S02_36C10B26Q0074_Censis VISN 4_Final.pdf

PDF 657 KB Posted

Attached to
DA01--VISN 4 Follow-on Censitrac Subscriptions and Support Federal contract opportunity
Solicitation number
36C10B26Q0074
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a Solicitation/Contract/Order for Commercial Products and Commercial Services (Standard Form 1449) for CensiTrac Subscriptions & Maintenance Support Services for the Department of Veterans Affairs (VA). The contract is for VA Veterans Integrated Services Network 4, covering multiple medical centers in Pennsylvania and Delaware, with a base period from December 6, 2025 to December 5, 2026 and two 12-month option periods. The total contract value is $47 million.

The solicitation covers subscriptions and renewals for various CensiTrac software products, including Instrument Trac, GOV Cloud Server, Service+, ScopeTrac Stand Advanced, and LoanerLink. These software systems are used for tracking and documenting surgical instrument reprocessing steps across multiple VA medical centers. The contract will be awarded on a firm-fixed-price basis to the lowest-priced, responsive, and responsible offeror. Quotes must be submitted electronically by November 26, 2025 at 11:00 am EDT, with the contract to be awarded by the VA Technology Acquisition Center in Eatontown, New Jersey.

View the file

Other files for this federal contract opportunity

Other files attached to DA01--VISN 4 Follow-on Censitrac Subscriptions and Support, newest first.
File Type Posted
P03_JA_VISN 4_CensiTrac Support_Final_Signed_redacted.pdf PDF
36C10B26Q0074_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

36C10B26Q0074 11-25-2025

Angela Key, Contract Specialist angela.key@va.gov 848-377-5202 11-26-2025

11:00 am EDT

36C10B

Department of Veterans Affairs

Office of Procurement, Acquisition and Logistics

Technology Acquisition Center

23 Christopher Way

Eatontown NJ 07724

513210

$47 Million

N/A

X

See Schedule of Supplies/Services

36C10B

Department of Veterans Affairs

Office of Procurement, Acquisition and Logistics

Technology Acquisition Center

Eatontown NJ 07724

Technology Acquisition Center

Financial Services Center

PO Box 149971

Austin TX 78714-8971

See website at: http://www.fsc.va.gov/einvoice.asp

Title: CensiTrac Subscriptions & Maintenance Support Services

– Veterans Integrated Services Network 4

Contract Specialist: Angela Key/angela.key@va.gov

Contracting Officer: John Vardouniotis/ ioannis.vardouniotis@va.gov

Period of Performance: 12/06/25 - 12/05/26 with two, 12-month option periods.

See Continuation Page

X X

John Vardouniotis

Contracting Officer

36C10B26Q0074

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 GOVERNING LAW CLAUSE

B.3 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT

B.4 SCHEDULE OF SUPPLIES/SERVICES

B.5 PRODUCT DESCRIPTION

SECTION C - CONTRACT CLAUSES

C.1 FAR 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.2 FAR 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

C.3 VAAR 852.204-71 INFORMATION AND INFORMATION SYSTEMS SECURITY

(FEB 2023)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 FAR 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

E.2 FAR 52.209-5 CERTIFICATION REGARDING RESPONSIBILITY MATTERS (NOV

2025)(DEVIATION)

E.3 FAR 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (OCT 2025)(DEVIATION)

E.4 FAR 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (OCT 2025)(DEVIATION)

E.5 FAR 52.216-1 TYPE OF CONTRACT (APR 1984)

E.6 FAR 52.233-2 SERVICE OF PROTEST (SEP 2006)

E.7 BASIS OF AWARD

E.8 QUOTE SUBMISSION

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: Censis Technologies, Inc 4031 Aspen Grove Drive Suite 350 Franklin, TN 37067

b. GOVERNMENT: Contracting Officer 36C10B John Vardouniotis

Technology Acquisition Center

Eatontown, NJ 07724

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X - In accordance with Schedule of Supplies/Services]

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic

Submission of Payment Requests.

See website at: http://www.fsc.va.gov/einvoice.asp

5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

B.2 GOVERNING LAW CLAUSE

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S.

Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.3 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT

(1). Definitions.

a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”

b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.

e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements, or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

(2). Software License.

a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b) The Government may use the software in a networked environment.

c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).

d) All limitations of software usage are expressly stated in the Schedule of

Supplies/Services and the Performance Work Statement/Product Description.

(3). Software Maintenance and/or Technical Support.

a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers to cause the software to perform according to its specifications, documentation or demonstrated claims.

c) Any telephone support provided by Contractor shall be at no additional cost.

d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding two business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).

e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

(4). Disabling Software Code.

The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software.

Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out, or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

(5). Manuals and Publications.

Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

http://www.cpars.gov/

B.4 SCHEDULE OF SUPPLIES/SERVICES

Any resulting contract will be awarded on a firm-fixed-price basis as defined by Federal Acquisition Regulation Subpart 16.202. Accordingly, the Contractor shall ensure that any and all costs associated with the Contractor’s proposed application(s), software products, software solution, and/or system, shall be included in the Contractor’s proposed firm-fixed price, and shall serve as the Contractor’s firm-fixed price for the life of any resulting contract. No additional costs or fees relative to the Contractor’s proposed application(s), software products, software solution, and/or system including, but not limited to, licensing costs and any associated licensing maintenance required for the development, delivery, integration, operation, and/or maintenance of the Contractor’s proposed solution will be allowed, accepted, and/or paid by the Government.

NOTE: Offeror is instructed to complete Section B.4 below and submit with its quote.

Offerors is cautioned that alterations to the line items as specified below will not be accepted and may render quote unacceptable.

Base Period

Period of performance: December 6, 2025 – December 5, 2026

Product Service Code (PSC): DA01 for all items unless otherwise noted.

Contract

Line- Item Number

(CLIN)

Description Part

Number Quantity

(Qty) Unit Unit Price Total Price

Subscription - Instrument Trac

All Sites

SUT301R 9

EACH

(EA)

Subscription Renewal - Censitrac GOV Cloud Server

All Sites

CSGOV 9 EA $ $

Subscription Renewal-Service +

All Sites

MSGL01b 9 EA $ $

ScopeTrac Stand Advanced Subscription Renewal

Sites: Erie, Wilmington, Philadelphia, Altoona, Lebanon, Wilkes Barre, and Pittsburgh

SUBST02R 7 EA $ $

Subscription Renewal - LoanerLink

Sites: Philadelphia, Pittsburgh, Lebanon

SUBLL01b 3 EA $ $

Base Period Total $

Option Period One

This 12-month option period may be exercised in accordance with (IAW) FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of the Base Period.

Period of performance: December 6, 2026 – December 5, 2027

PSC: DA01 for all items unless otherwise noted.

CLIN Description Part

Number Qty Unit Unit Price Total Price

Subscription-Instrument Trac

All Sites

SUT301R 9 EA $ $

Subscription Renewal - Censitrac GOV Cloud Server

All Sites

CSGOV 9 EA $ $

Subscription Renewal-Service +

All Sites

MSGL01b 9 EA $ $

ScopeTrac Stand Advanced Subscription Renewal

Sites: Erie, Wilmington, Philadelphia, Altoona, Lebanon, Wilkes Barre, and Pittsburgh

SUBST02R 7 EA $ $

Subscription Renewal - LoanerLink

Sites: Philadelphia, Pittsburgh, Lebanon

SUBLL01b 3 EA $ $

Option Period One Total $

Option Period Two

This 12-month option period may be exercised IAW FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of Option Period One.

Period of performance: December 6, 2027 – December 5, 2028

PSC: DA01 for all items unless otherwise noted

Line Item

Description Part

Number Qty Unit Unit Price Total Price

Subscription-Instrument Trac

All Sites

SUT301R 9 EA $ $

Summary:

Base Period $

Option Period One $

Option Period Two $

Grand Total $

Subscription Renewal - Censitrac GOV Cloud Server

All Sites

CSGOV 9 EA $ $

Subscription Renewal-Service +

All Sites

MSGL01b 9 EA $ $

ScopeTrac Stand Advanced Subscription Renewal

Sites: Erie, Wilmington, Philadelphia, Altoona, Lebanon, Wilkes Barre, and Pittsburgh

SUBST02R 7 EA $ $

Subscription Renewal - LoanerLink

Sites: Philadelphia, Pittsburgh, Lebanon

SUBLL01b 3 EA $ $

Option Period Two Total $

B.5 PRODUCT DESCRIPTION

PRODUCT DESCRIPTION (PD)

DEPARTMENT OF VETERANS AFFAIRS

Veterans Health Administration Veterans Integrated Services Network 4

CensiTrac Software Subscriptions and Maintenance Support Services

Date: November 20, 2025

VA-26-00007261

PD Version Number: 1.2

1.0 PRODUCT REQUIREMENTS

The Department of Veterans Affairs (VA), Veterans Integrated Service Network (VISN) 4 - Logistics Hub has a requirement for brand name CensiTrac software subscriptions with maintenance support services. CensiTrac Instrument Tracking Systems is a server-based software and database system used during processing of surgical instruments to track and document that all reprocessing steps were followed for all surgical instruments. It will provide surgical instrument tracking and documentation services for all VISN 4 Sterile Processing Services. To keep these systems fully functional and available for use, a software subscription and support agreement is required.

The Contractor shall provide standard CensiTrac Instrument Tracking System subscriptions and on-site staff training and support for the application in use at the following VISN 4 medical centers:

• Altoona VA Medical Center: 2907 Pleasant Valley Boulevard, Altoona, PA 16602

• VA Butler Healthcare: 353 North Duffy Road, Butler, PA 16001

• Coatesville VA Medical Center: 1400 Blackhorse Hill Road, Coatesville, PA 19320

• Erie VA Medical Center: 135 East 38th Street, Erie, PA 16504

• Wilmington VA Medical Center: 1601 Kirkwood Highway, Wilmington, DE 19805

• Lebanon VA Medical Center: 1700 South Lincoln Avenue, Lebanon, PA 17042

• Corporal Michael J. Crescenz VA Medical Center: 3900 Woodland Avenue, Philadelphia , PA 19104

• VA Pittsburgh Healthcare System: University Drive, Pittsburgh, PA 15240

• VA Hospital HJ Heinz Campus: 1010 Delafield Road, Pittsburgh, PA 15215

• Wilkes-Barre VA Medical Center: 1111 East End Boulevard, Wilkes-Barre, PA 18711

The period of performance shall be one, 12-month base period with two, 12-month option periods as follows:

Base Period: December 6, 2025 through December 5, 2026 Option Period One: December 6, 2026 through December 5, 2027 Option Period Two: December 6, 2027 through December 5, 2028

The Contractor shall provide the following in the base and option periods:

Description Part Number Quantity

Subscription - Instrument Trac SUT301R 9

Subscription - CensiTrac GOV Cloud Server

CSGOV 9

Subscription = Renewal- Service + MSGL01b 9

ScopeTrac Advanced Renewal SUBST02R 7

Subscription Renewal - Loaner Link SUBLL01b 3

1.1 SALIENT CHARACTERISTICS

• 24/7 Service Desk Support. The Contractor shall provide phone technical support 24 hours per day, 7 days per week excluding Government holidays. This includes software/technical support for CensiTrac functionality, troubleshooting help for supported hardware, general assistance with questions related to network connectivity and Information Technology (IT) related issues, and workflow process support related to CensiTrac usage.

• Dedicated Client Manager. The Contractor shall provide a Dedicate Client

Manager for each facility. The Client Manager will provide Client Management Business Reviews to review system utilization and make recommendations for effective use of CensiTrac system.

• Software Updates. The Contractor shall provide CensiTrac software releases generally available to CensiTrac installed customer base with CensiTrac support services.

• Access to Customer Portal. CensiTrac users at each facility shall have access to the Customer Support portal to include all documents and features generally available to CensiTrac installed customer base with CensiTrac support services.

• Censis University. Access to unlimited Live Event Training and Training Videos on Demand. Each site shall receive registration for two registrations for Censis Essentials for Management Courses including Continuing Education Units each period of performance.

2.0 NOTICE OF THE FEDERAL ACCESSIBILITY LAW AFFECTING ALL

INFORMATION AND COMMUNICATION TECHNOLOGY (ICT)

PROCUREMENTS (SECTION 508)

On January 18, 2017, the Architectural and Transportation Barriers Compliance Board (Access Board) revised and updated, in a single rulemaking, standards for electronic and information technology developed, procured, maintained, or used by Federal agencies covered by Section 508 of the Rehabilitation Act of 1973, as well as our guidelines for telecommunications equipment and customer premises equipment covered by Section 255 of the Communications Act of 1934. The revisions and updates to the Section 508-based standards and Section 255-based guidelines are intended to ensure that information and communication technology (ICT) covered by the respective statutes is accessible to and usable by individuals with disabilities.

2.1 SECTION 508 – INFORMATION AND COMMUNICATION

TECHNOLOGY (ICT) STANDARDS

The Section 508 standards established by the Access Board are incorporated into, and made part of all VA contracts, solicitations and purchase orders developed to procure ICT. These standards are found in their entirety at: Revised 508 Standards and 255 Guidelines (access-board.gov). A single PDF file version of the Revised Section 508 Standards and 255 Guidelines will be supplied upon request, or can be obtained from the Access Board website. Federal agencies must comply with the Rehabilitation Act of 1973, as amended.

The Contractor shall comply with “508 Chapter 2: Scoping Requirements” for all electronic ICT and content delivered under this contract. Specifically, as appropriate for the technology and its functionality, the Contractor shall comply with the technical standards marked here:

E205 Electronic Content – (Accessibility Standard -WCAG 2.0 Level A and AA Guidelines)

E204 Functional Performance Criteria E206 Hardware Requirements E207 Software Requirements E208 Support Documentation and Services Requirements

2.2 COMPATABILITY WITH ASSISTIVE TECHNOLOGY

The standards do not require installation of specific accessibility-related software or attachment of an assistive technology device. Section 508 requires that ICT be compatible with such software and devices so that ICT can be accessible to and usable by individuals using assistive technology, including but not limited to screen readers, screen magnifiers, and speech recognition software.

2.3 ACCEPTANCE AND ACCEPTANCE TESTING

Deliverables resulting from this solicitation will be accepted based in part on satisfaction of the Section 508 Chapter 2: Scoping Requirements standards identified above.

The Government reserves the right to test for Section 508 Compliance before delivery.

The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.

3.0 INFORMATION TECHNOLOGY USING SUSTAINABLE PRODUCTS AND

SERVICES

4.0 DELIVERY OF SOFTWARE

Inspection: Destination Acceptance: Destination Free on Board (FOB): Destination

Ship To and Mark For: Facility Biomed Departments https://www.access-board.gov/ict/ https://www.access-board.gov/ict/

The software shall be electronically delivered to the Facility Biomed Departments at the following sites:

Altoona VA Medical Center 2907 Pleasant Valley Blvd Altoona, PA 16602

POC:

Tammy Horne tammy.horne@va.gov

VA Butler Healthcare 353 N. Duffy Rd.

Butler, PA 16001

POC:

Diana Toy diana.toy@va.gov

Coatesville VA Medical Center 1400 Blackhorse Hill Road Coatesville, PA 19320

POC:

Joe Martin Joe.Martin2@va.gov

Erie VA Medical Center 135 East 38th Street Erie, PA 16504

POC:

Sherry Detrick sherry.detrick@va.gov

Wilmington VA Medical Center 1601 Kirkwood Hwy Wilmington, DE

POC:

Gerald Turlington gerald.turlington@va.gov

Lebanon VA Medical Center 1700 South Lincoln Avenue Lebanon, PA 17042

POC:

Nadine King Nadine.king@va.gov

Corporal Michael J. Crescenz VA Medical Center 3900 Woodland Avenue Philadelphia , PA 19104

POC:

Deannard Esnard Deannard.esnard2@va.gov

VA Pittsburgh Healthcare System University Drive Pittsburgh, PA 15240

POC:

Charlene Haynesworth charlene.haynesworth@va.gov

VA Hospital HJ Heinz Campus 1010 Delafield Rd.

Pittsburgh, PA 15215

POC:

Charlene Haynesworth charlene.haynesworth@va.gov

Wilkes-Barre VA Medical Center 1111 East End Blvd.

Wilkes-Barre, PA 18711

POC:

Tami Schiel tami.schiel@va.gov

5.0 GENERAL REQUIREMENTS

5.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall comply with the VA OIT Technical Reference Model (VA TRM).

Compliance with the VA TRM is achieved by using only technologies and standards that are listed as approved for use in the VA TRM. The Contractor shall provide all mailto:Nadine.king@va.gov necessary information requested by VA to ensure TRM approval is obtained prior to use on VA’s network.

5.2 ZERO TRUST – VA CRITICAL SECURITY CONTROLS

VA has established minimum mandatory security requirements and requires that any network connected software system or service must meet the VA Critical Security Controls as outlined in the VA Memorandum, “VA Security Controls”, https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010. VA Critical Security Controls identify the minimum mandatory requirements that must be implemented across all VA enterprise infrastructure, cloud computing environments, information systems, networks, and specialized devices (medical devices/systems, special-purpose systems, and research scientific computing devices) that process, store, and/or transmit VA data. Effective July 1, 2025, the Contractor shall implement these VA Critical Security Controls, within any network connected software system or service prior to being authorized for use in the VA. This functional requirement is not negotiable, and Plan of Action & Milestones (POAM) will not be accepted in the event these controls cannot be implemented for new systems. Critical Security Controls are intended to increase VA’s security posture and provide security and privacy risk visibility into the VA network and is not a new requirement. The Contractor’s failure to maintain these VA Critical Controls after implementation will result in VA discontinuing the use of the system.

5.3 SOCIAL SECURITY NUMBER (SSN) REDUCTION

The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the Integrated Control Number (ICN) in all VA information systems for all individuals. The Contractor shall ensure that all Contractor delivered applications and systems integrate with the VA Master Person Index (MPI) for identity traits to include the use of the ICN as the Primary Identifier. The Contractor solution may only use a Social Security Number to identify an individual in an information system if and only if the use of such number is required to obtain information VA requires from an information system that is not under the jurisdiction of VA.

5.4 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010 https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf file://///R04.med.va.gov/V03/EAS/Users/vhaeasWymbsk/TEMPLATES--NEW%20TAC%20PROCESS/PWS%20TEMPLATE%20(DO%20NOT%20TOUCH)%20-%20In%20Process%20Revisions/DO%20NOT%20TOUCH%20(next%20version/IPv6/(https:/www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1 file://///R04.med.va.gov/V03/EAS/Users/vhaeasWymbsk/TEMPLATES--NEW%20TAC%20PROCESS/PWS%20TEMPLATE%20(DO%20NOT%20TOUCH)%20-%20In%20Process%20Revisions/DO%20NOT%20TOUCH%20(next%20version/IPv6/(https:/www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1 https://doi.org/10.6028/NIST.SP.500-267Br1

(https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g.

web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

5.5 SOFTWARE AND LICENSING REQUIRMENTS

The Contractor shall be responsible for the provision of all software licenses and any associated licensing maintenance required for any development, delivery, integration, operation, and/or maintenance associated with its proposed application(s), software products, software solution, and/or system including, but not limited to, any and all application(s), software and/or software products that comprise, are a part of, or integrate with the Contractor’s proposed application(s), software products, software solution, and/or system for the life of any resulting contract.

5.6 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents.)

5.7 POSITION/TASK RISK DESIGNATION LEVEL(S)

6.0 INFORMATION SECURITY CONSIDERATIONS

All VA sensitive information shall be protected at all times in accordance with local security field office System Security Plans (SSP’s) and Authority to Operate (ATO)’s for all systems/LAN’s accessed while performing the tasks detailed in this Product Description.

7.0 POINTS OF CONTACT

Primary Contact:

Name: Benjamin Chang, Chief Healthcare Technology Manager Voice: 484-649-0107 Email: Benjamin.Chang@va.gov https://doi.org/10.6028/NIST.SP.800-119 https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf https://www.cisa.gov/publication/tic-30-core-guidance-documents

VA Program Manager:

Name: Heather Shimko Voice: 724-285-2256 Email: Heather.Shimko@va.gov

Contracting Officer:

Name: John Vardouniotis Address: 23 Christopher Way, Eatontown, NJ 07724 Voice: 848-377-5194 Email: ioannis.vardiouniotis@va.gov

Contract Specialist:

Name: Angela Key Address: 23 Christopher Way, Eatontown, NJ 07724 Voice: 848-377-5202 Email: angela.key@va.gov

ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/

PRIVACY LANGUAGE

NOTE: In the event of a conflict, VAAR Security Clauses take precedence over the language in this Addendum B.

APPLICABLE SECTIONS FROM: VA NOTICE 24-12, APRIL 22, 2024, UPDATE TO

VA HANDBOOK 6500.6, CONTRACT SECURITY, APPENDIX C VA INFORMATION

AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE, FOR INCLUSION

INTO CONTRACTS, AS APPROPRIATE

B1. GENERAL

This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, Subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.

B.2 VA INFORMATION CUSTODIAL LANGUAGE

a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this Contractor or order) is FAR 52.227-19, Commercial Computer Software License.

b. Information made available to the Contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The Contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

c. VA information will not be co-mingled with any other data on the Contractor’s information systems or media storage systems. The Contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of Contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The Contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to Contractor and Subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.

e. The Contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

f. The Contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contractor.

h. The Contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The Contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.

i. The Contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the Contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO.

The Contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.

k. Notwithstanding the provision above, the Contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the Contractor is in receipt of a court order or other requests for the above-mentioned information, the Contractor shall immediately refer such court order or other requests to the VA CO for response.

l. Information made available to the Contractor by VA for the performance or administration of this contract or information developed by the Contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.

m. Any data destruction done on behalf of VA by a Contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

n. The Contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the Contractor shall return all Federal Records to VA for disposition.

o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The Contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the Contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the Contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.)

used to store, process or access VA information will not be returned to the Contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

B3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

a. A Contractor/Subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of Contractor/Subcontractor and agent of Contractor/Subcontractor.

b. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

c. All Contractors and Subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

d. All Contractors and subcontractors shall comply with conditions specified in

VAAR 852.204-71(d); Contractor operations required to be in United States. All Contractors and Subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the Contractor must state where all non-U.S. services are provided. The Contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

e. The Contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

(1) Contractor/Subcontractor personnel no longer has a need for access to VA information or VA information systems.

(2) Contractor/Subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

(3) Contractor believes their own personnel or Subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes Contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

(4) Any previously undisclosed changes to Contractor/Subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

(5) Contractor/Subcontractor personnel have their authorization to work in the

United States revoked.

(6) Agreement by which Contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for Contractor personnel.

f. In such cases of contract fulfillment, termination, or other causes; the Contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by Contractor/Subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV – Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens.

Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

g. Contractors/Subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, Contractors shall notify the appropriate VA COR/CO.

B4. TRAINING

a. All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems:

(1) VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

(2) Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

(3) Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

b. The Contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

c. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

B5. SECURITY INCIDENT INVESTIGATION

a. The Contractor, Subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711).

The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the Contractor, Subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.

b. To the extent known by the Contractor/Subcontractor, the

Contractor/Subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:

(1) The date and time (or approximation of) the Security Incident occurred.

(2) The names of individuals involved (when applicable).

(3) The physical and logical (if applicable) location of the incident.

(4) Why the Security Incident took place (i.e., catalyst for the failure).

(5) The amount of data belonging to VA believed to have been compromised.

(6) The remediation measures the Contractor is taking to ensure no future incidents of a similar nature.

c. After the Contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The Contractor, Subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

d. VA IT Contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

e. In instances of theft or break-in or other criminal activity, the Contractor/Subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .