SAS Performance Work Statement.pdf
PDF 365 KB Posted
- Attached to
- Strategic Advisor Support (SAS) Services - DRAFT RFP Federal contract opportunity
- Solicitation number
- HT0015-24-R-0021
- Issued by
- Defense Health Agency
About this file
This document is a draft Performance Work Statement (PWS) for a Strategic Advisor Support (SAS) Services contract issued by the Defense Health Agency (DHA).
The PWS outlines the requirement for the contractor to provide strategic advisory support services to the DHA's Program Executive Office (PEO) Medical Systems (MS)/J-6 Chief Information Officer (CIO) across the Military Health System (MHS). The key objectives include providing guidance and direction to staff, management and technical coordination of acquisition actions, reporting and analysis, acquisition policy reviews, contract administration, and participation in Integrated Project Teams. The contract will have a one-year base period with four 12-month option periods. The work will be performed primarily at government sites in Falls Church, VA and San Antonio, TX. The Government is seeking feedback from industry on the PWS content, CLIN structure, instructions to offerors, evaluation criteria, and OCI mitigation plan.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HT001524R0021 Draft SAS Solicitation.pdf | ||
| Attachment 4- Past Performance Questionnaire.docx | DOCX document | |
| PWS 1.6. Exhibit C DHA Training.pdf | ||
| Attachment 3 - OCI Mitigation Plan Checklist.docx | DOCX document | |
| 52.212-1_Instructions to Offerors.pdf | ||
| 52.212-2_Evaluation Criteria.pdf | ||
| Attachment 2- SAS Minimum Employee Compensation Matrix.xlsx | XLSX spreadsheet | |
| Attachment 1- Pricing Matrix.xlsx | XLSX spreadsheet | |
| SAS Draft RFP Feedback Form.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Defense
Defense Health Agency
Performance Work Statement
Strategic Advisor Support (SAS) Services
Program Executive Office (PEO) Medical Systems (MS)/
J-6 Chief Information Officer (CIO)
Portfolio and Resource Management Division (PRMD)
Information Technology Business Strategy and
Rationalization (ITBSR) Branch and
Enterprise Information Technology Services (EITS)
Solicitation Number: HT0015-24-X-XXXX
Version: 1.0
Date: 24 June 2024
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide Strategic Acquisition Services (SAS) to support the Program Executive Office (PEO) Medical Systems (MS)/J-6 Chief Information
Officer (CIO).
1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform SAS as defined in this Performance Work Statement
(PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.
1.3 Background: The DHA operates under the policy guidance of the Office of the Assistant
Secretary of Defense Health Affairs (ASD[HA]). The PEO MS/J-6 CIO is a principal advisor to the ASD(HA), the Principal Deputy Assistant Secretary of Defense (PDASD[HA]), and the
DHA Director on all matters pertaining to the Military Health System (MHS) Information
Technology (IT), to include: strategic planning, IT capital planning and investment processes, linking performance measures to the MHS and DHA priorities and goals, emerging IT, data standardization, cybersecurity, establishing appropriate external coalitions and communications related to IT, consolidation of mandates of Section 702 of the National Defense Authorization
Act (NDAA) of 2017, as amended by Section 711 of the NDAA of 2019, Clinger-Cohen Act, Federal IT Acquisition Reform Act (FITARA) compliance, and guiding the IT integration and standardization across the MHS. The PEO MS/J-6 CIO is responsible for the organization and management of the directorate to accomplish its mission effectively and economically. In support of the PEO MS/J-6 CIO as principal advisor, its divisions include, but are not limited to:
Portfolio and Resource Management Division (PRMD), Market Technology Integration Office
(MTIO), Infrastructure and Operations Division (IOD), Engineering Solutions Architecture –
Business Analytics Division (ESABAD), Risk Management Executive Division (RMED), Solutions Delivery Division (SDD) and the Enterprise Information Technology Services (EITS).
1.4 Objectives: The contractor shall provide SAS to the PEO MS/J-6 CIO and its divisions in support of its mission across the MHS.
1.5 Scope: The contractor shall provide SAS to PEO MS/J-6 CIO and its divisions. Services include, but are not limited to: providing guidance and direction to staff across the MHS to accomplish IT implementation at all Military Medical Treatment Facilities (MTFs), providing management, supervision, technical direction and coordination of acquisition actions, reporting, and analytical activities, reviews and recommends acquisition policies related to J-6 for PEO
MS/J-6 CIO approval, coordinated acquisition activities for the PEO MS/J-6 CIO program offices and divisions, liaison acquisition activities with external/internal entities for PEO MS/J-6
CIO, draft acquisition policies related to IT products and services for PEO MS/J-6 CIO approval, managing procurement system administration, providing acquisition and Contracting Officer’s
Representative (COR) support for contracts valued at < $100 million, perform rationalization efforts on PEO MS/J-6 CIO contracts, review and ensure new, re-compete, modification contract packages (PWS, Acquisition Strategies, etc.) meet DHA standards, analyze and measure probable effects of various acquisition strategies, make recommendations on acquisition strategies and streamlining, and participation in Integrated Project Teams (IPTs).
1.6 Period of Performance (PoP): The PoP for this requirement is one 12-month base period and four 12-month option periods, unless the Option to Extend Services is exercised, allowing the PoP to be extended by up to six additional months.
1.7 Administrative specifications
1.7.1 Place of performance: The work shall be performed at Government sites within the Falls
Church, VA and San Antonio, TX areas. Falls Church, VA addresses include: The Defense
Health Headquarters (DHHQ) located at 7700 Arlington Blvd., and the Skyline Tower located at
5107 VA-7. The San Antonio, TX addresses include: Joint Base San Antonio Fort Sam Houston
(JBSA-FSH), Tech II located at 3130 General Hudnell Drive, and Lincoln Center at 7800 I-10
West. The contractor shall ensure their personnel are capable of meeting with Government personnel at different times and in different locations within the place of performance within forty-five (45) minutes after notification of a meeting by the COR. Meeting with the Government at different locations is defined as either virtual or via phone and/or video conferencing. In-person locations are limited to those outlined in this paragraph. All meetings occur as defined in paragraph 1.7.4., Hours of Operations. Work performed on vendor sites have been annotated in
Part 5 of this PWS.
1.7.2. Regular/Reoccurring Telework. Regular/reoccurring telework for Contractor staff may be authorized if determined by the Government. Situational telework may be authorized in certain temporary situations where the designated workplace has no Government oversight due to emergency or weather closures.
1.7.2.1. Situational Telework arrangements may be considered on a case-by-case basis. The
Contractor shall provide adequate oversight of tasks and deliverables to ensure contract adherence during regular/reoccurring and situational telework. The Contractor shall have formal telework policies in place if situational telework is employed. Regular/reoccurring and situational telework arrangements shall have final Government approval under the following:
Regular/Reoccurring and Situational Teleworking shall not result in an increase in contract price;
The Contractor is responsible for continuity of performance in accordance with the terms of the contract; Any equipment provided by the Government for regular/reoccurring and situational telework purposes will be treated as Government Furnished Equipment.
1.7.2.2. Contractors are authorized to work from an Alternate duty/remote location during emergency situations within their approved area of operations with the approval of the
Contracting Officer’s Representative and Contracting Officer. The Government does not authorize the use of off-site rates to accomplish alternate duty/remote location work and will not be responsible for any associated costs. Personal or company issued equipment may not be used to access the Government network infrastructure unless pre-approved; examples include using
VPN or a corporate network. However, inability to access the Government network infrastructure using authorized devices does not necessarily prohibit the contractor from performing off-site, whenever the work could be performed without such access.
1.7.3 Recognized Federal holidays. The contractor is not required to perform non-emergency services on the below list of recognized Federal holidays:
New Year’s Day Labor Day
Martin Luther King Jr.’s Birthday Columbus Day
President’s Day Veteran’s Day
Memorial Day Thanksgiving Day
Juneteenth Day Christmas Day
Independence Day
1.7.4 Hours of operation: The contractor is responsible for conducting business Monday thru
Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. Normal operating hours are 0730 to 1630, and core operating hours are 0900 to 1500, local time. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.7.5 Emergency Services:. On occasion, services may be required to support an activation or exercise of contingency plans outside the normal duty hours.
1.8. Organizational Conflict of Interest (OCI). Because the services covered in this PWS involve supporting the DHA in planning, programming, budgeting, and executing (PPBE) IT as well as strategically aligning and rationalizing PEO MS/J-6 CIO acquisition support functions and services across the MHS and managing the MHS IT portfolio, the contractor will have broad-based access to competitively useful information, will be in a position to influence the development of MHS IT requirements, and will regularly be called upon to provide the
Government with objective recommendations and advice. As such, the Contracting Officer has determined that the work performed under this PWS will give rise to OCI for the contract holder and any of its owners, partners, subsidiaries, affiliates, team members, and subcontractors both during performance and in relation to potential future Government contracts, particularly PEO
MS/J-6 CIO contract. Therefore, the contract holder and any of its owners, partners, subsidiaries, affiliates, team members, and subcontractors shall be ineligible to perform as a contractor, subcontractor, or team member on any of the to-be-awarded PEO MS/J-6 CIO associated contracts for the duration of the contract and for 18 months after the final day of performance under this contract.
1.8 Contractor travel: The contractor shall be required to travel within the Continental United
States (CONUS) and within the National Capitol Region (NCR) and San Antonio, TX, to attend meetings, conferences, and training. The contractor may be required to travel to off-site training locations and to ship training aids to these locations in support of this PWS. Contractor shall be authorized travel expenses consistent with Federal Travel Regulations (FTR) electronic Code of
Federal Regulations (eCFR) 41. All travel requires pre-approval/authorization by the COR and notification to the Contracting Officer. Arrangements for and costs of all travel, transportation, meals, lodging, and incidentals are the responsibility of the Contractor. All travel requests must be submitted to the COR for approval five (5) business days prior travel. Travel estimates for airfare, car rental, lodging, etc. shall accompany the request. All travel and transportation shall utilize commercial sources and carriers provided the method used for the appropriate geographical area results in reasonable charges to the Government. The Government will not pay for business class or first-class travel. A trip report and actual costs, by person, by trip, will be reported to the COR within five (5) business days of completion of travel (Exhibit A). Contractor shall attach supporting documentation (COR approval, trip report, associated receipts, etc.) with each travel invoice. Contractor will be authorized travel expenses consistent with the substantive provisions of the FTR eCFR 41specified in this contract. Estimated Travel is indicated below:
From To Round Trip
(Y/N)
# of
Trips
# of
People
# of Days
Falls Church, VA San Antonio, TX Y 4 2-4 4
San Antonio, TX Falls Church, VA Y 2 2 4
San Antonio, TX TBD, in support of
Defense Health
Information
Technology
Symposium (DHITS)
Y 2 3 5
Falls Church, VA TBD, in support of
Defense Health
Information
Technology
Symposium (DHITS)
Y 2 3 5
1.9 Other Direct Costs (ODC): All ODCs shall be pre-approved by the COR in writing and paid in accordance with (IAW) FAR 31.205-43.
1.10 Quality
1.10.1 Quality Control (QC): Reserved.
1.10.2 Quality assurance (QA): The Government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP)
(Attachment 1). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.11 Contractor personnel
1.11.1 CAC requirements: For all contractors who will work in Government facilities, the
Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the
Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated (Exhibit B DHA CAC Request Process) within 30 calendar days of award. A CAC is the standard identification for eligible DoD contractor personnel.
1.11.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).
1.11.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements within 30 calendar days of contract award and/or planned/unplanned personnel vacancies:
1.11.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA
Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx
1.11.2.2 The DHA’s contractor training instructions are included at Exhibit C.
1.11.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at:
https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure
(PKI)-restricted, printed versions available).
1.11.2.4 The DHA’s new employee handbook at Attachment 2.
1.11.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
1.11.4 Key control: Reserved.
1.12 Key personnel (Contractor): The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO.
The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between 0730 to 1630, local time, Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons.
1.13 Data rights: The Government shall retain rights to all data produced in the course of developing, deploying, training, using and supporting DHA or other federal agencies that utilize this contract.
1.14 Reporting
1.14.1 Service Contractor Reporting (SCR): RESERVED.
https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx
1.14.2 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.
1.14.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.14.4 Post award conference/periodic progress meetings: The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with FAR Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance.
At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government.
1.15 Contractor Identification
1.15.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy
Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.
Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.15.2 Contractor personnel will be required to attend meetings or otherwise communicate with
Government and/or other contract representatives to meet the requirements of this order.
Contractor personnel shall make their contractor status known during introductions.
1.15.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.16 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.16.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system. Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard
Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.
1.16.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the
DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.17 Personnel Security
1.17.1 The contractor shall comply with DoD Manual (DoDM) 8140.03, “Cyberspace
Workforce Qualification and Management Program; 8500.01, “Cybersecurity”, dated March 14, 2014, incorporating change 1 effective October 7, 2019; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy
Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense
Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM 5200.02 “Procedures for the DoD Personnel Security
Program (PSP),” incorporation change 1, effective October 29, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.17.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security
Office can be reached at dha.ncr.security.mbx.personnel-security-office@health.mil.
1.17.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.17.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE
PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D-
Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R-
Services)
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does
NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
2.2 Acronyms:
AIS Automated Information System
AQL Acceptable Quality Level
ATO Authority to Operate
CAC Common Access Card
CAP Cloud Access Point
CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme
CDI Covered Defense Information
CE Computer Environment
CDRL Contract Data Requirement List
CIO Chief Information Officer
CJCSM Chairman of the Joint Chiefs of Staff Manual
CMMC Cybersecurity Maturity Model Certification
CMR Contractor Manpower Reporting
CNSSI Committee on National Security Systems Instruction
CO Contracting Officer(s)
CONUS Continental United States (excludes Alaska and Hawaii)
COR Contracting Officer’s Representative
CSP Cloud Service Provider
CSSP Cyber Security Service Provider
CUI Controlled Unclassified Information
DAD-A Deputy Assistant Director for Acquisition
DC3 DoD Cyber Crime Center
DD Form 254 Department of Defense Contract Security Requirement List (if applicable)
DB Design-Build
DBB Design-Bid-Build
DFARS Defense Federal Acquisition Regulation Supplement
DHA Defense Health Agency
DISA Defense Information System Agency
DoD Department of Defense
DoDD Department of Defense Directive
DoDI Department of Defense Instruction
DoDM Department of Defense Manual
DSAs Data Sharing Agreements
DSAA Data Sharing Agreement Application
DMZ Demilitarized Zone
DoDM Department of Defense Manual
DPCLO DHA Privacy and Civil Liberties Office
DUA Data Use Agreement eMSM Enhanced Multi-Service Markets
EULA End User License Agreement
FAR Federal Acquisition Regulation
FCI Federal contract information
FE Facilities Enterprise
FedRAMP Federal Risk Authorization and Management Program
FISMA Federal Information Security Modernization Act
FRCS Facility Related Control Systems
FSO Facilities Security Officer
HA Health Affairs
HIPAA Health Insurance Portability and Accountability Act
HCA Head of the Contracting Activity
HIT Health Information Technology
IGCE Independent Government Cost Estimate
IA Information Assurance
IO Initial Outfitting
I/O In/Out Processing Portal
IPv Internet Protocol Version
IS Information System
ISP Internet Service Provider
IT Information Technology
ISCM Information Security Continuous Monitoring
IV&V Independent Verification & Validation
MedCOI Medical Community of Interest
MHS Military Health System
MIL-STD Military Standard
MTFs Military Medical Treatment Facilities
NCR National Capitol Region
NDA Non-Disclosure Agreement
NIAP National Information Assurance Partnership
NIST National Institute of Standards and Technology
OCONUS Outside Continental United States (includes Alaska and Hawaii)
ODC Other Direct Costs
OPM Office of Personal Management
OSD Office of the Secretary of Defense
P-ATO Personal Authorization to Operate
P&R Personnel and Readiness
PGI Procedures, Guidance and Information
PDT Project Delivery Team
PHI Protected Health Information
PII Personally Identifiable Information
PIT Platform Information Technology
PK Public Key
PKI Public Key Infrastructure
POA&M Plan of Action and Milestones
POC Point of Contact
PMO Program Management Office
PoP Period of Performance
PP Personal Property
PPSM Ports, Protocols, and Services Management
PRS Performance Requirements Summary
PSP Personnel Security Program
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Plan
RFP Request for Proposal
RFQ Request for Quotation
RMF Risk Management Framework
SP Special Publication
SPRS Supplier Performance Risk System
SRM Sustainment, Restoration and Modernization
SRG Security Requirements Guides
STIG Security Technical Implementation Guides
TOS Terms of Service
US United States
UFC Unified Facilities Criteria
VPN Virtual Private Network
XML Extensible Markup Language
2.3 Applicable Publications, DHA Administrative Instructions (AI), etc. Reserved.
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government will NOT provide Services in support of this contract. As a result, this paragraph is Not Applicable.
3.2 Facilities: The Government will NOT provide Facilities in support of this contract. As a
3.3 Utilities: The Government will NOT provide Utilities in support of this contract. As a
3.4 Equipment: The Government will provide government issued laptops. The Government provided Equipment is described below:
The Government will provide computer equipment to include laptops for use in performance under this contract. This equipment is authorized for transaction of official Government business only and shall not be used for personal business. Items issued will remain the property of the
Government and the contractor will maintain proper accountability of issued equipment. They are to be used, turned in and/or disposed of as directed by the COR or CO. Government information or data shall not go into non-Government computers or databases.
3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application
The contractor shall be responsible for obtaining and maintaining access, training and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP.
The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.
Contracting Office Responsibilities:
The Contracting Office shall ensure close coordination and validation of the GFP items with the
COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the
PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Government’s responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.
https://wawf.eb.mil/piee-landing/ https://wawf.eb.mil/piee-landing/ https://dodprocurementtoolbox.com/
The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the
Contracting Office and requested within the PIEE/GFP Module system.
Contractor Responsibilities:
A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a complete and accurate accounting of the
GFP applicable to the contract/task order. Contractors are required to report the receipt of any
GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract.
Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.
3.5 Materials: The Government:
Will NOT provide Materials in support of this contract. As a result, this paragraph is Not
Applicable.
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 Services: The Contractor:
Will NOT provide Contractor Furnished Services in support of this contract. As a result, this paragraph is Not Applicable.
4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Part 5 of this PWS.
4.3 Secret Facility Clearance: Reserved.
4.4 Materials: The contractor shall furnish materials, supplies, and equipment necessary to meet the requirements under this PWS.
4.5 Equipment: The Government shall furnish the government issued laptops for contractor use in performance of this PWS.
4.6 Facilities: Except as expressly provided in Part 3 of this PWS, the Contractor is responsible for providing the facilities and facilities-related support it needs to provide the Contractor
Services. The Contractor shall perform at contractor or other facilities when Government space is not available or during emergency/contingency situations. During emergency/contingency situations the contractor shall ensure necessary workspace for the contractor staff is available to provide the support outlined in the PWS to include desk space, telephones, computers, and other items necessary to maintain an office environment.
PART 5
5.0 SPECIFIC TASKS
This contract will support the DHA’s PEO MS/CIO(J-6) SAS efforts across the MHS.
For all contract support services and activities, a Monthly Performance Progress Report (MPPR) must be submitted by the 5th day of each Month (Exhibit D, or as required by Government Lead, or within a requested situational timeframe.
5.1 Strategic Advisor Support, Falls Church, VA: PEO MS/CIO(J-6) requires consulting expertise from personnel highly experienced in Department of Defense (DoD) acquisition and contracting processes to develop new acquisition strategies and contracting approaches. The following are critical Acquisition Regulatory related activities but are not limited to regulatory areas that must be considered.
5.1.1 The Contractor shall provide acquisition planning and strategic advice to identify, understand, analyze, articulate, and ensure compliance with acquisition (especially information technology) contracting regulations, guidelines, policies, processes/procedures.
5.1.2 The Contractor shall provide strategic advice on specific recommendations identified by the Section 809 Panel pending revisions to DoD Small Business strategy based on Section 851 of the FY 2019 NDAA, and acquisition reform provisions included in future National Defense
Authorization Acts.
5.1.3 The Contractor shall provide strategic advice and guidance related to acquisition planning, but not limited to, non-personal services, hardware and software acquisition practices, agile acquisition approaches and techniques, smarter use of common contract solutions and practices, best practices and state-of-the art techniques in fair opportunity and source selection.
5.1.4 The Contractor shall provide strategic advice and guidance on Acquisition of Software for
Defense Systems, Intellectual Property and Data Rights, current DoD cloud services acquisition initiatives, pending revisions to DoD Small Business strategies, and acquisition reform provisions included in recent and future NDAA.
5.1.5 The Contractor shall provide Acquisition Support training to ITBSR and PEO MS/CIO(J-6) staff. Additionally, the contractor shall help articulate and guide the PEO MS/CIO(J-6) acquisition process to address DHA acquisition needs across the innovation lifecycle, where appropriate, from problem definition to scaling tech solutions and transitioning pilots to programs of record. This shall include agile acquisition strategies and tech engagement in the following areas:
5.1.5.1. Horizon scanning to identify sector-specific mega-trends that can inform Government mission readiness.
5.1.5.2. Identification and prioritization of use cases that will attract the best technology with the greatest potential to improve mission outcomes.
5.1.5.3. Outreach and engagement to attract emerging tech companies for solicitation, industry days, tech roundtables, and other events.
5.1.5.4. Tech scouting and vetting to source emerging tech solutions that can best support
Government mission needs.
5.1.5.5. Agile acquisition strategy and support designed to encourage nontraditional emerging tech participation.
5.1.6 Special Qualifications: The Strategic Advisors must have a minimum of 15 years DoD acquisition experience and a master’s degree or two (2) additional years of experience in lieu of the master's degree requirement. Additionally, the Strategic Advisors are experts who demonstrate through leadership in their area of expertise through publications, speaking engagements, media citations, or other recognized interactions, by having actively participated and contributed to one or multiple acquisition DoD reforms in one of the following panels and/or
DoD acquisition innovations boards below:
5.1.6.1. Section 809 Panel (Streamlining and Codifying Acquisition Regulations)
5.1.6.2. Section 813 Panel on Intellectual Property and Data Rights report and recommendations
5.1.6.3. Defense Innovation Board (DIB) Software Acquisition Practices (SWAP) report and recommendations
5.2. Senior Multi-Sourcing Integration (MSI) Acquisition Advisor Support, San Antonio, TX: PEO MS/CIO(J-6) requires subject matter expertise from personnel highly experienced in
Multi-Sourcing Integration (MSI), Information Technology Service Management (ITSM), and
Information Technology Infrastructure Library 4 (ITIL) acquisition and contracting processes to develop new acquisition strategies and contracting approaches. Contractor is responsible for contributing to the establishment of MSI based PEO MS/CIO(J-6) Enterprise Information
Technology Services (EITS) guidelines, policies, and procedures for defining, developing, documenting, validating, and managing EITS initiatives and/or other similar projects. The following are critical related activities but are not limited to known current EITS effort areas that must be considered.
5.2.1. The Contractor shall provide acquisition and strategic advice to identify, understand, analyze, articulate, and ensure EITS efforts are implemented in a timely manner as determined by the EITS Program Manager and/or EITS Integrator (EITSI) Program Manager.
5.2.2. The Contractor shall provide acquisition planning and strategic support to realize EITS implementation of future EITSI call orders, Geographic Service Providers (GSP), Capability
Service Providers (CSP), and those determined by the EITS Program Manager or designated
Government lead.
5.2.3. Special Qualifications: The Senior MSI Acquisition Advisor must have experience in implementing MSI business model at state and/or federal Government institution(s) and have a minimum of 12 years state and/or Federal Government acquisition experience and a bachelor's degree.
5.3. Multi-Sourcing Integration (MSI) Acquisition Advisor Support, San Antonio, TX:
PEO MS/CIO(J-6) requires subject matter expert from personnel highly experienced in Multi-
Sourcing Integration (MSI), Information Technology Service Management (ITSM), and
Information Technology Infrastructure Library 4 (ITIL) acquisition and contracting processes to assisting in developing new acquisition planning strategies and contracting approaches. The
Contractor is responsible for contributing to the establishment of MSI based PEO MS/CIO(J-6)
Enterprise Information Technology Services (EITS) guidelines, policies, and procedures for defining, developing, documenting, validating, and managing EITS initiatives and/or other similar projects. The following are critical probable effects of various acquisition strategies, make recommendations on acquisition strategies and streamlining, participation in Integrated
Project Teams (IPTs), related activities, but are not limited to known current EITS effort areas that must be considered.
5.3.1. The Contractor shall provide acquisition planning and strategic support to identify, understand, analyze, and articulate EITS efforts in order to realize EITS implementation of future EITSI call orders, Geographic Service Providers (GSP), Capability Service Providers
(CSP), and those determined by the EITS Program Manager or designated Government lead.
5.3.2. Special Qualifications: The MSI Acquisition Advisor must have experience in implementing MSI business model at state and/or federal Government institution(s) and have a minimum of 8 years state and/or Federal Government acquisition experience and a bachelor’s degree.
(Optional) – The contractor shall provide MSI Acquisition Advisor Support for the SAS tasks lists in 5.3 of this PWS. The level of support is based o the roles and the number of FTEs outlined below.
MSI Acquisition Advisor 4.0
Total FTE 4.0
PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 All work under this contract is unclassified. however, contractor personnel without a current clearance will undergo a criminal background investigation and a favorable National Agency
Check with Inquiries (NACI) or higher. The contractor personnel must be able to obtain and maintain favorable suitability adjudication prior to commencement of duties; one major legal issue within 36 months of the suitability adjudication date is automatically disqualifying. The contractor will pre-screen employees for major issues relating to; Intoxicants, Drug Use, Financial Responsibility, Sexual Misconduct, Honesty, Disruptive or Violent Behavior, Employment Misconduct or Negligence, Illegal possession of Firearms or Weapons, acts of terrorism, Security denials or revocations, Serious Mental Health Issues, Associates or Relatives with issued that directly relate to the Contractor, and misuse of Information Technology
Systems. It is highly recommended Contractors bring their original passport or birth certificate.
The final Suitability Determination will be made by DHA leadership through the Security Office.
The Contractor personnel will be removed from the network and may be removed from the facility at any time if they are found unsuitable through the continuing evaluation process.
If Contractor personnel received interim declination or eligibility denial by the Defense
Industrial Security Office (DISCO) or any other Central Adjudication Facility (CAF), this action is automatically disqualifying and overrides local suitability determinations.
If a Contractor personnel is found unqualified for any reason or the personnel submits their resignation, the personnel shall be replaced with a qualified individual within 5 business days.
Contractor personnel will be required to sign a Non-Disclosure Agreement (NDA) due to access to Procurement Sensitive information. Violation of this NDA will be grounds for immediate removal of the contract employee.
6.2 The levels and position sensitivity designation for positions under this contract is:
6.2.1 TIER II: Non-critical sensitive position (A position where an individual is responsible for systems design, operation, testing, maintenance, and/or monitoring that is carried out.)
6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes
PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office
(DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into
DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect
MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.
After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:
6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity
Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.
6.4.1.2 Personally Identifiable Information Training (PII): DoD PII Training must be completed by all contractor employees and associated sub-contractor employees prior to issuance of network access and annually thereafter. DoD PII Training is available at the following website:
https://iase.disa.mil/eta/Pages/index.aspx.
6.4.1.3 Health Insurance Portability and Accountability Act (HIPAA) Training: DoD HIPAA training must be completed by all contractor personnel prior to issuance of network access and annually thereafter. DoD HIPAA training is available at the following website:
https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf?ORG=MHS.
6.4.1.4 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD
8570.01–M, IA Workforce Improvement Program and DoDD 8140.01, Cyberspace Workforce
Management requirements. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-7001, including:
6.4.1.4.1 As part of the DoD’s transition from DoD 8570-01-M to DoDD 8140.01, the
Government reserves the right to re-align DoD 8570.01 IA workforce functions to the appropriate DoD 8140 cyberworkforce roles to comply with DoDM 8140.03, Cyberspace
Workforce Qualification and Management Program implementation requirements. Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.
6.4.1.4.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction on Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS: RESERVED.
6.6 Risk Management Framework (RMF) for DoD IT: RESERVED.
6.7. Facility Related Control Systems: RESERVED.
6.8. System Communications: RESERVED.
6.9. Medical Logistics/Medical Devices: RESERVED.
6.10 MHS Demilitarized Zone (DMZ) Medical Community of Interest (MedCOI) Business-to-Business (B2B) Gateway
6.10.1 If there is an external system connection to a DoD IS required, then the contractor shall, in accordance with contract requirements, connect to the DHA B2B Gateway via a contractor procured Internet Service Provider (ISP) connection.
6.10.2 The contractor shall assume all responsibilities for establishing and maintaining their connectivity to the B2B Gateway. This shall include acquiring and maintaining the circuit used to connect to the B2B Gateway and the acquisition of a Virtual Private Network (VPN) device maintenance agreement and license compatible with the MHS VPN device. The list of compatible devices are detailed in the DHA B2B/MedCOI Gateway questionnaire.
6.10.3 The contractor shall submit a completed current version of the DHA B2B Gateway questionnaire to their Contracting Officer or COR within 10 calendar days after new requirements have been provided to the contractor.
6.10.4 The contractor shall provide information specific to their connectivity requirements, proposed path for the connection and last mile diagram.
6.11 Contractor Provided IT Infrastructure
6.11.1 Platforms shall support HyperText Transfer (Transport) Protocol (HTTP), HyperText
Transfer (Transport) Protocol Secure (HTTPS), web-derived Java Applets, and Secure File
Transfer Protocols (SFTPs) (e.g., STFP, Secure Socket Layer/Transport Layer Security), and all software that the contractor proposes to use to interconnect with DoD facilities.
6.11.2 The contractor shall configure their networks to support access to Government systems
(e.g., configure ports and protocols for access).
6.11.3 The contractor shall provide full time connections to a TIER 1 or TIER 2 ISP. Dial-up
ISP connections are not acceptable. All IP addresses need to be publicly routable. Private address space using Network Address Translation will not be permitted.
6.11.4 The contractor shall maintain a valid maintenance contract and pertinent licenses for all devices connecting to the MHS B2B Gateway.
6.12 System Authorization Access Request (SAAR), Defense Department (DD) Form 2875
6.12.1 The contractor shall submit the most current version of DD Form 2875, “System
Authorization Access Request (SAAR), in accordance with CO guidance for all contractors that use the DoD Gateways to access Government IT systems and/or DoD applications shall. A DD
Form 2875 shall be completed for each contractor employee who will access any system and/or application on a DoD network. The DD Form 2875 shall clearly specify the system and/or application name and justification for access to that system and/or application.
6.12.2 The contractor shall submit the completed DD Form 2875 to the DHA IT Security for verification of Tier I or Tier II Designation. The DHA Personnel Security will verify that the contractor employee has the appropriate background investigation completed or a request for background investigation has been submitted to the Office of Personal Management (OPM).
Acknowledgment from OPM that the request for a background investigation has been received and that an investigation has been scheduled will be verified by the DHA Personnel Security prior to access being approved.
6.12.3 Upon approval, DHA will notify the user of the ID and password via secure/encrypted e-mail upon the establishment of a user account. User accounts will be established for individual use and may not be shared by multiple users or for system generated access to any DoD application. Misuse of user accounts by individuals or contractor entities will result in termination of system access for the individual user account.
6.12.4 The contractor shall conduct a monthly review of all contractor employees who have been granted access to DoD…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .