SCOPE OF WORK.pdf

PDF 191 KB Posted

Attached to
6515--Replacement Eeg System- NATUS Brand Name Federal contract opportunity
Solicitation number
36C25723Q1086
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 17

About this file

This scope of work document outlines the requirements for replacing an EEG system at the El Paso Veterans Affairs Health Care System. Key requirements include a Natus Brain Monitor Amplifier with 64 AC channels and differential inputs, NeuroWorks/SleepWorks software, an ErgoJust cart, an IP-addressable HD PTZ camera, the ability to monitor multiple patients on one station through the software, and integration with the VA's CPRS/Vista EMR system. Installation and training is required within two days of installation, with additional training for staff and physicians if needed. The replacement system must be compliant with current VA operating systems and security requirements. The solicitation number is 36C25723Q1086 for this opportunity to provide a replacement EEG system from the Natus brand at the El Paso VAHCS.

View the file

Other files for this federal contract opportunity

Other files attached to 6515--Replacement Eeg System- NATUS Brand Name, newest first.
File Type Posted
Attachment C Clauses and Provisions.pdf PDF
36C25723Q1086_1.docx DOCX document
Attachment A Schedule of Prices.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

B.2 SCOPE OF WORK

1. GENERAL INFORMATION

El Paso Veterans Affairs Health Care System (EPVAHCS) Neurology Service requires replacement EEG Acquisition Desktop with IP PTZ 1080 HD Color/BW Camera unit.

The new unit will be compatible with new VA requirements for updated Operating Systems (Win 10 or greater). This unit will be utilized by Neurology Techs to address the incremental high volumes of outpatient routine EEGs. These units will seamlessly interface with VA arquitecture and offer HL7 Import and Export to our CPRS/Vista EMR.

The El Paso VA also requires an independent workstation for review and finalizing of captured EEG studies.

1.2. The Neuroworks EEG Acquisition unit is to replace existing unit that has reached end of life and functions on an outdated Operating System.

2.1. Minimum characteristics:

1. Natus Brain Monitor Amplifier

a. 64 AC channels, 6 Sensor inputs Referential Inputs

i. 40 referential + 24 programmable (from differential to ref)

b. Differential Inputs - Programmable up to 12

c. Sensor Inputs - 6 (Chest, Abdomen, Snore, Airflow, Pressure, Position)

d. DC Channels (patient side) - 4 non-isolated

e. DC Channels (computer side) - 12 isolated

2. Natus Base Unit – Touchscreen

3. NeuroWorks / SleepWorks 9 Software

4. ErgoJust Cart

5. IP Addressable HD PTZ camera and PSG Base Unit

a. CAT 5 or 6 network connection

b. TCP/IP (fixed and DHCP)

6. Ability to Monitor multiple patients on one station through the software

7. Must be Certified Citrix Ready!

8. https://citrixready.citrix.com/natus-medical-incorporated/neuroworks-sleepworks.html

9. Powerful Enterprise level SQL database as the back-end server

10. SQL Server 2019 and 2016 compatible

11. Windows Server 2019 and 2016 compatible

12. Must have Virtual Server Compliance

13. XLSecurity – Built-in HIPAA compliance software for role-based operation with Active

Directory

14. TLS 1.2 Security protocol

15. Stream data directly to a server and automatically switches to store to the local station if there is failure in the network connectivity

16. Automated power recovery – Study is automatically restarts if there is a power failure

17. Real time analyzers - user selectable to define which ones to run.

https://citrixready.citrix.com/natus-medical-incorporated/neuroworks-sleepworks.html

18. Unlimited look back / Scoring by the recording technologist while recording, with real time display of event counts and AHI.

19. Titration of all PAP devices (plus other devices - Matrx dental devices / Inspire nerve stimulator)

20. Allows users to log off and another user to login without interrupting the recording.

21. Remote viewing of data, looking back to the start of the recording and up to real-time

22. 6 dedicated sensor inputs

23. Integrated pulse oximeter and pressure sensor

24. Touchscreen display on base unit with real time interaction with ongoing studies

25. Add Tech Notes / Bio-Calibrations from the patient bedside base unit on a Touchscreen display

26. User customizable personal workspaces

2.2. INSTALLATION AND TRAINING:

a. Equipment must be fully installed and operational before contractor departs the facility the day of the installation.

b. Installation and training shall include minimum (2) days on-site in installation and specialized training for Administrator/s, Super User Level for Biomedical Specialist, and designated gynecology service Staff. With additional two (2) days on-site training for all Staff and Physicians, if needed.

c. Installation date/ time shall be coordinated in advanced with the gynecology and logistics services.

3. WORK HOURS:

3.1. Normal Work Hours: The service schedule shall be developed between the contractor and Contractor’s Representative (COR) prior to any service being performed.

3.2. The following is a list of U.S. Government holidays. If the holiday falls on a Saturday, the proceeding Friday is observed as the holiday; if the holiday falls on a Sunday, the following Monday is observed as the holiday and any other day specifically declared by the President of the United States to be a national holiday.

HOLIDAY DATE

New Year’s Day Jan 1 Martin Luther King’s Birthday 3rd Monday in Jan President’s Day 3rd Monday in Feb Memorial Day Last Monday in May Juneteenth National Independence Day June 19th Independence Day July 4 Labor Day 1st Monday in Sep Columbus Day 2nd Monday in Oct Veterans Day Nov 11

Thanksgiving Day 4th Thursday in November Christmas Day December 25

4. PERSONNEL

4.1. The contractor shall provide in writing the personnel name and phone number within (10) ten calendar days of the award of the contract. Personnel shall be a qualified and experienced to oversee the personnel assigned to perform the installation and maintenance services. The contractor’s personnel shall correspond with the COR on a regular basis to discuss any problems that the contractor or contractor’s personnel may be experiencing during the performance of this contract. Unresolved problems shall be referred to the Contracting Officer for resolution.

4.2. Contractor Service Personnel (CSP). All subcontractors performing work for primary contractor shall meet all specifications and standards that apply to CSP under this agreement. CSP shall maintain clean and neat appearance and shall wear an identification badge at all times when performing services at the Government site.

Identification badges shall be worn in a clearly visible area of the outer garment. The COR shall furnish this badge. Due to conflict of interest, the contractor shall not employ a current DOD employee, military or civilian to provide services under this contract.

4.3. Government point of contact (POC). The COR shall be the Government’s POC. If required, the COR shall be designated in writing to the Contractor and the scope of authority shall be set forth therein. Contractor shall respond only to calls from COR or a designated representative from the Medical Center.

5. SECURITY STATEMENT:

5.1. The Vendor shall not transfer any VA information to a location outside the VA and only to VA locations determined by the VA System Administrator. The information in these systems may be covered by the Privacy Act 1974 which contains criminal penalties of abuse of information.

5.2. The Vendor and all VA employees are required to immediately report any security violations to the Information Security Officer. No other security statements are required.

5.3. Information Security & Privacy.

a. The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract.

b. Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

c. A contractor/sub-contractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

d. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

e. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ.

The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

f. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

g. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct onsite inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

h. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

i. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.

j. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

k. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

Each risk analysis shall address all relevant information concerning the data breach, including the following:

i. Nature of the event (loss, theft, unauthorized access);

ii. Description of the event, including:

1. date of occurrence;

2. data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code.

3. Number of individuals affected or potentially affected.

4. Names of individuals or groups affected or potentially affected.

5. Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text.

6. Amount of time the data has been out of VA control.

7. The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons).

8. Known misuses of data containing sensitive personal information, if any.

9. Assessment of the potential harm to the affected individuals.

10. Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate.

11. Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

iii. The contractor/subcontractor agrees to comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act.

m. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

iii. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems.

iv. Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training.

v. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

vi. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]

1. The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

2. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

n. VA sensitive information is to be transferred between the device and VISTA only, will not go outside the VA network or information system.

6. ACRONYMS AND DEFINITIONS

6.1. Contracting Officer (CO). A person duly appointed with the authority to enter into and administer contracts on behalf of the U.S. Government.

6.2. Contracting Officer’s Representative (COR). An individual designated in writing by the Contracting Officer to act as an authorized representative of the Contracting Officer to perform specific contract administrative functions within the scope and limitations as defined by the Contracting Officer.

7. EQUIPMENT OWNERSHIP.

7.1. Title to equipment shall remain with the contractor until installed and established.

After completion, a satisfactory inventory and inspection is completed by Contractor, COR, and Maintenance personnel. Upon approved inspection, title, equipment, accessories and ownership shall be released to EL Paso Veterans Affairs Health Care System (ELPVAHCS).

8. LIMITED WARRANTY.

8.1. All equipment listed to the attached quote, shall be fit and sufficient for the purpose intended as set forth in the user manuals; and merchantable, of good quality and free from defects in materials or workmanship; for a period of one (1) year from the date of the first invoice under this agreement.

9. VHA PRIVACY AWARENESS

9.1 Pursuant to the Veteran Health Administration (VHA) Privacy principles and practices, Contractors shall comply with VA’s privacy, policies, and legal requirements found in this link: https://www.va.gov/privacy-policy/

9.2 The contractor must contact the education program manager at 915-564-6100 ext.

7600 to take the following Privacy Awareness Training that meets the requirements of the Health Insurance Portability and Accountability Act (HIPAA), Privacy Rule as determined by VHA, and the VA’s Privacy Training Monitoring SOP:

a.VA 10176 – VA Privacy and Information Security Awareness Training and Rules of Behavior b.VA 10203 – Privacy and HIPAA Focused Training c.VA 3185966 – VHA Mandatory Training for Trainees d.VA 3192008 – VHA Mandatory Training for Trainees – Refresher

10. NARA RECORDS MANAGEMENT

10.1 Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

10.2 In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

10.3 In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

10.4 El Paso Veteran Affairs Health Care System (EPVAHCS) and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of EPVAHCS or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701.

In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to EPVAHCS. The agency must report promptly to NARA in accordance with 36 CFR 1230.

10.5 The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to EPVAHCS control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

10.6 The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and EPVAHCS guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

10.7 The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with EPVAHCS policy.

10.8 The Contractor shall not create or maintain any records containing any non-public EPVAHCS information that are not specifically tied to or authorized by the contract.

10.9 The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

10.10 The EPVAHCS owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which EPVAHCS shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.

10.11 Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take VHA-provided records management training, Talent Management System (TMS) Item #10176, Privacy and Information Security, Rules of Behavior. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

10.12 References. VHA Directive 6300(1) National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a).

Security Statement. - The C&A requirements do not apply, and a Security Accreditation Package is not required.

B.2 SCOPE OF WORK

File details come from the government source that posted it. Updated .