SM SaaS PWS- 23 Feb 2021v2.3.docx

DOCX document 344 KB Posted

Attached to
DHA - Secure Messaging Federal contract opportunity
Solicitation number
HT0015-21-R-0016
Issued by
Defense Health Agency

About this file

This performance work statement outlines requirements for a secure messaging software as a service solution to support the Defense Health Agency's TRICARE Online Patient Portal. Key requirements include:

  • Providing a HIPAA-compliant, Risk Management Framework approved, software as a service infrastructure with DoD/MHS data segmented from commercial data.

  • Supporting 8,600 secure messaging subscriptions/licenses/connections during the base period from May 2021 through October 2021, decreasing incrementally over seven optional six-month periods as the MHS GENESIS patient portal is adopted.

  • Maintaining a single sign-on link using Defense Manpower Data Center authentication and data separation between DoD/MHS and commercial/non-MHS data.

  • Delivering virtual trainings, account management services, and monthly metric reports.

  • Complying with cybersecurity requirements including maintaining a DoD authority to operate, completing security scans and plans, and responding to security incidents.

The contractor must provide project management, documentation, and other operational support over the one-base and seven option-period contract term. The performance work statement outlines technical, security, and operational requirements for the secure messaging software as a service solution.

View the file

Other files for this federal contract opportunity

Other files attached to DHA - Secure Messaging, newest first.
File Type Posted
HT0015-21-R-0016 Amendment 3.pdf PDF
QA HT001521R0016 Secure Messaging.xlsx XLSX spreadsheet
HT0015-21-R-0016 Solicitation.docx DOCX document
HT0015-21-R-0016 Amendment 1.docx DOCX document
HT0015-21-R-0016 Amendment 2.docx DOCX document
HT0015-21-R-0016 Secure Messaging Conformed Solicitation.docx DOCX document
Secure Messaging Price Proposal Pricing Sheet - 09 March 2021.xlsx XLSX spreadsheet
SaaS Past Perf Questionnaire HT0015-21-R-0016.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense Defense Health Agency Performance Work Statement –

Tricare Online Patient Portal (TOL PP) Secure Messaging (SM) Software-as-a-Service (SaaS)

Deputy Assistant Director, Information Operations (DAD IO/J-6) Solution Delivery Division, Chief Information Officer (CIO)/ Health Care Delivery (HCD)

Solicitation Number:

Version: 2.3 Date: 23 February 2021

PART 1

1.0 GENERAL INFORMATION

1.1 This is a non-personal services contract to provide TOL PP Secure Messaging (SM) Software as a Service (SaaS) and services to meet the Defense Health Agency (DHA) enterprise SM requirement.

1.2 Description of services/introduction:

The contractor shall provide all personnel, facilities, support and sustainment of the TOL PP SM SaaS capability and non-personal services necessary to perform TOL PP SM SaaS capability as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.

1.3 Background:

TOL PP is an online patient-focused portal that provides eligible DOD beneficiaries and their families a convenient, personalized healthcare experience. TOL PP is a secure enterprise portal leveraging enterprise Single Sign-On (SSO) capability that serves as the MHS common enabling infrastructure for access to care and population health management.

TOL PP SM SaaS is a HIPAA- compliant asynchronous messaging capability providing an efficient, cost-effective method for patients to securely communicate with their health care team to seek non-emergency health care advice, request prescription renewals, and receive MTF/Clinic updates and alerts. Such communication can be used to provide patients with advice on lab and x-ray results, remind patients of needed preventive care, notify patients of needed follow-up of chronic diseases, educate patients about various topics, inform patients about available services, and provide direct care for non-urgent problems.

The TOL PP SM SaaS Application is an External IT Service as defined in DODi 8510.01. As an External IT Service for the DOD, the SM Application environment consisting of its Software, Platform, and the current data center Infrastructure will be assessed by DOD in accordance with the contract specified deliverables with DODi 8510.01 DOD RMF, CNSSI 1253 and DHA requirements.

TOL PP SM SaaS capabilities will be incrementally assumed by the MHS GENESIS Patient Portal. As MTFs adopt this new capability, the use of TOL PP SM SaaS will be discontinued at those sites. The MHS Genesis implementation schedule is managed by the Defense Healthcare Management System Modernization (DHMSM) Program Office, and subject to change.

1.4 Scope:

This PWS requires the Contractor to provide a secure HIPAA-compliant, DoD Risk Management Framework (RMF) approved, web-based SaaS infrastructure with DOD data segmented from commercial data.

TOL PP SM SaaS effort is broad reaching with execution of the tasks pursuant to this PWS requiring coordination with many organizations and program offices. The Contractor shall coordinate all contract efforts through the SDD PEO to ensure continuity and conformity with the following organizations: SM Service Representatives from the Army, Navy, Air Force, and National Capitol Region (NCR); Defense Health Agency (DHA); DHMSM; Defense Manpower Data Center (DMDC); Defense Information Systems Agency (DISA); and various suppliers/contractors providing support to SM SaaS.

1.5 Period of Performance (PoP):

The PoP shall be for one (1) Base period of six months and seven (7) six month option periods which will include a transition-in as part of the Base Period and a transition-out period as part of the final option period.

Base PoP:1 May 2021 - 31 October 2021
Option Period 11 November 2021 - 30 April 2022
Option Period 21 May 2022 - 31 October 2022
Option Period 31 November 2022 - 30 April 2023
Option Period 41 May 2023 - 31 October 2023
Option Period 51 November 2023 - 30 April 2024
Option Period 61 May 2024 - 31 October 2024
Option Period 71 November 2024 - 30 April 2025

1.5.1.1 Transition-in period. The period between the award date and full performance start date constitutes the transition in period. Full performance start date is 30 July 2021. Transition-in performance is defined as the incoming contractor to ensure key personnel are in place with assigned resources are properly equipped to begin work to include access to server and knowledge transfer from outgoing Contractor. During the transition-in period, the contractor shall prepare to meet all contract requirements; ensure incoming personnel are functionally trained and qualified, obtain DoD Risk Management Framework (RMF) approval to operate; implement helpdesk, and schedule trainings by the full performance start date. The remaining incoming personnel shall be trained and qualified within 15 days of the full performance start date. The Contractor shall provide a Transition-in Plan (Deliverable: Transition-in Plan) with their proposal which, at a minimum, addresses the tasks/timelines to complete the following:

· Identification of the services/information/access necessary to transition from outgoing vendor to successfully meeting the PWS requirements;

· Description of the Software as a Service (SaaS) subscription pricing model;

· Establishing the Risk Management Framework (RMF) compliant DoD environment;

· Establishing Data Separation of MHS data from the Non MHS data;

· Establish MTF Provider and staff accounts;

· Establish TOL PP single sign on (SSO) link;

· Establishing connection with the MTF enrolled patients;

· Plans for role based user training;

· Transfer of knowledge of SM technical environment, training, and other activities; and

· Staffing ramp-up activities.

1.5.1.2 Transition-out period. The transition-out plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract. The contractor shall provide a draft transition-out plan within six months of the end of the contract or within 30 days after learning that the next option period will not be exercised and renewed by the Government (Deliverable: Transition-out Plan)

1.6 Administrative specifications

1.6.1 Place of performance: The work to be performed under this contract will be performed at the Contractor’s facility.

1.6.2 Recognized Federal holidays:

New Year’s DayLabor Day
Martin Luther King Jr.’s BirthdayColumbus Day
President’s DayVeteran’s Day
Memorial DayThanksgiving Day
Independence DayChristmas Day

1.6.3 Hours of operation: The contractor is responsible for conducting business Monday thru Friday except Federal holidays. The Contractor shall be responsible for conducting business during SDD normal business hours, which are the hours of 0800 to 1700 Eastern Time (ET) with exception of Service Desk Support (see Section 5.5.1). The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.

1.6.4 Emergency Services: On occasion, services may be required to support an activation or exercise of contingency plans outside normal duty hours.

1.6.5 Conduct: Contractor personnel shall adhere to standards of conduct as established by the DHA.

1.7 Contractor travel:

Contractor may be required to travel Continental United States (CONUS), and Outside CONUS (OCONUS) during the performance of this contract to attend meetings, conferences, and training. The contractor may be required to travel to off-site training locations and to ship training aids to these locations in support of this PWS. Contractor shall be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation and the limitation of funds specified in this contract. All travel requires Government approval/authorization and notification to the Contracting Officer Representative (COR).

BASE Period Travel

The Base PoP travel shall be 2 trips from Vendor location to TBD CONUS locations with an estimated duration of 4 days and 2 trips from Vendor location to TBD OCONUS location with an estimated duration of 5 days.

Optional Periods Travel

Optional Periods 1 – 4 travel shall be 4 trips from Vendor location to TBD CONUS locations with an estimated duration of 4 days. No OCONUS trips are anticipated.

Optional Periods 5 – 7 travel shall be 2 trips from Vendor location to TBD CONUS locations with an estimated duration of 4 days. No OCONUS trips are anticipated.

1.8 Other Direct Costs (ODC): This category includes reproduction, and shipping expenses associated with training activities and visits to contractor facilities. It could also entail the renting of suitable training venues.

BASE

Description
Not to Exceed (NTE) Quantity
Miscellaneous (e.g., shipping, reproducible materials, ticketing maintenance, equipment hosting, incidentals, and software license and maintenance support, etc.)
NTE $5,000

OPTION PERIODs 1- 7

Description
NTE Quantity
Miscellaneous (e.g., shipping, reproducible materials, ticketing maintenance, equipment hosting, incidentals, and software license and maintenance support, etc.)
NTE $5,000 for each 6 month option period

1.9 Quality

1.9.1 Quality assurance: The Government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.10 Contractor personnel

1.10.1 Common Access Card (CAC) requirements: The contractor shall complete or provide to the Government all information required per the DHA CAC request process, current version 2.1, January 2018, or more recent when updated. See process attached in Section Part 7.1 of the PWS. A CAC is the standard identification for eligible DOD contractor personnel.

1.10.2 Contractor training. The contractor shall complete all requirements, training, and forms per the DHA’s Onboarding Checklist for Contractor Employees, current edition February 2018 or more recent when updated. See the form at: https://info.health.mil/sites/DOP/OnboardingCtr/Contractor_OnBoarding_Checklist.pdf.

1.10.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use.

1.10.4 Key control: RESERVED

1.10.5 Lock combinations: RESERVED

1.11 Key personnel (Contractor):

The contractor shall provide a contract Task Manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO. The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between 0800 to 1700 Eastern Time, Monday thru Friday except Federal holidays.

The follow personnel are considered key personnel by the government:

· Task Manager

· Deputy Task Manager/Account Manager

· Technical Lead

Substitutions of quoted Key Personnel shall not be allowed for a period of six months after award. Any substitution or replacement Key Personnel shall have qualifications equal to or greater than the individuals quoted. For temporary and/or permanent replacement of Key Personnel, the Contractor shall provide a resume for each individual to the COR. Resumes shall be provided at least two weeks (or as mutually agreed upon) prior to making any personnel changes. The Government reserves the right to pre-approve any replacement or substitution of Key Personnel. Contractor personnel must submit necessary information to be issued a clearance prior to reporting for performance.

1.12 Data rights:

The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.

1.13 Reporting

1.13.1 Contractor Manpower Reporting (CMR): The Office of the Secretary of Defense (OSD) Personnel and Readiness (P&R) operates and maintains a secure data collection site where the Contractor shall report Contractor manpower (including subcontractor manpower). Purchases with a total contract value of $3 million or more for services shall completely fill in all the information in the format using the following web address http://www.ecmra.mil/.

1.13.1.1 As part of its submission, the Contractor shall provide the estimated total cost (if any) incurred to comply with this reporting requirement. Reporting period shall be the period of performance not to exceed 12 months ending September 30 of each government fiscal year and must be reported by 31 October of each calendar year. Contractors may use a direct Extensible Markup Language (XML) data transfer to the database server or fill in the fields on the website. The XML direct transfer is a format for transferring files from a Contractor’s system to the secure website without the need for separate data entries for each required data element at the website. The specific formats for the XML direct transfer may be downloaded from the website.

1.13.1.2 Service portfolio groups are further define in DFARS PGI 237.102-74 Taxonomy for the acquisition of service and supplies and equipment.

1.13.1.3 Contractors shall direct questions to the help desk at: http://www.ecmra.mil/.

1.13.2 Non-Disclosure Agreement (NDA): All DHA Government contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA Contractor NDA (DHA Form 49) prior to beginning work on the subject contract. The Contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors. The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the Contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR (Deliverable: Non-Disclosure Agreement).

1.13.3 Contracting Officer Representative (COR): The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor Contractor's performance and notifies both the CO and Contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.

1.13.4 Post award conference/periodic progress meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.

PART 2

2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE PUBLICATIONS

2.1 Definitions:

2.1.1 Category D: Information Technology and Telecommunications Services (called D-Services)

2.1.2 Category R: Support (Professional/Administrative/Managements) Services (called R-Services)

2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.

2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the contracting officer to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.

2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance (See Attachment: Quality Assurance Surveillance Plan (QASP))

2.1.7 Contractor: A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.8 Defective Service: A service output that does not meet the standard of performance associated with the Performance Work Statement.

2.1.9. Deliverable: Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

2.1.10 Physical Security: Actions that prevent the loss or damage of Government property.

2.1.11 Subcontractor: One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.

2.2 Acronyms:

AOAuthorizing Official
ATOAuthority to Operate
CDRLContract Data Requirement List
CIOChief Information Officer
CJCSMChairman of the Joint Chiefs of Staff Manual
CND SPComputer Network Defense Service Provider
COContracting Officer
CONUSContiguous United States (excludes Alaska and Hawaii)
CORContracting Officer Representative
COTRContracting Officer's Technical Representative
CSContract Specialist
CUIControlled Unclassified Information
DD 254Department of Defense Contract Security Requirement List (if applicable)
DFARSDefense Federal Acquisition Regulation Supplement
DHADefense Health Agency
DHMSDefense Health Modernization Systems
DISADefense Information Systems Agency
DISNDefense Information Systems Network
DMDCDefense Manpower Data Center
DODDepartment of Defense
DoDIDepartment of Defense Instruction
FARFederal Acquisition Regulation
HITHealth Information Technology
iRAPTInvoicing, Receipt, Acceptance, and Property Transfer
IAInformation Assurance
iASIdentity Authentication Services
ISInformation System
IAVMInformation Assurance Vulnerability Management
MHSMilitary Health Systems
MTFMilitary Treatment Facility
NCRNational Capitol Region
NDANon-Disclosure Agreement
NISTNational Institute of Standards and Technology
NPINational Provider Identification
OCIOrganizational Conflict of Interest
OCONUSOutside Contiguous United States (includes Alaska and Hawaii)
ODCOther Direct Costs
PHIProtected Health Information
PIIPersonally Identifiable Information
PKPublic Key
PKIPublic Key Infrastructure
PMOProgram Management Office
POCPoint of Contact
PoPPeriod of Performance
PRSPerformance Requirements Summary
PWSPerformance Work Statement
QAQuality Assurance
QAPQuality Assurance Program
QASPQuality Assurance Surveillance Plan
QCQuality Control
RMFRisk Management Framework
SARSecurity Assessment Report
SMSecure Messaging
SPSpecial Publication
SRGSecurity Requirements Guide(s)
STIGSecurity Technical Implementation Guide(s)
TOL PPTRICARE Online Patient Portal
TOSTerms of Service

2.3 Applicable Publication

The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures.

Personnel Security

· The contractor shall comply with DoD Directive 8500.1, "Information Assurance (IA)," DoD Instruction 8500.2, "IA Implementation," DoD Directive 5400.11, "DoD Privacy Program," DOD 6025.18-R, "DoD Health Information Privacy Regulation," and DOD 5200.2-R, "Personnel Security Program Requirements."

· Follow the DHA Privacy Office guidelines for submittal of Automated Data Processor/Information Technology (ADP/IT) security clearances and ensure all contractor personnel are designated as ADP/IT-I, ADP/IT-II, or ADP/IT-III where their duties meet the criteria of the position sensitivity designations. Contact the DHA Privacy Office for guidance on the appropriate ADP/IT levels for personnel on the contract. The DHA Privacy Office procedures for personnel security are listed on the following website: http://www.tricare.osd.mil/DHAprivacy/personnel-security.cfm

· Initiate, maintain, and document personnel security investigations appropriate to the individual's responsibilities and required access to DHA Sensitive Information (SI).

· Ensure that all contractor personnel receive cybersecurity training before being granted access to DOD AISs/networks, and/or DHA SI.

Laws

· Federal Information Security Management Act of 2002

· Public Law 104-113: National Technology Transfer and Advancement Act of 1995. 104th Congress, March 7, 1996

· Public Law 104-106: Clinger-Cohen Act of 1996, February 10, 1996

· Health Insurance Portability and Accountability Act, 1996

· Public Law 93-579: Privacy Act of 1974 Security/Information Assurance/Technology

· DODD 4630.5 Interoperability and Supportability of Information Technology (IT) and National Security systems (NSS), May 5, 2004

· DODD 8100.2, Use of Commercial Wireless Devices and Services in the DOD Global Information Grid, April 14, 2004

· DODD 8500.1, Information Assurance, October 24, 2002

· DODD 8500.2, Information Assurance (IA) Implementation, February 6, 2003

· DODI 4630.8 Procedures for Interoperability and Supportability of Information Technology (IT) and National Security systems (NSS), June 30, 2004

· Interim DOD Certification and Accreditation Process Guidance, July 6, 2006.

· DOD CIO Memo “Internet Protocol Version,” Augut 16, 2005

· CJCSI 6212.01D Interoperability and Supportability of Information Technology and National Security systems (NSS), March 8, 2006

· NSTISSP No. 11, 4 National Policy Governing Information Assurance and Information Assurance Enabled Information Technology Products, January 2000

· http://www.defenselink.mil/nii/doc/DoDAF_v1_Volume_I.pdf

· http://www.defenselink.mil/nii/doc/DoDAF_v1_Volume_II.pdf

· http://disronline.disa.mil/DISR/index.jsp

· http://ipv6.disa.mil (A Common Access Card is required.)

· http://www.dtic.mil/whs/directives/corres/pdf/d83202_120204/d83202p.pdf (DODD 8320.2)

· http://www.dtic.mil/whs/directives/corres/pdf/p832002_041206/p832002p.pdf (DOD 8320-02G) DHA Enterprise Architecture Requirements -- General The Contractor shall adhere to goals, standards, constraints, guidelines, policies, architectural products, and processes established and approved by the DHA Enterprise Architecture Board, Chief Enterprise Architect, subordinate boards or Integrated Product Teams, or higher levels of authority. These products are available as GFE from the DHA Chief Architect.

The Contractor shall ensure that products and services (deliverables) are aligned and compliant with the current MHS Strategic Plan, MHS IM/IT Strategic Plan and Principles, DHA Enterprise Architecture, DoD Architectural Framework, Global Information Grid Architecture, DoD Business Enterprise Architecture, the Federal Enterprise Architecture Framework (OMB Reference Models), and when requested with Services’ Operational Architectures (e.g. AMEDD). These products are available as GFE from the DHA Chief Architect. COTS Vendors whose product conforms to the latest approved Department of Health and Human Services Health Information Technology Standards Panel (HITSP) standards, as detailed in the OV-7a MHS Data Standard list (see the MHS Enterprise Architecture V5.0), which include those formerly approved Consolidated Health Informatics Standards (see table below), and information assurance standards shall be given additional consideration during the selection process. These products are available as GFE from the DHA Chief Architect.

Internet Protocol version 6 (IPv6) The Contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria deemed IPv6 capable are:

· Conformance to the DoD Information Technology Standards Repository (DISR) developed DoD IPv6 Standards Profile. Systems being developed, procured or acquired shall comply with the Global Information Grid Architecture and DISR standard IPv6 Capable definition. An IPv6 Capable system must meet the IPv6 base requirements defined in the “DoD IPv6 Standards Profile v1.0” dated June 1, 2006 available from the DISR.

· Maintenance of interoperability with IPv4. Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities. Systems should implement IPv4/IPv6dual-stack and should also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems should employ IPv6.

· Evidence of a migration path and commitment to upgrade all applications and product features to IPv6 as directed by the COR.

· Availability of contractor/vendor IPv6 technical support for system development, implementation and management.

Dissemination of Information/Publishing There shall be no dissemination or publication, except within and between the Contractor and any subcontractors or specified Integrated Product/Process Team (IPT) members who have a need to know, of information developed under this order or contained in the reports to be furnished pursuant to this order without prior written approval of the DHA COR or the Contracting Officer. DHA approval for publication will require provisions which protect the intellectual property and patent rights of both DHA and the Contractor.

Contractor Identification The Contractor shall ensure that Contractor personnel identify themselves as Contractors when attending meetings, answering Government telephones, providing any type of written correspondence, or working in situations where their actions could be construed as official Government acts.

Attendance at Meetings Contractor personnel may be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order. Contractor personnel shall make their Contractor status known during introductions.

Use of Military Rank by Contractor Personnel Contractor personnel, while performing in a Contractor capacity, are prohibited from using their retired or reserve component military rank or title in all written or verbal communications associated with the contracts under which they provide services.

Records Management When creating and maintaining official government records, the Contractor shall comply with all federal requirements established by 44 United States Code (USC), 41 USC, 36 Code of Federal Regulations (CFR), Department of Defense (DOD) Administrative Instruction No. 15 (DOD AI-15), “Records Management, Administrative Procedures and Records Disposition Schedules,” and Chapter 2 of the TRICARE Operations Manual.

Enterprise-wide Contractor Manpower Reporting Application, dated November 28, 2013

CONTRACTOR MANPOWER REPORTING FOR CONTRACT PERFORMANCE WORK STATEMENTS AND RELATED BACKGROUND INFORMATION

The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for the SDD Clinical Division via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/ Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year, beginning with 2013. Contractors may direct questions to the help desk at help desk at: http://www.ecmra.mil

PART 3

3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

3.1 Services: Not applicable

3.2 Facilities: Not applicable

3.3 Utilities: Not applicable

3.4 Equipment: The Government will provide GFE laptops (NTE 4 laptops) to support the taskings as specified within this PWS.

3.5 Materials: The Government will provide access to applicable policies and procedures as well as tools necessary for the contractor’s successful accomplishments of taskings as specified within this PWS.

PART 4

4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES

4.1 General: Apart from the GFE identified herein, the Contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 3 of this PWS.

4.2 Secret Facility Clearance: Not applicable.

4.3 Materials: The Contractor shall furnish materials, supplies, and equipment necessary to meet the requirements under this PWS.

4.4 Facilities: The Contractor shall provide a secure HIPAA-compliant web-based Software as a Service infrastructure with the DOD /MHS data segmented from commercial/non-MHS data.

PART 5

5.0 SPECIFIC TASKS

5.1 Core Tasking

The core tasks of this PWS are:

5.1.1 The contractor shall provide a secure HIPAA-compliant, DoD RMF approved, web-based SaaS infrastructure with DoD/MHS data segmented from commercial/non-MHS data.

5.1.2 The contractor shall provide a capability of 8,600 SM SaaS subscriptions/licenses/ connections (further referred to as ‘subscriptions’) for MHS licensed healthcare providers assigned to non-MHS GENESIS MTFs supported by help desk/service operations including a toll-free number, workflow, database, and account management support, and analysis/reporting support for MHS providers, staff, and beneficiaries as part of the SM SaaS subscription base period offering. The Government intends to decrease the SM SaaS subscriptions as MHS GENESIS goes live at a MTF. Accordingly, the Contract shall propose the following subscription quantities as part of option period pricing based on the DHMSM MHS GENESIS fielding plan:

· Option Period #1: Provide 8,100 SM SaaS subscriptions

· Option Period #2: Provide 7,000 SM SaaS subscriptions

· Option Period #3: Provide 4,800 SM SaaS subscriptions

· Option Period #4: Provide 2,300 SM SaaS subscriptions

· Option Period #5: Provide 1,300 SM SaaS subscriptions

· Option Period #6: Provide 1,000 SM SaaS subscriptions

· Option Period #7: Provide 1,000 SM SaaS subscriptions

5.1.3 The contractor shall notify the Government of any provider accounts that are not active for 12 months for potential de-activation as directed by the Contract Officer’s Representative (COR).

5.1.4 The contractor shall obtain and/or maintain a DoD RMF Authority to Operate (ATO) accreditation and high cybersecurity posture for their proposed SM SaaS solution

5.1.5 The contractor shall establish and maintain a sign on (SSO) link for SM SaaS using the Defense Manpower Data Center (DMDC) DS Logon authentication methodology

5.1.6 The contractor shall establish and maintain data separation of DoD MHS data from commercial/non MHS data.

5.1.7 The contractor shall provide virtual trainings in support of their SM SaaS offering.

5.1.8 The contractor shall provide technical input and/or updates in response to SDD Taskers and/or initiatives as requested by the COR.

5.1.9 The contractor shall report, respond and mitigate suspected breaches as defined by the DHA Privacy & Civil Liberties Office Breach Reporting Instructions.

5.1.10 The contractor shall support customer awareness, communication, and outreach efforts to include, but not limited to, demonstrations, presentations, technical information exchanges, and outreach material content as directed by COR.

5.1.11 The contractor shall support MHS GENESIS Patient Portal fielding by disabling the SM SaaS capability as designated by the DHMSM go-live schedule.

5.2 Specific Tasks – Task Management:

The Contractor shall provide sufficient management to ensure that this task is performed efficiently, accurately, on time, and in compliance with the requirements of this document. Specifically, the Contractor shall designate a single manager to oversee this task and supervise staff assigned to this task.

5.2.1 Program Reviews – Deliverable 3

The Contractor shall ensure that they supply the Government with inputs to the Contract Kickoff Meeting are provided prior to the meeting and that data presented at program reviews is current within not more than ten (10) business days.

The Contractor shall conduct a progress review meeting with frequency of not less than once a week to review the status of activities under this PWS. Each review shall provide insight into expenditures, staffing, progress as well as noting any problems or risks with recommended solutions. The contractor shall provide formal Program Review material (Deliverable 3) to include, but not limited to, agenda items, action items, and minutes as requested by the COR.

5.2.2 Project Management Plan (PMP)

The Contractor shall develop a Project Management Plan (PMP) (Deliverable: Project Management Plan). This plan shall be applied by the Contractor to manage, track and evaluate the Contract performance. The PMP shall consist of control policies and procedures in accordance with standard industry practices for project administration, execution and tracking.

The PMP shall include the following:

· Identification of milestones where Government information/activity is required and timeline dependencies for subsequent Contractor activities;

· An Integrated Master Management Plan (IMMP) describing the Contractor’s overall management approaches, policies and procedures including suggested project metrics; and,

· A detailed staffing plan, list of personnel with access to Government data, and schedule for obtaining DoD Common Access Card (CAC).

· Description of the Contractor’s Configuration Management (CM) methods and procedures to include, but not limited to, configuration identification (CI), status accounting, change control, and verification/audit activities within their organization for work performed under this PWS.

5.2.3 Continuity of Operations Plan (COOP)

The Contractor shall develop and submit within 30 days after award a Continuity of Operations Plan (COOP) in accordance with DFARS provision 252.237-7024, Notice of Continuation of Essential Contractor Services (Deliverable: Continuity of Operations Plan). The Contractor TM, in coordination with the COR, must make use of the resources and tools available to continue contracted functions to the maximum extent possible under emergency circumstances. The COOP shall document the Contractor plans and procedures to maintain support during an emergency and include the following:

· A description of the Contractor’s emergency management procedures and policy

· A description of how the Contractor will account for their employees during an emergency.

· Planned temporary work locations or alternate facilities.

· How the Contractor will communicate with DHA during emergencies.

· A list of primary and alternate Contractor points of contact, each with primary and alternate telephone number(s) and e-mail addresses.

· Procedures for protecting Government furnished equipment and safeguarding sensitive and/or classified Government information.

Individual COOPs shall be activated immediately after determining that an emergency has occurred, shall be operational within twelve (12) hours of activation, and shall be sustainable until the emergency situation is resolved and normal conditions are restored or the contract is terminated, whichever comes first. In case of a life threatening emergency, the COR shall immediately make contact with the Contractor Task Manager (TM) to ascertain the status of any Contractor personnel who were located in Government controlled space affected by the emergency. When any disruption of normal, daily operations occur, the Contractor Task Manager shall promptly open an effective means of communication and verify:

· Key points of contact (Government and Contractor)

· Temporary work locations (alternate office spaces, telework, virtual offices, etc.)

· Communication means available under the circumstances, e.g. email, telephone, FAX, courier, etc.

· Essential work products expected to continue production by priority The Contractor must obtain approval from the COR and Contracting Officer prior to incurring costs over and above those allowed for under the terms of this contract. Regardless of contract type, and of work location, Contractors performing work in support of authorized tasks within the scope of their contract shall charge those hours accurately in accordance with the terms of this contract.

5.2.4 Monthly Progress Report (MPR) – Deliverable 1

The Contractor shall ensure that a MPR (Deliverable 1), is submitted outlining the expenditures, billings, progress, status, and any problems/ issues encountered in the performance of this task.

The MPR shall include the labor hours expended, by labor category, for each task and sub-task.

The Contractor shall require all subcontractors to provide input to the MPR where there are critical or significant tasks related to the prime contract. Critical or significant tasks shall be defined by mutual agreement between the Government and Contractor.

5.2.5 Subcontractor Expenditures Report

If Subcontractors are used, the Contractor shall prepare and deliver a Subcontract Expenditures Report as part of the MPR (Deliverable 1) that discloses actual subcontract expenditures by company name, business size standard (i.e. Woman Owned Business, Veteran Owned Business, etc.), and other socioeconomic programs (i.e. Indian Incentive Program, Historically Black Colleges and Universities and Minority Institutions, etc.).

5.2.6Contract Work Breakdown Structure (CWBS) – Not Required for this Task
5.2.7Integrated Master Schedule – Deliverable 2

The Contractor shall establish and maintain an IMS (Deliverable 2) in accordance with DID DI-MGMT-81650, “Integrated Master Schedule,” to be used to verify the attainability of task order objectives, to evaluate progress toward meeting program objectives, and to integrate the program schedule activities with all related components. The IMS shall be an integrated, logical network-based schedule depicting milestones, accomplishments, and discrete tasks/activities from task order award to the completion of task order that correlates to the PWS.

5.3 Specific Tasks – Project Management

5.3.1 Documentation

Reports and documents delivered by the Contractor in performance of this contract shall be considered “Technical Data” or “Computer Software Documentation”, whichever is applicable, as defined in the applicable DFARS “Rights in Data” clauses of the General Provisions. All documentation shall reflect the latest approved version number, unless specifically directed otherwise by the Government. All documentation shall be prepared in accordance with standard industry practices, ensuring electronically produced documents which reflect logical flow of material, tables of contents, indexes and page numbering. Where applicable, the Contractor’s attention is called to the availability of commercial, industry, federal, and military guides, instructions, and standards for many of the topics addressed in this contract.

5.3.2 Technical Documentation – Deliverable 4

The Contractor shall work with the SDD and external stakeholders as directed by the COR.

· Provide business and administrative planning, organizing, directing, coordinating and controlling to accomplish the tasks described in this PWS.

· Assist in defining system requirements, managing and implementing SM tasks, and support of the functional requirements in the development of goals and objectives as required.

· Identify and provide technical information, guidance, and recommendations to the COR for project-related issues and ensure open communication among all interested parties with respect to project performance.

· Provide and conduct briefings on specific topics related to SM SaaS product, sustainment, and engineering or security-related tasks, to include white papers, analysis of impacts, and rough orders of magnitude (ROMs).

· Provide, or update as requested, Technical Documentation (Deliverable 4) to include, but not limited to:

· SDD Requirements Worksheet (SRW)

· Information Support Plan (ISP)

· Interface Control Documentation (ICD)

· System Design Documents

· System Source Code update(s) to baseline as a result of patches, releases, and/or system updates

· Operational Views (OV) and System Views (SV)

5.3.3 Security Management Plan – Deliverable 4

In accordance with the Government’s Program Protection Plan or other Program Security Plan, the Contractor shall develop a Security Management Plan as part of the Technical Documentation (Deliverable 4) outlining the security assurance strategy to ensure that the requirements, design, implementation, and operating procedures for the identified product minimize or eliminate the potential for breaches of system security. The Security Management Plan will initially be submitted within 90 work days following award and updated as directed by the COR.

5.3.3.1 DoD Risk Management Framework RMF Support – Deliverable 4 The contractor shall maintain a dedicated DoD Environment and Data Separation of DoD data from the Non DoD data. The Contractor shall provide documents, data, access, and input to existing documentation DoD RMF documentation as part of the Technical Documentation (Deliverable 4) for any systems the Contractor supports to assist the Government in attaining C&A in accordance with the standards identified in the DOD 8500 series. C&A support is required if the system undergoes a major changes, recertification, risk assessment, or annual systems reviews. The Contractor shall comply with all applicable STIGs and manual checklists to include a list of all RMF controls that they are responsible for implementing and the associated artifacts that provide evidence that the controls have been implemented. Shared controls (controls that are implemented by both SDD and the Contractor) will require the Contractor to submit the associated artifacts for the subset of the shared control that they are implementing.

5.3.3.2 Security Scan Results – Deliverable 4

The Contractor shall scan and mitigate all the environments with all the applicable STIGs/Checklists and approved scan matrix. SDD will develop the scan matrix and provide to the Contractor at the start of each cybersecurity effort. The contractor shall:

a. Work with SDD Cybersecurity to develop a scan matrix that identifies all the products within all the environments.

b. Conduct the scans and provide Security scan results as part of the Technical Documentation (Deliverable 4).

c. Apply and test mitigations within the test environment.

d. Apply the security mitigations to production.

e. Rescan and submit updated Security scan results as part of the Technical Documentation (Deliverable 4).

5.3.3.3 Application Security Vulnerability Baseline – Deliverable 4 The Contractor shall be compliant with responding to the DoD Vulnerability Management Systems (VMS). The Government requires that the provider conduct a dynamic and static analysis for all applications and their respective code baselines through the use of such tools as Fortify 360® and WebInspect. The baseline findings, analysis, and recommended plan will be submitted individually as Application Security Vulnerability Baseline as part of the Technical Documentation (Deliverable 4).

5.3.3.4 Incident Response Plan – Deliverable 4

The Contractor shall provide an Incident Response Plan as part of Technical Documentation (Deliverable 4) to document the intrusion detection/prevention system and processes for host and network monitoring and event notification. In addition, the Contractor shall have a computer security incident response team (CSIRT) to support analysis of an event notification, response to an incident if the analysis warrants it, escalation path procedures, resolution, post-incident follow-up, and reporting to the appropriate parties. The Incident Response Plan will initially be submitted within 90 work days following award and updated as directed by the COR.

The Contractor shall protect against unauthorized disclosure of data to protect the privacy of Government contractors and private individuals on which the information is maintained. All data residing in TOL is subject to the provisions of United States Code (USC) Title 10 Armed Forces, Section 1102, and Confidentiality of medical quality assurance records: Qualified immunity for participants. This section of the laws requires protection of medical quality assurance data for specific use of the MHS and its Service medical communities in the performance of quality improvement activities. All data is subject to the provisions of the Privacy Act of 1974; DOD 5400.11-R, DoD Privacy Program; and DOD 5200.1-R, DoD Information Security Program Regulation. In addition, data falls within the content of Exemption Numbers 3, 4, and 6 of DoD 5400.7, DoD Freedom of Information Act (FOIA) Program. Each of these programs mandates adequate control and protection of sensitive data.

The Contractor shall use physical security safeguards for IS/Networks involved in the processing or storage of Government data to prevent the unauthorized access, disclosure, modification, destruction, use, etc., and to otherwise protect the confidentiality and ensure use conforms with DoD regulations. In addition, the Contractor shall support a Physical Security Audit (PSA) of the Contractor's internal information management infrastructure to be performed by the Government. The MHS Physical Security Audit Matrix is available at the following URL:

http://www.tricare.osd.mil/tmis_new/Policy/PSA_Matrix_%20012304%200930%20clean%20version.xls.

The Contractor shall correct any deficiencies identified by the Government of the Contractor’s physical security posture. The Contractor shall be required to follow all requirements in the MHS Cybersecurity Policy. New MHS policies will be posted to the Web site:

http://www.tricare.osd.mil/tmis_new/IA.htm.

The Contractor shall comply with DoD Directive 8500.1, “Information Assurance (IA),” DoD Instruction 8500.2, “Information Assurance (IA) Implementation,” DoD Directive 5400.11, “DoD Privacy Program,” DOD 6025.18-R, “DoD Health Information Privacy Regulation,” and DOD 5200.2-R, “Personnel Security Program Requirements.” The Contractor shall ensure that the application meets the features of Identification and Authentication, Auditing, and Discretionary Access Control. The Contractor shall also use FIPS 140-2–compliant encryption and digital certificates for Web-based components.

The Contractor shall ensure that developer test activities not be conducted on production instances of software releases and that any developer test data shall not expose the personal data of actual people whose data is in SM.

The Contractor shall include safeguards that ensure that its data is accurate, complete, and available when needed.

5.3.3.5 DoD Enterprise Mission Assurance Support Services (eMASS) Support.

The contractor shall register SM into the DoD Enterprise Mission Assurance Support Services (eMASS) system, Defense Health Program System Inventory Report Tool (DHP SIRT) and the DoD Defense Information Technology Portfolio Repository (DITPR). The contractor shall also unload and maintain all relevant artifact within DOD’s eMASS system.

Applicable for this Task

5.4 Specific Task – Training

5.4.1 Virtual Training

The Contractor shall deliver one virtual training session tailored to the user role (super user, nurse case manager, basic user, provider, etc.) on a monthly basis unless otherwise directed by the COR. Virtual Training sessions will be scheduled no later than one month in advance.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .