
| E.1 52.204-24 REPRESENTATION REGARDING CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021) | 49 |
| E.2 52.204-29 FEDERAL ACQUISITION SUPPLY CHAIN SECURITY ACT ORDERS—REPRESENTATION AND DISCLOSURES (DEC 2023) | 51 |
| E.3 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018) | 53 |
| E.4 52.211-6 BRAND NAME OR EQUAL (AUG 1999) | 54 |
| E.5 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (SEP 2023) | 55 |
| E.6 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2021) | 56 |
| E.7 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (MAY 2024) | 56 |
| E.8 52.216-1 TYPE OF CONTRACT (APR 1984) | 74 |
| E.9 52.233-2 SERVICE OF PROTEST (SEP 2006) | 74 |
| E.10 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018) | 75 |
| E.11 VAAR 852.239-75 INFORMATION AND COMMUNICATION TECHNOLOGY ACCESSIBILITY NOTICE (FEB 2023) | 75 |
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR:
b. GOVERNMENT: Contracting Officer 36C262 anthony.delacuz@va.gov Department of Veterans Affairs Network Contracting Office 22 4811 Airport Plaza Drive Suite 600 Long Beach CA 90815
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
| [X] |
| 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or |
| [] |
| 52.232-36, Payment by Third Party |
3. INVOICES: Invoices shall be submitted in arrears:
| a. Quarterly | [] |
| b. Semi-Annually | [] |
| c. Other | [X] Invoice for Supplies/Services – Upon Delivery and Approved receiving report of supplies/service. |
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
Department of Veterans Affairs Financial Services Center P.O. Box 149971 Submit invoices electronically to:
http://www.tungsten-network.com
B.2 STATEMENT OF WORK
BACKGROUND:
VA Southern Healthcare System, campuses, utilize Omnicell automated dispensing cabinets for supplies and medication storage throughout the VA Medical Center and CBOC’s clinics. The current Omnicell servers, supporting the automated dispensing cabinets, are hosted on hardware that is end-of-useful-life. These servers are also hosting an unsupported operating system, which is a security vulnerability and requires the upgrade to be completed timely. Requirements for sterile compounding at VA facilities have intensified in recent years with the full adoption of USP 797. Maintaining sterility in IV compounding rooms and accuracy of compounding activities are paramount. The Omnicell IVX Workflow facilitates both goals by allowing for remote checking of tech work by pharmacists thereby decreasing traffic into the sterile room. It also doubles checks technician work by comparing volumes/weights of drug solutions used in compounding with known standards to ensure that the correct amount of drug is administered. Omnicell IVX workflow also enhances facility capabilities to better document an record compounding activities. The system stores NDCs, lot numbers and photographs of compounded medications to assist in recall activities, investigations and data analytics. It’s able to do this while remaining sterile and minimizing the amount of equipment stored and used in the sterile room. This is important because it reduces both cleaning requirements and risk of contamination. To maintain compliance with the USP 797 guidelines, we are to maintain IVX in all IV room hoods. In addition, Omnicell XTE is a hardware and software upgrade for the Omnicell XT cabinets. The current Windows Operating System (OS) will be out of service by Windows starting October 2025. The XTE upgrade is the only way to upgrade the OS on the cabinets. The upgrade also includes a new touchscreen and keyboard for the cabinets. This upgrade package is essential to prevent the cabinets from being on an unsupported OS, and the hardware upgrade extends the end-of-life date of the cabinets until 2030.
SCOPE OF WORK: The Contractor shall provide all labor, personnel, equipment, tools, materials, supervision and other items and services necessary to install and connect the Omnicell Windows Server to the existing Omnicell units and network.
1. CONTRACTOR REQUIREMENTS:
The contractor shall provide all tools and equipment necessary to properly and safely perform the services set forth within this statement of work. This shall include, but is not limited, to all Personal Protective Equipment (PPE) which may be required for the work to be completed in a safe manner. Contractor will complete installation and functional validation of the products listed below:
2. TASK FREQUENCY AND INSTRUCTIONS:
· This will be a single visit, be it a single day or multiple days, at the facility for a period sufficient to complete the work set forth in the scope of work. This visit is to be scheduled in advance with the VA Medical centers’ HTM service. Contractor shall check in with HTM prior to visiting the worksite. Contractor shall work between normal business hours; Monday- Friday 0800-1600. Service report shall be provided within 5 business days of work completion. The contractor will work with HTM to complete all necessary installation, configuration, and data migration tasks to install and connect the Omnicell Windows Server to the existing Omnicell units and VA network Contractor shall submit all removable media to be used on a VA system to HTM for scanning with anti-virus software prior to use on the system. In the case of equipment turn-in, exchange, repair or replacement hard drives used by the VA shall be removed from the equipment and remain in possession of VA this includes loaned or rented equipment. install one IVX Workflow instances to include scales, interfaces, cloud connection, NiceLabel software, IVX color label printer, and IVX Zebra barcode scanner.
· Ensure that all components of system are function including but not limited to:
· Remote IV checking
· Storage of IV compounding details including:
· Photos taken during compounding
· Lot, NDC, expiration date of components used in compounding
· Names of personnel involved in compounding and checking
· Electronic storage will be sufficient to store at least two years of data.
· Train inpatient pharmacy staff on all functions of Omnicell IVX Workflow.
· Installation and configuration of interface will occur at a time determined by SAVAHCS.
· Installation is to include software and cloud licenses as well as warranties, maintenance and support.
· Ensure that all stored data is available for reporting
Deliverables: Successful installation testing and staff training
3. SPECIAL WORK REQUIREMENTS:
Working on the teams outlined in the requirements below.
4. PROPERTY DAMAGE:
The contractor shall take all necessary precautions to prevent damage to any government property. The contractor shall report any damages immediately and shall be assessed current replacement costs for property damaged by the contractor, unless corrective action is taken. Any damaged material (i.e., trees, shrubs, lawn/turf, curbs, gutters, sidewalks, etc.) will be replaced in a timely manner or corrected by the contractor with like materials, at no extra cost to the government, upon approval of the Contracting Officer.
5. IDENTIFICATION, PARKING, SMOKING, CELLULAR PHONE USE AND VA REGULATIONS:
The contractor's employees shall always wear visible identification while on the premises of the VA property. It is the responsibility of the contractor to park in the appropriate designated parking areas. Information on parking is available from the VA Police-Security Service. The VA will not invalidate or make reimbursement for parking violations of the contractor under any conditions. Smoking is prohibited inside any buildings at the VA. Cellular phones and two-way radios are not to be used within six feet of any medical equipment. Possession of weapons is prohibited. Enclosed containers, including tool kits, shall be subject to search. Violations of VA regulations may result in a citation answerable in the United States (Federal) District Court, not a local district state, or municipal court.
6. COMPLIANCE WITH OSHA BLOODBORNE PATHOGENS STANDARD:
The contractor shall comply with the Federal OSHA Bloodborne Pathogens Standard. The contractor shall:
a) Have methods by which all employees are educated as to risks associated with bloodborne pathogens.
b) Have policies and procedures which reduce the risk of employee exposure to bloodborne pathogens.
c) Have mechanisms for employee counseling and treatment following exposure to bloodborne pathogens.
d) Provide appropriate personal protective equipment/clothing such as gloves, gowns, masks, protective eyewear, mouthpieces for the employee during performance of the contract.
7. Information Technology Security Requirements: The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract. The contractor shall comply with all Federal laws and regulations the VA has developed when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor. The information made available to the contractor by VA for the performance of this contract will be used only for the purposes of performance under this contract. The certification and accreditation requirements do not apply to this requirement and a security accreditation package is not required.
8. Security Statement: Sensitive VA information is contained within the systems covered by this contract.
HTM shall perform virus scans on all removable media prior to use on VA medical equipment. This includes all types of removable media, including media (e.g., USB devices, CDs, dongles, etc.) that has been issued by VA, media not issued by VA, and media brought in by vendors or independent service organizations. Within accordance of VA Directive 6500, Information Security Program, September 2007 The Vendor will not transfer any VA information to a location outside the VA and only to VA locations determined by the VA System Administrator. The information in these systems may be covered by the Privacy Act 1974 which contains criminal penalties of abuse of information.
During onsite service, the Vendor shall be chaperoned by VA Personnel. However, the vendor shall not be issued a User ID/Password.
Non-volatile memory devices, working or non-working, shall NOT be removed from the VA Medical Center until the ISO has certified that the data has been destroyed. For magnetic devices and media, the data destruction will be by degaussing. Other forms of cleansing will be used for non-magnetic media.
The vendor will not have remote access to complete the repair(s) and preventive maintenance.
9. GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
10. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
Custom software development and outsourced operations must be in the U.S.
to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
11. VA INFORMATION CUSTODIAL LANGUAGE
Information Administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
a. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures follow VA directive requirements.
b. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor while performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
c. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
d. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
e. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
f. If a VHA contract is terminated for cause, the associated BAA must also be terminated.
and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
g. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
h. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.
i. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
j. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.
k. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.
12. GENERAL RULES OF BEHAVIOR
a. Rules of Behavior are part of a comprehensive program to provide complete information security. These rules establish standards of behavior in recognition of the fact that knowledgeable users are the foundation of a successful security program. Users must understand that taking personal responsibility for the security of their computer and the information it contains is an essential part of their job.
b. The following rules apply to all VA contractors. I agree to:
(1) Follow established procedures for requesting, accessing, and closing user accounts and access. I will not request or obtain access beyond what is normally granted to users or by what is outlined in the contract.
(2) Use only systems, software, databases, and data which I am authorized to use, including any copyright restrictions.
(3) I will not use other equipment (OE) (non-contractor owned) for the storage, transfer, or processing of VA sensitive information without a VA CIO approved waiver, unless it has been reviewed and approved by local management and is included in the language of the contract. If authorized to use OE IT equipment, I must ensure that the system meets all applicable 6500 Handbook requirements for OE.
(4) Not use my position of trust and access rights to exploit system controls or access information for any reason other than in the performance of the contract.
(5) Not attempt to override or disable security, technical, or management controls unless expressly permitted to do so as an explicit requirement under the contract or at the direction of the COTR or ISO. If I am allowed or required to have a local administrator account on a government-owned computer, that local administrative account does not confer me unrestricted access or use, nor the authority to bypass security or other controls except as expressly permitted by the VA CIO or CIO's designee.
(6) Contractors’ use of systems, information, or sites is strictly limited to fulfill the terms of the contract. I understand no personal use is authorized. I will only use other Federal government information systems as expressly authorized by the terms of those systems. I accept that the restrictions under ethics regulations and criminal law still apply.
(7) Grant access to systems and information only to those who have an official need to know.
(8) Protect passwords from access by other individuals.
(9) Create and change passwords in accordance with VA Handbook 6500 on systems and any devices protecting VA information as well as the rules of behavior and security settings for the system in question.
(10) Protect information and systems from unauthorized disclosure, use, modification, or destruction. I will only use encryption that is FIPS 140-2 validated to safeguard VA sensitive information, both safeguarding VA sensitive information in storage and in transit regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA.
(11) Follow VA Handbook 6500.1, Electronic Media Sanitization to protect VA information. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders.
(12) Ensure that the COTR has previously approved VA information for public dissemination, including e-mail communications outside of the VA as appropriate. I will not make any unauthorized disclosure of any VA sensitive information using any means of communication including but not limited to e-mail, instant messaging, online chat, and web bulletin boards or logs.
(13) Not host, set up, administer, or run an Internet server related to my access to and use of any information assets or resources associated with my performance of services under the contract terms with the VA unless explicitly authorized under the contract or in writing by the COTR.
(14) Protect government property from theft, destruction, or misuse. I will follow VA directives and handbooks on handling Federal government IT equipment, information, and systems. I will not take VA sensitive information from the workplace without authorization from the COTR.
(15) Only use anti-virus software, antispyware, and firewall/intrusion detection software authorized by VA. I will contact the COTR for policies and guidance on complying with this requirement and will follow the COTR's orders regarding my access to and use of any information assets or resources associated with my performance of services under the contract terms with VA.
(16) Not disable or degrade the standard anti-virus software, antispyware, and/or firewall/intrusion detection software on the computer I use to access and use information assets or resources associated with my performance of services under the contract terms with VA. I will report anti-virus, antispyware, firewall or intrusion detection software errors, or significant alert messages to the COTR.
(17) Understand that restoration of service of any VA system is a concern of all users of the system.
(18) Complete required information security and privacy training, and complete required training for the systems to which I require access.
13. PRIVACY
a. Contractors and any subcontractors must adhere to the provisions of Public Law 104-191, Health Insurance Portability and Accountability Act (HIPAA) of 1996. This includes both the Privacy and Security Rules published by the Department of Health and Human Services (HHS).
b. As required by HIPAA, HHS has promulgated rules governing the use and disclosure of protected health information by covered entities, Veterans Health Administration (VHA). In accordance with HIPAA, the contractor may be required to enter into a Business Associate Agreement (BAA) with VHA.
c. Business associates must follow VHA privacy policies and practices when applicable. All contractors and business associates must receive privacy training annually.
d. For contractors and business associates who do not have access to VHA computer systems, this requirement is met by completing VHA National Privacy Policy training, other VHA approved privacy training or contractor furnished training that meets the requirements of the HHS Standards for Privacy of Individually Identifiable Health Information as determined by VHA.
e. For contractors and business associates who are granted access to VHA computer systems, this requirement is met by completing VHA National Privacy Policy training or other VHA approved privacy training. Proof of training is required upon request.
14. Safety Requirements: In the performance of this contract, the Contractor shall take such safety precautions as the Contracting Officer may determine to be reasonably necessary to protect the lives and health of occupants of the building. The Contracting Officer shall notify the Contractor of any safety issues and the action necessary to correct these issues. Such notice, when served to the Contractor or his representative at the work site shall be deemed sufficient for the corrective actions to be taken. If the Contractor fails or refuses to comply promptly, the Contracting Officer may issue an order stopping all or part of the work and hold the Contractor in default.
15. Invoicing: Payment to be made as one-time payment in arrears by certified invoices and must contain the contract number in addition to the requirements detailed in 52.212-4 (G) to be considered valid. All invoices shall be submitted to the VA Financial Service Center and emailed to the COTR. All invoices will reference the purchase order number assigned to the contract.
16. Records Management Statement:
1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created while performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
4. VA Medical Center SAVAHC and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of the VA Medical Center or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to VA Medical Center West Haven. The agency must report promptly to NARA in accordance with 36 CFR 1230.
5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to VA Medical Center West Haven control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and VA Medical Center SAVAHCS guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with VA Medical Center policies.
8. The Contractor shall not create or maintain any records containing any non-public VA Medical Center in Tucson and information that are not specifically tied to or authorized by the contract.
9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
10. The VA Medical Center SAVAHC owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which VA Medical Center shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.22720.
11. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take VHA-provided records management training, Talent Management System (TMS) Item #3873736, Records Management for Records Officers and Liaisons. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.
17. Contractor employees who work in or travel to VHA locations must comply with the following:
Documentation cited in this section shall be digitally or physically maintained on each contractor employee while in a VA facility and is subject to inspection prior to entry to VA facilities and after entry for spot inspections by Contracting Officer Representatives (CORs) or other hospital personnel.
Documentation will not be collected by the VA; contractors shall, always, adhere to and ensure compliance with federal laws designed to protect contractor employee health information and personally identifiable information.
(SOW END)
B.3 PRICE/COST SCHEDULE
ITEM INFORMATION
| ITEM NUMBER |
| DESCRIPTION OF SUPPLIES/SERVICES |
| QUANTITY |
| UNIT |
| UNIT PRICE |
| AMOUNT |
| 1.00 |
| EA |
| _______ |
| _______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
IVX WORKFLOW
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing PRODUCT/SERVICE CODE: 6515 - Medical and Surgical Instruments, Equipment, and Supplies
MANUFACTURER PART NUMBER (MPN): IVS-HDW-001
| 1.00 |
| EA |
| _______ |
| ______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
1-IVX WORKFLOW SOFTWARE SUB (1-4 DEVICE)
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): IVS-SUB-201
| 1.00 |
| EA |
| ______ |
| _______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
TOTAL SUPPORT SERVICES
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): SUPPORT SERVICES
| 53.00 |
| EA |
| _______ |
| _______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
XT EXTEND CONSOLE, FULL HEIGHT CABINET
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): MED-PCB-501
| 5.00 |
| EA |
| _______ |
| _______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
OC REMOTE ACCESS LICENSE WIN2019,UPG
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): OMC-LIC-032
| 1.00 |
| EA |
| _______ |
| _______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
OC SERVER WIN2019 176-600 DEVICES
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): OMC-SRV-092
| 1.00 |
| EA |
| _______ |
| ______________ |
Brand name or Equal. Must identify manufacturer and part number for all equal to brand name products.
OC VIRTUAL WIN2019 TEST SERVER
Contract Period: Base POP Begin:
POP End:
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
MANUFACTURER PART NUMBER (MPN): OMC-SRV-094
| GRAND TOTAL |
| _______________ |
36C26225Q0594
Page 1 of Page 1 of
SECTION C - CONTRACT CLAUSES
C.1 52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND SERVICES DEVELOPED OR PROVIDED BY KASPERSKY LAB COVERED ENTITIES (DEC 2023)
(a) Definitions. As used in this clause—Kaspersky Lab covered article means any hardware, software, or service that—
(1) Is developed or provided by a Kaspersky Lab covered entity;
(2) Includes any hardware, software, or service developed or provided in whole or in part by a Kaspersky Lab covered entity; or
(3) Contains components using any hardware or software developed in whole or in part by a Kaspersky Lab covered entity.
Kaspersky Lab covered entity means—
(1) Kaspersky Lab;
(2) Any successor entity to Kaspersky Lab, including any change in name, e.g., ‘‘Kaspersky’’;
(3) Any entity that controls, is controlled by, or is under common control with Kaspersky Lab; or
(4) Any entity of which Kaspersky Lab has a majority ownership.
(b) Prohibition. Section 1634 of Division A of the National Defense Authorization Act for Fiscal Year 2018 (Pub. L. 115–91) prohibits Government use of any Kaspersky Lab covered article. The Contractor is prohibited from—
(1) Providing any Kaspersky Lab covered article that the Government will use on or after October 1, 2018; and
(2) Using any Kaspersky Lab covered article on or after October 1, 2018, in the development of data or deliverables first produced in the performance of the contract.
(c) Reporting requirement. (1) In the event the Contractor identifies a Kaspersky Lab covered article provided to the Government during contract performance, or the Contractor is notified of such by a subcontractor at any tier or any other source, the Contractor shall report, in writing, to the Contracting Officer or, in the case of the Department of Defense, to the website at https://dibnet.dod.mil. For indefinite delivery contracts, the Contractor shall report to the Contracting Officer for the indefinite delivery contract and the Contracting Officer(s) for any affected order or, in the case of the Department of Defense, identify both the indefinite delivery contract and any affected orders in the report provided at https://dibnet.dod.mil.
(2) The Contractor shall report the following information pursuant to paragraph (c)(1) of this clause:
(i) Within 3 business days from the date of such identification or notification: The contract number; the order number(s), if applicable; supplier name; brand; model number (Original Equipment Manufacturer (OEM) number, manufacturer part number, or wholesaler number); item description; and any readily available information about mitigation actions undertaken or recommended.
(ii) Within 10 business days of submitting the report pursuant to paragraph (c)(1) of this clause: Any further available information about mitigation actions undertaken or recommended. In addition, the Contractor shall describe the efforts it undertook to prevent use or submission of a Kaspersky Lab covered article, any reasons that led to the use or submission of the Kaspersky Lab covered article, and any additional efforts that will be incorporated to prevent future use or submission of Kaspersky Lab covered articles.
(d) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (d), in all subcontracts including subcontracts for the acquisition of commercial products or commercial services.
(End of Clause)
C.2 52.204-27 PROHIBITION ON A BYTEDANCE COVERED APPLICATION (JUN 2023)
(a) Definitions. As used in this clause— Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.
Information technology, as defined in 40 U.S.C. 11101(6)—
(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use—
(i) Of that equipment; or
(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;
(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but
(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.
(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub. L. 117–328), the No TikTok on Government Devices Act, and its implementing guidance under Office of Management and Budget (OMB) Memorandum M–23–13, dated February 27, 2023, ‘‘No TikTok on Government Devices’’ Implementation Guidance, collectively prohibit the presence or use of a covered application on executive agency information technology, including certain equipment used by Federal contractors. The Contractor is prohibited from having or using a covered application on any information technology owned or managed by the Government, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor’s employees; however, this prohibition does not apply if the Contracting Officer provides written notification to the Contractor that an exception has been granted in accordance with OMB Memorandum M–23–13.
(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.
(End of Clause) C.3 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (NOV 2023)
(a) Inspection/Acceptance. The Contractor shall only tender for acceptance those items that conform to the requirements of this contract. The Government reserves the right to inspect or test any supplies or services that have been tendered for acceptance. The Government may require repair or replacement of nonconforming supplies or reperformance of nonconforming services at no increase in contract price. If repair/replacement or reperformance will not correct the defects or is not possible, the Government may seek an equitable price reduction or adequate consideration for acceptance of nonconforming supplies or services. The Government must exercise its post-acceptance rights—
(1) Within a reasonable time after the defect was discovered or should have been discovered; and
(2) Before any substantial change occurs in the condition of the item, unless the change is due to the defect in the item.
(b) Assignment. The Contractor or its assignee may assign its rights to receive payment due as a result of performance of this contract to a bank, trust company, or other financing institution, including any Federal lending agency in accordance with the Assignment of Claims Act (31 U.S.C. 3727). However, when a third party makes payment (e.g., use of the Governmentwide commercial purchase card), the Contractor may not assign its rights to receive payment under this contract.
(c) Changes. Changes in the terms and conditions of this contract may be made only by written agreement of the parties.
(d) Disputes. This contract is subject to 41 U.S.C. chapter 71, Contract Disputes. Failure of the parties to this contract to reach agreement on any request for equitable adjustment, claim, appeal or action arising under or relating to this contract shall be a dispute to be resolved in accordance with the clause at Federal Acquisition Regulation (FAR) 52.233-1, Disputes, which is incorporated herein by reference. The Contractor shall proceed diligently with performance of this contract, pending final resolution of any dispute arising under the contract.
(e) Definitions. The clause at FAR 52.202-1, Definitions, is incorporated herein by reference.
(f) Excusable delays. The Contractor shall be liable for default unless nonperformance is caused by an occurrence beyond the reasonable control of the Contractor and without its fault or negligence such as, acts of God or the public enemy, acts of the Government in either its sovereign or contractual capacity, fires, floods, epidemics, quarantine restrictions, strikes, unusually severe weather, and delays of common carriers.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .