Section 3 - STATEMENT OF WORK AND FUNCTIONAL REQUIREMENTS.xlsx
XLSX spreadsheet 54 KB Posted
- Attached to
- DIN-PACS III Federal contract opportunity
- Solicitation number
- SPM2D1-10-R-0011
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SPM2D1-10-R-0011-0008.pdf | ||
| SF_30_SPM2D1-10-R-0011_0005.pdf | ||
| Amendment_0006.pdf | ||
| SPM2D1-10-R-0011-0004.pdf | ||
| Amendment_0005.pdf | ||
| SPM2D1-10-R-0011-0003.pdf | ||
| Amendment 0002.pdf | ||
| AMEND 0001 - SPM2D1-10-R-0011.pdf | ||
| SPM2D1-10-R-0011 - DIN-PACS III SOLICITATION.pdf | ||
| DINPACS III Contractor Price book Spreadsheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section 3
| TABLE OF CONTENTS | |
| TAB A | VENDOR QUALIFICATIONS |
| TAB B | PACS PRODUCT OVERVIEW |
| TAB C | VENDOR CONFIGURATION RESPONSE |
| TAB D | SYSTEM FUNCTIONALITY |
| TAB E | SYSTEM ACCEPTANCE |
| TAB F | SYSTEM RELIABILITY |
| TAB G | SYSTEM MAINTENANCE |
| TAB H | REPAIR PARTS STRATEGY |
| TAB I | SYSTEM DOCUMENTATION AND TRAINING |
| TAB J | DICOM REQUIREMENTS |
| TAB K | TELERADIOLOGY |
| TAB L | SYSTEM SECURITY |
| VENDOR RESPONSE CODES | ||
| Code | Description | |
| C | Current product fully complies. | |
| P | Not part of current product, but planned in a scheduled release. Vendor shall indicate the time frame when requirement will be available. | |
| O | Optional capability that can be provided at an additional charge, either as an optional feature, 3rd party option, or as a special order development. | |
| X | Requirement is neither available nor planned by the Vendor. | |
| note: Please add your company name to footer. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB A
TAB A VENDOR QUALIFICATIONS
| Please describe: | Description | |
| A1 | Overall company and description of DIN-PACS product line. | |
| A2 | Does your company have a history with integrating the proposed PACS soution with various Government and commercial RIS? Response should be very specific to CHCS if the vendor has such experience. | |
| A3 | Company/Product Literature – Please enclose company and product literature which highlights the company’s stability and position in the industry, as well as formal product literature for each item offered. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB B
TAB B PACS PRODUCT OVERVIEW
| Please describe: | Description | |
| B1 | Briefly describe sites where the product is installed in an enterprise–distributed radiology environment. | |
| B2 | Please describe what business partners your solution uses to provide the total solution. | |
| B3 | Briefly list and describe all sites, in the DoD or VA where your PACS product is installed. | |
| B4 | Briefly list and describe your commercial client references – minimum of five (5) (i.e. installed base of equipment) – Please include a point of contact and phone number for each listing |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB C
TAB C VENDOR CONFIGURATION RESPONSE
| Compliance Status | Description | ||
| C1 | Network Proposal – If requested at a specific site, the Vendor will be required to assess the capability of the existing hospital network to support the DIN-PACS, and provide recommendations for network upgrades, supplements, etc.. to the Government. | ||
| The requested proposal shall identify necessary augmentation or reconfiguration to provide maximum capability of the PACS. | |||
| The Vendor may also be required to review PACS network augmentation designs to be installed (at the Government’s request) by a third party, and validate that the proposed PACS will optimally perform over this network. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB D
TAB D SYSTEM FUNCTIONALITY
| Compliance Status | Description | ||
| D1 | A mechanism shall be provided to permit a system administrator to age patient records out of the database (for example, to remove records after twenty-seven years or after the age of majority of the patient). | ||
| D2 | The database shall support, as a minimum, ad hoc queries using search criteria based on the values, or range of values, of Table 1 data items, combined using logical operators, and with the ability to sort results. The purpose of this requirement is to assure that worklist query and administrative report queries can be constructed to support a range of needs. | ||
| TABLE 1 | |||
| DICOM Attribute Name (Searchable Item) | DICOM Tag | ||
| Patient’s Name | (0010, 0010) | ||
| Patient ID | (0010,0020) | ||
| Accession Number | (0008,0050) | ||
| Requesting Service | (0032, 1033) | ||
| Requested Procedure Code Sequence | (0032, 1064) | ||
| Study Time | (0008,0030) | ||
| Study Date | (0008,0020) | ||
| Study ID | (0020,0010) | ||
| Study Description | (0008,1030) | ||
| Study Status ID | (0032,000A) | ||
| Study Priority ID | (0032,000C) | ||
| Interpretation Status ID | (4008, 0212) | ||
| Modality | (0008, 0060) | ||
| Body Part | (0018, 0015) | ||
| Interpretation Diagnosis Code Sequence | (4008, 0117) | ||
| Institutional Department Name | (0008,1040) | ||
| Patient’s Institution Residence | (0038,0400) | ||
| Placer Order Number (DMIS ID) | (0040,2016) | ||
| D2.1 | The database must support a direct DICOM Query/Retrieve. | ||
| D3 | Storage System In this document, the term “storage system” refers to on-line storage for rapid access to exams. The basic element of storage and retrieval for the storage system shall be the exam. An “exam” includes both images and associated reports. | ||
| D3.1 | The Vendor shall describe their alternatives for storage systems. In particular, the Vendor should address the scalability of their storage system and the rationale behind their storage system selection, sizing, and architecture. All known limits on capacity of the storage system should be addressed. | ||
| D3.2 | The system shall not store an image in the storage system with non-reversible compression before the diagnosis of the exam of which the image is a part is complete. | ||
| D3.3 | The system shall make an exam available for retrieval by workstations within one minute of its receipt in the storage system. | ||
| D3.4 | The system shall not automatically delete from the storage system an exam until space for new exams is required. | ||
| D3.5 | The system shall select exams for automatic deletion from the storage system in order of priority as follows: | ||
| D3.5.1 | retrieved exams not associated with other exams | ||
| D3.5.2 | retrieved exams associated with exams for which the primary diagnosis is complete | ||
| D3.5.3 | archived exams for which the primary diagnosis is complete | ||
| D3.5.4 | retrieved exams associated with exams for which the primary diagnosis is not complete | ||
| D3.5.5 | archived exams for which the primary diagnosis is not complete. | ||
| D3.6 | The policy for automatic deletion of exams from the storage system shall be re-configurable by the system administrator. | ||
| D3.7 | The storage system shall monitor usage and provide real-time display to authorized administrative level users of usage patterns and statistics. | ||
| D3.8 | The storage system shall remain operational during the service required to correct a failed disk drive. | ||
| D3.9 | the storage system shall provide a means for notifying the system administrator in the event of a failure in the storage system. The use of SNMP for this function is preferred but not required. It is highly desired that this notification be provided automatically by the system (i.e. passive). | ||
| D3.10 | The Storage System shall be completely redundant, and shall support mirroring and hot swappable technology for failsafe operation without interruption. | ||
| D3.10.1 | Vendor shall describe RAID or alternative strategy for redundancy. Shall explain how failover occurs and define whether it is automated or requires IT staff involvement. | ||
| D4 | In this document, the term “archive” refers to storage for long-term access to images. | ||
| D4.1 | The PACS archive must be configurable to allow for the storage of “Lossless” and “Lossy” compressed images | ||
| Note: Lossy compressed images must display a notice indicating the use of Lossy Compression for archiving. | |||
| D4.2 | Vendor shall offer various alternative solutions for a PACS archive. | ||
| D4.3 | The archive system shall retrieve exams in response to ad hoc requests from users at workstations. | ||
| D4.4 | The archive system shall monitor usage and provide real-time display of usage patterns and statistics. | ||
| D4.5 | The system shall allow the user to designate for the archive, by modality, a compression algorithm that may include lossy and other configurable parameters to be used in archiving exams for that modality. | ||
| D4.6 | The Vendor shall guarantee that the archive system will be supported with media, spare parts, and service for at least seven years from the acceptance date, or guarantee a replacement strategy at no cost to Government. | ||
| D4.7 | Vendor is encouraged in their proposal to offer various Enterprise Storage Solutions. Vendors shall discuss various enterprise storage solutions being offered. | ||
| D5 | Information System Interface | ||
| CHCS will remain the primary site of data entry. The PACS must accept radiology orders, changes and updates to radiology orders, radiology reports/amendments, ADT messages, and Master File updates of radiology procedures, Master File updates of radiology locations, and Master File updates of users. | |||
| D5.1 | The vendor shall be able to accept HL7 messages from CHCS (uni-directional CHCS interface). In the future CHCS may be able to accept messages from the PACS (bi-directional CHCS interface). | ||
| D5.2 | Vendors are expected to support industries Integrating the Healthcare Enterprise (IHE) initiative as it evolves. |
| D6 | Image Display Workstations. The PACS shall support a variety of PACS workstations, with a variety of configurations for the primary reading and diagnosis, clinical review, and quality control of radiology studies. |
| D7 | Monitors |
| It is generally assumed that the vendor will respond with LCD flat panel technology display monitors. However, vendors are encouraged to propose alternatives as long as such alternatives are either optional or planned workstation developments, and performance requirements either meet or exceed those defined for LCD flat panel technology. | |
| D7.1 | All monitors must meet the American Association of Physicist in Medicine (AAPM), Task Group 18 performance recommendations for Medical Displays. |
| D7.2 | All monitors must comply with the Video Electronics Standards Association (VESA) flat panel display measurements standards version 2.0 |
| D7.3 | All monitors must have the capability to be calibrated to the DICOM Grayscale Standard Display Function, Part 14. |
| D7.4 | All monitors must comply with ISO 13406-2:201, Ergonomic Requirements for work with Visual Display based on Flat Panels. Part 2: Ergonomic Requirements for Flat Panel Displays (ISO 2001) standards. |
| D7.5 | Configuration |
| D7.5.1 | Workstation monitors shall display no fewer than 1024 shades of gray (10 bit depth). |
| D7.5.2 | Maximum monitor brightness shall be greater than or equal to 500 candela per meter squared (cd/m2) for primary monitors, 400 cd/m2 for secondary monitors and 600 cd/m2 for mammography monitors. |
| D7.5.3 | The monitor shall equal to or less than 15% brightness uniformity degradation from the center to the periphery. |
| D7.5.4 | he monitor shall have less than 3% nonlinearity from center to periphery. |
| D7.5.5 | The monitor shall have less than 2% geometric distrotion for primary monitors and 5% geometric distrotion for secondary monitors from center to periphery. |
| D7.5.6 | The electron beam spot size shall vary less than 20% from the center to any corner of a rectangle 1/2" inside the perimeter of the monitor. |
| D7.5.7 | The number of defective pixels per million shall not exceed the perameters defined in ISO 13406-2. |
| D7.5.8 | Vendor shall provide a description and specifications for the proposed Primary monitors including; Spatial Resolution and Diagonal Screen Dimensions for each of the following: |
| - Grayscale Flat Panel Monitors | |
| - Color Flat Panel Monitors | |
| D7.5.9 | Vendor shall provide a description and specifications for the proposed Secondary monitors including; Spatial Resolution and Diagonal Screen Dimensions for each of the following: |
| - - Grayscale Flat Panel Monitors | |
| - Color Flat Panel Monitors | |
| D7.6 | Monitor Calibration |
| D7.6.1 | Brightness and contrast adjustment range of the monitors shall support matching of the monitor grayscale displays on a workstation to less than 10%. |
| D7.6.2 | The three-month drift of monitor brightness and contrast shall be less than 5%. |
| D7.6.3 | All monitors will be calibrated in conformance to the performance requirements of the NEMA Standard on Gray-Scale Display Function. |
| D7.6.4 | The vendor shall supply a QC procedure and all required images and calibration equipment to assure that the test and calibration requirements in this Section are met. |
| D7.6.5 | The monitors viewing angel shall be greater than 140o horizontal and 140o vertical. |
| D7.6.6 | The angular performance of the monitor shall not reduce the luminance ratio by more than 30% within the operating ranges of the viewing angles. |
| D7.6.7 | The contrast response for any viewing angle shall not be greater than three times the expected limits on axis. (30% for diagnostic displays and 60% for clinical displays) |
| D7.6.8 | With their “Notice of Readiness to Inspect”, prior to the start of acceptance testing, Vendors will submit their calibration procedures, calibration data, and any associated log files to the Government or the Government’s representative. |
| D7.6.9 | All color monitors must be capable of being calibrated to a consistent color temperature. |
| D7.7 | Mammographic Monitors |
| D7.7.1 | Monitors used for mammographic displays shall meet regulatory requirements for quality assurance under the Mammography Quality Standards Act (MQSA) (21 CFR 900). |
| D7.7.2 | Mammographic monitors shall have no visual pixel defect artifacts. |
| D8 | Work Station Performance |
| D8.1 | The workstation shall display one 2K x 2.5K x 2byte image filling one monitor in two seconds. |
| D8.2 | The workstation shall display all the 512 x 512 x 2 byte images at original resolution to fill a monitor in two seconds. |
| D8.3 | The workstation shall meet D.8.1 and D.8.2 for each monitor in an exam filling several monitors. |
| D8.4 | The workstation shall display the first 20 results of any query of the system database within two seconds, 95% of the time. Display time is measured from the time the user completes selection of the query (e.g., worklist selection) until the 20th result is visible on the monitor. |
| D8.5 | The workstation shall display the report on a selected exam within four seconds of the request, 90% of the time. Display time is measured from the time the user initiates the request (for example, through selection of the exam) until the report is visible on the monitor. |
| D9 | Exams, Folders, Worklists, and Queries |
| D9.1 | It is desired that a mechanism be provided to permit a user with proper privileges to select images or exams for inclusion into one or more manually created folders for teaching and research purposes. |
| D10 | Image Display and Paging |
| D10.1 | The workstation shall provide a function to display the entire contents of the DICOM header for a selected image. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB E
TAB E SYSTEM ACCEPTANCE (SEE APPENDIX 5)
| Compliance Status | Description | ||
| E1 | System Acceptance Testing will be conducted in accordance with the Government’s Acceptance Testing (AT) Protocol (or other protocol if mutually agreed upon by both the Government and Contractor); the most current version available at the time of acceptance testing. A copy of the current version of this AT Protocol is available from the Contracting Officer. | ||
| E2 | Other systems or equipment items purchased from this contract, and not covered under the Government’s DIN-PACS AT protocol (e.g. Computed Radiography, Film Digitizers, etc.) may be tested by the Government. Systems will be tested per manufacturer’s commercial testing protocols unless an appropriate Government testing protocol is available. The following is a listing of currently available Government testing protocols for items available for purchase under this contract: | ||
| Computed Radiography (CR) Acceptance Testing Protocol. | |||
| A copy of the current version of this CR Acceptance Testing Protocol is available from the Contracting Officer. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB F
TAB F SYSTEM RELIABILITY (SEE APPENDIX 6)
| Compliance Status | Description | ||
| F1 | The Vendor will comply with the Government's system reliability requirements per Section H, Paragraph 2 of the Solicitation. | ||
| F2 | The system shall be designed with reasonable redundancy so that no single point of failure can cause a major breakdown of radiology service. | ||
| F3 | The system shall protect against the loss of acquired images and data. | ||
| F4 | If a failure interrupts or disables image acquisition, the system shall provide a means to enter the missed images from the imaging equipment at a later time. | ||
| F5 | Where appropriate to guarantee against loss of image or exam information during acquisition or storage in the PACS in the event of a power failure, the vendor shall supply an Uninteruptable Power Supply (UPS) with sufficient capacity to support the necessary equipment during the operation. This requirement is not intended to require UPS at all locations, only at those locations where a power failure would cause a loss of patient images or information. This requirement is also not intended to require that the system continue to operate for additional acquisitions during the power outage. | ||
| F6 | The system shall maintain a total system uptime of 99% monthly, and individual component uptimes of at least 90% monthly. Percentages will be calculated based on the Principal Period of Maintenance (see Appendix 6, Section 2.4 for calculation).Component and system downtimes will include scheduled and unscheduled outages. Vendors shall document their current experience with their product that would demonstrate to the Government that this requirement can be met. (see Appendix 6 for definitions of uptime and downtime.) |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB G
TAB G SYSTEM MAINTENANCE
| Compliance Status | Description | ||
| G1 | The Vendor will comply with the Government's system maintenance requirements specified in Appendix 6 . | ||
| G2 | Vendor shall offer maintenance service in accordance with the "maintenance scope of work options" specified in Appendix 6, paragraph 3.13. | ||
| G3 | Vendors are encouraged to offer their normal, commercial maintenance service plans (based on their standard commercial maintenance service terms and conditions) in addition to the Government specified service options above. | ||
| G4 | The offered maintenance plans shall specify the level of operations support, including all on-site field engineers, part-time and/or off-site personnel, as well as the hours of coverage. | ||
| G5 | Maintenance and support response time shall be 2 hours or less during the 0800-1700 time period and 2 hours or less during the remainder of the day. Response time is measured from the time the field engineer on call is paged until support personnel are on-site and actively working on the problem. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB H
TAB H REPAIR PARTS STRATEGY
| Compliance Status | Description | ||
| H1 | The vendor shall provide a guarantee that the Government will be able to purchase all required spare parts from the vendor for seven years from the date of final system acceptance. | ||
| H2 | If the Government elects not to upgrade existing systems to new versions (either hardware or software), the vendor shall guarantee that they will continue to provide support for hardware, software and spare parts FOR THE INSTALLED SYSTEM for a minimum of three years after release of the upgrade. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB I
TAB I SYSTEM DOCUMENTATION AND TRAINING
| Compliance Status | Description | ||
| I1 | The Vendor shall meet the Government's Documentation and Training requirements specified herein. | ||
| I2 | With every system purchased, as a minimum, two complete sets of manuals covering the system administration, operation, installation, and maintenance of all system components and explaining the operational concept of the system as a whole shall be provided. | ||
| I3 | If purchased with a particular system, the Vendor is required to provide the following Data Requirements (documentation). Further detail on the required content of this documentation is provided at Appendix 3. Vendors shall provide pricing for the completion and delivery of each of the following Data Requirements with their proposal. | ||
| I3.1 | Special Tools and Test Equipment List - used to identify all nonstandard tools, test equipment, and diagnostic software designed and developed by the manufacturer to perform maintenance, test/calibration, diagnostic/prognostic analysis and other related support of the equipment furnished under this contract and required for testing and successful operation and maintenance. | ||
| I3.2 | Master Parts List - The Contractor shall submit a detailed parts list for each component of the system. Each part, component or module shall be identified by the manufacturer's name and part number. Part identification is to be to the printed circuit board level, with diagram reference. | ||
| I3.3 | List of Spare Parts - The Contractor shall submit a recommended spare parts list sufficient for installation and startup tests, as well as for maintaining each line item for a period of at least 12 months following official Government acceptance. | ||
| I3.4 | List of Supplies - The Contractor shall submit a recommended supply list for each site for start-up and operation of the DIN-PACS system for a 12 month period. | ||
| I3.5 | Installation Plan - The Contractor shall submit an Installation Plan as specified in Appendix 3. | ||
| I3.6 | Drawings and Other Documentation - The Contractor shall submit specified Drawings and Other Documentation per Appendix 3, CDRL AG. | ||
| I3.7 | Status Reports - The Contractor shall submit weekly status reports for Level II and III turnkey efforts on the progress of the turnkey installation, beginning with "Notice to Proceed with Construction" through equipment installation and testing. Turnkey level definitions are included in Appendix 4 | ||
| I3.8 | As-Built Drawings - The Contractor shall submit as-built drawings per Appendix 3. | ||
| I3.9 | Training Plan - The Contractor shall submit a training plan per Appendix 3. | ||
| I3.10 | Electronic Security Plan - The Contractor shall submit a security plan for each site for safeguard of medical records. Requirement are specified in Appendix 3. | ||
| I3.11 | GFE DICOM Conformance Statement Analysis - Requirements are specified in Appendix 3. | ||
| I3.12 | A IHE Integration Statement for their proposed system | ||
| I3.13 | Quality Control Plan - The Contractor shall submit a complete QC program specific to each site. | ||
| I3.14 | Crisis Management Plan - The Contractor shall submit a crisis management plan as required for each site to illustrate all steps to be taken by the Contractor to insure clinical capability in case of a system crisis/shutdown (should include scenarios to cover all critical subsystems as well as the entire system overall). | ||
| I3.15 | Maintenance Plan | ||
| The contractor shall submit a maintenance plan that includes the following: | |||
| 1. Scheduled preventive maintenance details and schedule | |||
| 2. Corrective action/repair program details | |||
| 3. Database maintenance details | |||
| 4. Archive maintenance details | |||
| 5. Repair parts program details | |||
| 6. Technical support description | |||
| 7. Telemaintenance support | |||
| I3.16 | System Administration, Operation and Maintenance Manuals | ||
| The contractor shall provide a minimum of two complete copies of System Administration, Operator and Service literature for each component of the system. | |||
| I3.17 | Ongoing PACS Training to support existing and newly reporting personnel | ||
| The vendor should provide a training solution that is computer based (CBT) for use by the <SITE> training department. CBT should be offered either on standalone compact discs (CD's) or as a local web solution via the MTF intranet." |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB J
TAB J DICOM REQUIREMENTS
| Compliance Status | Description | ||
| DICOM Connectivity: DICOM requirements are described in detail in Appendix I. Vendor shall meet all requirements for DICOM connectivity as set forth in Appendix I. Major Requirements headings are listed in this section for Vendor's convenience in describing compliance. | |||
| J1 | Network Interfaces to DICOM Devices | ||
| J1.1 | The PACS vendor shall be responsible for providing all appropriate hardware and software to interface and integrate DICOM conforming devices to the PACS network to at least the minimum DICOM functionality specified in Appendix I. | ||
| The PACS vendor shall communicate and work directly with the imaging equipment vendors to ensure seamless integration and interface of the imaging devices to the PACS | |||
| J1.2 | The PACS vendor shall be responsible for communicating with each device vendor to determine and implement DICOM compatibility and connectivity between the device and the PACS. | ||
| The PACS vendor must provide the government a written list of any additional specific software and/or hardware upgrades, or licenses, required for successful integration of the PACS (to be purchased by the government separately). | |||
| J2 | The Vendor shall support all DICOM Correction Proposals and Supplements approved six months prior to the issuance of a site specific delivery order. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB K
TAB K TELERADIOLOGY
| Compliance Status | Description | ||
| K1 | Teleradiology. Vendor shall discuss their current and future capabilities. Vendor shall discuss their support of IHE initiatives to develop a standard for sending and receiving DICOM images and reports. | ||
| Shall describe the vendor's ability to send/receive images and reports across a wide area network to/from differing medical treatment facilities (MTF) that may or may not have the vendors PACS installed. | |||
| K2 | Vendor shall describe their willingness to work with other PACS vendors within the DoD Medical Healthcare System (MHS) to develop a cooperative solution for teleradiology that meets the government's requirement without proliferating additional equipment to existing sites. | ||
| K3 | Vendors shall discuss their commitment to meeting DICOM Structured Reporting. |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
TAB L
TAB L SYSTEM SECURITY
| Compliance Status | Description | ||
| L1 | General Security Requirements. The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all DoD data, to ensure the confidentiality, integrity, and availability of DoD data. As a minimum, this shall include provisions for personnel security, electronic security and physical security as listed in the sections that follow. | ||
| L1.1 | The Contractor shall comply with all information assurance/information security requirements listed in Appendix 7 in relation to each specific service. | ||
| L1.2 | The contractor shall comply with DoD Directive 5200.2, "DoD Personnel Security Program," DoD Directive 8500.1, "Information Assurance (IA)", DoD Instruction 8500.2, "Information Assurance (IA) Implementation," DoD Instruction 8510.01, "DoD Information Assurance Certification and Accreditation Process (DIACAP)," DoD 8551.1, "Ports, Protocols, and Services," and DoD 8580.02, "DoD Health Information Security Regulation." | ||
| L1.3 | The contractor shall ensure that data which contains Protected Health Information (PHI) is continuously protected from unauthorized access, use, modification, or disclosure. The contractor shall comply with all previously stated requirements for HIPAA, Personnel Security, Electronic Security, and Physical Security. | ||
| L2 | Health Insurance Portability and Accountability Act (HIPAA). Health Insurance Portability and Accountability Act of 1996 (HIPAA) Requirement. The HIPAA standard contract language is mandatory whenever a business associate, (i.e., outside person or agency) creates, receives, maintains, or transmits electronic protected health information (PHI) on behalf of a covered entity. This contract or agreement requires the business associate to: | ||
| Note: Additional guidance can be found in DoD 8580.02 -R, Health Information Security Regulation. | |||
| L2.1 | Implement administrative, physical, and technical safeguards that will protect the confidentiality, integrity, and availability of the PHI | ||
| L2.2 | Ensure all agents or subcontractors to whom the business associate provides PHI will also implement reasonable and appropriate safeguards to protect the information. | ||
| L2.3 | Report all security incidents In Accordance With each of the services procedures. | ||
| L2.4 | Authorize termination of the contract if the organization finds that the business associate has violated the terms of the contract. | ||
| L3 | Follow the DoD guidelines for submittal of Information Technology (IT) security background checks and ensure all contractor personnel are designated as IT-I, IT-II, or IT-III where their duties meet the criteria of the position sensitivity designations. Contact the service Program Management Office (PMO) for guidance on the appropriate IT levels for personnel on the contract. Any vendor personnel that will be accessing the PACS while installed on a DoD network will be required to have a National Agency Check (NAC) completed. Typically, this requires an investigation to support a "Public Trust Position" and requires the person(s) to complete and submit a Standard Form 85P (SF 85P), Questionnaire for Public Trust Positions, via the Electronic Personnel Security Questionnaire (EPSQ). Questions relating to SF85Ps and the EPSQ process may be directed to 1-888-282-7682 or online at http://www.dss.mil/index.htm. | ||
| L3.1 | Immediately report to the PMO and deny access to any automated information system (AIS), network, or information if a contractor employee filling a sensitive position receives an unfavorable adjudication, if information that would result in an unfavorable adjudication becomes available, or if directed to do so by the appropriate Service representative for security reasons. | ||
| L3.2 | Ensure that all contractor personnel receive Information Assurance (IA) training before being granted access to DoD AISs. | ||
| L4 | Electronic Security. Contractor systems that are involved in the operation of systems in support of DoD's Health System shall operate in accordance with controlling laws, regulations, and DoD policy. DoD IA Certification and Accreditation (C&A) requirements apply to all DoD and contractor systems that receive, process, display, store or transmit DoD information. | ||
| L4.1 | Certification is the determination of the appropriate level of protection required for an Information System (IS). Certification also includes a comprehensive evaluation of the technical and non-technical security features and countermeasures required for each system. | ||
| L4.2 | Accreditation is the formal approval by DoD to operate the system in a particular security mode using a prescribed set of safeguards at an acceptable level of risk. In addition, accreditation allows a system to operate within the given operational environment with stated interconnections; and with appropriate level of protection for the specified period. | ||
| L4.3 | The contractor shall comply with DIACAP requirements, as specified by DoD that meet appropriate DoD and Service IA and C&A requirements. The contractor shall initiate the process by providing the required documentation necessary to meet Service C&A requirements. The contractor shall make their IS available for C&A testing if required by the Service and initiate the process well in advance of a contract delivery order. The requirements shall be met before the contractor's system is authorized to access DoD data or interconnect with any DoD network that receives, processes, stores, displays or transmits DoD data. Additional Service specific requirements must also be met as stated later in the service specific section. The contractor shall ensure the proper contractor support staff is available to participate in all phases of the C&A process. They include, but are not limited to: | ||
| L4.3.1 | Completing and maintaining all documentation necessary to obtain C&A | ||
| L4.3.2 | Attending and supporting C&A meetings with the Service, as necessary | ||
| L4.3.3 | Support/conducting the vulnerability mitigation process to comply with IA controls listed in DoD 8500.2. | ||
| L4.3.4 | Supporting the C&A Team during system security testing | ||
| L4.3.5 | Contractors must confirm that their systems are locked down prior to initiating C&A testing. | ||
| L4.4 | Vulnerabilities that have been identified by DoD as "must-fix" issues during the C&A process must be mitigated according to the timeline identified by the Service Representative. Checklists are provided for complying with DoD and Service requirements. Reference material, a copy of the Windows Gold Disk, SRRs, and STIGs may be obtained at the Defense Information Systems Agency website: http://iase.disa.mil/stigs/SRR/index.html | ||
| L4.5 | Ports Protocols and Services. Vendors shall follow all current DoD and Service standards and requirements for acceptable Ports, Protocols, and Services. Any requests for exception to using the current DoD and Service Ports, Protocols, and Services standards requires an request for exception sent through the Program Manager to the DAA. | ||
| L4.6 | Public Key Infrastructure and Encryption. Vendors shall follow the DoD and Service standards, policies, and procedures related to the use of Public Key Infrastructure (PKI) certificates for positive authentication. Where interoperable PKI is required for the exchange of unclassified information between DoD and its vendors and contractors, industry partners shall obtain all necessary certificates. | ||
| (Are there any known issues with vendors meeting this? Can all major vendors do this?) | |||
| Vendors must turn over to DoD all encryption keys for deployed systems, backdoor algorithms, and procedures for their use in remote support. The Vendor must provide a written report detailing all of the above, prior to task order expiration, regardless of modifications or extensions. | |||
| L5 | Physical Security. The contractor shall employ physical security safeguards for IS/Networks involved in processing or storage of DoD Data to prevent the unauthorized access, disclosure, modification, destruction, use, etc., and to otherwise protect the confidentiality and ensure use conforms with DoD and Service regulations. The contractor shall be required to follow all requirements in the DoD's Information Assurance Policy. New DoD and Service policies will be posted to specific websites. | ||
| L6 | Post-Accreditation Reviews & Site Acceptance Testing. PMs will conduct a review of all applicable IA controls and perform validation procedures on those controls as identified in the Site Acceptance Protocols. Auditing all new systems at delivery to ensure all applicable electronic patches are installed on the system before the PMO accepts the product. | ||
| L6.1 | Ensuring vendors acquire, develop, and maintain the Certification & Accreditation (C&A) documentation to ensure both initial and continued compliance with DIACAP requirements as specified by DoD and Service Information Assurance requirements for all contractor systems that receive, process, store, display, or transmit DoD data, or has a physical or logical connections to a DoD certified network. | ||
| L6.2 | An annual IA review shall be conducted that comprehensively evaluates existing policies and processes to ensure procedural consistency and the IS continues to operate in the manner to which it was certified. The annual review process should account for the analysis of projected policy needs, and produce a plan for development or implementation of new policies or processes. | ||
| L7 | VAAR 852.273-75 Security requirements for unclassified information technology resources. | ||
| The contractor ans their perssonel shall be subject to the same Federal Laws, regulations, standards and VA policies as VA personnel, reguarding information and information system security. These include, but are not limited to Federal Information Security Management Act (FISMA), Appendix III of OMB Circular A-130, and Guidance and standards, available from the Department of Commerce's National Institute of Standards and Technology (NIST). This also includes the use of common security configurations available from NIST's Web site at: http://www.iprm.oit.va.gov | |||
| L8 | To ensure that appropriate security controls are in place, Contractors must follow the procedures ser forth in "VA information System Security/Privacy Requirements for IT Contracts" located at the following Web site: http://www.iprm.oit.va.gov |
&F SPM2D1-10-R-0011
OFFEROR NAME &P of &N
File details come from the government source that posted it. Updated .