RFQ N0018322Q0113.docx

DOCX document 83 KB Posted

Attached to
ABIOMED Perfusion Pumps Federal contract opportunity
Solicitation number
N0018322Q0113
Issued by
Department of the Navy Naval Supply Systems Command

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

N0018322Q0113

Section A - Solicitation/Contract Form

VENDOR TO COMPLETE THE FOLLOWING:

COMPANY NAME: ______________________

CAGE:___________________
UEID:___________________

Vendor POC: ____________________

Phone:____________________
Fax:____________________

Vendor email: _________________________________

Naval Medical Center Portsmouth, VA Acquisition Office

POC:David C. Anaya
Phone:757-953-7456
Email:david.c.anaya.civ@mail.mil

Product/Services for: Naval Medical Center Portsmouth VA 620 John Paul Jones Circle Portsmouth VA 23708-2297 Phone: 757-953-1494

Vendor to reference RFQ Number: N0018322Q0113 on all inquiries.

AVAILABILITY OF FUNDS

Pursuant to Section I, Availability of Funds (FAR 52.232-18), of the contract, “Funds are not presently available for this contract. The Government's obligation under this contract is contingent upon the availability of appropriated funds from which payment for contract purposes can be made. No legal liability on the part of the Government for any payment may arise until funds are made available to the Contracting Officer for this contract and until the Contractor receives notice of such availability, to be confirmed in writing by the Contracting Officer.”

PAYMENT INFORMATION

Payment in Arrears (Check One): Monthly Quarterly Semi-Annually Annually *Please ensure that quoted price matches the choice above and is evenly divisible depending on the selection

PROMPT PAYMENT

For Prompt Payment Act Purposes, this contract is:

Subject to the 7-calender day constructive acceptance period.

Note: Vendor will be required to provide billing electronically via the WAWF Electronic Invoicing Method. For additional information, a review of the following web sites may be required: websites: https://wawf.eb.mil or http://wawftraining Email: usn.detrick.navmedlogcomftdmd.list.nmlc-wawf@mail.mil

DISCOUNTS

The vendor's initial response to this RFQ should reflect the Vendors' best price including all allowable discounts that are available to the Federal Government. Please identify all discounts that are being offered as part of the vendor's quote submission. The government does not intend to go out for a best and final offer.

EMAIL QUOTES/PROPOSALS TO: david.c.anaya.civ@mail.mil DO NOT forward via U.S. Mail service. It is the Contractor’s responsibility to confirm receipt of quote/proposal.

Section B - Supplies or Services and Prices

ITEM NO
SUPPLIES/SERVICES
QUANTITY
UNIT
UNIT PRICE
AMOUNT
1
Job

Annual Maintenance for Perfusion Pumps

FFP

TWO (2) ABIOMED PUMPS

MDL: 00420000US

SERIAL #'S: IC3193, IC3194

*** See Section C for Performance Work Statement *** FOB: Destination

PURCHASE REQUEST NUMBER: 0011740111

PSC CD: J065

NET AMT

Section C - Descriptions and Specifications

PERFORMANCE WORK STATEMENT

This contract shall provide for maintenance services which include on-site corrective repairs, normal working hour coverage (8:00 A.M. to 4:30 P.M. Monday through Friday excluding Federal holidays) or 24-hour emergency service and routine preventive maintenance services to Department of Defense owned equipment, as listed on the: DD Form 1155 “Order for Supplies or Services”. It shall include all systems, subsystem components, and assemblies that were part of the original system purchased. All maintenance provisions shall apply to hardware, firmware, and software, as appropriate, unless otherwise stated.

1. General

a. The Contractor shall comply with Federal, State, Local laws, and Federal Regulations as applicable to the performance of this contract.

b. The Contractor shall not accept any instructions issued by any person employed by the U. S. Government, other than: the Contracting Officer (KO), or Biomedical Engineering Division (BME), all acting within the limits of their authority.

2. Scope of Work

a. The Contractor shall provide trained, experienced, English speaking personnel, labor, tools, diagnostic equipment, software, test phantoms, material, supplies, transportation, parts and equipment necessary to perform Preventive Maintenance (PM), Calibration (CAL), Safety testing (ST) and corrective maintenance.

b. The Contractor shall provide telephonic communications with the Government to discuss technical matters relating to the performance of this contract. A systems operator will be made available to answer technical questions regarding system operations and applications.

c. Equipment listed in this contract will be maintained to meet the original equipment manufacturers (OEM’s) specifications.

d. Equipment and associated components shall be serviced as listed on: DD Form 1155, “Order for Supplies or Services”.

e. The Contractor Point of Contact (POC). The Contractor shall provide in writing the name and telephone number of a primary and alternate English-speaking individual to act as their representative for the scheduling and coordination of service calls, and to be responsible for the coordination of the contract with the Government.

3. Government furnished property, Materials and Services.

a. The Contractor representative(s) at each site may request a pre-maintenance inspection prior to the onset of the contract. Any equipment found to be inoperable during this pre-maintenance inspection would be repaired using a separate purchase order. The government certifies that the equipment to be maintained under this contract will be in good operating condition on the effective date of this contract. For the purpose of this contract, the clause, “good operating condition” means the conditions necessary for the equipment to function as intended without corrective maintenance. The Contractor agrees to leave the equipment in good operating condition at the expiration of this contract. During the final week of this contract, the Government will make final inspection of the equipment. Any correction of deficiencies noted during this inspection shall be resolved prior to contract end.

b. The government will be responsible for maintaining the proper environment, including utilities and site requirements necessary for the system to function properly as specified by the OEM.

c. The Government will operate the system in accordance with the instruction manual provided by the OEM.

d. The Government will not be responsible for the damage or loss due to fire, theft, accident, or other disaster of Contractor supplies, materials, or for the personal belongings brought onto Government property by Contractor’s personnel.

4. Contractor Furnished Property and Material.

a. The Contractor shall provide all service literature, reference publications, laptop computers and diagnostic software to be used by the contractor service technicians and as required for the completion of the services in accordance with this contract.

5. Replacement Parts.

a. The Contractor shall have ready access to unique and/or high mortality replacement parts. All parts supplied shall be compatible with the existing system.

b. The Contractor shall at their expense; replace all worn or defective parts necessary to restore the equipment to 100% operational condition as specified by the OEM.

c. Contractor installed replacement parts shall become the property of the Government and the replaced malfunctioning part shall become the property of the Contractor.

d. Freight, postage, and storage charges associated with shipment and receipt of replacement parts, and the return of parts shall be the responsibility of the Contractor.

e. The Contractor shall use only new or warranted replacement parts where the quality is equal to or better than the OEM’s original part. When discrepancies occur, the Government will make the final determination on whether a replacement part is of equal or better quality.

f. The Contractor must include software revisions and upgrades (field service changes) which are required due to FDA or manufacturer announced safety-hazard recall, to include FDA Year 2000 Compliance Directive, as part of the contract at no additional cost to the Government.

Specific Tasks.

6. Contractor Report Requirements.

a. During normal duty hours, Contracted Field Service Engineer (FSE) personnel shall check-in with the Biomedical Engineering Division upon arrival at the Government site and again prior to departure. The Contractor FSEs shall personally notify Biomedical Engineering (BME) of problems that result in the equipment being left disabled upon their departure. After normal duty hours, Contractor FSEs shall notify the Officer of the Day Desk (Bldg 2, 2nd Floor) and the systems operator designated by (BME).

b. The Contractor shall provide to (BME) a full service report within two (2) days after completion of all service performed. The service report shall include, but not be limited to: contract number, contractor’s log number, detailed description of the service(s) performed, replacement part(s) information (part number, part value, nomenclature, unit price, manufacturer, if not OEM, and whether the part is new/used/reconditioned), the completion date and time, man-hours expended and the hourly rate normally charged for the type of service performed, model and serial numbers, and the name of the FSE performing the service.

7. Contractor Responsibility.

a. The Contractor shall be responsible for the repair/replacement of damaged Government owned equipment and property due to the negligence of the Contractor or his representatives. All such replacement or repair shall be at the Contractor’s expense and shall be inspected to the satisfaction of the KO or appointed representative.

8. Preventive Maintenance Services.

a. In accordance with Naval Medical Logistics Command (NAVMEDLOGCOM) Risk Assessment Criteria. Preventive maintenance shall be performed one (1) time during the length of this contract.

b. The Government shall select the months in which preventive maintenance services are to be performed. The preventive maintenance visits shall be performed during the following months: TBT

The Contractor shall schedule and complete preventive maintenance services prior to the 15th of the selected month.

c. All test equipment used in the performance of this contract will be within calibration shall be in compliance with Joint Commission on Accreditation of Healthcare Organization (JCAHO), Original Equipment Manufacturer (OEM) and Federal Drug Administration (FDA) standards.

9. Corrective Maintenance

a. Normal Working Hour Maintenance Coverage Maintenance Coverage will be Monday through Friday, between 8:00 A.M. to 4:30 P.M. The contractor shall respond via telephone within 2 hours after receipt of trouble call, and provide on-site service within 24 hours. Equipment shall be operational within 48 hours. The Government reserves the right to deduct from the Contractor’s payment an amount per hour equal to the number of hours the Contractor fails to respond, as specified in the contract. Emergency service outside the normal working hours by the Government site shall be billable to the Government at published commercial rates, and negotiated prior to services rendered.

b. Government request for corrective maintenance will be placed by (BME), to the Contractor’s POC. Corrective Maintenance shall be completed during the hours specified in the contract.

c. The Contractor shall assign a unique Log/Reference Number to each Government request for corrective Maintenance.

d. Contractor’s response to requests for service may include telephone consultation with the equipment user/operator and a Contractor FSE. Telephone consultation shall: 1) provide instruction in determining operator error; 2) to determine the most likely cause of the problem; 3) to determine if resolution of the problem requires the dispatch of a FSE; and 4) to identify replacement parts likely to be required in order to return the equipment to 100% operational condition as specified by the OEM.

e. Each level of service shall include all parts to be furnished by the Contractor at No cost to the Government, unless otherwise indicated. Any/all exclusions are listed as follows:

No Exclusions

f. The Contractor shall have his/her own service manuals, specifications, schematic diagrams, and parts lists to assist in the evaluation/repair of all equipment included in this contract.

10. Removal of Government Property

a. Whenever the repair of equipment cannot be performed at the Government site as determined by the Contractor, the Contractor shall notify (BME) who will make arrangements for the Contractor to remove the item to the Contractor’s designated site. The Contractor may be required to sign a Government form accepting responsibility for the Government equipment.

b. All charges resulting from a Contractor determined requirement to transport Government owned property, covered by this contract, to and from an alternate repair location shall be the responsibility of the Contractor.

11. Equipment Modification Upgrades

a. The Contractor shall only incorporate OEM specified modifications, alterations and upgrades. Approval shall be obtained from (BME) prior to the Contractor installation of any modification, alteration, or upgrades.

b. The Contractor shall maintain contact with the OEM to determine the requirement for field modifications and to ensure accomplishment of these modifications in accordance with the time schedule set forth by the OEM.

c. The Government shall not alter the system without prior notification to the Contractor.

d. The contractor at no additional cost shall provide software upgrade to the Government. Installation of upgrades will be left to the discretion of the Government.

12. Service beyond the Scope of the Contract

a. The Contractor shall immediately, but not later than 24 consecutive hours after discovery, notify (BME), in writing, of the existence or the development of any defects in, or repair required to the scheduled equipment which the Contractor considers they are not responsible for under the terms of this contract.

b. At the same time of the notification, the Contractor shall furnish (BME) with written estimate of the cost to make the necessary repairs. Repairs considered by the Contracting Officer to be outside the scope of this contract shall not be covered under this contract, but shall be ordered under a separate purchase order.

Section E - Inspection and Acceptance

INSPECTION AND ACCEPTANCE TERMS

Supplies/services will be inspected/accepted at:

CLIN
INSPECT AT
INSPECT BY
ACCEPT AT
ACCEPT BY
0001
Destination
Government
Destination
Government

CLAUSES INCORPORATED BY REFERENCE

52.246-4
Inspection Of Services--Fixed Price
AUG 1996

Section F - Deliveries or Performance

DELIVERY INFORMATION

CLIN
DELIVERY DATE
QUANTITY
SHIP TO ADDRESS
DODAAC / CAGE
0001
POP 01-OCT-2022 TO

30-SEP-2023

N/A
NAVAL MEDICAL CENTER

RECEIVING OFFICER

54 LEWIS MINORS STREET

BLDG. 250

PORTSMOUTH VA 23708-2298

757-953-5770 FOB: Destination

HT0242

52.211-17
Delivery of Excess Quantities
SEP 1989
52.247-34
F.O.B. Destination
NOV 1991

Section G - Contract Administration Data

CLAUSES INCORPORATED BY FULL TEXT

252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)

(a) Definitions. As used in this clause—

“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.

“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).

“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.

“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.

(c) WAWF access. To access WAWF, the Contractor shall—

(1) Have a designated electronic business point of contact in the System for Award Management at https://www.sam.gov; and

(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.

(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.

(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.

(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:

(1) Document type. The Contractor shall submit payment requests using the following document type(s):

(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.

(ii) For fixed price line items—

(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.

(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)

(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.

(Contracting Officer: Insert either “Invoice 2in1” or the applicable invoice and receiving report document type(s) for fixed price line items for services.)

(iii) For customary progress payments based on costs incurred, submit a progress payment request.

(iv) For performance based payments, submit a performance based payment request.

(v) For commercial item financing, submit a commercial item financing request.

(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.

[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]

(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.

Routing Data Table*

Field Name in WAWF
Data to be entered in WAWF
Pay Official DoDAAC
____
Issue By DoDAAC
____
Admin DoDAAC**
____
Inspect By DoDAAC
____
Ship To Code
____
Ship From Code
____
Mark For Code
____
Service Approver (DoDAAC)
____
Service Acceptor (DoDAAC)
____
Accept at Other DoDAAC
____
LPO DoDAAC
____
DCAA Auditor DoDAAC
____
Other DoDAAC(s)
____

(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert “See Schedule” or “Not applicable.”) (**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)

(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.

(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.

(g) WAWF point of contact.

(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.

(Contracting Officer: Insert applicable information or “Not applicable.”)

(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.

(End of clause)

Section H - Special Contract Requirements

PRIVACY

BUSINESS ASSOCIATE AGREEMENT

Privacy, Access, Use, and Disclosure of Protected Health Information

1. Introduction. In accordance with 45 C.F.R. §§ 164.502(e)(2) and 164.504(e), and DoDM 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, this document serves as a Business Associate Agreement (BAA) between the signatory Parties for purposes of the HIPAA and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA issuances (both defined below). The Parties are (1) a DoD Military Health System (MHS) component command such as a Navy Medicine Medical Treatment Facility (MTF) (Naval Medical center or Naval hospital), or special mission command (research, public health, other), acting as a HIPAA covered entity, and (2) another Federal or Government organization, civilian academic institution, or other civilian entity, acting as a HIPAA Business Associate (BA). The HIPAA Rules require BAAs between covered entities and BAs. Implementing this BAA requirement, the applicable DoD HIPAA issuances (DoDM 6025.18) provides that requirements applicable to BAs must be incorporated (or incorporated by reference) into the contract or agreement between the Parties.

2. Definitions:

a. Terms. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules (DoDM6025.18-): Data aggregation, designated record set, disclosure, health care operations, individual, minimum necessary, notice of privacy practices, protected health information (PHI), required by law, secretary, security incident, subcontractor, unsecured PHI, and use.

b. Breach. means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other Personally Identifiable Information (PII) (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of “Breach” in DoD Privacy Act issuances as defined herein.

c. BA. shall generally have the same meaning as the term “BA” in the DoD HIPAA issuances, and in reference to this BAA, shall mean the entity (another Government organization, civilian academic institution, or other civilian organization), entering into agreement with a Navy Medicine MTF or special mission command.

d. Agreement. means this BAA together with the documents or other arrangements under which the BA signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA.

e. Covered Entity. shall generally have the same meaning as the term “covered entity” in the DoD HIPAA issuances, and in reference to this BAA, shall mean a Navy Medicine MTF or special mission command under the Bureau of Medicine and Surgery.

f. DHA Privacy Office. means the Defense Health Agency (DHA) Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate.

g. DoD HIPAA Issuances. means the DoD issuances implementing the HIPAA Rules in the DoD MHS. These issuances are DoDM 6025.18 Implementation of the HIPAA Privacy Rule in DoD Health Care Programs,” March 13, 2019; DoD Instruction 6025.18, Privacy of Individually Identifiable Health Information in DoD Health Care Programs of December 2009, and DoD Instruction 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs of August 2015.

h. DoD Privacy Act Issuances. means the DoD issuances implementing the Privacy Act, which are DoD Directive 5400.11, DoD Privacy Program of 29 October 2014, and DoD 5400.11-R, Department of Defense Privacy Program of 8 May 2007.

i. HIPAA Rules. means, collectively, the HIPAA privacy, security, breach and enforcement rules, issued by the United States (US) Department of Health and Human Services (HHS) and codified at 45 C.F.R. §§ 160 and 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and 45 C.F.R. § 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules which implemented the “HITECH Act” provisions of Publication L. 111-5. See 78 Federal Regulation 5566-5702 of 25 January 2013 (with corrections at 78 Federal Regulation 32464 of 7 June 2013. Additional HIPAA rules regarding electronic transactions and code sets (45 C.F.R. § 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

j. HHS Breach. means a breach that satisfies the HIPAA Breach Rule definition of “Breach” in 45 C.F.R. § 164.402.

k. Service-Level Privacy Office. means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance.

3. Obligations and Activities of BA:

a. The BA shall not access, use, or disclose PHI other than as permitted or required by this Agreement, the controlling Memorandum of Understanding (MOU) or training affiliation agreement, or as required by law.

b. The BA shall use appropriate safeguards and comply with the DoD HIPAA Rules with respect to electronic PHI to prevent use or disclosure of PHI other than as provided for by this Agreement, the controlling MOU, or law.

c. The BA shall report to the covered entity any Breach of which it becomes aware and shall proceed with breach response steps required by paragraph 7 (Breach Response) of this BAA. With respect to electronic PHI, the BA shall also respond to any security incident of which it becomes aware in accordance with any information assurance provisions of the Understanding. If at any point the BA becomes aware that a security incident involves a breach, the BA shall immediately initiate breach response as required by paragraph 7 (Breach Response) of this BAA.

d. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii)) and 164.308(b)(2), respectively, as applicable, the BA shall ensure that any entities that create, receive, maintain, or transmit PHI on behalf of the BA agree to the same restrictions, conditions, and requirements that apply to the BA with respect to such PHI.

e. The BA shall make available PHI in a designated record set, to the covered entity or, as directed by the covered entity, to an Individual, as necessary to satisfy the covered entity obligations under 45 C.F.R. § 164.524.

f. The BA shall make any amendment(s) to PHI in a designated record set as directed or agreed to by the covered entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy covered entity’s obligations under 45 C.F.R. § 164.526.

g. The BA shall maintain and make available the information required to provide an accounting of disclosures to the covered entity or an individual as necessary to satisfy the covered entity’s obligations under 45 C.F.R. § 164.528.

h. To the extent the BA is to carry out one or more of the covered entity’s obligation(s) under the HIPAA privacy rule, the BA shall comply with the requirements of HIPAA privacy rule that apply to the covered entity in the performance of such obligation(s).

i. The BA shall make its internal practices, books, and records available to the Secretary and the covered entity for purposes of audit and in determining compliance with the HIPAA Rules.

4. Permitted Uses and Disclosures by BA:

a. The BA may only use or disclose PHI as necessary to perform the services set forth in the Understanding or as required by law. The BA is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 C.F.R. § 164.514(a) through (c), nor is it permitted to use or disclose de-identified PHI except as provided by the Understanding or directed by the covered entity.

b. The BA agrees to use, disclose, and request PHI only in accordance with the HIPAA privacy rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA issuances.

c. The BA shall not use or disclose PHI in a manner that would violate the DoD HIPAA issuances or HIPAA privacy rules if done by the covered entity, except uses and disclosures for the BA’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs:

(1) Except as otherwise limited in the understanding, the BA may use PHI for the proper management and administration of the BA or to carry out the legal responsibilities of the BA. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.

(2) Except as otherwise limited in the Understanding, the BA may disclose PHI for the proper management and administration of the BA or to carry out the legal responsibilities of the BA, provided that disclosures are required by law, or the BA obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the BA of any instances of which it is aware in which the confidentiality of the information has been breached.

(3) Except as otherwise limited in the Understanding, the BA may use PHI to provide Data Aggregation services relating to the covered entity’s health care operations.

5. Provisions for Covered Entity to Inform BA of Privacy Practices and Restrictions:

a.The covered entity shall provide the BA with the notice of privacy practices that the covered entity produces in accordance with 45 C.F.R.§ 164.520 and the corresponding provision of the DoD HIPAA issuances (DoDM 6025.18).
b.The covered entity shall notify the BA of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the BA’s use or disclosure of PHI.

c. The covered entity shall notify the BA of any restriction on the use or disclosure of PHI that the covered entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such changes may affect the BA’s use or disclosure of PHI.

6. Permissible Requests by Covered Entity. The covered entity shall not request the BA to use or disclose PHI in any manner that would not be permissible under the HIPAA privacy rule or any applicable Government regulations (including without limitation, DoD HIPAA issuances) if done by the covered entity, except for providing Data Aggregation services to the covered entity and for management and administrative activities of the BA as otherwise permitted by this BAA.

7. Breach Response:

a. General. Breach Response is designed to satisfy the DoD Privacy Act issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA issuances. In general, the BA shall report the breach to the covered entity, assess the breach incident, notify affected individuals, and take mitigating actions, as applicable. Because DoD defines “Breach” to include possible (suspected) as well as actual (confirmed) breaches, the BA shall implement these breach response requirements immediately upon the BA’s discovery of a possible breach. The following provisions set forth the BA’s Privacy Act and HIPAA breach response requirements for all breaches, including but not limited to HHS breaches (defined below). In the event of a breach of PII or PHI held by the BA, the BA shall follow the breach response requirements set forth under paragraphs 7, 8, and 9 of this BAA, which are designed to satisfy both the Privacy Act and HIPAA, as applicable.

(1) If a breach involves PII without PHI, then the BA shall comply with DoD Privacy Act issuance breach response requirements only.

(2) If a breach involves PHI (a subset of PII), then the BA shall comply with both Privacy Act and HIPAA breach response requirements.

(3) If a breach involves PHI, it may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the BA has no HIPAA breach response obligations. In such cases, the BA must still comply with breach response requirements under the DoD Privacy Act issuances.

b. HHS Breach. If the DHA Privacy Office determines that a breach is an HHS Breach, then the BA shall comply with both the HIPAA Breach Rule and DoD Privacy Act issuances, as directed by the DHA Privacy Office, regardless of where the breach occurs.

c. Non-HHS Breach. If the DHA Privacy Office determines that the breach does not constitute an HHS Breach, then the BA shall comply with DoD Privacy Act issuances, as directed by the applicable Service-Level Privacy Office.

d. Service-Level Privacy Office Point of Contact (POC). Brian Martin, who may be reached at Comm: 904-542-3559, DSN: 312-942-3559, or via E-mail: brian.k.martin4.civ@mail.mil, or usn.ncr.bumedfchava.list.bumed-pii-rpt@mail.mil.

BRIAN K. MARTIN
CODE M31 PRIVACY OFFICE
BUMED DETACHMENT JACKSONVILLE
H2005 KNIGHT LANE
PO BOX 140
NAVAL AIR STATION JACKSONVILLE FL 32212

8. Breach Reporting Provisions:

a. The BA shall report the breach within 1 business day of discovery to the US Computer Emergency Readiness Team (US-CERT) and within 24 hours of discovery to the DHA Privacy Office and the other Parties set forth below. The BA is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer, or other agent of the BA.

b. The BA shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report. Before submission to US-CERT, the BA shall save a copy of the on-line report. After submission, the BA shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the 1 hour deadline for submission, the BA shall submit the US-CERT report by the deadline. The BA shall e-mail updated information as it is obtained, following the instructions at: http://www.us-cert.gov/pgp/email.html. The BA shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office and the applicable Service-Level Privacy Office, if requested by either.

BA questions about US-CERT reporting shall be directed to the DHA or Service-Level Privacy Office, not the US-CERT office.

c. The BA report due within 24 hours shall be submitted by completing the New Breach Reporting Form DD 2959 at the Breach Response page on the DHA Privacy Office web site and emailing that form to, as applicable, the DHA Privacy Office, the Service-Level Privacy Office, the Contracting Officer (CO) and Contracting Officer’s Representative (COR) (if the Understanding is not a contract, delete these references to the CO and COR), and the BA’s DoD POC unless the POC specifies another addressee for breach reporting. Encryption is not required, because Breach Report Forms should not contain PII or PHI. The email address for notices to the DHA Privacy Office is provided at the Privacy Office web site breach response page. If electronic mail is not available, telephone notification is also acceptable, but all notifications and reports delivered telephonically must be confirmed by email as soon as technically feasible.

d. If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The BA shall inform the DHA Privacy Office as soon as possible if it believes that “single event” breach response is appropriate; the DHA Privacy Office will determine how the BA shall proceed and, if appropriate, consolidate separately reported breaches for purposes of BA report updates, beneficiary notification, and mitigation.

e. When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the BA shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the BA shall report include, but are not limited to:

(1) Confirmation on the exact data elements involved.

(2) Root cause of the incident.

(3) Any mitigation actions to include, sanctions, training, incident containment, follow-up, etc. The BA shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the DHA Privacy Office to make timely final determinations on any subsequent notifications or reports. The BA shall provide updates to the same Parties as required for the initial Breach Reporting Form. The BA is responsible for reporting all information needed by the DHA Privacy Office to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act issuances.

f. In the event the BA is uncertain on how to apply the above requirements, the BA shall consult with the DHA privacy office or service-level privacy office when determinations on applying the above requirements are needed.

9. Breach - Individual Notification Provisions:

a. Determine if Notification is Required. If the DHA Privacy Office determines that individual notification is required, the BA shall provide written notification to individuals affected by the breach as soon as possible, but no later than 60 working days after the breach is discovered and the identities of the individuals ascertained. The 60-day period begins when the BA is able to determine the identities (including addresses) of the individuals whose records were impacted.

b. Draft Proposed Notification. The BA’s proposed notification to be issued to the affected individuals shall be submitted to the Parties to which reports are submitted under paragraph 7 (breach response) for their review and for approval by the DHA Privacy Office. Upon request, the BA shall provide the DHA Privacy Office with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the BA shall provide the text of the letter for each group. PII shall not be included with the text of the letter(s) provided. Copies of further correspondence with affected individuals need not be provided unless requested by the Privacy Office. The BA’s notification to the individuals, at a minimum, shall include the following:

(1) Identify PII Lost. The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth are involved, it is critical to advise the individual that these data elements potentially have been breached.

(2) Inform. The affected individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.

(3) Protective Actions. The affected individual(s) must be informed of what protective actions the BA is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline: Toll Free: 1-877-ID-THEFT (438-4338), TTY: 1-866-653-4261.

(4) Credit Monitoring. The individual(s) must also be informed of any mitigating support services (e.g., 1 year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the BA may offer affected individuals, the process to follow to obtain those services, the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information.

(5) Labeling. BAs shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents (e.g., “Data Breach Information Enclosed”) and that the envelope is marked with the identity of the BA or subcontractor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, email address, and postal address.

c. Notification within 60 Days. If the BA determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 60-day period after discovering the breach, the BA shall so indicate in the initial or updated Breach Report Form. Within the 10-day period, the BA shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 60 days after identities and addresses are ascertained. The BA shall consult with the DHA Privacy Office, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The BA shall issue a generalized media notice(s) to that population in accordance with Privacy Office approval.

d. Costs. The BA shall, at no cost to the government, bear any costs associated with a breach of PII or PHI that the BA has caused or is otherwise responsible for addressing.

e. Security Incident versus Breach. Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII or PHI. In the event of a security incident not involving a PII or PHI breach, the BA shall follow applicable DoD Information Assurance requirements under its Understanding. If at any point the BA finds that a cyber security incident involves a PII or PHI breach (suspected or confirmed), the BA shall immediately initiate the breach response procedures set forth herein. The BA shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.

10. Termination:

a. Termination. Noncompliance by the BA (or any of its staff, agents, or subcontractors) with any requirements in this BAA may subject the BA to termination under any applicable default or other termination provision of the Understanding.

b. Effect of Termination.

(1) If the Understanding has records management requirements, the BA shall handle such records in accordance with the records management requirements. If the Understanding does not have records management requirements, the records should be handled in accordance with subparagraphs (2) and (3) below. If the Understanding has provisions for transfer of records and PII or PHI to a successor BA or if DHA gives directions for such transfer, the BA shall handle such records and information in accordance with such Understanding provisions or DHA direction.
(2) If the Understanding does not have records management requirements, except as provided in the following paragraph (3), upon termination of the Understanding, for any reason, the BA shall return or destroy all PHI received from the covered entity, or created or received by the BA on behalf of the covered entity that the BA still maintains in any form. This provision shall apply to PHI that is in the possession of subcontractors or agents of the BA. The BA shall retain no copies of the PHI.

(3) If the Understanding does not have records management provisions and the BA determines that returning or destroying the PHI is infeasible, the BA shall provide to the covered entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the covered entity and the BA that return or destruction of PHI is infeasible, the BA shall extend the protections of the Understanding to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the BA maintains such PHI.

11. Miscellaneous:

a. Survival. The obligations of BA under the “Effect of Termination” provision of this BAA shall survive the termination of the Understanding.

b. Interpretation. Any ambiguity in the Understanding shall be resolved in favor of a meaning that permits the covered entity and the BA to comply with HIPAA and the DoD HIPAA Rules.

Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information (Jan 2017)

Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The Deputy Secretary of Defense Directive-Type Memorandum (DTM) 08-006 – “DoD Implementation of Homeland Security Presidential Directive – 12 (HSPD-12)” dated November 26, 2008 (or its subsequent DoD instruction) directs implementation of HSPD-12. This clause is in accordance with HSPD-12 and its implementing directives.

APPLICABILITY

This text applies to contractor employees requiring physical access to any area of a federally controlled base, facility or activity and/or requiring access to a DoN or DoD computer/network/system to perform certain unclassified sensitive duties. This clause also applies to contractor employees who access Privacy Act and Protected Health Information, provide support associated with fiduciary duties, or perform duties that have been identified as National Security Position, as advised by the command security manager. It is the responsibility of the responsible security officer of the command/facility where the work is performed to ensure compliance.

Each contractor employee providing services at a Navy Command under this contract is required to obtain a Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command’s Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual’s performance under the contract.

ACCESS TO DOD IT SYSTEMS

In accordance with SECNAV M-5510.30, contractor employees who require access to DoN or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to information protected under the Privacy Act, to include Protected Health Information (PHI). All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity’s Command Information Assurance Manager.

Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation , which is a higher level investigation than the National Agency Check with Law and Credit (NACLC)/T3/T3R described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1, and must be trained and certified on the Operating System or Computing Environment they are required to maintain.

Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee’s duties, such employees shall in-process with the Navy Command’s Security Manager and Information Assurance Manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the “supervisor”.

The SAAR-N shall be forwarded to the Command’s Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.

When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Information Assurance (IA) training, and maintain a current requisite background investigation. The Contractor’s Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.

INTERIM ACCESS

The Command's Security Manager may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .