S02 - 36C26226Q0493.pdf

PDF 1 MB Posted

Attached to
6515--Omnicell Equipments Federal contract opportunity
Solicitation number
36C26226Q0493
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 22

About this file

This is a Request for Quotation (RFQ) for Omnicell pharmacy and anesthesia equipment and related services for the Department of Veterans Affairs Southern Arizona VA Health Care System in Tucson, Arizona.

The solicitation seeks brand-name Omnicell equipment or equal alternatives, including 16 anesthesia workstation units with associated components (drawers, organizers, scanners, printers, and wireless upgrades), five MED 1-Cell pharmacy cabinets, one MED 2-Cell pharmacy cabinet, 56 metal locking drawers, 62 external return bins, and six XT FlexLock units with installation. A 120-month software subscription for Premium Windows 10 packages is also required. All equipment must be fully compatible with the facility's existing Omnicell enterprise server environment and Electronic Health Record system, with secure encrypted communication protocols compliant with federal cybersecurity requirements. Offerors must submit completed quotes by May 1, 2026, at 10:00 a.m. PST to Sam.choo@va.gov in PDF format. All offerors must be registered in SAM.gov and include their UEI number. The procurement is unrestricted and open to all eligible contractors. Award will be made on a firm-fixed-price basis to the lowest-priced responsive offeror meeting all technical requirements. Offerors must provide OEM authorization letters dated within 90 days of the quote deadline and demonstrate clear evidence of meeting all solicitation requirements, including VA information security, cybersecurity, and data protection standards outlined in extensive contract security clauses.

View the file

Other files for this federal contract opportunity

Other files attached to 6515--Omnicell Equipments, newest first.
File Type Posted
36C26226Q0493_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

678-26-2-071-0079

36C26226Q0493 04-16-2026

Choo, Sam 562-766-2337 05-01-2026

10:00 AM PDT

36C262

Department of Veterans Affairs

Network Contracting Office 22

4811 Airport Plaza Drive

Suite 600

Long Beach CA 90815

X

Y

339112

1000 Employees

NET 30

N/A

36C678

Department of Veterans Affairs

Southern Arizona VA Health Care System

Tucson Main Campus

3601 S 6’th Avenue (1-119)

Tucson AZ 85723

36C262

Department of Veterans Affairs

Network Contracting Office 22

4811 Airport Plaza Drive

Suite 600

Long Beach CA 90815

Department of Veterans Affairs

Financial Services Center

Submit invoices electronically to:

Tungsten Network

Tungsten support: 1-877-489-6135

This is a requirement for Omnicell Equipments in accordance with (IAW) B.2 and B.3.

The contractor shall show clear, and compelling evidence that meet all requirements of this solicitation.

This solicitation is Unrestricted, Full and Open market.

This contract type will be a FFP.

Award will be made IAW ADDENDUM to FAR 52.212-1 INSTRUCTIONS

TO OFFERORS – COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES, a

FAR 52.212-2 EVALUATION-COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES.

ALL quotes must be received by Friday, May 1, 2026, 10:00 AM PST.

All quotes must ensure to follow and meet E.2, detailed offer submission instruction.

There is no NMR Class Waiver under NAICS 339112.

FAC NUMBER 2025-06, EFFECTIVE DATE 10/01/2025

X 1

Anthony Dela Cruz

VA-VHA-RPOW-2024-0101

36C26226Q0493

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 SCOPE OF WORK

B.3 PRICE/COST SCHEDULE

ITEM INFORMATION

B.4 DELIVERY SCHEDULE

SECTION C - CONTRACT CLAUSES

C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (NOV 2023)

C.2 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)

(DEVIATION)

C.3 52.240-92 SECURITY REQUIREMENTS (DEVIATION) (NOV 2025)

C.4 52.240-93 BASIC SAFEGAURDING OF COVERED CONTRACTOR

INFORMATION SYSTEMS (DEVIATION) (NOV 2025)

C.5 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV

2018)

C.6 VAAR 852.242-71 ADMINISTRATIVE CONTRACTING OFFICER (OCT 2020) ... 43

C.7 VAAR 852.247-71 DELIVERY LOCATION (OCT 2018)

C.8 VAAR 852.247-73 PACKING FOR DOMESTIC SHIPMENT (OCT 2018)

C.9 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.10 52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS (NOV

2023)

C.11 52.204-13 SYSTEM FOR AWARD MANAGEMENT—MAINTENANCE

(DEVIATION) (NOV 2025)

C.12 VAAR 852.203-70 COMMERCIAL ADVERTISING (MAY 2018)

C.13 52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR

PERSONNEL (JAN 2011)

C.14 VAAR 852.204-70 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR

PERSONNEL (MAY 2020)

C.15 VAAR 852.204-71 INFORMATION AND INFORMATION SYSTEMS SECURITY

(FEB 2023)

C.16 VAAR 852.211-76 LIQUIDATED DAMAGES - REIMBURSEMENT FOR DATA

BREACH COSTS (FEB 2023)

C.17 VAAR 852.212-71 GRAY MARKET AND COUNTERFEIT ITEMS (FEB 2023) ... 56

C.18 VAAR 852.215-71 EVALUATION FACTOR COMMITMENTS (OCT 2019)

C.19 VAAR 852.222-71 COMPLIANCE WITH EXECUTIVE ORDER 13899

(DEVIATION)(APR 2025)

C.20 VAAR 852.246-71 REJECTED GOODS (OCT 2018)

C.21 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT

STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (OCT 2025) (DEVIATION FEB 2025)

C.22 52.225-5 TRADE AGREEMENTS (NOV 2023)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (SEP 2023)

E.2 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL

PRODUCTS AND COMMERCIAL SERVICES

E.3 52.201-1 ACQUISITION 360: VOLUNTARY SURVEY (SEP 2023)

E.4 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (OCT 2018)

E.5 52.216-1 TYPE OF CONTRACT (NOV 2025) (DEVIATION)

E.6 52.233-2 SERVICE OF PROTEST (SEP 2006)

E.7 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS

AND CERTIFICATIONS (NOV 2025) (DEVIATION)

E.8 VAAR 852.233-70 PROTEST CONTENT/ALTERNATIVE DISPUTE RESOLUTION

(OCT 2018)

E.9 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)

E.10 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

(FEB 1998)

E.11 52.204-7 SYSTEM FOR AWARD MANAGEMENT—REGISTRATION

(DEVIATION) (NOV 2025)

E.12 52.214-21 DESCRIPTIVE LITERATURE (APR 2002)

E.13 52.229-11 TAX ON CERTAIN FOREIGN PROCUREMENTS—NOTICE AND

REPRESENTATION (JUN 2020)

E.14 VAAR 852.215-72 NOTICE OF INTENT TO RE-SOLICIT (OCT 2019)

E.15 VAAR 852.239-75 INFORMATION AND COMMUNICATION TECHNOLOGY

ACCESSIBILITY NOTICE (FEB 2023)

E.16 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (NOV 2021)

E.17 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—

COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (OCT 2025) (DEVIATION

FEB 2025)

E.18 52.225-6 TRADE AGREEMENTS CERTIFICATE (FEB 2021)

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR: Company Name:

POC:

Phone:

Email:

b. GOVERNMENT: Contracting Officer 36C262 Anthony Dela Cruz

Department of Veterans Affairs

Network Contracting Office 22

4811 Airport Plaza Drive

Suite 600

Long Beach CA 90815

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X] Invoice for Supplies/Services – Upon Delivery andApproved receiving report of supplies/service.

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment

Requests.

Financial Services Center http://www.tungsten-network.com

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

C-1

B.2 SCOPE OF WORK

The Department of Veterans Affairs (VA) is seeking sources capable of providing Omnicell Equipments and related services OR EQUAL for Tucson VA Healthcare System.

1. Performance Monitoring

1.1. Pharmacy Service Line staff will ensure proper testing and functionality of the new Omnicell cabinets to ensure proper working order prior to accepting receipt of the items and services.

1.1.1. The vendor shall submit a cost proposal with an associated project management plan addressing the tasks associated with the SOW, as described in the evaluation criteria section.

1.1.1.1. Subtasks not specified in the SOW will be identified and include associated costs by project task, milestones and deliverable dates.

1.1.1.2. All written deliverables must be phrased in terms and language that can be easily understood by non-technical personnel, i.e. a person without subject matter expertise.

1.1.1.3. All document deliverables, hard copy and electronic, must be in formats specified-at a minimum, the formats must be in industry accepted standards.

1.1.1.4. A kickoff meeting will be held at a location and time selected by VAMC Tucson where the vendor and its staff will be introduced.

1.1.1.5. The vendor and/or its staff must have knowledge and expertise of the environment for which the work is to be performed.

1.1.1.6. The vendor shall provide total system integration for each of procedure rooms listed above.

2. Security Requirements

2.1. The proposed project uses an existing Virtual Local Area Network (VLAN), standing

HL7 interfaces and existing secure vendor remote access.

2.2. Other Pertinent Information or Special Considerations

2.2.1. This system will be located on a secure Virtual Local Area Network (VLAN). The system, while using VA IT resources for networking, does not link, nor have access to, other VA network resources.

3. Packaging, Packing and Shipping Instructions

3.1. All systems/components/software are to be shipped to their final destinations prior to installation; any associated shipping costs must be included in the contract.

4. Inspection and Acceptance Criteria.

4.1 The Program Manager, COR, and designated representatives will test and verify the proposed equipment prior to acceptance to ensure compliance with the solicitation’s brand-name-or-equal requirements. VA currently operates an established, integrated workflow utilizing Omnicell technology across pharmacy and clinical operations. Testing scenarios will replicate routine use cases to confirm that any offered “equal” product is fully compatible with existing VA workflows, maintains required interoperability, and supports uninterrupted clinical operations. While VA staff are trained on current Omnicell processes, the evaluation will also consider the operational impact of integrating an alternate manufacturer’s system, including any required configuration changes and training needs.

C-2

This approach ensures that any “equal” product meets all functional, interoperability, and performance requirements without degrading existing clinical workflows.

Any alternative equipment requiring connection to VA networks, servers, or any VA information system must comply with all applicable VA information security and interoperability requirements. This includes, but is not limited to, prior approval and listing within the VA Technical Reference Model (VA TRM), assessment for compatibility with existing VA infrastructure, and full adherence to VA cybersecurity, privacy, and data-protection standards. Vendors offering an “equal” product must demonstrate that the proposed solution meets all VA TRM requirements, can successfully pass VA security assessments, and includes all necessary documentation, such as Authority to Operate (ATO) artifacts, interface control information, and technical specifications required for VA Office of

Information and Technology (OIT) review. Failure to meet VA TRM approval or any associated VA IT compliance requirements will render an “equal” product unacceptable, as the system cannot be connected to VA networks without these mandatory validations.

5. Risk Control:

5.1. The system addition presents no additional infection, physical security, and/or information security risk.

5.2. Place of Performance

5.2.1. Government site: Southern Arizona VA Health Care System – main campus

(Tucson, AZ)

5.2.2. 3601 S 6’th Avenue (1-119), Tucson AZ 85723

6. Equipments:

6.1. OMNICELL Anesthesia Cart Workstations

6.1.1. Deliverables: Successful installation, testing, and, where applicable, staff training

Item # Description/Part Number*

Qty

FLEXBIN 3131,XT SNGLDOSE

DRW GUIDELIGHT

2 Drawer, 12 Bin Locking, AWS-XT 16

3 XT ANESTHESIA WORKSTATION W-BIO ID 16

4 PANEL,EMERGENCY BREAKAWAY,AWS-XT 16

5 TILT 4-BIN ORGANIZER, AWS-XT 16

6 TILT 5-BIN ORGANIZER, AWS-XT 16

7 TILT 6-BIN ORGANZER, AWS-XT 16

8 EXTERNAL RETURN BIN, AWS-XT 16

9 KIT, UPGRADE, WIRELESS, AWS-XT 16

10 SYRINGE LABEL PRINTER-EPSON & SHELF 16

11 2D ITEM SCAN, AWS-XT 16

12 PREMIUM WIN10 PACKAGE (120 Months) 1

C-3

Figure 1

6.2. OMNICELL Pharmacy Cabinets

6.2.1. Deliverables: Successful installation, testing, and, where applicable, staff training

Item # Description/Part Number* Qty

MED-DRW-009 METAL LOCKING DRAWER 56

MED-FRM-501 MED 1-CELL CABINET (XTE 2.0) 5

MED-OPT-002 MED 2-CELL CABINET (XTE 2.0) 1

MED-OPT-002 XT EXTERNAL RETURN BIN,

WIRED CAB MOUNT

MSA-SUB-006 PREMIUM WIN10 PACKAGE

Prices are calculated based on 120 month subscription term

SRD-OPT-012 XT FLEXLOCK WITH 50 FT

CABLE,INSTALLED

SUP-OTH-002 XT PULLOUT SHELF 16

C-4

Figure 2

Figure 3

C-5

Figure 4

Figure 5

C-6

Figure 6

Figure 7

C-7

6.3. Omnicell Return Bins

6.3.1. Deliverables: Successful installation, testing, and, where applicable, staff training

Item # Description/Part Number*

Qty

1 MED-OPT-002 56

6.4. System Integration:

6.4.1. All proposed equipment shall be fully compatible with the facility’s existing

Omnicell enterprise server environment, including OmniCenter® or other Omnicell-supported centralized platforms currently in use. The Contractor shall ensure that all components connect reliably to the enterprise server for authentication, data management, and system configuration.

6.5. Data Management and Integration

6.5.1. The systems shall support centralized management of medication inventory, access logs, transaction histories, configuration settings, and user profiles. All data shall be stored and managed through the facility’s Omnicell central server, without local retention beyond temporary operational buffering.

6.5.2. The Contractor shall ensure the solution supports integration with the facility’s Electronic Health Record (EHR) system and any associated interface engines required for clinical documentation, medication administration, or workflow interoperability.

6.6. Cybersecurity and Network Requirements

6.6.1. The Contractor shall ensure all communication between the devices and the centralized Omnicell server utilizes secure, encrypted protocols compliant with federal and organizational cybersecurity requirements.

6.6.2. The Contractor shall provide documentation outlining required network ports, communication protocols, and server dependencies to support secure deployment and sustainment.

7. VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE

7.1. GENERAL. This entire section applies to all acquisitions requiring any Information

Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.

7.2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.

7.2.1. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.

7.2.2. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the

C-8 service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.

7.2.3. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.

7.2.4. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), VA HANDBOOK 6500.6

APPENDIX C

April 22, 2024

C-9

7.2.5. and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.

7.2.6. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.

7.2.7. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.

7.2.8. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.

7.2.9. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.

7.2.10. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.

7.2.11. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.

7.2.12. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain

VA HANDBOOK 6500.6

7.2.13. medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV).

If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response.

7.2.14. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.

7.2.15. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.

7.2.16. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.

7.2.17. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA.The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information.

Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.

7.2.18. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.

7.3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. This section

7.3.1. applies when any person requires access to information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract.

VA Handbook 6500.6

C-11

7.3.2. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor.

7.3.3. Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA’s information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted.

7.3.4. All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information.

The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM).

7.3.5. All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted.

7.3.6. The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following:

7.3.6.1. Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems.

7.3.6.2. Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason.

7.3.6.3. Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data.

7.3.6.4. Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record.

7.3.6.5. Contractor/subcontractor personnel have their authorization to work in the United States revoked.

7.3.6.6. Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel.

C-12

7.3.7. In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV

– Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal.

7.3.8. Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO.

7.4. TRAINING. This entire section applies to all acquisitions which include section 3.

7.4.1. All contractors and subcontractors requiring access to VA information and

VA information systems shall successfully complete the following before being granted access to VA information and its systems:

7.4.1.1. VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter.

7.4.1.2. Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and

7.4.1.3. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access [to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document – i.e., any role-based information security training].

7.4.2. The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required.

7.4.3. Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete.

7.5. SECURITY INCIDENT INVESTIGATION.

7.5.1. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711).

The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.

7.5.2. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:

7.5.2.1. The date and time (or approximation of) the Security Incident occurred.

7.5.2.2. The names of individuals involved (when applicable).

7.5.2.3. The physical and logical (if applicable) location of the incident.

C-13

7.5.2.4. Why the Security Incident took place (i.e., catalyst for the failure).

7.5.2.5. The amount of data belonging to VA believed to have been compromised.

7.5.2.6. The remediation measures the contractor is taking to ensure no future incidents of a similar nature.

7.5.3. After the contractor has provided the initial detailed incident summary to

VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.

7.5.4. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.

7.5.5. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

7.5.6. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.

7.5.7. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.

7.5.8. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages— Reimbursement for Data Breach Costs.

7.6. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE.

7.6.1. This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (cloud and non-cloud) hosted, operated, maintained, or used on behalf of VA at non-VA facilities.

7.6.2. The contractor shall comply with all Federal laws, regulations, and VA policies for Information systems (cloud and non-cloud) that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities. Security controls for collecting, processing, transmitting, and storing of VA sensitive information, must be in place. The controls will be tested by VA or a VA sanctioned 3PAO and approved by VA prior to hosting, operation, maintenance or use of the information system or systems by or on behalf of VA. This includes conducting compliance risk assessments, security architecture analysis, routine vulnerability scanning, system https://www.va.gov/oal/library/vaar/vaar852.asp#85221176 https://www.va.gov/oal/library/vaar/vaar852.asp#85221176 https://www.va.gov/oal/library/vaar/vaar852.asp#85221176

C-14 patching, change management procedures and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures shall be the same as procedures used to secure VA-operated information systems.

7.6.3.

7.6.4. Outsourcing (contractor facility, equipment, or staff) of systems or network operations, telecommunications services or other managed services require Assessment and Authorization (A&A) of the contractor’s systems in accordance with VA Handbook 6500 as specified in VA Information Security Knowledge Service. Major changes to the A&A package may require reviewing and updating all the documentation associated with the change. The contractor’s cloud computing systems shall comply with FedRAMP and VA Directive 6517 requirements.

7.6.5. The contractor shall return all electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) on non-VA leased or non-VA owned IT equipment used to store, process or access VA information to VA in accordance with A&A package requirements. This applies when the contract is terminated or completed and prior to disposal of media. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Information Security Knowledge Service requirements and NIST 800-88. The contractor shall send a self-certification that the data destruction requirements above have been met to the COR/CO within 30 business days of termination of the contract.

7.6.6. All external internet connections to VA network involving VA information must be in accordance with VA Trusted Internet Connection (TIC) Reference Architecture and VA Directive and Handbook 6513, Secure External Connections and reviewed and approved by VA prior to implementation. Government-owned contractor-operated systems, third party or business partner networks require a Memorandum of Understanding (MOU) and Interconnection Security Agreements

(ISA).

7.6.7. Contractor procedures shall be subject to periodic, announced, or unannounced assessments by VA officials, the OIG or a 3PAO. The physical security aspects associated with contractor activities are also subject to such assessments. The contractor shall report, in writing, any deficiencies noted during the above assessment to the VA COR/CO. The contractor shall use VA’s defined processes to document planned remedial actions that address identified deficiencies in information security policies, procedures, and practices. The contractor shall correct security deficiencies within the timeframes specified in the VA Information Security Knowledge Service.

7.6.8. All major information system changes which occur in the production environment shall be reviewed by the VA to determine the impact on privacy and security of the system. Based on the review results, updates to the Authority to Operate (ATO) documentation and parameters may be required to remain in compliance with VA Handbook 6500 and VA Information Security Knowledge Service requirements.

7.6.9. The contractor shall conduct an annual privacy and security self-assessment on all information systems and outsourced services as required.

Copies of the assessment shall be provided to the COR/CO. The VA/Government reserves the right to conduct assessment using government personnel or a third-party if deemed necessary. The contractor shall correct or mitigate any weaknesses discovered during the assessment.

7.6.10. VA prohibits the installation and use of personally owned or contractor-owned equipment or software on VA information systems. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW, PWS, PD or contract. All security controls required for government furnished equipment must be utilized in VA approved Other Equipment (OE). Configuration changes to the contractor OE, must be funded by

C-15 the owner of the equipment. All remote systems must use a VA-approved antivirus software and a personal (host-based or enclave based) firewall with a VA-approved configuration. The contractor shall ensure software on OE is kept current with all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-virus software and the firewall on the non-VA owned OE.

Approved contractor OE will be subject to technical inspection at any time.

7.6.11. The contractor shall notify the COR/CO within one hour of disclosure or successful exploits of any vulnerability which can compromise the confidentiality, integrity, or availability of the information systems. The system or effected component(s) need(s) to be isolated from the network. A forensic analysis needs to be conducted jointly with VA. Such issues will be remediated as quickly as practicable, but in no event longer than the timeframe specified by VA Information Security Knowledge Service. If sensitive personal information is compromised reference VA Handbook 6500.2 and Section 5, Security Incident Investigation.

7.6.12. For cases wherein the contractor discovers material defects or vulnerabilities impacting products and services they provide to VA, the contractor shall develop and implement policies and procedures for disclosure to VA, as well as remediation. The contractor shall, within 30 business days of discovery, document a summary of these vulnerabilities or defects. The documentation will include a description of the potential impact of each vulnerability and material defect, compensating security controls, mitigations, recommended corrective actions, root cause analysis and/or workarounds (i.e., monitoring). Should there exist any backdoors in the products or services they provide to VA (referring to methods for bypassing computer authentication), the contractor shall provide the VA CO/CO written assurance they have permanently remediated these backdoors.

7.6.13. All other vulnerabilities, including those discovered through routine scans or other assessments, will be remediated based on risk, in accordance with the remediation timelines specified by the VA Information Security Knowledge Service and/or the applicable timeframe mandated by Cybersecurity & Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 22-01 and BOD 19-02 for Internet-accessible systems. Exceptions to this paragraph will only be granted with the approval of the COR/CO.

7.7. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT

AND AUDITING.

7.7.1. Should VA request it, the contractor shall provide a copy of their (corporation’s, sole proprietorship’s, partnership’s, limited liability company (LLC), or other business structure entity’s) policies, procedures, evidence and independent report summaries related to specified cybersecurity frameworks (International Organization for Standardization (ISO), NIST Cybersecurity Framework (CSF), etc.). VA or its third-party/partner designee (if applicable) are further entitled to perform their own audits and security/penetration tests of the contractor’s IT or systems and controls, to ascertain whether the contractor is complying with the information security, network or system requirements mandated in the agreement between VA and the contractor.

7.7.2. Any audits or tests of the contractor or third-party designees/partner VA elects to carry out will commence within 30 business days of VA notification. Such audits, tests and assessments may include the following: (a): security/penetration tests which both sides agree will not unduly impact contractor operations; (b):

interviews with pertinent stakeholders and practitioners; (c): document review; and (d): technical inspections of networks and systems the contractor uses to destroy, maintain, receive, retain, or use VA information.

7.7.3. As part of these audits, tests and assessments, the contractor shall provide all information requested by VA. This information includes, but is not limited

C-16 to, the following: equipment lists, network or infrastructure diagrams, relevant policy documents, system logs or details on information systems accessing, transporting, or processing VA data.

7.7.4. The contractor and at its own expense, shall comply with any recommendations resulting from VA audits, inspections and tests. VA further retains the right to view any related security reports the contractor has generated as part of its own security assessment. The contractor shall also notify VA of the existence of any such security reports or other related assessments, upon completion and validation.

7.7.5. VA appointed auditors or other government agency partners may be granted access to such documentation on a need-to-know basis and coordinated through the COR/CO. The contractor shall comply with recommendations which result from these regulatory assessments on the part of VA regulators and associated government agency partners.

7.8. PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT AND

ANTI-TAMPERING.

7.8.1. The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, “Securing the Information and Communications Technology and Services (ICTS) Supply Chain”, which prohibits ICTS Transactions from foreign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs or the platforming or data hosting of applications for consumer download.

7.8.2. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor are authentic. If procurement is unavailable from an OEM or authorized reseller, the contractor shall submit in writing, details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.

7.8.3. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, information protection practices, integrity management program for sub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractor(s) shall specify how digital delivery for procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.

7.8.4. If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).

7.8.5. The contractor shall provide a software bill of materials (SBOM) for procured (to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials (SBOM).”

7.8.6. Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S. registered mail and/or tamper-evident packaging for physical deliveries.

C-17

7.8.7. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering).

7.8.8. The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware.

7.9. VIRUSES, FIRMWARE AND MALWARE.

7.9.1. The contractor shall execute due diligence to ensure all provided software and patches, including third-party patches, are free of viruses and/or malware before releasing them to or installing them on VA information systems.

7.9.2. The contractor warrants it has no knowledge of and did not insert, any malicious virus and/or malware code into any software or patches provided to VA which could potentially harm or disrupt VA information systems. The contractor shall use due diligence, if supplying third-party software or patches, to ensure the third-party has not inserted any malicious code and/or virus which could damage or disrupt VA information systems.

7.9.3. The contractor shall provide or arrange for the provision of technical justification as to why any “false positive” hit has taken place to ensure their code’s supply chain has not been compromised. Justification may be required, but is not limited to, when install files, scripts, firmware, or other contractor-delivered software solutions (including third-party install files, scripts, firmware, or other software) are flagged as malicious, infected, or suspicious by an anti-virus vendor.

7.9.4. The contractor shall not upload (intentionally or negligently) any virus, worm, malware or any harmful or malicious content, component and/or corrupted data/source code (hereinafter “virus or other malware”) onto VA computer and information systems and/or networks. If introduced (and this clause is violated), upon written request from the VA CO, the contractor shall:

7.9.4.1. Take all necessary action to correct the incident, to include any and all assistance to VA to eliminate the virus or other malware throughout VA’s information networks, computer systems and information systems; and

7.9.4.2. Use commercially reasonable efforts to restore operational efficiency and remediate damages due to data loss or data integrity damage, if the virus or other malware causes a loss of operational efficiency, data loss, or damage to data integrity.

7.10. CRYPTOGRAPHIC REQUIREMENT.

7.10.1. The contractor shall document how the cryptographic system supporting the contractor’s products and/or services protect the confidentiality, data integrity, authentication and non-repudiation of devices and data flows in the underlying system.

7.10.2. The contractor shall use only approved cryptographic methods as defined in FIPS 140-2 (or its successor) and NIST 800-52 standards when enabling encryption on its products.

7.10.3. The contractor…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .