Solicitation Attachment C - VA Directive 6550 Appendix A.pdf
PDF 668 KB Posted
- Attached to
- Nationwide Infusion Pump Requirement Federal contract opportunity
- Solicitation number
- 36C24125R0070_1
About this file
VA Directive 6550 Appendix A is a comprehensive cybersecurity and technical assessment document for medical devices procured by the Department of Veterans Affairs (VA). The form is specifically designed for network-connected and non-network-connected medical devices that store sensitive information, with a focus on thoroughly evaluating technical specifications, security features, and potential risks. The document covers critical areas such as device operating systems, encryption methods, network connectivity, authentication mechanisms, vulnerability scanning capabilities, data storage practices, interface compatibility, and compliance with VA security standards.
The document requires detailed information across 31 key sections, including device categorization, manufacturer details, network configurations, encryption protocols, backup capabilities, and electronic health record (EHR) interface compatibility. Notably, the form prohibits procurement of devices with unsupported operating systems, non-FIPS 140-2/140-3 compliant wireless networking, and devices that cannot support automated patching or VA-approved antivirus solutions. The form must be completed and signed by Biomedical Engineering, Area Manager, and Information Systems Security Officer, with specific timelines for review and submission, ultimately serving as a critical risk assessment tool for medical device procurement within the VA healthcare system.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 0003 Attachment - Questions and Answers.xlsx | XLSX spreadsheet | |
| 36C24125R0070 0003.docx | DOCX document | |
| 36C24125R0070 0002.pdf | ||
| Amendment 0001 Attachment - Revised FAR 52.212-1 Instructions to Offerors.pdf | ||
| Amendment 0001 Attachment - Revised FAR 52.212-2 Evaluation.pdf | ||
| 36C24125R0070 0001.pdf | ||
| Amendment 0001 Attachment - Revised Statement of Work.pdf | ||
| Amendment 0001 Attachment - Questions and Answers.xlsx | XLSX spreadsheet | |
| Solicitation Attachment A - Pricing Worksheet.xlsx | XLSX spreadsheet | |
| 36C24125R0070.pdf | ||
| Solicitation Attachment B - NEMA MDS2 Worksheet.xlsx | XLSX spreadsheet |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
VA Directive 6550 Appendix A
VA DIRECTIVE 6550 Appendix A – To be completed for all procurements of network-connected medical devices and non-network-connected medical devices that store sensitive information. For client/server systems, a separate 6550 Appendix A is required for each the client and the medical server.
1.1 Equipment Category (VA-MDNS)
1.2 Manufacturer
1.3 Model
1.4 NSI Number (if known)
1.5 Application Name and Software Version #
1.6 Requesting Service
1.7 VISN
1.8 Facility Name
1.9 Facility Number
1.10 Manufacturer Point of Contact
Phone Number E-mail address
1.11 Biomedical Engineering Point of Contact
Phone Number E-mail address
1.12 Responsible Service if Biomedical Engineering is NOT the Primary System Manager for system maintenance, support and lifecycle management
1.13 Medical Device Type ☐ Discrete device
☐ Software ☐ Client ☐ Application server
1.14 Device Description (i.e. equipment function and systems it communicates with)
1.15 MDIA VLAN Number for installation (if known)
1.16 Device Operating System (OS)
Please include OS build level.
Review support status for Windows OS versions here.
Procurement of devices with unsupported operating systems is prohibited. Unsupported operating systems are OSs that are not supported by the manufacturer and have reached the end of the OS lifecycle as published by the OS manufacturer (i.e. no further security patches will be released for the OS by the manufacturer after the OS end-of-life nor will be available by other methods such as extended warranty purchases from the OS manufacturer).
1.17 Does the device support wireless network connection? ☐ Yes ☐ No If yes, what is the FIPS 140-2 or 140-3 certification number?
If no, does the vendor support the installation of FIPS 140-2 or 140-3 wireless cards? ☐ Yes ☐ No
Procurement of devices using 802.11 wireless networking that are not FIPS 140-2 or 140-3 compliant is prohibited.
1.18 Does the device have an existing, active Enterprise Risk
Analysis (ERA)? ☐ Yes ☐ No If yes, what is the ERA number?
If the device has a direct connection to Cerner or EHRM interface, does the device have an existing MedMod ERA? ☐ Yes ☐ No
If yes, what is the MedMod ERA number?
**Note that the ERA must be for the same make, model, and application software version to apply to the requested device. A new ERA is required for major software or operating system updates (e.g. version 2.0 to 3.0) but is not required for minor updates (e.g. version 2.0 to version 2.1).
If an ERA exists for the requested device, completion of the 6550 Appendix A is not required beyond this point. Please sign to certify that an existing ERA is available for the requested device and forward the document to either the Area Manager or
ISSO for signature, as appropriate. Please note that if the device is an EHRM device, a MedMod ERA is required.
https://learn.microsoft.com/en-us/lifecycle/products/
2.1 Can the OS be automatically patched? ☐ Yes ☐ No
**Note that devices that do not support automated patching via the VHA MD Update Server (MDUS) or via vendor channels impose a significantly higher risk to the VA network.
If patching is not automated, what is the patching process and/or limitations?
2.2 For applications and sub-applications (e.g., Java, Apache) on the device, is automatic patching or updating supported? ☐ Yes ☐ No **Note that devices that do not support automated patching impose a significantly higher risk to the VA network.
If patching is not automated, what is the patching process and/or limitations?
2.3 Is a device hardening guide available? ☐ Yes ☐ No
2.4 Does the device have logging or other auditing mechanisms in place? ☐ Yes ☐ No If yes, can these logs be exported to a syslog or similar server?
2.5 Does the device include a database? ☐ Yes ☐ No
If yes, what is the database version and type (e.g., SQL, Oracle)?
**Note that procuring and deploying devices with unsupported database versions imposes a significantly higher risk to the VA network.
Does the vendor support database conversion from SSN to electronic data interchange personal identifier (EDIPI)? ☐ Yes ☐ No ☐ No PHI
Does the vendor database support multiple identifiers? ☐ Yes ☐ No ☐ No PHI
2.6 Can the device run Defender, ESET, or McAfee antivirus? ☐ Yes ☐ No
**Note that devices that do not support VA-approved antivirus scanning or an antivirus scanning solution managed by the vendor impose a significantly higher risk to the VA network.
If antivirus is not supported, what are the AV processes and/or the limitations?
2.7 Can a commercial-off-the-shelf (COTS) endpoint management system be installed (e.g., IBM Big Fix, Goverlan, SCCM)? ☐ Yes ☐ No If so, which one(s)?
2.8 For Windows-based devices, can the existing Microsoft service be enabled to communicate with the VHA SMAK-AM server?
☐ Yes ☐ No ☐ Non-Windows-based system
If no, has the vendor agreed to provide a complete software and application inventory for all system components as per FISMA requirements?
☐ Yes ☐ No
**Note that devices that do not support communication with the SMAK-AM server or for which the vendor does not agree to provide a complete software inventory impose a significantly higher risk to the VA network.
2.9 Does the device support the use of two-factor authentication? ☐ Yes ☐ No **Note that devices that do not support two-factor authentication impose a significantly higher risk to the VA network. Please review the VA’s requirements for two-factor authentication here.
Does the device require interactive login service accounts?
**Note that devices that require interactive login service accounts impose a significantly higher risk to the VA network.
2.10 Will the device be joined to the VA domain? ☐ Yes ☐ No
**Note that devices that are not joined to the domain impose a significantly higher risk to the VA network.
2.11 Does the device allow for encryption of the data drive or OS drives? ☐ Yes ☐ No What level of encryption is allowed?
2.12 Are post-quantum cryptography (PQC) ciphers being used for this implementation? ☐ Yes ☐ No https://vaww.oed.portal.va.gov/sites/vrm/IAM/playbooks/Pages/PIV%20Compliance/PIV%20Compliance.aspx
2.13 What method of encryption is used for data in transit? ☐ SSL
☐ HTTPS
☐ TLS (version: )
☐ SFTP
☐ None ☐ Other:
**Note that use of SSL is prohibited and that TLS versions 1.0/1.1 impose a significantly higher risk to the VA network.
2.14 Is sensitive data stored at rest on the device? ☐ Yes ☐ No If yes, how many records can be stored on the device? ☐ <500 ☐ >500 If yes, does the device support on demand purging of data from the local hard drive? ☐ Yes ☐ No
2.15 Will sensitive data be stored outside of the VA network (e.g.
cloud-based service provider – excludes Electronic Medical Record connection)?
☐ Yes ☐ No
2.16 Does the device send/receive VA data to/from an external, vendor-managed cloud? ☐ Yes ☐ No
If yes, has the cloud platform been approved by the VA Digital Transformation Center (DTC)?
To determine approval status, please visit the Digital VA Product Marketplace.
☐ Yes ☐ No
If yes, what is the cloud type, determined by the VA DTC? ☐ Software as a Service (SaaS) ☐ Managed Service
If SaaS, what is the FedRAMP package ID?
If SaaS, is it FedRAMP authorized? ☐ Yes ☐ No Is there an approved VA ATO for the cloud platform? ☐ Yes ☐ No
2.17 Is connectivity external to the VA required for device
operation? ☐ Yes ☐ No
2.18 Is connectivity external to the VA required for device support? ☐ No ☐ Yes - VA S2S VPN ☐ Yes - VA Citrix ☐ Yes – VA Azure Virtual Desktop ☐ Yes – Other
If other, describe the remote access method.
What is the MOU/ISA number?
2.19 How many IP addresses are required?
2.20 What kind of IPs does the device use? ☐ Static IP ☐ DHCP
**Devices should be deployed with static IPs unless DHCP is required.
2.21 Is IPv6 supported? ☐ Yes ☐ No
If yes, please list any limitations.
2.22 If server-based, select one from each column: ☐ Vendor-provided
☐ VHA-provided ☐ Other - describe
☐ Physical server ☐ Virtual host ☐ Cloud virtual host
2.23 If server-based, list server specifications (cores, RAM, power, storage) and rack space.
Attach additional documentation, as needed.
2.24 Does the device use Java? ☐ Yes ☐ No
2.25 Does the device utilize machine learning/artificial intelligence? ☐ Yes ☐ No
2.26 What type of vulnerability scanning is allowed on the device? ☐ Active ☐ Passive ☐ Both
If active, is credentialed scanning allowed? ☐ Yes ☐ No https://www.oit.va.gov/marketplace/ https://www.oit.va.gov/marketplace/
2.27 If the device uses digital signatures, is it compliant with FIPS 186-4? ☐ Yes ☐ No ☐ N/A
2.28 Does this system include a pre-production (test) environment? ☐ Yes ☐ No
2.29 Does the device support backups? ☐ Yes ☐ No
Does this procurement include a backup solution? ☐ Yes ☐ No ☐ N/A
2.30 Does this device include an HL7 interface? ☐ Yes ☐ No
If yes, what will the HL7 interface be used for? ☐ Orders ☐ Results ☐ Billing (DFT)
☐ ADT
☐ Other:
If the requested device does not have an EHRM approved connection or interface to Cerner, completion of the 6550 Appendix A is not required beyond this point. Please sign this document and route it for signature, as appropriate.
2.31 Does the device have an EHRM approved Cerner interface?
For more information, please reference the approved EHRM interface list and the EHRM IO HTM SharePoint site
☐ Yes ☐ No
If no, has an NSR been submitted for interface approval? ☐ Yes ☐No NSR Number:
If no, to which security authorization boundary will this device/system be added?
For more information on MedMod zones and MD-LITE, please reference the EHRM IO HTM SharePoint site or contact the EHRM IO HTM team at EHRMIOHTM@va.gov.
☐ MedMod Zone 6A ☐ MedMod Zone 6B
☐ MD-LITE
☐ Other
If no, what is the proposed EHR connection(s)/integration(s) type(s)?
For additional guidance, please contact the EHRM IO HTM team at EHRMIOHTM@va.gov.
☐ Openlink (HL7) ☐ Compass Router (DICOM) ☐ EHR Gateway (Non-DICOM Image Routing) ☐ Cerner Connectivity Engine (CCE) ☐ CCE Terminal Server (CCE-TS) ☐ Separate HL7 Interface/Middleware Server ☐ None ☐ Other:
Submittal/Approval
Biomedical Engineering Date
Area Manager* Date
*Area manager signature only required for client/server medical systems. Please sign within 10 business days of receipt.
Information Systems Security Officer** Date
** Please sign within 5 business days of receipt and return the document to Biomedical Engineering and the Area Manager. If an ERA is required, please submit this form with the ERA package to the Specialized Device Cybersecurity Department (SDSD) to initiate the ERA process.
https://dvagov.sharepoint.com/sites/OEHRMCMIOCNIOHTMBiomed2/Lists/OEHRM%20HTM%20Gap%20Analysis/AllItems.aspx https://dvagov.sharepoint.com/sites/OEHRMCMIOCNIOHTMBiomed2/Lists/OEHRM%20HTM%20Gap%20Analysis/AllItems.aspx https://dvagov.sharepoint.com/sites/OEHRMCMIOCNIOHTMBiomed2/SitePages/Clinical-Interfaces.aspx https://dvagov.sharepoint.com/sites/OEHRMCMIOCNIOHTMBiomed2/SitePages/Cybersecurity.aspx mailto:EHRMIOHTM@va.gov mailto:EHRMIOHTM@va.gov
| PRE-PROCUREMENT ASSESSMENT AND IMPLEMENTATION OF MEDICAL DEVICES/SYSTEMS |
| CERTIFIED BY: |
| BY DIRECTION OF THE SECRETARY OF VETERANS AFFAIRS: |
| PRE-PROCUREMENT ASSESSMENT AND IMPLEMENTATION FOR MEDICAL DEVICES/SYSTEMS |
| 2. BACKGROUND. |
| 3. POLICY. |
| 4. RESPONSIBILITIES. |
| d. Information Systems Security Officers (VISN ISSOs for VISN-wide procurements.) ISSOs shall: |
| e. OIS Specialized Device Security Division (SDSD). SDSD shall: |
| g. Deputy Under Secretary of Health for Operations Management (DUSHOM). |
| 5. REFERENCES. |
| APPENDIX B – PRE-PROCUREMENT AND IMPLEMENTATION WORKFLOW |
| Model: |
| NSI Number if known: |
| Application Name and Software Version: |
| Requesting Service: Healthcare Technology Management |
| VISN: N/A |
| Facility Name: VACO |
| Facility Number: 101 |
| Manufacturer Point of Contact: |
| Phone Number: |
| Email address: |
| Biomedical Engineering Point of Contact: Liana Lucky |
| Phone Number_2: 504-380-1836 |
| Email address_2: Liana.Lucky@va.gov |
| Responsible Service if Biomedical Engineering is NOT the Primary System Manager for system maintenance support and lifecycle management: |
| Discrete device: Off |
| Software: Off |
| Client: Off |
| Application server: Off |
| Discrete device Software Client Application serverDevice Description ie equipment function and systems it communicates with: |
| Discrete device Software Client Application serverMDIA VLAN Number for installation if known: |
| Discrete device Software Client Application serverDevice Operating System OS Please include OS build level Review support status for Windows OS versions here: |
| other methods such as extended warranty purchases from the OS manufacturer: Off |
| Yes NoIf yes what is the FIPS 1402 or 1403 certification number: |
| undefined_3: Off |
| If patching is not automated what is the patching process andor limitations: |
| If patching is not automated what is the patching process andor limitations_2: |
| undefined_14: Off |
| Yes NoIf yes can these logs be exported to a syslog or similar server: |
| undefined_15: Off |
| Yes NoIf yes what is the database version and type eg SQL Oracle: |
| undefined_16: Off |
| undefined_17: Off |
| If antivirus is not supported what are the AV processes andor the limitations: |
| undefined_20: Off |
| Yes NoIf so which ones: |
| Does the device require interactive login service accounts: |
| undefined_30: Off |
| Yes NoWhat level of encryption is allowed: |
| SSL: Off |
| HTTPS: Off |
| TLS version: Off |
| SFTP: Off |
| None: Off |
| Other: Off |
| undefined_33: |
| undefined_44: Off |
| Software as a Service SaaS: Off |
| Managed Service: Off |
| Software as a Service SaaS Managed ServiceIf SaaS what is the FedRAMP package ID: |
| No_10: Off |
| Yes VA S2S VPN: Off |
| Yes VA Citrix: Off |
| Yes VA Azure Virtual Desktop: Off |
| Yes Other: Off |
| No Yes VA S2S VPN Yes VA Citrix Yes VA Azure Virtual Desktop Yes OtherIf other describe the remote access method: |
| No Yes VA S2S VPN Yes VA Citrix Yes VA Azure Virtual Desktop Yes OtherWhat is the MOUISA number: |
| No Yes VA S2S VPN Yes VA Citrix Yes VA Azure Virtual Desktop Yes OtherHow many IP addresses are required: |
| undefined_51: Off |
| undefined_52: Off |
| undefined_53: Off |
| Yes NoIf yes please list any limitations: |
| Vendorprovided: Off |
| VHAprovided: Off |
| Other describe: Off |
| Physical server: Off |
| Virtual host: Off |
| Cloud virtual host: Off |
| If serverbased list server specifications cores RAM power storage and rack space Attach additional documentation as needed: |
| undefined_60: Off |
| undefined_65: Off |
| Orders: Off |
| Results: Off |
| Billing DFT: Off |
| ADT: Off |
| Other_2: Off |
| undefined_68: |
| undefined_69: Off |
| Yes No NSR Number: |
| MedMod Zone 6A: Off |
| MedMod Zone 6B: Off |
| MDLITE: Off |
| Other_3: Off |
| undefined_72: |
| Openlink HL7: Off |
| Compass Router DICOM: Off |
| EHR Gateway NonDICOM Image Routing: Off |
| Cerner Connectivity Engine CCE: Off |
| CCE Terminal Server CCETS: Off |
| Separate HL7 InterfaceMiddleware Server: Off |
| None_2: Off |
| Other_4: Off |
| Manufacturer: |
| Equipment Category: INFUSION PUMPS: MULTITHERAPY |
| undefined_73: |
| Yes NoIf yes what is the ERA number: |
| MedMod ERA Number: |
| vendor support installation of FIPS 140-2 or 140-3: Off |
| MedMod ERA: Off |
| Automatic Patching: Off |
| Hardening Guide: Off |
| OS Auto Patching: Off |
| Antivirus: Off |
| FISMA Inventory: Off |
| SMAK-AM: Off |
| PQC: Off |
| VA domain: Off |
| 2FA: Off |
| Data Storage at Rest: Off |
| # Records Stored: Off |
| On Demand Data Purging: Off |
| External Data Storage: Off |
| Send/Receive Data from External Cloud: Off |
| FedRAMP: Off |
| VA ATO for Cloud Platform: Off |
| External Connectivity for Operation: Off |
| Java: Off |
| AI: Off |
| Vulnerability Scanning Type: Off |
| Credentialed Scanning: Off |
| HL7 Interface: Off |
| Backups: Off |
| Pre-Prod: Off |
| NSR: Off |
File details come from the government source that posted it. Updated .