S02 - Attachment B - Salary Survey Data PWS.pdf

PDF 739 KB Posted

Attached to
R405--Total Compensation Analysis (VA-23-00011103) Federal contract opportunity
Solicitation number
36C77624R0042
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This performance work statement outlines third-party survey data services required by the Veterans Health Administration. The contractor will purchase approximately 50 national and regional salary, benefits, and staffing surveys on behalf of VHA. The contractor must collect and submit VHA employee compensation data to the surveys, and analyze and report the collected market data to VHA. The contractor will also develop geographic differentials to report survey results by individual VHA facility locations, and provide a cloud-based compensation survey database and instruction guide. Additional requirements include assisting VHA with job architecture and analysis, monthly progress reports, and quarterly meetings. The base period of performance is one year with four optional one-year extensions. The contract type is firm-fixed-price. The anticipated place of performance is at the contractor's facilities.

View the file

Other files for this federal contract opportunity

Other files attached to R405--Total Compensation Analysis (VA-23-00011103), newest first.
File Type Posted
S05 - Total Compensation Analysis Questions and Answers.docx DOCX document
36C77624R0042 A0001.docx DOCX document
S02 - Attachment A - Past Performance Questionnaire 02.docx DOCX document
36C77624R0042.docx DOCX document
S02 - Attachment E - Wage Rates.txt TXT text file
S02 - Attachment D - Subcontracting Plan Template.docx DOCX document
S02 - Attachment C - Salary Survey Data QASP.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Veterans Health Administration Office of Workforce Management and Consulting

Third-Party Survey Data

Performance Work Statement (PWS)

1. Background: The Department of Veterans Affairs (VA), Veterans Health Administration (VHA) is one of the largest employers for health care professionals in the United States. VHA employs nurses, physicians, dentists, and many other health care occupations and ancillary support positions which are the cornerstone of our nation's largest healthcare system. As such, it is critical that individual VA medical centers are provided access to accurate, reliable, and recurring market-based third-party salary survey data. This market-based data is used to assess VA’s competitive position in each local labor market area and allows VA facilities to make informed, consistent, accurate, and timely compensation decisions for a wide variety of critical occupations. The majority of these health care professionals are appointed and paid pursuant to Title 38 United States Code (U.S.C.) Section 74, Veterans Health Administration-Personnel (38 U.S.C. §§ 7401-7474). More specifically, VHA is required by 38 U.S.C 7451 (Section 7451) to utilize third-party survey data, when available, to determine if Title 38 Locality Pay System (LPS) adjustments are necessary in order to compensate nurses, nurse anesthetists, physician assistants, as well as any other occupation covered by the Title 38 LPS (Section 7451). VHA competes with major employers in the health care market to fill health care positions and relies heavily on the flexibility to utilize third-party survey data to adjust salaries to enhance the VA’s ability to recruit and retain high quality employees.

VA is challenged in its ability to easily assess the health care labor market conditions due to a shortage of human resources staff, difficulty in obtaining quality data from competing entities due to anti-trust regulations, a lack of understanding of the data required during the analysis phases, and inconsistent job matching.

Additionally, the recent passage of the PACT Act (Sergeant First Class Heath Robinson Honoring our Promise to Address Comprehensive Toxics Act of 2022, or the Honoring our PACT Act of 2022 (P.L. 117-168)), which includes many new and improved compensation flexibilities, and the Secretary’s ten-point human infrastructure plan to recruit and retain VA employees requires VHA to be on the forefront of managing compensation.

In addition, VHA relies heavily on third-party survey data when making salary determinations for special salary rates approved under the authority of 38 U.S.C.

7455 for healthcare occupations and VHA police officers, as well as 5 U.S.C. 5305 for administrative and engineering positions. The special rates established under these authorities may be competitive with, but not exceed, pay for comparable positions at non-Federal facilities in the local labor market.

VHA also utilizes third-party survey data to assist in making market pay determinations for positions covered by the Physician, Dentist, and Podiatrist (PDP)

Pay System pursuant to 38 U.S.C. 7431. Title 38 LPS, special rate schedules, and PDP market pay are routinely established and adjusted based on third-party survey data for specific local labor market areas.

2. Scope of Work: The VHA is seeking a contractor who is an expert in compensation consulting and can provide the following services:

a. Survey Identification, Schedule, and Purchasing. Contractor will assist VHA in identifying a list of approximately 50 national and regional salary, benefits, and productivity/staff ratio surveys to participate in and receive survey data from. The contractor shall establish an agreement with each third-party survey provider, maintain and publish a calendar to submit timely VHA employee salary and other compensation data on VHA’s behalf, purchase surveys on behalf of VHA, and t apprise VHA as to when each third-party survey deliverable will be received.

b. VHA Survey Data Collection and Distribution. In order to perform appropriate job matching/benchmarking and participate in surveys on behalf of VHA, the contractor must have extensive knowledge of VHA healthcare occupations; knowledge of VHA’s unique grade and salary structure; and a thorough understanding of the various qualification standards for each VHA healthcare occupation.

Contractor shall collect and provide VHA employee survey and benefits data on behalf of 152+ VA medical centers, in different local labor market areas to third party survey providers on behalf of the VHA. By accessing large VHA electronic employee data files, the contractor shall extract, analyze, benchmark jobs based on VA job descriptions, and provide employee specific salary and benefit data including duty station locations to different third-party survey sources on VHA’s behalf. Each third-party survey may require data analysis of employee salaries for clinical, professional, administrative, technical, clerical, trade, engineering, security, or other healthcare occupations and will cover any duty station location within the VA Health Care System. This includes locations throughout the continental United States (CONUS), Alaska, Hawaii, and U.S. territories to include Puerto Rico, Guam, American Samoa, and the U.S. Virgin Islands.

c. Data Analysis and Report Generation - The contractor shall collect the third-party salary survey results and provide the results in a cloud-based database. Results must include the aggregate market data and analysis and create market comparisons for national and regional salary data. The contractor shall develop appropriate market analysis and market comparisons for occupations eligible for pay pursuant to 38 U.S.C. §§ 7401-7474. The contractor shall provide the compensation of all positions surveyed to include, minimum, median, maximum, and mean salary amounts for each position, minimum, median, and maximum ranges when available, and total cash compensation amounts. The total compensation shall include premium pay and differential amounts, recruitment and/or relocation benefits paid, educational assistance/debt reductions incentives (including student loan repayment programs), and other monetary benefits typically paid by employers. The contractor shall also obtain information on any other work/life benefits paid or offered to non-federal employees.

d. Application of Geographic Differentials - In order for VA to utilize national third-party survey data, upon purchase of the surveys the contractor must provide geographic differentials in order to extrapolate and report survey data for each individual VA local labor market area, using recognized industry standards and survey methodology comparable to the methodology used by the Bureau of Labor Statistics (BLS). A differential or percentage is calculated and applied to national survey data. The contractor shall develop and provide reports which allow VA to apply the determined geographic differentials to aggregate and individual national survey data sets for all established duty station locations.

e. Job Architecture (JA). Contractor will assist VHA in clearly defining and aligning employees to career paths through career tracks and job leveling to support competitive benchmarking and compensation validation. Employee data will be mapped and integrated into the cloud-based survey data solution and VHA’s Human Capital Management System (HR Smart). The Contractor will analyze VHA’s current pay structures and provide potential redesign options that will promote fair and competitive compensation compared to the external market.

All data files, reports, deliverables, etc., provided by the contractor shall be formatted and delivered to enable importing the data to an external, cloud-based database or compensation system.

The survey methodology performed by the Contractor shall comply with 38 U.S.C.

§7404, 7431, 7451, and 7455, as well as VA policy promulgated in VA Handbook 5007, specifically parts VI, IX, and X.

3. Period of Performance: The period of performance (PoP) shall be one (1) year from date of award, with four (4) twelve (12) month option periods.

The principal place of performance shall be at the Contractors’ facilities.

No work at any Government site will take place on Federal holidays or weekends, unless directed by the Contracting Officer (CO).

Authorized holidays for Contractor personnel performing work at a Government installation shall correspond with Government holidays. There are ten (10) Federal holidays set by law (5 U.S.C. §6103). Under current definitions, four (4) are set by date:

New Year's Day January 1st Juneteenth June 19th Independence Day July 4th Veterans Day November 11th Christmas Day December 25th

If any of the above falls on a Saturday, then the preceding Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday. The other six (6) are set by a day of the week and month:

Martin Luther King's Birthday Third (3rd) Monday in January Washington's Birthday Third (3rd) Monday in February Memorial Day Last Monday in May Labor Day First (1st) Monday in September Columbus Day Second (2nd) Monday in October Thanksgiving Fourth (4th) Thursday in November

4. Type of Order: All orders placed against this contract shall be Firm Fixed Price

(FFP).

5. Travel: The contractor must obtain written approval from the Contracting Officer’s

Representative (COR) before any travel begins, utilizing Section D, S02 Attachment 8 Travel Authorization Request Form. Travel and per diem expenses will be reimbursed on an actual expenditures basis in accordance with Federal Travel Regulations and FAR 31.205-46. Travel that occurs without written pre-approval will NOT be reimbursed. The contractor(s) MUST use S02 Attachment 1 Travel Authorization Request Form for travel pre-approval. Other documents or e-mails will NOT be accepted as pre-approval.

In order to be reimbursed for travel, the contractor(s) shall submit supporting documentation as required by Federal Travel Regulations with invoices for expenses incurred. Expenses for subsistence and lodging will be reimbursed to the contractor only to the extent where an overnight stay is necessary and authorized by Federal Travel Regulations in effect at the time of the stay for the specific location. Profit and G&A will not be an allowable reimbursement expense for travel. Additional information can be found at:

http://www.gsa.gov/Portal/gsa/ep/channelView.do?pageTypeId=17113&channelPag e=%2Fep%2Fchannel%2FgsaOverview.jsp&channelId=-24564

6. Deliverables:

TASK TASK NAME TASK DESCRIPTION

TASK 1 Contract Kick Off Meeting

The contractor shall hold a project kick-off meeting with a project advisory group comprised of key stakeholders and Subject Matter Experts (SMEs) to be identified by the VA PM. The contractor shall schedule the kick-off meeting to be held no later than (10) business days after contract award or as agreed upon between the VA PM and contractor. At the kick-off meeting, the contractor shall review the details of their intended approach, work plan and project schedule.

SUBTASK

1.1

Kickoff Meeting Minutes The contractor shall provide minutes to document the discussion during the kickoff meeting. Meeting minutes shall include the contractor's presentation, meeting attendees, and staff roster.

SUBTASK

1.2

Integrated Master Schedule of Deliverables

The contractor shall develop and maintain an Integrated Master Project Schedule (IMPS) of deliverables assigned in accordance with this PWS. The IMPS shall contain Gantt charts, and work breakdown structure.

TASK 2 –

PARA 2(B)

VA Data Collection The contractor shall be responsible for ensuring receipt of VA employee salary data files, duty station files, LPS schedules, special rate schedule files, General Schedule (GS) locality pay schedules, Title 38 pay schedule files, Federal Wage System pay schedules, Senior Executive Service pay schedule files from VHA WMC HRCoE as needed. The contractor will use these data files to provide detailed information to third-party survey sources on behalf of VA.

SUBTASK

2.1

VA Data Reformatting The Contractor shall reformat employee compensation data based on data that is duty station specific (City/State) to benchmark positions in each Third-Party Surveyor.

SUBTASK

2.2

VHA Data Distribution /Survey Participation

The contractor shall be responsible for the entire survey submission process on behalf of VA. This includes providing detailed information using employee data files and location files (see Task 2) in order to provide VHA information requested from a variety of third-party survey data companies/organizations that have been identified by

VHA.

TASK 3 –

PARA 2(A),

(C), (D)

Survey Collection/Purchasing

The contractor shall purchase surveys on behalf of VHA .

and Analysis of Third- Party Surveys - Para 2(a)

SUBTASK

3.1

Data Analysis – Para 2(c) The contractor shall analyze the data collected from the third-party surveyors. This analysis shall include aggregation of the market data.

SUBTASK

3.2

Geographical Differential Analysis – Para 2(d)

The contractor shall provide geographical differentials (drilled down to city/state) for all VHA duty station locations to national survey data.

TASK 4 –

PARA 2(C)

Compensation Survey Database

The contractor shall provide a cloud-based compensation survey database to be used by VHA employees working in human resource departments. This database shall be capable of the following:

A. Using established geographic differentials, solution shall apply a differential or percentage which is used to calculate survey data in order to populate salary information for a specific VHA duty station location.

This survey data is then reported for all established VHA duty station locations for a wide variety of clinical, professional, administrative, technical, clerical, trade, engineering, security/law enforcement, or other healthcare occupations.

B. HR specialists will be able to apply the appropriate differential to the desired city and state. The solution shall report the national survey data based on the geographic differential for the selected location.

C. The contractor shall provide a listing of all VHA duty station locations and the geographic differential percentage applied for the specific duty station location.

D. The solution shall also provide job titles, job descriptions along with the corresponding VHA job match, and a list of participating establishments.

E. Survey data shall include the following components:

minimum and maximum rates actually paid in a given job category, published minimum and maximum rates paid, mean salary, median salary, and percentile survey data, minimum, midpoint, and maximum reported rate ranges, along with additional data for premium or differential pay rates, bonuses, any performance or merit based pay components, etc.

F. A version of all data files and/or reports provided by the contractor shall afford VHA the ability to import the data to an external, cloud-based compensation system.

G. Reporting capability to export survey data from multiple surveys to excel and apply the appropriate geographic differential.

If required, the development of the compensation survey cloud based solution will only be required during the base year.

SUBTASK

4.1

INSTRUCTION GUIDE

FOR COMPENSATION

Contractor shall develop a survey deliverable instruction guide/training tool containing information on data definitions, instructions on how to utilize the solution, as well as a description of how the geographic differentials were determined and applied.

SURVEY FILE/

SOLUTION

SUBTASK

4.2

INSTRUCTION GUIDE

UPDATES

The contractor shall refer to tasks 1 and 2 to update the compensation survey file/database. The file/database, along with the corresponding instruction guides, shall be updated each option year to include the newly collected VHA and third-party salary survey information. The updated compensation survey files/database and instruction guides will then be provided (or updated) to the VHA WMC HRCoE Program Manager based on an agreed upon delivery schedule.

TASK 5 –

PARA 2 (E)

JOB ARCHITECTURE

APPROACH

Contractor will assist VHA in clearly defining and aligning employees to career paths through career tracks and job leveling to support competitive benchmarking and compensation validation. Employee data will be mapped and integrated into the cloud-based survey data solution and VHA’s Human Capital Management System (HR Smart). The Contractor will analyze VHA’s current pay structures and provide potential redesign options that will promote fair and competitive compensation compared to the external market.

SUBTASK

5.1

EMPLOYEE

MAPPING

Contractor will work collaboratively with VHA to conduct mapping of employees to the correct functions, families, career tracks and levels to align with the job architecture framework, prepare the information for upload to the compensation analysis modules (HCM Platform (currently HR Smart) and cloud-based survey data solution)

SUBTASK

5.2

VALIDATE

JOB/EMPLOYEE

DATA

Contractor will match job data and employee data in the cloud-based survey data system and provide and develop plan for integration of data into compensation analysis module in VHA’s HCM platform.

SUBTASK

5.3

BENCHMARKING Contractor will conduct market benchmarking, create market composites, and summarize key findings/trends, and conduct analysis to identify outliers.

SUBTASK

5.4

PAY STRUCTURE

ANALYSIS

Contractor will assess current state of VHA pay structure and provide guidance on aligning with competitive compensation practices. Contractor will conduct pay gap analysis to determine external and internal quality and prepare financial analysis and strategy to migrate to a new structure, to include total compensation analysis.

TASK 6 MONTHLY PROGRESS

REPORT

The contractor shall provide a monthly summary report detailing the status of the contractor's work on the requirements of the PWS. The report shall include project issues which arose during the preceding month and the contractor’s actions for resolutions.

TASK 7 QUARTERLY

MEETING AGENDAS

The contractor shall provide meeting management services each quarter during the Period of Performance.

The contractor shall schedule meetings, develop meeting agenda and topics, meeting related documentation. The meetings shall convey contractor's work status in accordance with the deliverables of the PWS.

SUBTASK

7.1

QUARTERLY

MEETING MINUTES

The contractors shall provide meeting minutes for each of the contractor led quarterly meetings. Quarterly meeting minutes shall include the contractor's presentation, meeting attendees, discussion points during the meetings, and actions, upcoming work related to the requirements of the PWS and the IMPS.

7. Formal Acceptance or Rejection of Deliverables: The Government will have ten

(10) business days to review each deliverable and provide feedback/comments.

The contractor shall have three (3) business days to incorporate feedback/comments and make appropriate revisions. The contractor shall provide the revised version of each deliverable to the COR and VA PM. The COR will review and determine final acceptance by the Government. The COR will notify the contractor of final acceptance within five (5) business days.

Method and Distribution of Deliverables: The Contractor shall deliver documentation in cloud-based or electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include the latest version of the following software, but no earlier than 2016: Microsoft (MS) 365, MS Word, MS Excel, MS PowerPoint, MS Project, MS Visio, AutoCAD, and Adobe PDF. These files must have the capability to be imported into an external site. One version of all data files and/or reports provided by the contractor shall afford VA the ability to import the data to an external, cloud-based database or compensation system.

The contractor shall adhere to all pertinent Veterans Affairs (VA) policy standards including but not limited to ensuring that all documentation and deliverables are provided within one week of their completion. The contractor shall be responsible for adhering to all pertinent VA information technology policies and procedures, which are discussed in Section 11 of this PWS.

8. Section 508 Acceptance Criteria: Supplies or services delivered as a result of this solicitation will be accepted based in part on satisfaction of identified Section 508 requirements for accessibility. If the deliverable includes features and functions in addition to those identified as requirements, these features and functions also need to conform to relevant Section 508 technical provisions, functional performance criteria, and information, documentation and support.

NOTE FOR DELIVERABLE ACCEPTANCE / QUALITY ASSURRANCE: Generally accepted inspection and test methods corresponding to the identified Section 508 standards is reflected in the attached EIT Acceptance Guide. This guide may be used to assist in the inspection and testing of supplies and services provided as contract deliverables corresponding to this solicitation.

9. Changes to the Statement of Work: Only the Contracting Officer is authorized to make any changes to this PWS; and the Contract Specialist will authorize such changes only through written correspondence. The Contract Specialist will keep a copy of each change in a project folder along with all other products of the project.

The contractor shall bear any and all costs incurred by the contractor through the actions of parties other than the Contracting Officer.

10. The COR and PM representative or any other individual (including VA or other

Government agency employees or employees of other contractors) other than the VA Contracting Officer are not authorized to make any changes of a contractually binding nature to the period of performance, funding and/or any other terms and conditions of any award or order resulting from this solicitation.

11. General Requirements

11.1 POSITION/TASK RISK DESIGNATION LEVEL(S) AND CONTRACTOR

PERSONNEL SECURITY REQUIREMENTS

POSITION/TASK RISK DESIGNATION LEVEL(S)

Position Sensitivity

Background Investigation (in accordance with Department of Veterans Affairs 0710 Handbook, “Personnel Security Suitability Program,” Appendix A)

Low

National Agency Check with Written Inquiries (NACI) A NACI is conducted by OPM and covers a 5-year period. It consists of a review of records contained in the OPM Security Investigations Index (SII) and the DOD Defense Central Investigations Index (DCII), FBI name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is used for Non-sensitive or Low Risk positions.

Moderate

Moderate Background Investigation (MBI) A MBI is conducted by OPM and covers a 5-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check], a credit report covering a period of 5 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, law enforcement check; and a verification of the educational degree.

High

Background Investigation (BI) A BI is conducted by OPM and covers a 10-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check report], a credit report covering a period of 10 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, spouse, neighbors, supervisor, co-workers; court records, law enforcement check, and a verification of the educational degree.

The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the Performance Work Statement are:

Position Sensitivity and Background Investigation Requirements

TASK NUMBER LOW/NACI MODERATE/MBI HIGH/BI

ALL TASKS

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

11.2 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

a. All Contractor employees who require access to the Department of Veterans Affairs’ (VA’s) information or computer systems shall be the subject of a background investigation in accordance with VA Directive 0710. This requirement is applicable to all subcontractor personnel requiring the same access. All Contractor (and subcontractor) employees who require access to the Department of Veterans Affairs’ building(s), ground(s), and space(s) (public and secure) will be issued a Contractor Personnel Identification Verification (PIV) Credential as described by Homeland Security Presidential Directive -12 (HSPD-12) and VA Directive 0735. The VA Directive 0710 provides additional guidance and clarification specific to Contractors’ investigations. In all cases, access (physical and computer) cannot be granted until the COR is officially notified by Security Investigations Center (SIC), Little Rock, Arkansas that contractor staff have meet the requirements of this section. Access can be granted however, prior to VA receiving final adjudication results.

(1) Position Sensitivity – The position sensitivity for each Contractor position is determined by the U.S. Office of Personnel Managements, Position Designation of National Security and Public Trust Positions (OPM – PDAT).

Each position will be designated at the high, moderate, or low risk level, depending on the position’s potential for adverse impact to the integrity and efficiency of the services (CFR 731.106). Multiple positions within a skilled trade or professional classification (examples: electricians’, general construction labors’, Health Care Professionals (RN, DO, MD,) maybe documented on a single PDAT Form. Risk levels determine what level of investigation is required.

(2) Background Investigation – The level of background investigation commensurate with the required level of access may be either a Special Agreement Check (SAC)/National Criminal History Check (NHCH), National Agency Check with Inquiries (NACI) (low risk), Moderate Background Investigation (MBI) (moderate risk), or Background Investigation (high risk).

Non-citizen contract personnel appointed to low risk positions will be subject to a National Agency Check with Law Enforcement and Credit Check.

(3) Contractor Personnel Identification Verification (PIV) Credential – This form of universal government identification is the only acceptable form or Federal Identification permitted on government property. This credential is government property and will be surrendered upon the completion of contract or at the destruction of the government. The bearer is responsible for the loss, theft or improper destruction, and as such may be subject to replacement costs at time of reissue. PIV Credentials have an expiration date and will be become void upon the date indicated. The type of PIV Credential required is commensurate with the required level of access, length of contract award, and physical/computer access. There are three types of Contractor PIV Credentials:

a. Flash Badge PIV Credential – requires the bearer to be subject to agency

ID Proofing and issued for periods of one (1) day up to 180 days (continual usage).

b. Non-PIV Credentials - requires the bearer to be subject to agency ID

Proofing, a SAC/NCHC (fingerprinting), to undergo a background investigation (low risk), and issued for periods of 180 days up to one (1) year.

c. PIV Credential - requires the bearer to be subject to agency ID Proofing, a

SAC/NCHC (fingerprinting), to undergo a background investigation (low risk), and issued for periods of one (1) year up to three (3) years.

NOTE: There are no costs for the issuance of the Contractor PIV Credential.

(4) Contractor Responsibilities:

(a) The Contractor (subcontractor) shall prescreen all personnel requiring access to VA information or any VA computer systems to ensure that they are able to read, write, speak, and understand the English language.

(b) E-mail notifications will be received by the Contractor from the VA

Security Investigations Center (SIC) explaining specific instructions once an investigation has been ordered. The Contractor (subcontractor) employees will be required to complete their background investigation using the Electronic Questioner Investigation Process (eQIP) hyperlink within the allotted period (5 calendar days) from notification by the SIC.

The Contractor will be required to complete and provide all required background investigation document(s) to the SIC via traceable method (FedEx, DHL, etc.) within three (3) calendar days of electronic release of the eQIP background investigation.

(c) Contractors who have a favorably adjudicated background investigation and it has been determined by the SIC to be acceptable may be eligible for Reciprocity. The Contractor will be required to complete the

Declaration of Federal Employment Form (OF-306) and complete a new SAC/NCHC submission. The SIC is the Agency Authority regarding Reciprocity. Access to the VA facilities, information, or systems cannot be granted until the SIC has received all requirements from the Contractor. (subcontractor).

(d) The Contractor (subcontractor) employee shall complete the SAC/NCHC

(fingerprinting) requirement electronically at the VA Medical Center. The Contractor shall contact by telephone the local VA Medical Center (VA Police or VA Human Resource Office) or visit http://www.va-piv.com to establish appointments for fingerprinting. VA uses electronic fingerprint machines which require the Contract (subcontractor) employee to fill out the Electronic Fingerprint Verification Letter on the Veteran Health Administration (VHA) Service Center Website.

Please feel free to contact the SIC at VSC.Security@va.govwith any questions during this process.

(e) The Contractor, when notified of an unfavorable determination by the Government, will immediately withdraw the employee from consideration from working under the contract and return all Government Property.

(f) Upon contract award and request by the contracting office, the Contractor

(subcontractor) shall furnish the Information Security Office and the Contracting Officer a list of personnel performing work on the contract.

The list will include a brief description of the work to be performed and degree of access to information management systems required. The description of required degree of access will address if remote access is required. The Contractor shall update and submit the list of personnel performing work on the contract to the Information Security Office every (calendar) year, throughout the contract period. Furthermore, the Contractor shall notify the Information Security Office when personnel performing work under this contract no longer require access to the information management systems within 24 hours of employee change.

(g) Per VA Directive 6500 the Contractor (subcontractor) employee shall complete all required VA Information Security Training classes entitled “VA Information Security Awareness” and VHA Privacy Policy” on a yearly basis. Certificate(s) of successful completion will be generated for each course. These certificates of successful completion shall be maintained by the Contractor, the Information Security Office and the Contracting Officer and be made available for inspection and audit as determined by the Government.

(h) Failure to comply with the Contractor personnel security requirements shall result on termination of the contract for default.

(5) Government Responsibilities:

(a) Upon receipt, the VA Office of Security and Law Enforcement will review the completed electronic submission(s), and all completed forms for accuracy, then release (electronically) and forward via official mail the forms to OPM to conduct the background investigation.

(b) The VA facility/activity will pay for the investigations conducted by the

Office of Personnel Management (OPM) in advance. In these instances, the Contractor WILL reimburse the VA within 30 days of receiving the Bill of Collections for these costs.

(c) The VA Office of Security and Law Enforcement will notify the

Contracting Officer and Contractor after adjudicating the results of the background investigation(s) received by OPM using the Certificate of Investigations Form.

(d) The Contracting Officer will ensure that the Contactor (subcontractor) provides evidence that investigations have been completed or are in process of being requested.

b. Contractor (subcontractor) personnel performing work under this contract shall satisfy all requirements for appropriate security eligibility in dealing with access to sensitive information and information systems belonging to or being used on behalf of the Department of Veterans Affairs’. The Contractor (subcontractor) will be responsible for the actions of those individuals they provide to perform work for the VA under this contract. In the event that damages arise from work performed by Contractor (subcontractor) provided personnel, under the auspices of this contract, the Contractor will be responsible for all resources necessary to remedy the incident. Printed output containing sensitive VHA data will be stored in a secured area and disposed of properly by shredding using NIST-compliant shredder or other VA approved method. Under the provisions of the Privacy Act of 1974 as amended, personnel performing work under this contract have an obligation to protect VA information indefinitely.

Furthermore, it is the Contractor’s responsibility to notify the Information Management Staff when access to Information Management systems is no longer needed by personnel performing work under this contract.

c. No contractor (non-VA) equipment is permitted to be connected to the VA network without prior approval. If a laptop or desktop computer must be connected, a security check must be completed by the Information Technology Staff at the local Information Security Office. If unapproved equipment is detected, it will be immediately disconnected from the VA network.

d. If remote access is required in order to perform the work in this contract, a VPN request form must be completed and approved by the local COR designee, and submitted to the Information Security Office (ISO). The account will be given access only to the IP addresses required by this contract. The Contractor (subcontractor) will make every attempt to use the VA’s RESCUE software in order to remotely connect to the VA network. Use of CITRIX may also be used to remotely connect to the VA network with proper authorization. If RESCUE/CITRIX cannot be used to perform the required risks, then a waiver request must be submitted in order to use temporary "PIV EXEMPT

PASSWORD".

e. Contractor (subcontractor) personnel are not permitted to have administrative rights on a VA server without an approved waiver. Contractor personnel must work with the local VA IT staff to perform administrative functions. A waiver will only be considered in cases where the use of VA IT staff is not possible or not feasible. The waiver must be submitted to and approved by the Information Security Office.

13.0 FACILITY/RESOURCE PROVISIONS - The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.

The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.

VA will provide access to VA specific systems/network as required for execution of the task via remote access technology (e.g. Citrix Access Gateway (CAG), site-to-site VPN, or VA Remote Access Security Compliance Update Environment (RESCUE)). The Contractor shall utilize Government-provided software development and test accounts, document and requirements repositories, etc. as required for the development, storage, maintenance and delivery of products within the scope of this effort. The Contractor shall not transmit, store or otherwise maintain sensitive data or products in Contractor systems (or media) within the VA firewall IAW VA Handbook 6500.6 All VA sensitive information shall be protected at all times in accordance with VA policy.

11.3 GOVERNMENT FURNISHED PROPERTY

The Government will not provide property to the contractor.

11.4 VA INFORMATION CUSTODIAL LANGUAGE

The following security requirement must be addressed regarding Contractor supplied equipment: Contractor supplied equipment, PCs of all types, equipment with hard drives, etc. for contract services must meet all security requirements that apply to Government Furnished Equipment (GFE) and Government Owned Equipment (GOE). Security Requirements include: a) VA Approved Encryption Software must be installed on all laptops or mobile devices before placed into operation, b) Bluetooth equipped devices are prohibited within the VA; Bluetooth must be permanently disabled or removed from the device, c) VA approved anti-virus and firewall software, d) Equipment must meet all VA sanitization requirements and procedures before disposal. The COR, CO, the Project Manager, and the Information Security Officer (ISO) must be notified and verify all security requirements have been adhered to.

a. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

b. VA information should not be co-mingled, if possible, with any other data on the Contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

c. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Directive 6500, Cybersecurity Program. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.

d. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose, and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

e. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

f. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

h. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

i. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval.

The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.

l. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the

COR.

12. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

a. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.

b. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.

c. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor’s systems in accordance with VA Handbook 6500.3, Assessment, Authorization, and Continuous Monitoring Of VA Information Systems and/or the VA OCS Certification Program Office.

Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.

d. The contractor/subcontractor’s system shall adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process.

The contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government.

Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing, and updating, all the documentation (PIA, System Security Plan, Contingency Plan). The

Certification Program Office can provide guidance on whether a new C&A would be necessary.

e. The contractor/subcontractor shall conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment shall be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor shall take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

f. VA prohibits the installation and use of personally owned or contractor/subcontractor owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.

g. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information shall be handled in adherence with VA Handbook 6500. Media (hard drives, optical disks, CDs, back-up tapes, etc.)

used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500 requirements. This shall be completed within 30 days of termination of the contract.

13. SECURITY INCIDENT INVESTIGATION

a. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access, in accordance with VA Handbook

6500.2 Management of Security and Privacy Incidents

b. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

c. In instances of theft or break-in or other criminal activity, the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .