Solicitation 36C26323Q0558.pdf

PDF 633 KB Posted

Attached to
6515--Sterile Processing Laser Engraver - CI Federal contract opportunity
Solicitation number
36C26323Q0558
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 23

View the file

Other files for this federal contract opportunity

Other files attached to 6515--Sterile Processing Laser Engraver - CI, newest first.
File Type Posted
36C26323Q0558_1.docx DOCX document
52.225-2 Buy American Act Certificate-COTS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE 1 OF 1. REQUISITION NO.

2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE

a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL

TIME

9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

WOMEN-OWNED SMALL BUSINESS

(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM

EDWOSB

8(A)

NAICS:

SIZE STANDARD:

11. DELIVERY FOR FOB DESTINA-

TION UNLESS BLOCK IS

MARKED

SEE SCHEDULE

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE

TELEPHONE NO. UEI: EFT:

PHONE: FAX:

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED

SEE ADDENDUM

19. 20. 21. 22. 23. 24.

ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)

27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.

27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE

ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)

PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212

7. FOR SOLICITATION

INFORMATION CALL:

STANDARD FORM 1449

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

636-23-3-3169-0012

36C26323Q0558 05-08-2023

John Milroy 605-336-3230 05-12-2023

4:00 PM CDT

Department of Veterans Affairs

NETWORK 23 CONTRACTING OFFICE

2501 W. 22nd St.

Sioux Falls SD 57105

X 100

X

339112

1000 Employees

N/A

X

Central Iowa VA Health Care System

3600 30th Street

Des Moines IA 50310

2501 W. 22nd St.

Sioux Falls SD 57105

Department of Veteran Affairs

Electronic Invoicing System

Tungsten Electronic Invoicing

VA Tungsten Number is: AAA544240062

Refer to VAAR Clause 852.232-72

1-877-489-6135

See CONTINUATION Page

Procurement of a Laser Engraver and yearly service maintenance for the Central Iowa VA Health Care System.

This procurement is a total Service-Disabled Veteran Owned

Small Business (SDVOSB) Set-aside.

At the time of submission of offer, the offeror shall be registered in the Small Business Administration Veteran

Small Business Certification (VetCert) as a Service-Disabled

Veteran Owned Small Business (SDVOSB) and have an active registration in the System for Award Management (SAM) at www.sam.gov.

The Buy American Act provisions apply. Check 52.225-1 Buy

American-Supplies for more information. Completion of

52.225-2 Buy American Certificate is required. Copy of

Certificate Attached to Solicitation.

Failure to submit any of the required information, statement or certifications may result in rejection of the quote without further consideration for award.

See CONTINUATION Page

636-3630160-3169-844200-2632 SPR0S00A3

636-23-3-3169-0012

X X

X One

John Milroy

VA-VHA-RPOC-2023-0067

36C26323Q0558

Table of Contents

SECTION A

A.1 SF 1449 SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

B.2 PRICE/COST SCHEDULE

ITEM INFORMATION

B.3 Specification of Sterile Processing Laser Marking System

B.4 STATEMENT OF WORK for Laser Engraver and Scanner System

SECTION C - CONTRACT CLAUSES

C.1 52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (DEC 2022)

C.2 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT

STATUTES OR EXECUTIVE ORDERS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (MAR 2023)

C.3 52.225-2 BUY AMERICAN CERTIFICATE (OCT 2022)

C.4 VAAR 852.247-73 PACKING FOR DOMESTIC SHIPMENT (OCT 2018)

C.5 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

C.6 VAAR 852.219-73 VA NOTICE OF TOTAL SET-ASIDE FOR VERIFIED SERVICE-

DISABLED VETERAN-OWNED SMALL BUSINESSES (NOV 2022)

C.7 VAAR 852.219-76 VA NOTICE OF LIMITATIONS ON SUBCONTRACTING--

CERTIFICATE OF COMPLIANCE FOR SUPPLIES AND PRODUCTS (NOV 2022)

C.8 VAAR 852.232-72 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (NOV

2018)

C.9 VAAR 852.252-70 SOLICITATION PROVISIONS OR CLAUSES INCORPORATED

BY REFERENCE (JAN 2008)

SECTION D - CONTRACT DOCUMENTS, EXHIBITS, OR ATTACHMENTS

SECTION E - SOLICITATION PROVISIONS

E.1 52.212-1 INSTRUCTIONS TO OFFERORS—COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (MAR 2023)

E.2 ADDENDUM to FAR 52.212-1 INSTRUCTIONS TO OFFERORS— COMMERCIAL

ITEMS

E.3 52.212-2 EVALUATION—COMMERCIAL PRODUCTS AND COMMERCIAL

SERVICES (NOV 2021)

E.4 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS—

COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEC 2022)

E.5 52.216-1 TYPE OF CONTRACT (APR 1984)

E.6 52.233-2 SERVICE OF PROTEST (SEP 2006)

E.7 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB

1998)

E.8 VAAR 852.233-71 ALTERNATE PROTEST PROCEDURE (OCT 2018)

SECTION B - CONTINUATION OF SF 1449 BLOCKS

B.1 CONTRACT ADMINISTRATION DATA

1. Contract Administration: All contract administration matters will be handled by the following individuals:

a. CONTRACTOR:

b. GOVERNMENT: Contracting Officer 36C263

2501 W. 22nd St.

Sioux Falls SD 57105

2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:

[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or

[] 52.232-36, Payment by Third Party

3. INVOICES: Invoices shall be submitted in arrears:

a. Quarterly []

b. Semi-Annually []

c. Other [X] After equipment is delivered and installed

4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment

Requests.

ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:

AMENDMENT NO DATE

B.2 PRICE/COST SCHEDULE

ITEM INFORMATION

ITEM

NUMBER

DESCRIPTION OF

SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

1.00 un __________________ __________________ Laser Engraver for Sterile Processing, similar to NuTrace Laser NUX20NG, that meets the Specification of Sterile Processing Laser Marking System.

Including Onsite Training, 1 Year Maintenance, User Manuals, and Cleaning Instructions.

Contract Period: Base POP Begin: 08-01-2023 POP End: 07-31-2024 PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing PRODUCT/SERVICE CODE: 6515 - Medical and Surgical Instruments, Equipment, and Supplies

LOCAL STOCK NUMBER: NUX20 NG

5.00 un __________________ __________________ Laser Engraver Scanner System for instrument inventory management that is connected to the Censitrak Inventory Management System, similar to NuTrace R+ Scanner.

Contract Period: Base POP Begin: 08-01-2023 POP End: 07-31-2024 PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing PRODUCT/SERVICE CODE: 6515 - Medical and Surgical Instruments, LOCAL STOCK NUMBER: NuTrace 2 Tier Services

5.00 dy __________________ __________________ Contractor provided service of marking of up to 25,000 pieces of exisitng inventory with unique device identifier, similar to NuTrace 2 Tier Services.

Including Placing marked existing inventory into Censitrac Inventory Management System.

Contract Period: Base POP Begin: 08-01-2023 POP End: 07-31-2024 PRINCIPAL NAICS CODE: 339112 - Surgical and Medical Instrument Manufacturing PRODUCT/SERVICE CODE: 6515 - Medical and Surgical Instruments, LOCAL STOCK NUMBER: NuTrace R+ Scanner

GRAND TOTAL __________________

B.3 Specification of Sterile Processing Laser Marking System The Department of Veteran Affairs Central Iowa VA Health Care System, 3600 30th Street, Des Moines, IA 50310 has a requirement for Laser Engraver for the Sterile Processing Unit.

Salient Characteristics for the Laser Engraver System are:

• At least a 20W 1064nm MOPA air cooling laser (similar to NuTrace Laser NUX20NG).

• 110/220V 50/60Hz 10Amp.

• Compact work station the unit can’t be larger than 12x12x14

• Marking items as small as 1.5mm x 1.5mm area

• 5 ft fiber cable for easy module

• Fume extraction port and laser protection glass.

• Top handle for easy carrying.

• FDA Compliant

• Approved for use on VA Network by the Department of Veteran Affairs Office of Information

Technology.

• Must be able to mark existing instruments all types of surgical instruments including titanium, stainless steel, bronze, anodized aluminum, anodized titanium, hard plastics, and glass including cylindrical items.

• Mark instruments with unique marking for current instument for tracability.

• Have a scanner and reader to read each instrument that interface and enter inventory information into Censitrak Inventory Management System, similar to NuTrace R+ Scanner.

• Must be able to verify GS1 U.S. FDA Unique Device Identification (UDI) compliance for new instrument.

• On-site training

• Package must include:

• (1 each) Maintenance Manuals (CD, PDF or Word)

• (1 each) User Manuals

• (1 each) Cleaning Instructions for all equipment, supplies and accessories

• Normal manufacturer warranty.

• 1-year of service and support including calibration services will be provided as part of the equipment purchase.

Note: All shipping a delivery of equipment must be included in the cost of the equipment.

Other items to be provided:

• Contractor needs to also provided service of marking of up to 25,000 pieces of exisitng inventory with unique device identifier. Placing marked inventory in Censitrac Inventory Management System.

• Contractor will also need to provide service and preventative maintenance for 4 additional years on an optional year bases. This is not guaranteed basis and will be evaluated on a yarly basis.

B.4 STATEMENT OF WORK for Laser Engraver and Scanner System

1. Scope of Work:

1.1. The contractor will provide service and preventative maintenance for Sterile Processing Laser Engraver to support Central Iowa VA Health Care System.

2. Period of Performance: August 01, 2023 to July 31, 2024.

3. Place of Performance:

3.1.1. Central Iowa VA Health Care System, 3600 30th Street, Des Moines, IA 50310

4. Hours of Operation

4.1. The VA Health Care System are open from 7:30 AM to 4:00 PM (CT) M-F except for Federal

Holidays.

4.2. Federal holidays observed by Central Iowa VA Health Care System can be located at https://www.opm.gov/policy-data-oversight/pay-leave/federal-holidays/

5. Services To Be Provided

5.1. General:

5.1.1. The vendor will provide the necessary manpower and supervision to properly execute the repair and preventative maintenance of the sterile process laser engraver, scanner and associated equipment and software.

5.1.2. The vendor must furnish all tools and materials (e.g. service manuals, diagnostic software, etc.) required to maintain the equipment to manufacturer specifications.

5.1.3. A “Field Service Report” (FSR) must be provided to the Central Iowa VAHCS’s facility contact or designee after each repair.

https://www.opm.gov/policy-data-oversight/pay-leave/federal-holidays/

5.2. Maintenance and Repair:

5.2.1. All repairs will be performed between the hours of 8:00am and 5:00pm CST, Monday thru

Friday, except Federal Holidays.

5.2.1.1. If work must be performed outside of normal business hours (“over-time” billable work), The vendor must obtain prior approval from the Contracting Officer.

5.2.1.2. If such work is at the cost of the Central Iowa VA Healthcare System, Contracting

Officer Approval must be obtained by the vendor prior to performing any work outside of scope of this contract.

5.2.2. The vendor will provide all parts for repairs performed by vendor qualified technician.

5.2.3. The vendor will provide telephone technical support at no additional charge to the VA.

5.2.4. The vendor responds to service calls via telephone immediately, and will arrive on-site for repair within 24 hours of placing a service call by the VA.

5.2.5. The vendor will provide preventive maintenance and cleaning with trained staff member at manufacturer specified intervals, but no less than semi-annually.

5.2.5.1. Preventative Maintenance will be to the original equipment manufacturing procedure. All parts that are to be replaced by the, cleaning, lubricating, inspection, calibration and other procedures will be performed be manufacturers specifications will be performed.

5.2.5.2. A copy of the manufacturers preventative maintenance procedure will be provided to the Facility Point of Contact.

5.3. Loaner Equipment

5.3.1. If unit needs to be shipped to the manufacturer for repairs, the vendor will provide a loaner unit at no additional charge.

5.3.2. The vendor will uninstall, pack, and ship unit for repair and loaner unit at the cost of the vendor. This applies to when the unit for repair is uninstalled and loaner unit is installed and when the loaner unit is uninstalled and the repaired unit is installed.

5.3.3. This activity will be coordinated with the Facility Point of Contact.

5.4. New Equipment:

5.4.1. Equipment may be added or deleted from the service contract as needed upon notification by the Contracting Officer (to be documented in writing via contract modification). Deleted equipment will be credited on a prorated basis if deleted before any maintenance or repair has been performed on it.

6. Confidentiality, Privacy, And Security

6.1. The Contractor will not require or be granted access to VA Sensitive Information, Personal

Identifiable Information (PII) or Personal Health Information (PHI). Contractor services under this agreement will be performed with the appropriate security requirements listed in VA

Directive and Handbook 6500.6 Appendix A.

6.2. Contractor Personnel will report the VA Presonnel and will be accompanied by VA Personnel at all times when performing Accreditation Services while at the Nebraska-Western Iowa VA

Health Care System.

6.3. Contractor’s FSE(s) shall wear visible identification at all times while on the premises of the

VA. Identification shall include, as a minimum, the employee’s name, position, and the contractor’s trade name.

7. Parking, Smoking, and VA Regulations:

7.1. It is the responsibility of the contractor to park in the appropriate designated parking areas.

Information on parking is available from VA Police Service. VA will not invalidate or make reimbursement for parking violations of the contractor under any conditions.

7.2. Smoking is prohibited inside all VA buildings.

7.3. Possession of weapons is prohibited. Enclosed containers, including tool kits, shall be subject to search.

7.4. Violations of VA regulations may result in citation answerable in the United States (Federal)

District Court, not a local district, state or municipal court.

8. Limitations on Subcontracting

8.1. By submission of an offer and execution of a contract, the Offeror/Contractor agrees in performance of the contract in the case of a contract for Services, it will not pay more than 50 percent of the amount paid by the Government for contract performance to subcontractors that are not similarly situated entities. Any work that a similarly situated entity further subcontracts will count toward the 50 percent subcontract amount that cannot be exceeded.

8.2. An independent contractor shall be considered a subcontractor. “Similarly Situated” means that entity subcontracted to is same type of entity as the Prime Contractor (i.e., SDVOSB subcontracts to SDVOSB, small business subcontracts to small business).

9. Confidentiality, Privacy, And Security

9.1. Confidentiality: The Department of Veteran Affairs will provide the contractor with access to pertinent patient information for the purposes of providing IT Support to the Department of

Veteran Affairs. The contractor shall ensure the confidentiality of veteran’s personal information and shall be held liable in the event of breach of confidentiality. Contractor shall adhere to VA Directive 6500.6, Contract Security. Any person who knowingly or willingly discloses confidential information from the VA may be subject to criminal penalties.

9.2. Privacy Act and Authorization to Release Information: As a result of this contract, the contractor shall be subject to the Privacy Act of 1974. The veteran’s personal information described in this solicitation are irreplaceable personal information that must be safeguarded at all times. Contractor shall refer to the Privacy Act Notification (FAR 52.224-1) and Privacy

Act Clause (FAR 52.224-2) as found in the clauses section. The contractor shall develop and maintain a method of tracking any data obtained from the VA. The contractor is not authorized to release any veteran’s information. The Department of Veteran Affairs is the sole entity authorized to release any information upon written authorization from the patient.

9.3. Veteran’s Personal Information: Contractor personnel who obtain access to the veteran’s personal information or access hardware/software that may store sensitive information protected under 38 U.S.C. 4132 or 3305, as defined by the VA, shall not have access to the records unless absolutely necessary to perform the requirement. Any contractor employee required to access pertinent data shall not disclose to anyone that is not involved in the performance of this task. Any violation of these provisions may involve criminal penalties.

9.4. Veteran’s Personal Information Handling and Storage: Department of Veteran Affairs will allow the contractor personnel to work off-site, remote from the VA facility. However, the contractor is responsible for ensuring that the employees maintain the records in a safe and secure environment. Any examples for content, reference, or formatting must be de-identified.

9.5. In accordance with Federal Acquisition Regulation (FAR) 4.703, the Contractor’s contract files must be maintained for three years after final payment. The Contractor shall destroy the files on the anniversary of the third year after final payment has been received. The destruction shall be coordinated with the VA.

9.6. Destruction of VA Information – All VA data kept onsite by the contractor will be destroyed and/or shredded when not needed. Acceptable methods of onsite final destruction for all content would include burning, pulping, and/or erasing.

9.7. Certification of Destruction – The contractor will provide to the Contracting Officer

Representative and the Contracting Officer written documentation that all records were destructed at the end of the period of performance.

10. Contractor Personnel Security Requirements

10.1. All contractor employees are subject to the same level of investigation as VA employees who have access to VA Sensitive Information. The level of background investigation commensurate with the level of access needed to perform the statement of work is: National

Agency Check with Inquiries (Low levels of investigation are significant enough for access to patients, patient records, restricted areas, etc.) (NACI). This requirement is applicable to all subcontractor personnel requiring the same access.

10.2. Before being granted access to VA information or information systems, all contractor employees and subcontractor employees requiring such access shall sign on an annual basis an acknowledgment that they have read, understand, and agree to abide by VA's Contractor

Rules of Behavior which is attached to this contract.

10.3. Before being granted access to VA information or information systems, all contractor employees and subcontractor employees requiring such access shall complete on an annual basis either: (i) the VA security/privacy awareness training (contains VA's security/privacy requirements) within 1 week of the initiation of the contract, or (ii) security awareness training provided or arranged by the contractor that conforms to VA's security/privacy requirements as delineated in the hard copy of the VA security awareness training provided to the contractor. If the contractor provides their own training that conforms to VA's requirements, they will provide the Contracting Officer Representative and Contracting Officer, a yearly report (due annually on the date of the contract initiation) stating that all applicable employees involved in VA's contract have received their annual security/privacy training that meets VA's requirements and the total number of employees trained.

10.4. Users will not divulge their passwords and will follow VA guidelines for creating passwords.

10.5. While on the VA computer network, users will abide by VA directives, policies, and procedures.

10.6. Users are not authorized to use remote access services to engage in any activity that is illegal under local, state, federal, or international laws; or that violates VA policies.

11. Government Roles and Responsibilities:

11.1. The following personnel shall oversee and coordinate surveillance activities.

11.2. Contracting Officer (CO) – The CO shall ensure performance of all necessary actions for effective contracting, ensure compliance with the awarded contract, and shall safeguard the interests of the United States in the contractual relationship. The CO shall also assure that the

Contractor receives impartial, fair, and equitable treatment. The CO is ultimately responsible for the final determination of the adequacy of the Contractor’s performance.

11.3. Facility Point of Contact (POC) – The POC is responsible for technical administration of the awarded contract and shall assure proper Government surveillance of the Contractor’s performance. The POC shall review all invoices for accuracy and certify correct invoices for payment. The POC is not empowered to make any contractual commitments or to authorize any contractual changes on the Government’s behalf.

12. Gray Market Prevention

12.1. Gray market items are Original Equipment Manufacturers (OEM) goods sold through unauthorized channels in direct competition with authorized distributors. This procurement is for new OEM medical supplies, medical equipment and/or services contracts for maintenance of medical equipment (i.e. replacement parts) for VA Medical Centers. No remanufactures or gray market items will be acceptable.

12.2. Vendor shall be an OEM, authorized dealer, authorized distributor or authorized reseller for the proposed medical supplies, medical equipment and/or services contracts for maintenance of medical equipment (i.e. replacement parts), verified by an authorization letter or other documents from the OEM, such that the OEM’s warranty and service are provided and maintained by the OEM. All software licensing, warranty and service associated with the medical supplies, medical equipment and/or services contracts for maintenance of medical equipment shall be in accordance with the OEM terms and conditions.

12.3. The delivery of gray market items to the VA in the fulfillment of an order/award constitutes a breach of contract. Accordingly, the VA reserves the right enforce any of its contractual remedies. This includes termination of the contract or, solely at the VA’s election, allowing the

Vendor to replace, at no cost to the Government, any remanufactured or gray market item(s) delivered to a VA medical facility upon discovery of such items. Reverse engineered and/or refurbished parts shall not be utilized under the terms of this contract without explicit permission, in writing, from the Contracting Officer.

13. National Archives and Records Administration (NARA) Records Management Language for Contracts

13.1. Applicability

13.1.1. This clause applies to all Contractors whose employees create, work with, or otherwise handle

Federal records, as defined in Section B, regardless of the medium in which the record exists.

13.2. Definitions

13.2.1. “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

13.2.2. The term Federal record:

13.2.2.1. includes Department of Veteran Affairs records.

13.2.2.2. does not include personal materials.

13.2.2.3. applies to records created, received, or maintained by Contractors pursuant to their

Department of Veteran Affairs contract.

13.2.2.4. may include deliverables and documentation associated with deliverables.

13.3. Requirements

13.3.1. Contractor shall comply with all applicable records management laws and regulations, as well as

National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter

XII Subchapter B, and those policies associated with the safeguarding of records covered by the

Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

13.3.2. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of

44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

13.3.3. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

13.3.4. Department of Veteran Affairs and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of Department of Veteran Affairs or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of

Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to Department of Veteran Affairs. The agency must report promptly to NARA in accordance with 36 CFR 1230.

13.3.5. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the contract action. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to

Department of Veteran Affairs control or the Contractor must hold it until otherwise directed.

Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the contract action. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

13.3.6. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The

Contractor (and any sub-contractor) is required to abide by Government and Department of

Veteran Affairs guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

13.3.7. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with Department of Veteran Affairs policy.

13.3.8. The Contractor shall not create or maintain any records containing any non-public Department of

Veteran Affairs information that are not specifically tied to or authorized by the contract.

13.3.9. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

13.3.10. The Department of Veteran Affairs owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which

Department of Veteran Affairs shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.

13.3.11. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take Department of Veteran Affairs-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

13.3.12. [Note: To the extent an agency requires contractors to complete records management training, the agency must provide the training to the contractor.]

13.4. Flowdown of requirements to subcontractors

13.4.1. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this contract action, and require written subcontractor acknowledgment of same.

13.4.2. Violation by a subcontractor of any provision set forth in this clause will be attributed to the

Contractor.

14. VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE FOR

INCLUSION INTO CONTRACTS, AS APPROPRIATE

14.1. GENERAL

14.1.1. Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.

14.2. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS

14.2.1. A contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

14.2.2. All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and

Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

14.2.3. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of

Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security

Service within the Office of Operations, Security, and Preparedness.

14.2.4. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-

U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

14.2.5. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

14.3. VA INFORMATION CUSTODIAL LANGUAGE

14.3.1. Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).

14.3.2. VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements.

VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.

14.3.3. Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records

Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information

Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records

Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA

Contracting Officer within 30 days of termination of the contract.

14.3.4. The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable

Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.

14.3.5. The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.

14.3.6. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under

Federal Acquisition Regulation (FAR) part 12.

14.3.7. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate

Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.

14.3.8. The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.

14.3.9. The contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.

14.3.10. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with

VA’s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.

14.3.11. Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or

Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.

14.3.12. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.

14.4. INFORMATION SYSTEM DESIGN AND DEVELOPMENT

14.4.1. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS

199 system security categorization (reference Appendix D of VA Handbook 6500, VA

Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COTR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.

14.4.2. The contractor/subcontractor shall certify to the COTR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration

(FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.

14.4.3. The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default

“program files” directory and silently install and uninstall.

14.4.4. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.

14.4.5. The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST

Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal

Information Systems, VA Handbook 6500, Information Security Program and VA Handbook

6500.5, Incorporating Security and Privacy in System Development Lifecycle.

14.4.6. The contractor/subcontractor is required to design, develop, or operate a System of Records Notice

(SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.

14.4.7. The contractor/subcontractor agrees to:

14.4.7.1. Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:

14.4.7.1.1. The Systems of Records (SOR); and

14.4.7.1.2. The design, development, or operation work that the contractor/subcontractor is to perform;

14.4.7.2. Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a

SOR on individuals that is subject to the Privacy Act; and

14.4.7.3. Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.

14.4.8. In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a

SOR on individuals to accomplish an agency function, the contractor/subcontractor is considered to be an employee of the agency.

14.4.8.1. “Operation of a System of Records” means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.

14.4.8.2. “Record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person’s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.

14.4.8.3. “System of Records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

14.4.8.4. The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as “Systems”), throughout the life of this contract and any extension, warranty, or maintenance periods. This includes, but is not limited to workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the

Systems.

14.4.8.5. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system).

Such issues shall be remediated as quickly as is practical, but in no event longer than ____ days.

14.4.8.6. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within ____ days.

14.4.8.7. All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph

(e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA Assistant Secretary for Office of Information and Technology.

14.5. SECURITY INCIDENT INVESTIGATION

14.5.1. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

14.5.2. To the extent known by the contractor/subcontractor, the contractor/subcontractor’s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

14.5.3. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

14.5.4. In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with

VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

14.6. LIQUIDATED DAMAGES FOR DATA BREACH

14.6.1. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

14.6.2. The contractor/subcontractor shall provide notice to VA of a “security incident” as set forth in the

Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .