S02 36C10B26Q0621_Rapid_8.25.26_Final.pdf

PDF 837 KB Posted

Attached to
DA01--Rapid Enterprise Implementation Federal contract opportunity
Solicitation number
36C10B26Q0621
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This is a Request for Quote (RFQ) for the Rapid Enterprise Implementation – National Telestroke Program (NTSP), issued by the Department of Veterans Affairs Technology Acquisition Center on a sole-source basis to iSchemaView, Inc. The solicitation number is 36C10B26Q0621, with an offer due date of September 1, 2026 at 10:00 AM ET and an anticipated award date of September 15, 2026. The contract is valued at $47 million and structured as a firm fixed-price award with a base 12-month performance period and two optional 12-month extension periods. The Contractor shall provide the commercial Rapid platform solution deployed in the VA Enterprise Cloud (VAEC), including all software licenses, implementation services, system integration with VA imaging infrastructure, managed services sustainment, and project management to support up to 6,000 patients annually, with optional capacity for an additional 1,500 patients per period.

The implementation spans three phases over 90 days: Phase 1 (days 1-30) covers installation, configuration, secure connectivity, and DICOM destination setup; Phase 2 (days 31-60) includes vulnerability resolution, training, and connectivity testing; Phase 3 (days 61-90) encompasses end-user rollout, role-based access control configuration, mobile application deployment, and operational validation leading to go-live. Following implementation, the Contractor shall provide 24/7/365 technical support with severity-based response and resolution targets ranging from 1 hour to 3 business days, along with managed software services including system monitoring, updates, patches, upgrades, automated backup, and disaster recovery. The Contractor must comply with extensive cybersecurity, accessibility, privacy, and federal requirements including VA Critical Security Controls, FICAM authentication standards, IPv6 compliance, TIC 3.0 standards, and AI governance requirements. Additional deliverables include project management plans, weekly progress reports, training materials, technical documentation, and AI compliance attestations. All work shall be performed at Contractor facilities, with no government travel anticipated, and invoices submitted electronically in accordance with VA financial submission procedures.

View the file

Other files for this federal contract opportunity

Other files attached to DA01--Rapid Enterprise Implementation, newest first.
File Type Posted
36C10B26Q0621.docx DOCX document
Rapid JA-Redacted.pdf PDF
Attachment A - Artificial Intelligence Self Certification.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

640-26-3-401-0067

36C10B26Q0621 8-25-2026

Brendan Hopkins, Contract Specialist 1-848-377-5074 9-1-2026

10AM ET

36C10B Department of Veterans Affairs Office of Procurement Operations Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724

513210

$47 Million

N/A

X

See B.4 Schedule of Supplies/Services

36C10B

Department of Veterans Affairs Office of Procurement Operations Technology Acquisition Center

Department of Veterans Affairs Financial Services Center PO Box 149971 Austin TX 78714-8971 See website at: http://www.fsc.va.gov/einvoice.asp

877-353-9791

See CONTINUATION Page

Title - Rapid Enterprise Implementation - National Telestroke Program (NTSP)

Points of Contact:

CO: John Vardouniotis, ioannis.vardouniotis@va.gov CS: Brendan Hopkins, Brendan,Hopkins@va.gov

This is a firm fixed priced contract.

This solicitation is being issued on a sole source basis to iSchemaView, Inc.

See Continuation Page

See CONTINUATION Page

X X

John Vardouniotis Contracting Officer

Request for Quote 36C10B26Q0621 Rapid Enterprise Implementation - National Telestroke Program

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 GOVERNING LAW

B.3 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT

B.4 SCHEDULE OF SUPPLIES/SERVICES

B.5 PERFORMACNE WORK STATEMENT

SECTION C - CONTRACT CLAUSES

C.1 RFO 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.2 RFO 52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN

FEDERAL TRANSACTIONS (NOV 2025 DEVIATION)

C.3 RFO 52.209-6 PROTECTING THE GOVERNMENT'S INTEREST WHEN

SUBCONTRACTING WITH CONTRACTORS DEBARRED, SUSPENDED, PROPOSED

FOR DEBARMENT, OR VOLUNTARILY EXCLUDED (NOV 2025 DEVIATION)

C.4 RFO 52.217-7 OPTION FOR INCREASED QUANTITY—SEPARATELY PRICED

LINE ITEM (NOV 2025 DEVIATION)

C.5 RFO 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (NOV 2025

DEVIATION)

C.6 RFO 52.219-8 UTILIZATION OF SMALL BUSINESS CONCERNS (NOV 2025

DEVIATION)

C.7 VAAR 852.204.71 INFORMATION AND INFORMATION SYSTEMS SECURITY

(FEB 2023)

C.8 VAAR 852.211-76 LIQUIDATED DAMAGES-REIMBURSEMENT FOR DATA

BREACH COSTS (FEB 2023)

C.9 VAAR 852.222-71 COMPLIANCE WITH EXECUTIVE ORDER 13899

(DEVIATION) (APR 2025)

C.10 VAAR 852.239-76 INFORMATION AND COMMUNICATION TECHNOLOGY

ACCESSIBILITY (FEB 2023)

C.11 VAAR 852.240-70 COMPLIANCE WITH PUBLIC LAW 119-37, SECTION 258

(MAR 2026)(DEVIATION)

C.12 ARTIFICIAL INTELLIGENCE IN VA CONTRACTS

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 RFO 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

E.2 RFO 52.216-1 TYPE OF CONTRACT (NOV 2025 DEVIATION)

E.3 RFO 52.233-2 SERVICE OF PROTEST (NOV 2025 DEVIATION)

E.4 BASIS OF AWARD

E.5 SUBMISSION INSTRUCTIONS

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: iSchemaView, Inc.

405 El Camino Real, Suite 601

Menlo Park, CA 94025

b. GOVERNMENT: Contracting Officer 36C10B

Department of Veterans Affairs Technology Acquisition Center

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System for

Award Management, or [ ] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly [ ]

b. Semi-Annually [ ]

c. Other [x - In accordance with B.4 Schedule of Supplies/Services]

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VA Acquisition Regulation (VAAR) Clause 852.232-72 Electronic Submission of Payment Requests.

See website at: http://www.fsc.va.gov/einvoice.asp

5. ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NUMBER DATE

http://www.fsc.va.gov/einvoice.asp

B.2 GOVERNING LAW

Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order;

those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), Source Code Harmonization and Reuse in Information Technology Act “SHARE IT Act” (P.L.

118-187), and FAR clauses 52.212-4, 52.227-14 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14, this includes any custom code developed for the purpose of performing under this contract. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.

B.3 SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT

1. Definitions.

a. Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs

(“VA”) and is synonymous with “Government.”

b. Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired. The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.

c. Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.

d. Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions, and upgrades, as further defined below.

e. Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.

f. Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements, or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.

g. Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).

2. Software License.

a. Unless otherwise stated in the Schedule of Supplies/Services, the Performance

Work Statement, or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.

b. The Government may use the software in a networked environment.

c. All limitations of software usage are expressly stated in the Schedule of

Supplies/Services and the Performance Work Statement/Product Description.

d. The commercial computer software delivered under this contract may not be used, reproduced, or disclosed by the Government except as provided below or as expressly stated otherwise in this contract. The commercial computer software may be-

i. Used or copied for use with the computer(s) for which it was acquired, including use at any Government installation or agency to which the computer(s) may be transferred;

ii. Used or copied for use with a backup computer if any computer for which it was acquired is inoperative;

iii. Reproduced for safekeeping (archives) or backup purposes;

iv. Modified, adapted, or combined with other computer software;

v. Disclosed to and reproduced for use by support service Contractors or their subcontractors, subject to the same restrictions set forth in this contract; and

vi. Used or copied for use with a replacement computer.

e. Unauthorized Obligations.

i. Except as stated in paragraph (ii), when any supply or service acquired under this contract is subject to any commercial supplier agreement (as defined in 502.101) that includes any language, provision, or clause requiring the Government to pay any future fees, penalties, interest, legal costs or to indemnify the Contractor or any person or entity for damages, costs, fees, or any other loss or liability that would create an Anti-Deficiency Act violation ( 31 U.S.C. 1341), the following shall govern:

1. Any such language, provision, or clause is unenforceable against the Government.

2. Neither the Government nor any Government authorized end user shall be deemed to have agreed to such clause by virtue of it appearing in the commercial supplier agreement. If the commercial supplier agreement is invoked through an “I agree” click box or other comparable mechanism (e.g., “click-wrap” or “browse-wrap” agreements), execution does not bind the Government or any Government authorized end user to such clause.

3. Any such language, provision, or clause is deemed to be stricken from the commercial supplier agreement.

ii. Paragraph (u)(1) of this clause does not apply to indemnification or any other payment by the Government that is expressly authorized by statute and specifically authorized under applicable agency regulations and procedures.

f. Commercial supplier agreements unenforceable clauses.

i. This agreement is a part of a contract between the commercial supplier and the U.S. Government for the acquisition of the supply or service that necessitates a license or other similar legal instrument (including all contracts, task orders, and delivery orders under FAR 12).

ii. End user. This agreement shall bind the ordering activity as end user but shall not operate to bind a Government employee or person acting on behalf of the Government in his or her personal capacity.

iii. Law and disputes. This agreement is governed by Federal law. Any language purporting to subject the U.S. Government to the laws of a U.S. state, U.S. territory, district, or municipality, or a foreign nation, except where Federal law expressly provides for the application of such laws, is hereby deleted.

1. Any language requiring dispute resolution in a specific forum or venue that is different from that prescribed by applicable Federal law is hereby deleted. Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(e).

2. Any language prescribing a different time period for bringing an action https://www.acquisition.gov/gsam/part-502#GSAM_502_101 http://uscode.house.gov/browse.xhtml%3Bjsessionid%3D114A3287C7B3359E597506A31FC855B3 than that prescribed by applicable Federal law in relation to a dispute is hereby deleted.

3. Continued performance. The supplier or licensor shall not unilaterally revoke, terminate, or suspend any rights granted to the Government except as allowed by this contract. If the supplier or licensor believes the ordering activity to be in breach of the agreement, it shall pursue its rights under the Contract Disputes Act or other applicable Federal statute while continuing.

4. Arbitration; equitable or injunctive relief. In the event of a claim or dispute arising under or relating to this agreement, a binding arbitration shall not be used unless specifically authorized by agency guidance, and equitable or injunctive relief, including the award of attorney fees, costs or interest, may be awarded against the U.S. Government only when explicitly provided by statute (e.g., Prompt Payment Act or Equal Access to Justice Act).

iv. Updating terms. After award, the contractor may unilaterally revise commercial supplier agreement terms if they are not material. A material change is defined as:

1. Terms that change Government rights or obligations;

2. Terms that increase Government prices;

3. Terms that decrease overall level of service; or

4. Terms that limit any other Government right addressed elsewhere in this contract.

5. For revisions that will materially change the terms of the contract, the revised commercial supplier agreement must be incorporated into the contract using a bilateral modification.

6. Any agreement license terms or conditions unilaterally revised subsequent to award that are inconsistent with any material term or provision of this contract shall not be enforceable against the Government, and the Government shall not be deemed to have consented to them.

v. No automatic renewals. If any license or service tied to periodic payment is provided under this agreement (e.g., annual software maintenance or annual lease term), such license or service shall not renew automatically upon expiration of its current term without prior express consent by an authorized Government representative.

vi. Indemnification. Any clause of this agreement requiring the commercial supplier or licensor to defend or indemnify the end user is hereby amended to provide that the U.S. Department of Justice has the sole right to represent the United States in any such action, in accordance with 28 U.S.C. 516.

vii. Audits. Any clause of this agreement permitting the commercial supplier or licensor to audit the end user's compliance with this agreement is hereby amended as follows:

1. Discrepancies found in an audit may result in a charge by the commercial supplier or licensor to the ordering activity. Any resulting invoice must comply with the proper invoicing requirements specified in the underlying Government contract or order.

2. This charge, if disputed by the ordering activity, will be resolved in accordance with FAR 52.212-4(e); no payment obligation shall arise on the part of the ordering activity until the conclusion of the dispute process.

3. Any audit requested by the contractor will be performed at the contractor's expense, without reimbursement by the Government.

3. Software Maintenance and/or Technical Support.

a. If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.

b. The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers to cause the software to perform according to its specifications, documentation or demonstrated claims.

c. Any telephone support provided by Contractor shall be at no additional cost.

d. The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding two business days) in resolving software problems will be noted in the

Government’s various past performance records on the Contractor (e.g.,www.cpars.gov).

e. If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.

4. Disabling Software Code.

The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out, or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and https://www.acquisition.gov/gsam/part-552#GSAM_552_212_4 http://www.cpars.gov/ the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.

5. Manuals and Publications.

Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no cost.

B.4 SCHEDULE OF SUPPLIES/SERVICES

Any resulting contract will be awarded on a firm-fixed-price basis as defined by Federal Acquisition Regulation (FAR) Subpart 16.202. Accordingly, the Contractor shall ensure that any and all costs associated with the Contractor’s proposed application(s), software products, software solution, and/or system, shall be included in the Contractor’s proposed firm-fixed price, and shall serve as the Contractor’s firm-fixed price for the life of any resulting contract. No additional costs or fees relative to the Contractor’s proposed application(s), software products, software solution, and/or system including, but not limited to, licensing costs and any associated licensing maintenance required for the development, delivery, integration, operation, and/or maintenance of the Contractor’s proposed solution will be allowed, accepted, and/or paid by the Government.

NOTE: Respondents are instructed to complete Section B.4 below and submit with its quote. Respondents are cautioned that alterations to the line items as specified below will not be accepted and may render its quote unacceptable.

Inspection/Acceptance: Destination Electronic Submission to: Contracting Officer (CO), Contracting Officer’s Representative (COR), and VA Project Manager (PM)

Base Period

The period of performance shall be 12 months from the date of award.

Product Service Code (PSC): DA10 for all Contract Line-Item Numbers(CLIN)/Sub-Line Item Numbers (SLIN)

CLIN/SLIN Description Quantity Unit Unit Price Total Price

0001 Project Management In accordance with (IAW) Performance Work Statement (PWS) Sections 5.1 and 7.2.2, and all subsections.

Firm Fixed Price (FFP)

This CLIN includes all labor, material, supplies, travel, and any other costs required for successful completion for the services detailed in PWS Section 5.1,

7.2.2 and all subsections.

The price of this CLIN shall be included in the priced line items.

12 Months

(MO)

Not Separately

Priced (NSP)

NSP

0001AA Deliverable Contractor Project Management Plan

IAW PWS 5.1.1

Due 30 days after contract award and updated monthly thereafter.

1 Lot

(LT)

NSP NSP

0001AB Deliverable Weekly Progress Report

IAW PWS 5.1.2

Due by the 5th calendar day of each month throughout the PoP.

1 LT NSP NSP

0001AC Deliverable Technical Kickoff Meeting Agenda, Presentation, and Minutes

IAW PWS 5.1.3

Draft Agenda due at least five business days prior to the meeting.

Final Kickoff Meeting Presentation due within three business days of Kickoff Meeting

0001AD Deliverable AI Statement of Attestation

IAW PWS 7.1.12

Due three days after CO Authorization for use of AI and at a minimum annually thereafter (submitted prior to the exercise of any option periods), and at COR request, and upon the Contractor’s proposed use of any new AI tools not contemplated at the time of last reporting.

0001AE Deliverable AI System/LLM Development and Operation Documentation Package

IAW PWS 7.1.12.1

Due 15 days after award and updated Annually Thereafter as revisions require.

0001AF Deliverable AI Compliance Monitoring and Reporting Plan

IAW PWS 7.1.12.2

Due 30 days after award.

0001AG Deliverable AI Corrective Action Plan

IAW PWS 7.1.12.2

Due 10 business days after identification of any deviation of AI Principles.

0001AH Deliverable AI Model/LLM Change Disclosure

IAW PWS 7.1.12.3

Due 30 days prior to implementation of change

0001AJ Deliverable Contractor Staff Roster

IAW PWS 7.2.2.

Due three days after award, updated within five working days after each calendar quarter, and updated within one business day of any personnel change throughout the PoP.

0002 Rapid Enterprise Platform License In accordance with (IAW) Performance Work Statement (PWS) section 5.2, 5.3,

5.4 and all subsections.

Inclusive of all modules (PWS Table 1), all Rapid Workflow features (PWS Table 2), Technical Support (PWS 5.3), and Managed Software Services (PWS 5.4);

up to 6,000 patients/year.

1 Each

(EA)

0003 Implementation - Phase One IAW PWS section 5.2 and 5.2.1.

Installation and Configuration (VAEC install/config, first DICOM destination, secure connectivity, mobile app plan, Phase 1 deliverables); accepted at Phase 1 go/no-go

Completion within 30 days of award.

1 LT $ $

0003AA Deliverable Mobile Application Install and Configuration Plan and Configured Mobile Application

IAW PWS 5.2.1

Due within 10 days of award.

0003AB Deliverable Rapid Installation Documentation

Due within 30 days of award

0003AC Deliverable Secure Connectivity and VA Imaging Infrastructure Integration Documentation

0003AD Deliverable DICOM Destination Documentation

0004 Implementation - Phase Two IAW PWS sections 5.2 and 5.2.2.

Vulnerability Resolution, Training, Connectivity Testing and Validation (OIT vulnerability remediation, superuser/end-user training, DICOM routing proof, VAEC server configuration instructions, Rapid Insights dashboards); accepted at Phase 2 go/no-go.

Due within 60 days of award.

1 LT $ $

0004AA Deliverable Superuser and End-user Training Materials

IAW PWS 5.2.2

Due within 60 days of award.

1 LT NSP NSP

0004AB Deliverable Configuration Instructions for the VAEC Rapid Server

IAW PWS 5.2.2

Due within 60 days of award.

1 LT NSP NSP

0005 Implementation - Phase Three IAW PWS 5.2 and 5.2.3.

Training Support, Mobile App Deployment Support, RBAC, and Validation of Operation; culminates in Operational Go- Live by Day 90; accepted at Phase 3 go/no-go

Due within 90 days of award.

1 LT $ $

0005AA Deliverable Instructions for Setting Role-Based Access Control for New End-Users

IAW PWS 5.2.3

Due within 90 days of award.

1 LT NSP NSP

0005AB Deliverable Escalation Process for Issue Resolution Document

IAW PWS 5.2.3

Due within 90 days of award.

Base Period Total $

Base Period Optional Task

This optional task may be exercised in accordance with FAR 52.217-7 Option for Increased Quantity- Separately Priced Line Item. The Government may exercise the optional tasks multiple times, at any time during the base period up to the Not-to-Exceed (NTE) quantities. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

PSC: DA10

CLIN Description Quantity Unit Unit Price Total Price

Optional Task - Additional Quantities for the Base Period IAW PWS section 6.1

This optional task provides additional patient capacity, inclusive of all Products & Modules of PWS Tables 1 and 2.

NTE

1,500

EA $ $

Base Period Optional Task Total $

Base Period Total inclusive of Optional Task $

Option Period One

This option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term of the Contract.

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of the Base Period.

1001 Project Management IAW PWS Sections 5.1 and 7.2.2, and all subsections.

FFP

This CLIN includes all labor, material, supplies, travel, and any other costs required for successful completion for the services detailed in PWS Section 5.1,

7.2.2 and all subsections.

The price of this CLIN shall be included in the priced line items.

12 MO NSP NSP

1001AA Deliverable Contractor Project Management Plan

IAW PWS 5.1.1

Updated monthly.

1001AB Deliverable Weekly Progress Report

IAW PWS 5.1.2

Due by the 5th calendar day of each month throughout the PoP.

1001AC Deliverable AI Statement of Attestation

IAW PWS 7.1.12

Due three days after CO Authorization for use of AI and at a minimum annually thereafter (submitted prior to the exercise of any option periods), and at COR request, and upon the Contractor’s proposed use of any new AI tools not contemplated at the time of last reporting.

1001AD Deliverable AI System/LLM Development and Operation Documentation Package

IAW PWS 7.1.12.1

Due 15 days after award and updated Annually Thereafter as revisions require.

1001AE Deliverable AI Compliance Monitoring and Reporting Plan

IAW PWS 7.1.12.2

Due 30 days after award.

1001AF Deliverable AI Corrective Action Plan

IAW PWS 7.1.12.2

Due 10 business days after identification of any deviation of AI Principles.

1001AG Deliverable AI Model/LLM Change Disclosure

IAW PWS 7.1.12.3

Due 30 days prior to implementation of change

1001AH Deliverable Contractor Staff Roster

IAW PWS 7.2.2.

Updated within five working days after each calendar quarter, and updated within one business day of any personnel change throughout the PoP.

1002 Rapid Enterprise Platform License IAW PWS sections 5.3, 5.4, 6.2 and all subsections.

Inclusive of all modules (PWS Table 1), all Rapid Workflow features (PWS Table 2), Technical Support (PWS 5.3), and Managed Software Services (PWS 5.4);

up to 6,000 patients/year.

1 EA $ $

Option Period One Total $

Option Period One Optional Task

Separately Priced Line Item. The Government may exercise the optional tasks multiple times, at any time during the base period up to the NTE quantities. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

Optional Task - Additional Quantities for Option Period One IAW PWS section 6.2.1

This optional task provides additional patient capacity, inclusive of all Products & Modules of PWS Tables 1 and 2.

NTE

1,500

EA $ $

Option Period One Optional Task Total $

Option Period One Total inclusive of Optional Task $

Option Period Two

This option may be exercised in accordance with FAR 52.217-9, Option to Extend the Term of the Contract.

Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer. If exercised, this option shall commence immediately after expiration of Option Period One.

2001 Project Management IAW PWS Sections 5.1 and 7.2.2, and all subsections.

FFP

This CLIN includes all labor, material, supplies, travel, and any other costs required for successful completion for the services detailed in PWS Section 5.1, 7.2.2

12 MO NSP NSP

and all subsections.

The price of this CLIN shall be included in the priced line items.

2001AA Deliverable Contractor Project Management Plan

IAW PWS 5.1.1

Updated monthly.

1 LT NSP NSP

2001AB Deliverable Weekly Progress Report

IAW PWS 5.1.2

Due by the 5th calendar day of each month throughout the PoP.

1 LT NSP NSP

2001AC Deliverable AI Statement of Attestation

IAW PWS 7.1.12

Due three days after CO Authorization for use of AI and at a minimum annually thereafter (submitted prior to the exercise of any option periods), and at COR request, and upon the Contractor’s proposed use of any new AI tools not contemplated at the time of last reporting.

1 LT NSP NSP

2001AD Deliverable AI System/LLM Development and Operation Documentation Package

IAW PWS 7.1.12.1

Due 15 days after award and updated annually thereafter as revisions require.

1 LT NSP NSP

2001AE Deliverable AI Compliance Monitoring and Reporting Plan

IAW PWS 7.1.12.2

Due 30 days after award.

1 LT NSP NSP

2001AF Deliverable AI Corrective Action Plan

IAW PWS 7.1.12.2

Due 10 business days after identification of any deviation of AI Principles.

1 LT NSP NSP

2001AG Deliverable AI Model/LLM Change Disclosure

IAW PWS 7.1.12.3

Due 30 days prior to implementation of change.

1 LT NSP NSP

2001AH Deliverable Contractor Staff Roster

IAW PWS 7.2.2.

Summary:

Base Period $ Base Period Optional Task $ Option Period One $ Option Period One Optional Task $ Option Period Two $ Option Period Two Optional Task $ Contract Total $

Updated within five working days after each calendar quarter, and updated within one business day of any personnel change throughout the PoP.

2002 Rapid Enterprise Platform License IAW PWS sections 5.3, 5.4, 6.3 and all subsections.

Inclusive of all modules (PWS Table 1), all Rapid Workflow features (PWS Table 2), Technical Support (PWS 5.3), and Managed Software Services (PWS 5.4); up to 6,000 patients/year.

1 EA $ $

Option Period Two Total $

Option Period Two Optional Task

Separately Priced Line Item. The Government may exercise the optional tasks multiple times, at any time during the base period up to the NTE quantities. Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer.

Optional Task - Additional Quantities for Option Period Two IAW PWS section 6.3.1

This optional task provides additional patient capacity, inclusive of all Products & Modules of PWS Tables 1 and 2.

NTE

1,500

EA $ $

Option Period Two Optional Task Total $

Option Period Two Total inclusive of Optional Task $

B.5 PERFORMANCE WORK STATEMENT

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Veterans Health Administration (VHA) National Telestroke Program (NTSP)

Rapid Enterprise Implementation

Date: August 25, 2026

VA-26-00060052

Version: 5.0

1.0 BACKGROUND

The Department of Veterans Affairs, National Telestroke Program (NTSP), established in 2016, provides 24/7/365 access to expert vascular neurology consultation for rural and underserved Veterans. The clinical stakes are high: approximately 2 million neurons die each minute following a stroke, making rapid diagnosis and treatment the difference between recovery and permanent disability or death.

Since launching services in 2017, the program has grown to serve 43 states and territories (including San Juan, Puerto Rico), with 81 VA facilities currently enrolled as Telestroke sites and continuing to grow. To date, NTSP has served approximately 4.57 million Veterans across these facilities. A Veteran's ZIP code does not determine the quality of emergency stroke care they receive. NTSP depends on the immediate availability of acute stroke imaging so neurologists can make rapid, accurate treatment decisions. The current imaging workflow does not reliably meet this standard.

NTSP leverages real-time videoconferencing to connect bedside care teams with vascular neurologists, enabling specialists to conduct live neurological examinations at the patient's bedside via telehealth review and emergent radiological imaging (e.g., CT scans). This approach provides immediate diagnosis and evidence-based treatment recommendations and documents consultation notes directly into the local VA medical record. This model consistently delivers expert consultation more expeditiously than traditional in-house neurology, making it especially vital for facilities that lack on-site stroke specialists.

Rapid is currently deployed and operating within the VA environment under a current Authority to Operate (ATO) and is integrated with VA imaging and telehealth infrastructure. This effort provides for the continued licensing, sustainment, and enterprise-wide expansion of that existing deployment across additional NTSP Telestroke sites during the period of performance.

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. “Federal Information Security Modernization Act of 2014”

2. Federal Information Processing Standards (FIPS) Publication 140-3, “Security Requirements for Cryptographic Modules”, March 22, 2019

3. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

4. FIPS Pub 200, “Minimum Security Requirements for Federal Information and

Information Systems,” March 2006

5. FIPS Pub 201-3, “Personal Identity Verification of Federal Employees and

Contractors,” January 2022

6. 10 U.S.C. § 2224, "Defense Information Assurance Program", as amended

7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

8. Public Law 109-461 (P.L. 109-461), Veterans Benefits, Health Care, and

Information Technology Act of 2006, as amended, Title IX, Information Security Matters

9. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”, as amended

10. VA Directive 0710, “Personnel Vetting Program,” September 8, 2025, https://www.va.gov/vapubs/index.cfm

11. VA Handbook 0710, “Personnel Vetting Program,” September 8, 2025, https://www.va.gov/vapubs/index.cfm

12. VA Directive 6102, “Internet/Intranet Services,” August 5, 2019

13. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” as amended

14. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

15. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)”, as amended

16. NIST SP 800-66 Rev. 2, “Implementing the Health Insurance Portability and

Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide,” February 2024

17. 45 C.F.R Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”); and 45 C.F.R.

Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”); as amended

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (see VA

NOTICE 24-18, dated September 27, 2024, “Update to VA Directive 6500 Cybersecurity Program”, and VA Notice 25-07, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”)

21. VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021 (see VA Notice 25-01, dated October 15, 2024, “Update to VA Handbook 6500 Risk Management Framework for VA Information Systems VA Information Security Program”, and VA Notice 25-06, dated 3/18/25, “Amending VA Directive 6500 to incorporate M-24-15”, VA Notice 25-16, dated September 15, 2025, “Amending VA Handbook 6500 to Replace Enterprise Mission Assurance Support Services Tool With Office of Information Technology Governance Risk Compliance Tool, and VA Notice 25-17, dated September 22, 2025, “Rescission Of Office Of Information Security (OIS) Deputy Assistant Secretary (DAS) Memorandum – Requirements of Proper Plan of Action and Milestones (POA&M) Completion)

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” June 30, 2023

23. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (see VA Notice 24-12, dated April 22, 2024, “Update to VA Handbook 6500.6, Contract Security, Appendix C VA Information and Information System Security/Privacy Language For Inclusion Into Contracts, As Appropriate”)

24. VA Handbook 6500.8, “Information System Contingency Planning,” March 25, 2025 https://www.va.gov/vapubs/index.cfm https://www.va.gov/vapubs/index.cfm http://www.va.gov/vapubs http://www.va.gov/vapubs

25. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018 (see VA NOTICE 25-10, dated June 9, 2025, “Use of Personally Owned Mobile Devices Policy Amendment of Department of Veterans Affairs Handbook 6500.10”, and VA Notice 25-15, dated August 22, 2025, “Update to VA Handbook 6500.10 Mobile Device Security Policy”)

26. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

27. OIT Process Asset Library (PAL), OIT Process Asset Library.

28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and

Privacy Impact Assessment,” October 15, 2014

30. VA Directive 6510, “VA Identity, Credential and Access Management,”

September 3, 2024

31. VA Handbook 6510, “VA Identity, Credential and Access Management,”

September 27, 2024

32. VA Directive and Handbook 6513, “Secure External Connections,” October

12, 2017

33. VA Directive 6300, “Records and Information Management,” September 21,

34. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

35. NIST SP 800-37 Rev 2, “Risk Management Framework for Information

Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

36. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

37. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

38. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-

12) Program,” March 24, 2014

39. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

40. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

41. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

42. Federal Identity, Credential, and Access Management (FICAM) Architecture, June 30, 2023 (FICAM Architecture (idmanagement.gov))

43. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

44. NIST SP 800-63 Rev 4, 800-63A-4, 800-63B-4, 800-63C-4, “Digital Identity Guidelines,” August 1, 2025

45. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

46. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland

Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514) https://digital.va.gov/process-asset-library/ https://www.va.gov/trm/TRMHomePage.aspx https://www.idmanagement.gov/arch/#:%7E:text=FICAM%20is%20the%20federal%20government%E2%80%99s%20enterprise%20approach%20to,identity%20processes%2C%20practices%2C%20policies%2C%20and%20information%20security%20disciplines.

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514

47. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

48. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

49. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

50. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

51. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

52. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (P.L. 110–140), December 19, 2007

53. Section 104 of the Energy Policy Act of 2005, (P.L. 109–58), August 8, 2005

54. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August

2, 2001

55. Executive Order 14148, “Initial Rescissions of Harmful Executive Orders and

Actions,” dated January 20, 2025

56. VA Directive 0057, “VA Environmental Management Program,” October 25,

57. OIS VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

58. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

59. “Veteran Focused Integration Process (VIP) Guide 4.0,” March 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

60. VA Memorandum “Proper Use of Email and Other Messaging Services,”

January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

61. “Product Line Management Transformation Playbook” version 3.1, August 2023, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

62. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

63. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol

Version 6 (IPv6),” November 19, 2020

64. Social Security Number (SSN) Fraud Prevention Act of 2017

65. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23,

66. C.F.R Title 15 Part 7, “Securing the Information and Communications

Technology and Services (ICTS) Supply Chain”, as amended

67. Executive Order 14028, “Executive Order on Improving the Nation's

Cybersecurity,” May 12, 2021, https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/

68. OMB Memorandum M-22-09, “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles”, January 26, 2022, https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf.

https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.cisa.gov/publication/tic-30-core-guidance-documents https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946 https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://bidenwhitehouse.archives.gov/briefing-room/presidential-actions/2025/01/16/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf

69. NIST SP 800-52 Revision 2, “Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations

70. OMB M-26-05, “Adopting a Risk-based Approach to Software and Hardware Security,” January 23, 2026

71. OMB M-21-31, “Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents,” August 27,

72. NIST SP 800-88 Revision 1 “Guidelines for Media Sanitization,” December

73. CISA Binding Operational Directive (BOD) 19-02: “Vulnerability Remediation Requirements of Internet-Accessible Systems,” April 29, 2019, BOD 19-02:

Vulnerability Remediation Requirements for Internet-Accessible Systems |

CISA

74. CISA BOD 22-01: “Reducing the Significant Risk of Known Exploited Vulnerabilities,” November 3, 2021, BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities | CISA

75. CISA BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks.” Cybersecurity & Infrastructure Security Agency (CISA), BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks | CISA

76. VA Directive 6550, Pre-Procurement Assessment and Implementation of Medical Devices/Systems, June 03, 2019

77. VA Memorandum, “VA Security Controls,” January 17, 2025, https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010

78. E.O. 13960, “Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government,” December 3, 2020

79. E.O. 14319, “Preventing Woke AI in the Federal Government,” July 23, 2025

80. OMB Memorandum M-25-21, “Accelerating Federal Use of AI through

Innovation, Governance, and Public Trust,” April 3, 2025

81. OMB Memorandum M-25-22, “Driving Efficient Acquisition of Artificial

Intelligence in Government,” April 3, 2025

82. OMB Memorandum M-26-04, “Increasing Public Trust in Artificial Intelligence

(AI) Through Unbiased AI Principles,” December 11, 2025

83. VA Directive 6066, “Protected Health Information (PHI) And Business

Associate Agreements Management”, September 2, 2014

3.0 SCOPE OF WORK

The Contractor shall provide the Rapid platform solution in the VA Enterprise Cloud (VAEC), all required software licenses, implementation services; system integration with VA imaging infrastructure; managed services sustainment; and project management.

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The Period of Performance (PoP) shall be one 12-month base period with two 12-month option periods with optional tasks to add patient capacity to support program growth.

https://www.cisa.gov/news-events/directives/bod-19-02-vulnerability-remediation-requirements-internet-accessible-systems https://www.cisa.gov/news-events/directives/bod-19-02-vulnerability-remediation-requirements-internet-accessible-systems https://www.cisa.gov/news-events/directives/bod-19-02-vulnerability-remediation-requirements-internet-accessible-systems https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks https://www.voa.va.gov/DocumentView.aspx?DocumentID=5010…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .