S02 36C26326Q1067.pdf
PDF 500 KB Posted
- Attached to
- Surgical Simulation System Federal contract opportunity
- Solicitation number
- 36C26326Q1067
About this file
Solicitation Summary: VISN 23 Surgical Simulation System Replacements
This is a Solicitation/Contract/Order for Commercial Products and Commercial Services (Standard Form 1449) issued by the Department of Veterans Affairs, Network Contracting Office 23 on September 3, 2026, with solicitation number 36C26326Q1067. The solicitation seeks to procure four surgical simulation systems to replace aged equipment at VA medical centers in Fargo and Minneapolis. Required systems include: (1) VA Fargo Endo Suite Simulator with specific endoscopes and modules for gastrointestinal, bronchoscopy, and ERCP procedures; (2) VA Minneapolis Angio Mentor Flex Pro with dual access configuration and vascular intervention modules; (3) VA Minneapolis GI Mentor Express portable system; and (4) VA Minneapolis Arthro Mentor II with orthopedic arthroscopy modules. Each item is procured on a firm-fixed-price basis with delivery required within 30 days after receipt of order (ARO) to respective VA facilities.
Quotes are due by September 11, 2026, at 10:00 AM Central Time, with technical questions accepted through September 8, 2026. The contract will be evaluated using a Lowest Price Technically Acceptable (LPTA) methodology. The contractor must provide all installation services, project management, training, removal of existing equipment, and obtain trade-in credits where applicable. Contractor responsibilities include coordinating with facility points of contact, ensuring compliance with VA information security and privacy requirements, providing minimum one-year warranty on installed equipment, and submitting electronic invoices through Tungsten Network. The acquisition is unrestricted (not set aside for small business), with principal NAICS code 339112 (Surgical and Medical Instrument Manufacturing) and PSC 6515 (Medical and Surgical Instruments, Equipment, and Supplies).
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
499-26-4-6720-0012
36C26326Q1067 09-03-2026
Marie Weathers 605-347-2511 09-11-2026
10AM CDT
36C263
DEPARTMENT OF VETERANS AFFAIRS
NETWORK CONTRACTING OFFICE 23
VA BLACK HILLS HCS FORT MEADE CAMPUS
113 COMANCHE RD
FORT MEADE SD 57741
X
339112
1000 Employees
N/A
X
Department of Veteran Affairs VISN 23 VA Healthcare System 2805 Dodd Rd., Suite 250 Eagan, MN 55121
DEPARTMENT OF VETERANS AFFAIRS
NETWORK CONTRACTING OFFICE 23
VA BLACK HILLS HCS FORT MEADE CAMPUS
113 COMANCHE RD
FORT MEADE SD 57741
Tungsten Electronic Invoicing VA Tungsten Number: AAA544240062 va.registration@tungsten-network.com Refer to VAAR 852.232-72
See CONTINUATION Page
Surgical Simulator (Brand Name or Equal) in support of the VISN 23 VA Healthcare System.
Refer to Section B.2 for line items requested.
Refer to Statement of Work for more details.
FOB Destination Deliver 30 Days ARO
All technical questions must be received in writing by 09/08/2026 by 10:00AM CT by marie.weathers@va.gov
All Quotes must be received by 09/11/2026 by 10:00AM Ct by marie.weathers@va.gov
See CONTINUATION Page
499-3660160-6720-825500-3131-010065275 499-26-4-6720-0012
X X
X 1(one)
Scott Morrison
VA-VHA-RPOC-2026-0024
36C26326Q1067
Table of Contents
SECTION A
A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS
AND COMMERCIAL SERVICES
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
B.2 PRICE/COST SCHEDULE
B.3 DELIVERY SCHEDULE
B.4 Statement of Work
B.5 VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY
LANGUAGE
SECTION C - CONTRACT CLAUSES
C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS
AND COMMERCIAL SERVICES (OCT 2025) (DEVIATION)
C.2 52.222-40 NOTIFICATION OF EMPLOYEE RIGHTS UNDER THE NATIONAL
LABOR RELATIONS ACT (NOV 2025) (DEVIATION)
C.3 52.222-90 ADDRESSING DEI DISCRIMINATION BY FEDERAL CONTRACTORS
(DEVIATION APR 2026)
C.4 52.223-23 SUSTAINABLE PRODUCTS (NOV 2025) (DEVIATION)
C.5 52.240-91 SECURITY PROHIBITIONS AND EXCLUSIONS (NOV 2025)
(DEVIATION)
C.6 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS
SECTION E - SOLICITATION PROVISIONS
E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND
COMMERCIAL SERVICES (OCT 2025) (DEVIATION)
E.2 52.216-1 TYPE OF CONTRACT (NOV 2025) (DEVIATION)
E.3 52.225-6 TRADE AGREEMENTS CERTIFICATE (FEB 2021)
E.4 52.233-2 SERVICE OF PROTEST (SEP 2006)
E.5 52.240-90 SECURITY PROHIBITIONS AND EXCLUSIONS REPRESENTATIONS
AND CERTIFICATIONS (NOV 2025) (DEVIATION)
E.6 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)
E.7 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB
1998)
E.8 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL
SERVICES (OCT 2025) (DEVIATION)
SECTION B - CONTINUATION OF SF 1449 BLOCKS
B.1 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR:
b. GOVERNMENT: Contracting Officer 36C263
NETWORK CONTRACTING OFFICE 23
VA BLACK HILLS HCS FORT MEADE CAMPUS
113 COMANCHE RD
FORT MEADE SD 57741
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer-System For Award Management, or
[ ] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears: Upon Delivery and Acceptance
4. Billing/Accounting/Invoices
4.1 Payments shall be made upon delivery and acceptance in arrears upon receipt of a properly prepared invoice. IAW FAR 52.212-4 (g), FAR 52.232-33, and VAAR 852.232-72.
4.2 In order to comply with the Improper Payment Elimination and Recovery Act of 2010 (IPERA), the VA has mandated electronic invoice submission to the Veterans Affairs Financial Services Center (VAFSC). VAFSC has partnered with Tungsten Corporation e lnvoicing network for submissions of all electronic invoices to VA. Tungsten Network electronic invoicing is free to all VA vendors. In order to submit electronic invoices, all VA vendors must register with Tungsten Network by submitting an email to VA.Registration@tungsten-network.com or calling 1-877-752-0900 option 2 for Enrollment.
4.3 Invoices will be electronically submitted to the Tungsten website at Tungsten direct vendor support number is 877-489-6135 for VA contracts. The VA-FSC pays all associated transaction fees for VA orders. During Implementation (technical set-up) Tungsten will confirm your Tax Payer ID Number with the VA-FSC. This process can take up to 5 business days to complete to ensure your invoice is automatically routed to your Certifying Official for approval and payment.
To successfully submit an invoice to VA-FSC please review "How to Create an Invoice" within the how to guides. All invoices submitted through Tungsten to the VA-FSC should mirror your current submission of Invoice, with the following items required. Clarification of additional requirements should be confirmed with your Certifying Official (your CO or buyer). The VA-FSC requires specific information in compliance with the Prompt Pay Act and Business Requirements. For additional information, please contact:
Tungsten Support Phone: 1-877-489-6135
Website: https://www.tungsten-network.com/us/support/
Department of Veterans Affairs Financial Service Center Phone: 1-877-353-9791 Email:
vafscched@va.gov
4.4 Reduction in Services: This is a fixed quantity contract for a specified number of hours.
If, at the end of the period of performance, the government has not utilized the total number of hours required under this contract because of a change in its requirements, the parties agree that they will attempt to negotiate in good faith a contract modification reducing the scope of the contract with a corresponding adjustment in the total contract price.
4.5 In no event will VA pay for hours worked that exceed the total number of hours specified in the contract for the period of performance.
4.6 Payments in full/no billing VA beneficiaries: The Contractor shall accept payment for services rendered under this contract as payment in full. VA beneficiaries shall not under any circumstances be charged nor their insurance companies charged for services rendered by the Contractor, even if VA does not pay for those services. This provision shall survive the termination or ending of the contract.
4.7 To the extent that the Veteran desires services which are not a VA benefit or covered under the terms of this contract, the Contractor must notify the Veteran that there will be a charge for such service and that the VA will not be responsible for payment.
4.8 The Contractor shall not bill, charge, collect a deposit from, seek compensation, remuneration, or reimbursement from, or have any recourse against, any person or entity other than VA for services provided pursuant to this contract. It shall be considered fraudulent for the Contractor to bill other third-party insurance sources (including Medicare) for services rendered to Veteran enrollees under this contract. Contractor shall submit an electronic invoice by the tenth (10th) of the following month services were performed to the Veterans Affairs Financial Services Center (VAFSC) e-lnvoice through the website at https://portal.tungsten-network.com/Login.aspx. For questions regarding the submission of VA electronic invoices, OB10 customer service may be contacted at 1-877-489-6135.
4.9 For questions regarding invoice receipt or payment, please call VAFSC directly at 1-877- 353-9791 or email vafsccshd@va.gov.
ACKNOWLEDGMENT OF AMENDMENTS: The offerer acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION
ITEM
NUMBER
DESCRIPTION OF
SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
1.00 EA __________________ __________________
VA Fargo Endo Suite Simulator
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing PRODUCT/SERVICE CODE: 6515 - Medical and Surgical Instruments, Equipment, and Supplies
VA Minneapolis Angio Mentor
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
VA Minneapolis - GI Mentor Express
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
VA Minneapolis - Arthro Mentor II
PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing
GRAND TOTAL __________________
B.3 DELIVERY SCHEDULE
ITEM
NUMBER SHIPPING INFORMATION QUANTITY
DELIVERY
DATE
0001 SHIP TO: Fargo VA Healthcare System 2101 Elm St. NE Fargo, ND 58102
1.00 30 Days ARO
AMENDMENT NO DATE
USA
MARK FOR: Wendy Reyes 651-405-5653 wendy.reyes@va.gov
FOB: DESTINATION
0002 SHIP TO:
MARK FOR:
FOB:
Minneapolis VA Healthcare System 1 Veterans Dr., Minneapolis, MN 57747
USA
Wendy Reyes 651-405-5653 wendy.reyes@va.gov
DESTINATION
0003 SHIP TO:
System 1 Veterans Dr., Minneapolis, MN 57747
USA
Wendy Reyes 651-405-5653 wendy.reyes@va.gov
DESTINATION
0004 SHIP TO:
System 1 Veterans Dr., Minneapolis, MN 57747
USA
Wendy Reyes 651-405-5653 wendy.reyes@va.gov
DESTINATION
B.4 Statement of Work
VISN 23 – Surgical Simulation System Replacements (Brand Name or Equal)
Scope mailto:wendy.reyes@va.gov mailto:wendy.reyes@va.gov mailto:wendy.reyes@va.gov
The purpose of this requirement is to replace aged and outdated surgical simulation systems used at the Fargo and Minneapolis VA Medical Centers with the Endo Suite, Angio Mentor Flex Pro, GI Mentor Express, and Arthro Mentor II simulation systems to continue providing realistic hands-on training of critical skills and full procedures. The selected vendor will also be responsible for providing any installation services required to complete these projects. These services are to include, but are not limited to, system design, project management, training, and removal of the outdated systems mentioned in Appendix A. The selected contractor should quote the installation services separately per site. Travel to and from the place of performance shall also be included in the contractor’s proposal. This purchase will include all equipment, materials, design services, installation labor, implementation services, training, and incidental materials/labor/services to fully replace the current Endo and Angio systems.
Qualifications
To be eligible for consideration, the vendor will provide the equipment specified below for each site.
- VA Fargo: ENDO Mentor Suite Platform (Brand Name or Equal) o Interchangeable cartridge for inserting scopes o At least a 27” touchscreen w/ a FHD resolution (1920x1080) and wireless keyboard and mouse o GI scope hangers with clips to hang the scope insertion o Triple foot switch to utilize in the modules for actions o Must include the following endoscopes:
Colonoscope Duodenoscope Bronchoscope o Any necessary tools/accessories such as Master tool and additional red/blue wires used for endoscopic retrograde cholangio pancreatography (ERCP) modules o Dimensions: Length: 130-186 cm (max), Height: 135-180 cm (max), Width 57- 87cm (max), Weight:500lbs (max) o Must include the following Basic and Advance Modules for SAGES Fundamentals of Endoscopic Surgery (FES) testing, as required by the American Board of Surgery (ABS) for all general surgery residency graduates in North America Endo Suite Basic GI Endo Suite Bronch ERCP I and II Module EUS Educational and Tasks Modules Essential EBUS Module GI Endoscopy Fundamental Skills (EFS) Emergency Bronchoscopy Module Sigmoidoscopy Module Diagnostic Bronchoscopy Module Colonoscopy I and II module Cyberscopy Module Gastroscopy I and II Module
GI Endoscopy Skills Competition Module
- VA Minneapolis: Angio Mentor Flex Pro (Brand Name or Equal) o High performance laptop with 17in touch screen monitor for interface o 24in flat touch screen monitor for fluoroscopy and ultrasound o Wireless mouse o Dual access configuration, capable of cascading 3 tools simultaneously in each simulation unit o Triple foot switch to utilize in the modules for actions (such as X-ray and CINE) o Force feedback devices o Control box with two joysticks for simulated table and C-arm control o Modules needed:
Lower extremities CTO Carotid stenting EVAR Repair (AAA) TEVAR Repair (TAA) Advanced TEVAR Angio Aortic Repair Cardio Basic Skills EP Basic Skills Endovascular Basic Skills Angio Peripheral Arterial and Venous C-Arm Basics Flex Pro EDU
- VA Minneapolis: Arthro Mentor II (Brand Name or Equal) o High performance PC with a 24in flat touch screen monitor o Double foot pedal o Height adjustable platform o Knee, hip, and shoulder models o Simulated endoscopic camera, probe, and grasper o Modules needed:
Complete shoulder Arthroscopy Advanced knee
FAST
Hip Diagnostics
- VA Minneapolis: GI Mentor Express (Brand Name or Equal) o High performance laptop with at least a 16in screen o Must be portable o Must include a colonoscope o Any necessary tools/accessories such as GI Master tool device and a foot pedal o Modules needed:
GI Endoscopy – Fundamental Skills Training Cyberscopy Colonoscopy I and II Gastroscopy I and II
- All laptops and PCs must receive the latest supported operating system
- Must provide all installation services required to complete the projects. These services should include, but are not limited to, project management, product upgrade, installation, travel to and from the VA facilities.
- Must remove the current simulation systems used at VA Fargo and Minneapolis.
Equipment details are on Appendix A.
- If the equipment is offered a trade in value, the vendor must coordinate with the site’s system administrator to properly remove the equipment from the facility.
- The offeror will include separate line items for the hardware, hardware installation, project management, and implementations. These should be clearly delineated in separate line-items, even if some are zero-cost. This purchase will include all equipment, materials, design services, installation labor, implementation services, training (if applicable) and incidental materials/labor/services to fully replace the surgical simulation systems at VA Fargo and at VA Minneapolis.
Implementation/Project Management Services
Implementation Services shall include, but are not limited to, a project manager, a detailed project timeline with defined roles and responsibilities (including contractor-provided and VA resources), on-site installation coordination of all equipment, software and accessories, and schedule for Go-Live. The contractor shall perform the onsite setup, including system diagnostics and calibration procedures, as well as provide training.
a) VISN 23 has designated points of contact (POCs) for each facility that shall be provided upon award. The contractor shall work with these individuals to implement the technology.
b) The contractor shall hold a kickoff meeting with the designated POCs for each facility.
The project management plan and communications plan shall be reviewed at the kickoff meeting. Discussion about the site order and schedule for implementation will begin at the kick-off meeting.
c) The project manager shall hold periodic project meetings as needed with the facility POCs and the VISN Contracting Officer’s Representative (COR).
d) The contractor shall collaborate with site POCs to minimize interference with normal operations.
Place of Performance
The contractor will deliver and pick up the requested products to the Fargo and Minneapolis VA Medical Centers.
• VA Fargo Address: 2101 Elm St NE, Fargo, ND 58102
• VA Minneapolis Address: 1 Veterans Dr, Minneapolis, MN 55417
Delivery Requirements
The Contractor shall coordinate in advance with on-site designated facility POC(s) and COR delivery of equipment to the final destination and obtain the appropriate Supply Chain Management POC to include in the communication plan. All equipment must be processed through Supply Chain Management prior to going to final destination. The Contractor shall make any changes to the delivery schedule at the request of facility POC(s) and COR. The Contractor shall provide delivery, shipping and tracking information to the facility POC(s) and COR in advance before equipment arrival at the facility.
The Contractor is responsible for inventorying materials prior to delivery to VA sites to check for accuracy in quantity and part number. The Contractor shall deliver materials to the job site in the appropriate protective containers or packager, clearly labeled with the contractor’s name, address, equipment make and model and serial identification numbers, and Purchase Order (PO) number and facility Technical POC.
In the case of multiple container deliveries, a statement readable near the VA PO number shall indicate total number of containers for the complete shipment (i.e., “Package 1 of 2”), clearly readable on manifests and external shipping labels. Facility POC (s) may reject items that do not conform to any of these requirements.
The Contractor shall provide shipping to return any defective repairs from VA Facilities to the Contractor. There shall be no additional cost to the Government for shipping
Installation Requirements
Contractor shall coordinate with facility POCs to minimize interruption of normal operations.
Contractor shall provide and wear attire that is appropriate to the areas they occupy, for example, Bunny Suit, shoe covers, hats, beard covers, face masks, etc. All waste will be removed by the contractor. Contractor shall work with onsite staff to limit interference with all clinical activities.
Warranty
The contractor shall provide a minimum one-year warranty on newly installed equipment. The warranty period shall begin after VA authorized personnel have accepted the products delivery, installation, and functionality. In addition, contractor shall indicate availability and cost of extended parts warranty options.
APPENDIX A – Equipment Replacement Information
The sites would like the following equipment to be considered for trade-in credits:
VA Fargo
• Manufacturer: Surgical Science
• VA Asset Number: 437EE27348
• Model: GI Bronch
• SN: G015-07-14
VA Minneapolis
• Manufacturer: Surgical Science
• VA Asset number: 618EE106336
• Model: Angio Flex Slim
• SN: A130-01-13/A131-11-13
APPENDIX B – Facility Point of Contacts
Site Service POC Email VA Fargo Education Service Amanda Wallace Amanda.Wallace3@va.gov VA Minneapolis Simulation Program Robin Rabey Robin.Rabey2@va.gov
VISN 23
Healthcare Technology Management Wendy Reyes Wendy.Reyes@va.gov
B.5 VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE
B1. GENERAL. This entire section applies to all acquisitions requiring any Information Security and Privacy language. Contractors, contractor personnel, subcontractors and subcontractor personnel will be subject to the same federal laws, regulations, standards, VA directives and handbooks, as VA personnel regarding information and information system security and privacy.
B2. VA INFORMATION CUSTODIAL LANGUAGE. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter “contract”) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License.
b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data – General.
c. VA information will not be co-mingled with any other data on the contractor’s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization.
d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and V VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations.
mailto:Wendy.Reyes@va.gov
The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies.
f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service.
g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor.
h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements.
The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations.
i. The contractor’s firewall and web services security controls, as applicable, shall meet or exceed VA’s minimum requirements.
j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer to all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response.
k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer to such court order or other requests to the VA CO for response.
l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service.
m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules.
n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition.
o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer’s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract.
p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO.
B3. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS. – This section is not applicable.
B4. TRAINING. – This section is not applicable.
B5. SECURITY INCIDENT INVESTIGATION. This entire section applies to all acquisitions requiring any Information Security and Privacy language.
a. The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD.
b. To the extent known by the contractor/subcontractor, the contractor/ subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following:
(1) The date and time (or approximation of) the Security Incident occurred.
(2) The names of individuals involved (when applicable).
(3) The physical and logical (if applicable) location of the incident.
(4) Why the Security Incident took place (i.e., catalyst for the failure).
(5) The amount of data belonging to VA was believed to have been compromised.
(6) The remediation measures the contractor is taking to ensure no future incidents of a similar nature.
c. After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employes shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination.
d. VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation.
e. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
f. The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches.
g. With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA.
h. If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract;
the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages—Reimbursement for Data Breach Costs.
B6. INFORMATION SYSTEM DESIGN AND DEVELOPMENT. – This entire section applies to information systems, systems, major applications, minor applications, enclaves, and platform information technologies (to include the subcomponents of each) designed or developed for or on behalf of VA by any non-VA entity.
a. Information systems designed or developed on behalf of VA at non-VA facilities shall comply with all applicable Federal law, regulations, and VA policies. This includes standards for the protection of electronic Protected Health Information (PHI), outlined in 45 C.F.R. Part 164, Subpart C and information and system security categorization level designations in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems and FIPS 200, Minimum Security Requirements for Federal Information Systems.
Baseline security controls shall be implemented commensurate with the FIPS 199 system security categorization (reference VA Handbook 6500 and VA Trusted Internet Connections (TIC) Architecture).
b. Contracted new developments require creation, testing, evaluation, and authorization in compliance with VA Assessment and Authorization (A&A) processes in VA Handbook 6500 and VA Information Security Knowledge Service to obtain an Authority to Operate (ATO). VA Directive 6517, Risk Management Framework for Cloud Computing Services, provides the security and privacy requirements for cloud environments.
c. VA IT contractors, subcontractors and third-party service providers shall address and/or integrate applicable VA Handbook 6500, VA Handbook 6517, Risk Management Framework for Cloud Computing Services and Information Security Knowledge Service specifications in delivered IT systems/solutions, products and/or services. If systems/solutions, products and/or services do not directly match VA security requirements, the contractor shall work though the COR/CO to identify the VA organization responsible for governance or resolution. Contractors shall comply with FAR 39.1, specifically the prohibitions referenced.
d. The contractor (including producers and resellers) shall comply with Office of Management and Budget (OMB) M-22-18 and M-23-16 when using third-party software on VA information systems or otherwise affecting the VA information. This includes new software purchases and software renewals for software developed or modified by major version change after the issuance date of M-22-18 (September 14, 2022). The term “software” includes firmware, operating systems, applications and application services (e.g., cloud-based software), as well as products containing software. The contractor shall provide a self-attestation that secure software development practices are utilized as outlined by Executive Order (EO)14028 and NIST Guidance. A third-party assessment provided by either a certified Federal Risk and Authorization Management Program (FedRAMP) Third Party Assessor Organization (3PAO) or one approved by the agency will be acceptable in lieu of a software producer's self-attestation.
e. The contractor shall ensure all delivered applications, systems and information systems are compliant with Homeland Security Presidential Directive (HSPD) 12 and VA Identity and Access management (IAM) enterprise identity management requirements as set forth in OMB M-19-17, M-05-24, FIPS 201-3 Personal Identity Verification (PIV) of Federal Employees and Contractors (or its successor), M-21-31 and supporting NIST guidance. This applies to Commercial Off-The- Shelf (COTS) product(s) that the contractor did not develop, all software configurations and all customizations.
f. The contractor shall ensure all contractor delivered applications and systems provide user authentication services compliant with VA Handbook 6500, VA Information Security Knowledge Service, IAM enterprise requirements and NIST 800-63, Digital Identity Guidelines, for direct, assertion-based authentication and/or trust-based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV and/or Common Access Card (CAC), as determined by the business need and compliance with VA Information Security Knowledge Service specifications.
g. The contractor shall use VA authorized technical security baseline configurations and certify to the COR that applications are fully functional and operate correctly as intended on systems in compliance with VA baselines prior to acceptance or connection into an authorized VA computing environment. If the Defense Information Systems Agency (DISA) has created a Security Technical Implementation Guide (STIG) for the technology, the contractor may configure to comply with that STIG. If VA determines a new or updated VA configuration baseline needs to be created, the contractor shall provide required technical support to develop the configuration settings. FAR 39.1 requires the population of operating systems and applications includes all listed on the NIST National Checklist Program Checklist Repository.
h. The standard installation, operation, maintenance, updating and patching of software shall not alter the configuration settings from VA approved baseline configuration. Software developed for VA must be compatible with VA enterprise installer services and install to the default “program files” directory with silently install and uninstall. The contractor shall perform testing of all updates and patching prior to implementation on VA systems.
i. Applications designed for normal end users will run in the standard user context without elevated system administration privileges.
j. The contractor-delivered solutions shall reside on VA approved operating systems. Exceptions to this will only be granted with the written approval of the COR/CO.
k. The contractor shall design, develop, and implement security and privacy controls in accordance with the provisions of VA security system development life cycle outlined in NIST 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, VA Directive and Handbook 6500, and VA Handbook 6517.
l. The Contractor shall comply with the Privacy Act of1974 (the Act), FAR 52.224-2 Privacy Act, and VA rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish a VA function.
m. The contractor shall ensure the security of all procured or developed information systems, systems, major applications, minor applications, enclaves and platform information technologies, including their subcomponents (hereinafter referred to as “Information Systems”) throughout the life of this contract and any extension, warranty, or maintenance periods. This includes security configurations, workarounds, patches, hotfixes, upgrades, replacements and any physical components which may be necessary to remediate all security vulnerabilities published or known to the contractor anywhere in the information systems (including systems, operating systems, products, hardware, software, applications and firmware). The contractor shall ensure security fixes do not negatively impact the Information Systems.
n. When the contractor is responsible for operations or maintenance of the systems, the contractor shall apply the security fixes within the timeframe specified by the associated controls on the VA Information Security Knowledge Service. When security fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the contractor shall provide written notice to the VA COR/CO that the patch has been validated as to not affecting the Systems within 10 business days.
B7. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE OR USE. – This section is not applicable.
B8. SECURITY AND PRIVACY CONTROLS COMPLIANCE TESTING, ASSESSMENT AND
AUDITING. This entire section applies whenever section 6 or 7 is included.
a. Should VA request it, the contractor shall provide a copy of their (corporation’s, sole proprietorship’s, partnership’s, limited liability company (LLC), or other business structure entity’s) policies, procedures, evidence, and independent report summaries related to specified cybersecurity frameworks (International Organization for Standardization (ISO), NIST Cybersecurity Framework (CSF), etc.). VA or its third-party/partner designee (if applicable) are further entitled to perform their own audits and security/penetration tests of the contractor’s IT or systems and controls, to ascertain whether the contractor is complying with the information security, network or system requirements mandated in the agreement between VA and the contractor.
b. Any audits or tests of the contractor or third-party designees/partner VA elects to carry out will commence within 30 business days of VA notification. Such audits, tests and assessments may include the following: (a): security/penetration tests which both sides agree will not unduly impact contractor operations; (b): interviews with pertinent stakeholders and practitioners; (c):
document review; and (d): technical inspections of networks and systems the contractor uses to destroy, maintain, receive, retain, or use VA information.
c. As part of these audits, tests and assessments, the contractor shall provide all information requested by VA. This information includes, but is not limited to, the following: equipment lists, network or infrastructure diagrams, relevant policy documents, system logs or details on information systems accessing, transporting, or processing VA data.
d. The contractor and at its own expense, shall comply with any recommendations resulting from VA audits, inspections, and tests. VA further retains the right to view any related security reports the contractor has generated as part of its own security assessment. The contractor shall also notify VA of the existence of any such security reports or other related assessments, upon completion and validation.
e. VA appointed auditors or other government agency partners may be granted access to such documentation on a need-to-know basis and coordinated through the COR/CO. The contractor shall comply with recommendations which result from these regulatory assessments on the part of VA regulators and associated government agency partners. transfer, installation, dealing in or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs or the platforming or data hosting of applications for consumer download.
b. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor are authentic. If procurement is unavailable from an OEM or authorized reseller, the contractor shall submit in writing details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.
c. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, information protection practices, integrity management program for sub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractor(s) shall specify how digital delivery for procured products, including patches, will be validated, and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.
d. If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).
e. The contractor shall provide a software bill of materials (SBOM) for procured (to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials (SBOM).”
f. Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S. registered mail and/or tamper-evident packaging for physical deliveries.
g. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering).
h. The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware.
B9 PRODUCT INTEGRITY, AUTHENTICITY, PROVENANCE, ANTI-COUNTERFEIT AND
ANTI-TAMPERING. This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.
a. The contractor shall comply with Code of Federal Regulations (CFR) Title 15 Part 7, “Securing the Information and Communications Technology and Services (ICTS) Supply Chain”, which prohibits ICTS Transactions from foreign adversaries. ICTS Transactions are defined as any acquisition, importation, transfer, installation, dealing in or use of any information and communications technology or service, including ongoing activities, such as managed services, data transmission, software updates, repairs or the platforming or data hosting of applications for consumer download.
b. When contracting terms require the contractor to procure equipment, the contractor shall purchase or acquire the equipment from an Original Equipment Manufacturer (OEM) or an authorized reseller of the OEM. The contractor shall attest that equipment procured from an OEM or authorized reseller or distributor are authentic. If procurement is unavailable from an
OEM or authorized reseller, the contractor shall submit in writing details of the circumstances prohibiting this from happening and procure a product waiver from the VA COR/CO.
c. All contractors shall establish, implement, and provide documentation for risk management practices for supply chain delivery of hardware, software (to include patches) and firmware provided under this agreement. Documentation will include chain of custody practices, inventory management program, information protection practices, integrity management program for sub-supplier provided components, and replacement parts requests. The contractor shall make spare parts available. All contractors shall specify how digital delivery for procured products, including patches, will be validated and monitored to ensure consistent delivery. The contractor shall apply encryption technology to protect procured products throughout the delivery process.
d. If a contractor provides software or patches to VA, the contractor shall publish or provide a hash conforming to the FIPS Security Requirements for Cryptographic Modules (FIPS 140-2 or successor).
e. The contractor shall provide a software bill of materials (SBOM) for purchase (to include licensed products) and consist of a list of components and associated metadata which make up the product. SBOMs must be generated in one of the data formats defined in the National Telecommunications and Information Administration (NTIA) report “The Minimum Elements for a Software Bill of Materials (SBOM).”
f. Contractors shall use or arrange for the use of trusted channels to ship procured products, such as U.S. registered mail and/or tamper-evident packaging for physical deliveries.
g. Throughout the delivery process, the contractor shall demonstrate a capability for detecting unauthorized access (tampering).
h. The contractor shall demonstrate chain-of-custody documentation for procured products and require tamper-evident packaging for the delivery of this hardware.
B10. VIRUSES, FIRMWARE AND MALWARE. - This entire section applies when the acquisition involves any product (application, hardware, or software) or when section 6 or 7 is included.
a. The contractor shall execute due diligence to ensure all provided software and patches, including third-party patches, are free of viruses and/or malware before releasing them to or installing them on VA information systems.
b. The contractor warrants it has no knowledge of and did not insert any malicious virus and/or malware code into any software or patches provided to VA which could potentially harm or disrupt VA information systems. The contractor shall use due diligence, if supplying third-party software or patches, to ensure the third-party has not inserted any malicious code and/or virus which could damage or disrupt VA information systems.
c. The contractor shall provide or arrange for the provision of technical justification as to why any “false positive” hit has taken place to ensure their code’s supply chain has not been…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .