SOW_Thoracic On-Call Service Contract_10-19-2020 v1.docx
DOCX document 70 KB Posted
- Attached to
- Q524--Thoracic On Call - 603 Sources Sought Federal contract opportunity
- Solicitation number
- 36C24921Q0057
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C24921Q0057.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
THORACIC ON-CALL COVERAGE CONTRACT
STATEMENT OF WORK
I. STATEMENT OF OBJECTIVES
A. The Contractor shall furnish board eligible and/or board certified Thoracic Attendings to provide the following as noted below. It is understood that the quantities presented for bid are good faith estimates and that the actual number may be greater or less than those stated.
1. On-Call Coverage for General Thoracic - The Contractor will provide on-call consultation coverage in the absence of the Robley Rex VA Medical Center (VAMC) staff Thoracic Attending during weekdays, weekends (3:30 PM Friday through 7:00 AM Monday), holidays and periodic vacation days or other authorized absences. This on-call includes acceptance of Veteran patients presenting with Thoracic conditions that can be managed at the Robley Rex VAMC, Louisville, KY. In cases of high complexity or unavailability of equipment and/or instrumentation, transfer is appropriate. The Contractor shall transfer the Veteran patient to a local hospital of the Contractor’s choice; however, it must be within 20 miles of the Robley Rex VAMC. The Contractor must be able to properly manage acute Thoracic patients and must have admitting privileges at the specified local hospital. Except in cases of emergency, requirements for on-call coverage will be scheduled 90 days in advance. Coverage will include consultation with the Robley Rex VAMC’s physicians regarding the appropriate medical care of Veterans presenting with Thoracic conditions and inpatient follow-up visits for any unstable inpatient. Initial response is expected within 30 minutes. Charges for hospital care completed at the VAMC will be reimbursed by the Robley Rex VAMC, Surgical Service, Louisville, KY. Charges for hospital care completed at a local hospital will be reimbursed by the Robley Rex VAMC, Non-VA Care Office, Louisville, KY. Reimbursement for on-call services will be based on an agreed upon unit(s) cost and reimbursement for consultation, rounding and/or surgical care will be based on Center for Medicare and Medicaid Services (CMS) rates.
a. Consultation services requested from the VA Emergency Department - Consultation services requested from the VA Emergency Department are expected to be made on-site at the Robley Rex VAMC in a timely manner, as agreed upon with the consulting physician, unless the requesting provider determines that an initial telephone consultation is sufficient. All on-site Emergency Department consultations will be documented in the Computer Patient Record System (CPRS).
b. Consultations services requested for VA hospitalized patients - Consultations services for VA hospitalized patients include direct (on-site, in-person) care of new consults, as deemed appropriate by the primary team. Response to the initial call is expected within 30 minutes. Consultation services necessitating direct care are expected to be seen on-site at the Robley Rex VAMC in a timely manner, as agreed upon with the consulting physician. Consultation/rounding services for VA hospitalized patients also includes inpatient follow-up, as determined by the Robley Rex VAMC staff Thoracic Attending or Primary Team. The Contractor will continue to provide inpatient follow-up/rounding through the coverage period if clinically required. All on-site inpatient consultations/rounding will be documented in the Computerized Patient Record System (CPRS).
2. Transfer of Care/Hand-off Dialogue
A. It is expected that a transfer of care/hand-off dialogue will take place between the Robley Rex VAMC staff Thoracic Attending and the Contractor’s physician on-call. At the beginning of the on-call coverage period, the Robley Rex VAMC staff Thoracic Attending will contact the Contractor’s on-call physician to discuss any inpatient who will need direct care follow-up during the coverage period. Likewise, at the end of the coverage period, the Contractor’s on-call physician will contact the Robley Rex VAMC staff Thoracic Attending to discuss new consults and concerning follow-up cases seen during the coverage period. This communication is expected to be made by 8:00 AM the morning the coverage period ends.
B. The Contractor will provide a schedule to the VA Surgical Service Administrative Office which contains 90 days of on-call rotation. This will be provided at least three (3) working days before the start of each month. The on-call schedule will be faxed to (502) 287-6802 or e-mailed to the Administrative Officer for Surgical Service/Contracting Officer’s Representative (COR). The schedule will provide the names of the Thoracic Attending physicians assigned to provide both acute care and general Thoracic coverage, as well as contact information, such as pager or cell phone numbers. The schedule will be updated and forwarded to the Surgical Service Administrative Office whenever changes are made.
C. All contract healthcare providers (HCP) assigned to provide general Thoracic coverage must be credentialed and privileged at the Robley Rex VAMC. Those scheduled to provide only acute Thoracic coverage at another facility may not be required to be credentialed and privileged. Specific requirements are outlined in Paragraph VI, Credentialing and Privileging.
D. All contract healthcare providers (HCP) assigned to provide general Thoracic coverage at the Robley Rex VAMC will participate in the Respiratory Protection Program by completing Fit Testing or providing documentation to validate this has been completed at another facility. Additionally, all contract healthcare providers (HCP) assigned to provide general Thoracic coverage at the Robley Rex VAMC will maintain BLS and ACLS certification.
II. DEFINITIONS
Terms used in this contract shall be interpreted as follows unless the context expressly requires a different construction and/or interpretation. In case of a conflict in language between the Definitions and other sections of this contract, the language in this section shall govern.
Contracting Officer (CO) – The person executing this contract on behalf of the Government with the authority to enter, administer contracts, and make related determinations and findings.
Contracting Officer’s Representative (COR) - A person appointed by the CO to take necessary action to ensure the contractor performs in accordance with and adheres to the specifications contained in the contract and to protect the interest of the Government. The COR shall report to the CO promptly any indication of non-compliance in order that appropriate action can be taken.
Credentialing – is the systematic process of screening and evaluation qualification and other credentials, including licensure, required education, relevant training and experience, and current competence and health status
Privileging (Clinical Privileging) – Is the process by which a practitioner, licensed for independent practice; i.e., without supervision, direction, required sponsor, preceptor, mandatory collaboration, etc.; is permitted by law and the facility to practice independently, to provide specific medical or other patient care services within the scope of the individual’s license, based upon the individual’s clinical competence as determined by peer references, professional experience, health status, education, training, and licensure. Clinical privileges must be facility-specific and provider- specific.
Veterans Health Administration (VHA) -- The central office for administration of the VA medical centers throughout the United States. The VHA is located in Washington, DC
Veterans Integrated Services Network (VISN) – The regional oversight for the VA Medical Centers in Memphis, TN, Tennessee Valley Healthcare System (Murfreesboro and Nashville), Louisville, KY, Lexington, KY, and Mountain Home, TN. The VISN office is located at 1801 West End Avenue, Suite 1100, Nashville, TN 37203.
Veterans Integrated Systems Technology Architecture (VISTA) – A PC based system that will capture and store clinical imagery, scanned documents and other non-textual data files and integrates them into patient’s medical record and with the hospital information system.
Computerized Patient Record System (CPRS) – Electronic patient charting system that houses all pertinent healthcare records; i.e., laboratory and radiology results, doctor’s orders, progress notes, surgery reports, etc.
III. QUALITY & QUALIFICATION REQUIREMENTS
A. The Contractor must ensure that all Contractor employees or sub-contractors providing services under this contract are fully trained and completely competent to perform the required services. The Contractor is required to maintain records that document competency/performance level of Contractor employees and sub-contractors providing services under this contract in accordance with the Joint Commission (JC) and/or other regulatory body requirements. The Contractor shall provide current copies of these records upon request as needed.
B. If the providers are not employees of the Contractor, they must be regarded as sub-contractors. When this is the case, the Contractor will be responsible for all care rendered by any sub-contractor(s) and must ensure the sub-contractors meet all aspects of this contract.
IV. CREDENTIAL REVIEWS/PRIVILEGING
A. General: The requirements of the government as stated in this Statement of Work (SOW) are for the performances of professional medical services. The Director of the Robley Rex VAMC grants privileges. As a prerequisite to performance under the contract, if a contract healthcare provider (HCP) performs services at the Robley Rex VAMC, this HCP must be credentialed and privileged at the Robley Rex VAMC. If services are not performed at the Robley Rex VAMC and the services are distributed to two or more HCPs of the group and the services are not directed towards a single provider, then the HCP is not required to be credentialed and privileged. If the HCP in a group is providing all the service, or all of a specific service, the HCP MUST be credentialed and privileged. When applicable, compliance with the credentialing and privileging process is essential to the performance under this contract. Any failure to meet these requirements is considered nonperformance and the basis for assessment of liquidated damages and/or termination for default.
B. The credentialing and privileging process is subject to the provisions of 38 U.S.C. 4104 (1); VHA Handbook 5005, Staffing; VHA Handbooks 1100.17 (National Practitioner Data Bank Reports) and 1100.19 (Credentialing and Privileging); VHA Directive 2012-030, Credentialing of Health Care Professionals, dated October 11, 2012; VHS&RA Supplements; Joint Commission; Medical Staff By Laws; and Robley Rex VAMC Memorandum 603-13-11-023, Credentialing and Privileging. The Credentialing Committee, a subcommittee of the Healthcare Delivery Board (formerly Clinical Executive Board) established at the VAMC is the sole agency authorized to accept applications for privileges submitted by the Contractor to the Chief of Staff and to make recommendations on the granting of privileges. The Robley Rex VAMC Director is the final authority for approving or denying clinical privileges for all contract physicians.
C. Request for privileges and completed credential packets shall be submitted sixty (60) days prior to the physician’s scheduled start date.
D. Once privileges are granted, subsequent actions taken concerning the privileges of contract providers, including any limitation on privileges, will be governed by the procedures in VHA Handbook 1100.19 Credentialing and Privileging; Joint Commission, Medical Staff Bylaws and Robley Rex VAMC Memorandum 603-13-11-023, Credentialing and Privileging.
E. All contract healthcare providers (HCP) assigned to provide general Thoracic coverage at the Robley Rex VAMC will maintain BLS and ACLS certification.
V. ENVIRONMENT OF CARE:
A. The Government will schedule and provide an initial orientation which all Contract staff shall attend prior to working in the VAMC.
B. The VAMC will provide all other ancillary personnel services required for performing services, including but not limited to nursing personnel, x-ray technologists, medical assistants and laboratory technicians.
C. The Government will provide an identification badge to each Contract personnel during facility orientation. The Contract personnel shall always wear the identification badge on the front of the outer clothing when providing services under this contract.
D. The Government shall provide space for consultations, conferences, study, telephone conversations and privacy.
VI. HIPPA AND OTHER REGULATORY COMPLIANCE
A. Contractor shall adhere to provisions of Public Law 104-191, Health Insurance Portability and Accountability Act (HIPPA) of 1996 and the National Standards to Protect the Privacy and Security of Protected Health Information (PHI).
B. Contractor shall provide healthcare to patients seeking such from or though VA. As such, the Contractor is considered part of the Department health activity for purposes of the following statutes and the VA regulations implementing these statutes: The Privacy Act, 5 U.S.C. 552A and 38 U.S.C. sections 5701, 7705, and 7332. Contractor and its employees may have access to the VA patient medical records to the extent necessary for the Contractor to perform the contract, notwithstanding patient treatment records only pursuant to explicit disclosure authority from VA. Contractor and its employees are subject to the penalties and liabilities provided in the statutes and regulations mentioned in the paragraph for unauthorized disclosures of such records and their contents. Records created by the Contractor in the course of treating VA patients under this agreement, are the property of the VA and shall not be accessed, released, transferred, or destroyed except in accordance with applicable Federal Law and Regulations. Upon the expiration of this contract or termination of the contract, the contract shall promptly provide the VA with the individually identified VA patient treatment records. VA has unrestricted access to the records generated by the Contractor pursuant to this contract.
VII. INFECTION CONTROL
A. Standard precautions will be observed for all patients. Persons with infectious diseases that require additional precautions will be cared for utilizing transmission-based isolation. Contact with body fluids will be minimized when possible. All supervisors will evaluate all procedures, supplies, and equipment on an ongoing basis to assure employee and patient safety.
B. Needles and syringes will be placed in puncture resistant containers that are labeled, "Biohazard." The recapping of needles is contraindicated. Sharps will be handled with care and disposed of in accordance with Robley Rex VAMC Memorandum, Disposal of Needles, Sharp Objects, Syringes, and Regulated Medical Waste.
C. The service will comply with the Occupational Health program, which includes annual screening for Tuberculosis (TB) and appropriate testing and screening after exposures to contagious diseases. Hepatitis B vaccine is available on a voluntary basis to all employees who have contact with blood and body fluids. All exposures to blood and body fluids and other contagious disease will be reported to Occupational Health for follow-up. Appropriate screening and prophylaxis will be initiated.
D. All new employees will attend Infection Control orientation and annual review in-services. Infectious diseases will be reported to the Infection Control Nurse who reports them to the appropriate agency. Robley Rex VAMC staff will comply with hand hygiene policies and procedures to prevent the spread of micro-organisms. If additional services are located off site, Contractor is responsible for infection control.
E. All contract healthcare providers (HCP) assigned to provide general Thoracic coverage at the Robley Rex VAMC will participate in the Respiratory Protection Program by completing Fit Testing or providing documentation to validate this has been completed at another facility.
VIII. ADMINISTRATIVE TASKS/TIME AND CLINICAL TASK/TIME
The Contractor may be required to attend meetings with the Robley Rex VAMC medical and administrative staff to discuss patient care and contract issues.
IX. REQUIREMENTS AND HOW THEY WILL BE BILLED
A. The Contractor shall provide, within five (5) days of award of contract, both a clinical and administrative point of contact to coordinate services and billing.
B. Service shall be available 24 hours per day, 7 days per week including Federal holidays when scheduled for Thoracic weekend or vacation on-call services.
C. The Administrative Officer for Surgical Service will serve as the Contracting Officer’s Representatives (COR) and is the point of contact at the Robley Rex VAMC for the purposes of providing guidance on VA processes/procedures, requests for documentation, and processing invoices for payment for services. The COR will be responsible for coordinating Robley Rex VAMC resources to assist in the continuity of care for Robley Rex VAMC patients when necessary and informing the Contractor who the appropriate contact person is in each situation. In the absence of the COR, the Contractor should contact the VA Chief, Surgical Service, for assistance.
D. For services provided on-site, all medical record documentation must be entered via the appropriate method; i.e., electronically via CPRS. CPRS is the only acceptable method for documenting notes regarding services provided under this contract. The COR will ensure there is no delinquent documentation prior to the invoices being paid. The VA will review the invoice against its records and notify the Contractor of invoice discrepancies. Upon resolution of the discrepancies, the VA will approve the invoice and make payment to the Contractor.
E. Payments made to the Contractor by the Department of Veterans Affairs (VA) under this contract shall be for the total cost of services provided. The Contractor hereby agrees, that in no event shall the Contractor or his agents bill, charge, collect a deposit from, seek compensation, remuneration, or reimbursement from, or have any recourse against the beneficiary, the beneficiary’s family, private insurer, Medicare, or any other entity acting on the beneficiary’s behalf, for services provided pursuant to this contract. When properly invoiced and processed, VA payment for services provided to VA beneficiaries under the terms of this agreement shall constitute payment in full.
F. Reimbursement for VA beneficiaries presented prior to the expiration of this agreement shall be made at the contract rate in effect at the time of patient referral.
G. The documentation and coding of consults, treatment, procedures, progress notes, etc., will be in accordance with documentation guidelines published by the Center for Medicare and Medicaid Services (CMS), and all applicable coding standards. All diagnosis(es) will be coded using the current International Classification of Disease Index, ICD-9-CM or ICD-10, when applicable.
H. Contractor shall submit monthly invoices for services provided. Invoices shall be mailed to the following address or submitted electronically:
| For FedEx: |
| FMS-VA-2 (603) |
| 1615 Woodward Street |
| Austin, TX 78772 |
| For Standard Mail: |
| FMS-VA-2 (603) |
| P.O. Box 149971 |
| Austin, TX 78714 |
NOTE: Invoices submitted by the vendor will only be submitted with the agreed upon contract price. At no time will invoices be submitted with amounts that may be greater than the agreed upon rates. Should any invoices be submitted with amounts that are higher than the agreed upon rates which results in an overpayment, reimbursement will be requested from the vendor. Additionally, invoices shall only be submitted once for payment. Multiple invoices should not be submitted to the Austin Finance Center as this creates double work and may result in reimbursement by the Contractor.
I. The Department of Veterans Affairs (VA Financial Service Center FSC) is the designated agency office for invoice receipt in accordance with the Prompt Payment Act (5 CFR Part 1315). FSC or its designated representative may contact the vendor to provide specific instructions for electronic submission of invoices. The vendor will be responsible for any associated expenses. FSC may utilize third-party Contractors to facilitate invoice processing. Prior to contact by FSC or its designated representative for electronic invoicing submissions, the vendor shall continue to submit all invoices to the FSC at the addresses noted above.
J. In addition to the requirements in FAR clause 52.212-4, paragraph (g), invoices shall contain the following information: The Contractor’s Tax ID number; dates of service; description of services rendered; and fees at the contracted rate. All invoices that are not complete and correct will be returned to the provider without action. For the invoice to be reconsidered, appropriate corrections must be made and submitted as a new invoice. The VA will review the invoice against its records and notify the Contractor of invoice discrepancies. Upon resolution of the discrepancies, the VA will approve the invoice and make payment to the Contractor.
X. IF ON SITE VA-CLEAR DESCRIPTION OF DUTY HOURS
A. Timeliness is an essential component of this contract and the Contractor must adhere to established timeframes for the provision of service for work completed in the Operating Room Suite, wards and/or units and/or Emergency Department. Contractor shall be available 24/7 via telephone for consultation services when requested 100%. Response is required within 30 minutes of a call for services. Failure to provide the documentation required by this agreement or to provide documentation to support the charges being assessed will be incomplete services and will result in delayed processing of invoices.
B. Written documentation associated with each visit must be available to the VA within 24 hours of each visit and must be entered electronically into CPRS. Documentation of treatment; i.e., H&Ps, progress notes, operative notes, formal consultations and discharge summaries, etc.; shall be completed on the day the service is rendered. When requested, such written documentation must be provided to the VA within two (2) hours. In order to authenticate medical documentation in a timely manner, the Contractor shall apply, as soon as the contract is awarded, for Virtual Private Network (VPN) access through the VA’s Information Security Officer (ISO). This will allow off-site access to VA medical records for review and authentication.
C. On-Call Services: A monthly on-call list shall be provided in advance by the Contractor to the Administrative Officer, Surgical Service. The Contractor shall provide on-call services during evenings, weekends and legal Federal holidays, as assigned. The on-call Contract physician is not required to remain at place of residence while on-call but must be available by pager/cell phone during this time. He/she is required to respond telephonically within 15 minutes of receiving the call and must be in-house within 30 minutes of the original page or telephone call to provide Thoracic services and/or assistance at the VAMC, whether in the OR Suite, on the floor/unit or Emergency Department. As required, the Contract Attending(s) will present to care for the Veteran patient.
D. National Holidays: The 10 holidays observed by the Federal Government are:
New Year’s Day Martin Luther King’s Birthday Presidents Day Memorial Day Independence Day Labor Day Columbus Day Veterans Day Thanksgiving Day Christmas Day
Any other day specifically declared by the President of the United States to be a national holiday.
E. Deduction Schedule: The VA will track delays or cancellations of surgery due to lack of Thoracic Contractor Attending(s). Invoice adjustments shall be made for any delays or cancellations due to unavailability of the Contractor’s Thoracic Attending(s) as these create untimely care of the patient and may create decreased patient satisfaction. The following is a deduction schedule:
a. Delays: Delays can occur if any of the following items are not in place at the time the patient's surgery is scheduled to begin: patient's paperwork not completed; i.e., history and physical, consent, etc.; equipment not available; prosthetic item(s) not available and/or surgeon not available to begin case. Information regarding delays will be collected from the nursing staff/surgeons and Contract Thoracic Attending(s) by the Administrative Officer, Surgical Service who is the COR. The COR/Administrative Officer will discuss the information with the Chief of Surgery, who will then investigate the issue through discussions with the nursing staff/surgeons and Contract Thoracic Attending(s). This information will then be provided to the Contracting Officer for a determination of delay and penalty to be assessed.
(1) In the event, the Contract Thoracic Attending is unavailable to ensure the surgery case begins at the assigned time, the Contractor's monthly invoice shall be reduced $1,000.00 per delay.
(2) In the event, there is a delay in care due to non-response of the Contract Thoracic Attending when they are consulted on an inpatient or a patient in the emergency room, the Contractor's monthly invoice shall be reduced $1,000.00 per delay.
b. Cancellations: In the event of each surgery cancelled by the Contractor Thoracic Attending for medical or non-medical reasons, the Contractor's monthly invoice shall be reduced $1,000.00 per cancellation.
c. Documentation: In the event of delays or non-existent medical documentation for services provided for clinic/ED visits or operative cases, and/or failure to see inpatients on a daily basis, the Contractor's monthly invoice shall be reduced $1,000.00 per each instance of non-compliance.
d. Quality Improvement Data: In the event of non-receipt or delay in receipt of quality improvement data and/or the monthly on-call schedule, the Contractor’s monthly invoice shall be reduced $1,000.00 per instance of non-compliance.
XI. RESEARCH ELEMENTS – No research requirements are associated with this contract.
XII. RESIDENT REQUIREMENTS – Not applicable.
B.2 PRICE/COST SCHEDULE
ITEM INFORMATION (WILL BE INSERTED DURING SOLICITATION)
TERM OF CONTRACT
This contract is effective for the period of June 1, 2021 through May 31, 2022, with four (4) one (1) option years to renew. The option to extend for additional periods (if required) will be at the discretion of the Government. This contract is subject to the availability of VA funds.
B.4 INFORMATION MANAGEMENT SECURITY
VA HANDBOOK 6500.6, APPENDIX A
A. GENERAL
Contractors, Contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
B. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
1. A Contractor/subcontrator shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
2. All Contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for Contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
3. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
4. Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the Contractor/ subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.
5. The Contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the Contractor or subcontractor’s employ. The Contracting Officer must also be notified immediately by the Contractor or subcontractor prior to an unfriendly termination.
C. VA INFORMATION CUSTODIAL LANGUAGE
1. Information made available to the Contractor or subontractor by VA for the performance or administration of this contract or information developed by the Contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the Contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
2. VA information should not be co-mingled, if possible, with any other data on the Contractors/subcontractor’s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the Contractor must ensure that VA’s information is returned to the VA or destroyed in accordance with VA’s sanitization requirements. VA reserves the right to conduct on-site inspections of Contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are following VA directive requirements.
3. Prior to termination or completion of this contract, Contractor/subcontractor must not destroy information received from VA, or gathered/created by the Contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a Contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the Contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
4. The Contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
5. The Contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on Contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the Contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
6. If VA determines that the Contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the Contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
7. If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
8. The Contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
9. The Contractor/subcontractor’s firewall and Web services security controls, if applicable, shall meet or exceed VA’s minimum requirements. VA Configuration Guidelines are available upon request.
10. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the Contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA’s prior written approval. The Contractor/ subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA Contracting Officer for response.
11. Notwithstanding the provision above, the Contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the Contractor/subcontractor is in receipt of a court order or other requests for the above-mentioned information, that Contractor/ subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response.
12. For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the Contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COR.
D. INFORMATION SYSTEM DESIGN AND DEVELOPMENT
1. Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.
2. The Contractor/subcontractor shall certify to the COR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.
3. The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default “program files” directory and silently install and uninstall.
4. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
5. The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, VA Handbook 6500, Information Security Program and VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle.
6. The Contractor/subcontractor is required to design, develop, or operate a System of Records Notice (SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.
7. The Contractor/subcontractor agrees to:
a. Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:
(1) The Systems of Records (SOR); and
(2) The design, development, or operation work that the Contractor/ subcontractor is to perform;
b. Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and
c. Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.
8. In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish an agency function, the Contractor/subcontractor is considered to be an employee of the agency.
a. “Operation of a System of Records” means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.
b. “Record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person’s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.
c. “System of Records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying assigned to the individual.
9. The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as “Systems”), throughout the life of this contract and any extension, warranty, or maintenance periods. This includes, but is not limited to workarounds, patches, hot-fixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the Systems.
10. The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than 10 working days.
11. When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within three working days.
12. All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph (e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA Assistant Secretary for Office of Information and Technology.
E. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
1. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, Contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The Contractor’s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA’s network involving VA information must be reviewed and approved by VA prior to implementation.
2. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
3. Outsourcing (Contractor facility, Contractor equipment or Contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the Contractor’s systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) Contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.
4. The Contractor/subcontractor’s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA’s POA&M management process. The Contractor/subcontractor must use VA’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with Contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.
5. The Contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COR. The government reserves the right to conduct such an assessment using government personnel or another Contractor/subcontractor. The Contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.
6. VA prohibits the installation and use of personally owned or Contractor/ subcontractor owned equipment or software on VA’s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.
7. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the Contractor /subcontractor or any person acting on behalf of the Contractor/ subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the Contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the Contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.
8. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:
a. Vendor must accept the system without the drive;
b. VA’s initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or
c. VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.
d. Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;
(1) The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and
(2) Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be preapproved and described in the purchase order or contract.
(3) A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed. The ISO needs to maintain the documentation.
F. SECURITY INCIDENT INVESTIGATION
1. The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The Contractor/subcontractor shall immediately notify the COR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the Contractor/subcontractor has access.
2. To the extent known by the Contractor/subcontractor, the Contractor/ subcontractor’s notice…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .