Statement of Work.pdf

PDF 194 KB Posted

Attached to
H999--Certification of Sterile Compounding Facilities Federal contract opportunity
Solicitation number
36C25721Q1324
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 17

About this file

This combined synopsis/solicitation requests quotations for Certification of Sterile Compounding Facilities services. The South Texas Veterans Health Care System seeks these services for the Audie L. Murphy VA Medical Center in San Antonio, Texas, for a base year plus four option years. Interested Service-Disabled Veteran-Owned Small Businesses must submit quotes by August 27, 2021 addressing the Statement of Work and Price/Cost Schedule to certify primary and secondary engineering controls, conduct environmental testing, and certify compounding personnel in accordance with USP and CETA standards. Evaluation will consider technical acceptability and price, with eligible offerors required to provide CETA and RCPSCF certifications along with verification as an SDVOSB. The place of performance is the Audie L. Murphy VA Medical Center. Award is a fixed-price contract using best value tradeoff source selection.

View the file

Other files for this federal contract opportunity

Other files attached to H999--Certification of Sterile Compounding Facilities, newest first.
File Type Posted
SCHEDULE.pdf PDF
36C25721Q1324.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work Certification of Sterile Compounding Facilities

South Texas Veterans Health Care System

Audie L. Murphy Memorial VA Hospital 7400 Mertin Minter Blvd.

San Antonio, TX

Period of performance: 10/01/2021-09/30/2022 (Base Year)

Period of performance: 10/01/2022-09/30/2023 (Option Year 1) 10/01/2023-09/30/2024 (Option Year 2) 10/01/2024-09/30/2025 (Option Year 3) 10/01/2025-09/30/2026 (Option Year 4)

1. BACKGROUND: The United States Pharmacopeia (USP) establishes standards for cleanroom design, environmental monitoring, and competencies for the preparation, handling, and storage of Compounded Sterile Preparations (CSPs). The Joint Commission (TJC) established new Medication Compounding (MC) standards for non-sterile and sterile compounded preparations which are based on USP standards. Additionally, the Food and

Drug Administration (FDA) has the authority to inspect VA medical facilities using the USP standards.

VHA Directive 1108.12, Management and Monitoring of Pharmaceutical Compounded Sterile

Preparations, dated November 5, 2018, defines organizational responsibility for USP <797> and USP <800> standards for cleanroom design and engineering controls, environmental monitoring and cleaning of primary and secondary engineering controls, and the core competencies for personnel involved in the processes of compounding sterile preparations including HDs (both sterile and nonsterile dosage form preparations). It is VHA policy that each VA medical facility that provides CSPs have a pharmaceutical CSP program in place that conforms to the standards in USP Chapter <797> “Pharmaceutical Compounding‐Sterile

Compounding” and USP <800> “Hazardous Drugs – Handling in Healthcare Settings.”

According to VHA Directive 1108.12, all VA medical facilities must establish a separate and dedicated contract for all applicable USP <797> and USP <800> CSP performance evaluations, testing, and certifications requirements.

2. OBJECTIVE: South Texas Veterans Healthcare System seeks a contract for testing and certification of the Audie L. Murphy Memorial VA Hospital Pharmacy Service’s primary engineering controls (PECs) and secondary engineering controls (SECs) used for preparation of Compounded Sterile Preparations (CSPs) in addition to testing of compounding personnel for aseptic technique by gloved fingertip and thumb sampling and media fill testing. PECs include biological safety cabinets (BSCs) and laminar airflow workstations (LAFWs) hoods.

Testing and certification will be completed in accordance with United States Pharmacopeia

(USP) Chapter <797> and <800> guidelines using Controlled Environment Testing

Association (CETA) Certified National Board of Testing (CNBT) certified individuals/companies to establish consistent PEC certification procedures using the

Certification Guide for Sterile Compounding Facilities CAG-003-2006. USP <797> implies

Controlled Environment Testing Association (CETA) Controlled Applications Guides (CAGs)

“or equivalent” may be used. CETA CAGs define certification procedures to assess the PEC is performing and operating as designed to maintain a sterile environment for the preparation of CSPs. According to VHA Directive 1108.12, VA adopted CETA CAGs as the mandatory standard; no “equivalent” standards may be used. All vendors used to conduct primary and secondary engineering controls certifications/assessments must be registered with CETA, as

Registered Certified Professionals for Sterile Compounding Facilities (RCPSCF).

3. SCOPE OF WORK

3.1. Primary Engineering Controls (PECs) Certification: Certification procedures defined in

CETA CAG-003-2006 must be performed by a CETA National Board of Testing (CNBT) certified testing individual no less than every 6 months or whenever the PEC or room is relocated or altered or when major service to the sterile compounding facility is performed. Certification of PECs must include the following:

3.1.1.1. Airflow testing: Airflow testing is performed to determine acceptability of the air velocity and volume, the air exchange rate, and the room pressure differential in doorways between adjacent rooms to ensure consistent airflow and that the appropriate quality of air is maintained under dynamic operating conditions. The ACPH from HVAC, ACPH contributed from the PEC, and the total ACPH must be documented on the certification report.

3.1.1.2. HEPA filter integrity testing: HEPA filters must be leak tested at the factory and then leak tested again after installation and as part of recertification.

3.1.1.3. Total particle count testing: Total particle count testing must be performed under dynamic operating conditions using calibrated electronic equipment.

Calibration of equipment used must be included in the final report.

3.1.1.4. Airflow smoke pattern test: Both static and dynamic smoke studies verifying a continuous flow of HEPA filtered air void of turbulence, dead air zones, and refluxing from the HEPA filters to and across the entire work area and to the air returns must be performed and documented by video. Video of dynamic smoke test must document the demonstration of unidirectional airflow and sweeping action over and away from the preparation(s). Contractor to leave digital video via the preferred technology by the customer (i.e. email, flash drive, etc.) of smoke test on site prior to completion of certification process for each of the listed PECs.

3.1.2. The contractor shall test and certify each PEC to the most current version of IEST

RP CC002 (Unidirectional-flow, clean-air devices) and to the manufacturer’s specifications. The contractor shall use a NIST traceable or comparable calibrated piece of equipment to perform all testing. The contractor shall report each individual face velocity reading and the average of those readings, the downstream concentration reading of the HEPA filter leak test and the results of the induction leak test and backstreaming test. Any failures shall be reported directly to the identified site point of contact(s) as soon as practicable.

3.1.3. Horizontal Laminar Flow Hoods certifications shall be certified according to The

Institute of Environmental Sciences RP-CC-002 Testing Laminar Air Flow Devices.

3.1.4. The contractor shall certify all Class II biological safety cabinets to the current version (2016 or higher) of NSF/ANSI 49, Annex F specifications. All equipment used to certify biological safety cabinets shall have National Institute of Standards and Technology (NIST) traceable or comparable calibration certification. Any unit that fails to meet NSF 49 specifications shall be clearly marked with a sign that will notify technicians that the unit is out of order until further notice. In addition, any failures shall be reported directly to the site identified point(s) of contact (POC) as soon as practicable.

3.1.5. The list of tests includes, but is not limited to:

3.1.5.1. HEPA filter leak test

3.1.5.2. Cabinet leak test

3.1.5.3. Inflow velocity test to include exhaust airflow volume rate

3.1.5.4. Airflow Smoke pattern test

3.1.5.5. Electrical leakage and ground circuit resistance and polarity tests

3.1.5.6. Lighting intensity test

3.1.5.7. Vibration test

3.1.5.8. Noise level test

3.1.5.9. Ultraviolet (UV) lamp test

3.1.6. For each PEC passing the required certification tests, the contractor will supply each unit with a certification sticker with the following information:

3.1.6.1. Company name and address

3.1.6.2. Unit make, model and serial number

3.1.6.3. Report number

3.1.6.4. Location (room number)

3.1.6.5. Certification date

3.1.6.6. Recertification date

3.1.6.7. Technician name and signature

3.2. Secondary Engineering Controls (SECs) Certification: The contractor will provide comprehensive cleanroom testing and certification services every 6 months to include:

3.2.1.1. HEPA filter integrity testing: HEPA filters must be leak tested after installation and as part of recertification.

3.2.1.2. Airflow profiling and uniformity testing

3.2.1.3. Particulate monitoring

3.2.1.4. Room pressurization monitoring

3.2.1.5. Temperature and Humidity monitoring

3.2.1.6. Air pattern analysis

3.2.1.7. Airflow smoke pattern test (commissioning of new sterile compounding areas): Both static and dynamic smoke studies verifying a continuous flow of

HEPA filtered air void of turbulence, dead air zones, and refluxing from the

HEPA filters to and across the entire work area and to the air returns must be performed and documented by video. Video of dynamic smoke test must document the demonstration of unidirectional airflow and sweeping action over and away from the preparation(s). Contractor to leave video of smoke test on site prior to completion of certification process for each of the listed

SECs.

3.2.2. Air Changes per Hour: The contractor shall calculate the total room volume for each buffer, ante room, and hazardous drug storage room. A sketch of the room with dimensions, exhaust/supply diffuser locations and equipment locations shall be included in the report. The report provided will specify flow rates detailing returns and supply that were obtained during the testing. The contractor shall calculate air changes per hour (ACPH) for each buffer and ante room and include their findings in the report. In the event that a room does not meet USP<797> requirements for

ACPH the identified site POC(s) shall be informed immediately.

3.2.3. Pressure Requirements: The contractor shall include in their report differential pressure readings from each buffer/ante room and hazardous drug storage room to all surrounding areas. The report shall indicate whether the room is required to be a negative or positive pressure room per USP<797> and USP <800>. The contractor shall report all pressures to an accuracy of 0.0001” water column (4 decimal places). Pressure differentials will be reflected on a report showing the sketch of the room(s).

3.2.4. Pass-through chambers must be included in the facility’s certification to ensure that particles are not compromising the air quality of the negative-pressure buffer room

3.3. Non-Viable Testing: The contractor shall perform environmental nonviable particle testing at least once every 6 months. The contractor shall derive the minimum number of sampling locations using Annex A in the ISO 14644-1.2 standard. Testing shall be performed by qualified operators using current, state-of-the-art electronic equipment with results of the following:

3.3.1. ISO Class 5: not more than 3520 particles 0.5 µm and larger size per cubic meter of air for any area primary engineering control (BSC or LAFW).

3.3.2. ISO Class 7: not more than 352,000 particles 0.5 µm and larger size per cubic meter of air for any buffer area or hazardous compounding ante room.

3.3.3. ISO Class 8: not more than 3,520,000 particles 0.5 µm and larger size per cubic meter of air for any non-hazardous compounding ante room.

3.4. Viable Environmental Testing: The contractor shall perform viable environmental (air and surface) sampling every month for fungi and bacteria using high volume impaction samplers to conduct the sampling.

3.4.1. A general microbiological growth media that supports the growth of bacteria and fungi must be used. COAs from the manufacturer must verify that the media meets the expected growth promotion, pH, and sterilization requirements. Samples must be incubated in an incubator at temperatures that will promote growth of bacteria and fungi. The incubator temperature must be monitored during incubation, either manually or by a continuous recording device, and the results must be reviewed and documented as described in the Contractor’s SOPs.

3.4.2. Quality assurance results of media plates used and calibrations of equipment used to incubate media plates must be provided in each report.

3.4.3. Air Sampling: Volumetric active air sampling of all classified areas using an impaction device must be conducted in each classified area during dynamic operating conditions every month. A sufficient volume of air (1000 liters) shall be tested at each location in order to maximize sensitivity. Samples of less than 1000 liters will not be acceptable. Air sampling sites must be selected in all classified areas and illustrated on a diagram of the cleanroom suite.

3.4.3.1. If levels measured during the viable air monitoring program are equal to or greater than the levels as defined in USP <797> for the ISO classification levels of the area sampled, the Contractor must identify any microorganisms recovered to the genus level with the assistance of a microbiologist and provide the results within one business day of results. The Contractor must repeat the sampling within 5 business days of results to validate the facility’s corrective action has been effective.

3.4.4. Surface Sampling: The Contractor must perform surface sampling of all classified areas and pass-through chambers connecting to classified areas for microbial contamination every month. The Contractor must perform the surface sampling at the end of compounding activity or shift, but before the area has been cleaned and disinfected

3.4.5. The areas that require surface sampling include, but are not limited to the following:

3.4.5.1. The interior of the PEC and the equipment contained in it

3.4.5.2. Staging or work area(s) near the PEC

3.4.5.3. Frequently touched surfaces

3.4.6. Any laboratory results equal to or greater than the action level will require notification of the POC(s) within 24 hours upon receipt of results. The Contractor must repeat the sampling within 5 business days of results to validate the facility’s corrective action has been effective.

3.4.7. Reports to include at a minimum:

3.4.7.1. Date and time sampling was taken.

3.4.7.2. Environmental sampling reports will contain both the quantitative number of bacterial/fungal isolates reported as colony forming units (CFUs) as well as the species grown.

3.4.7.3. Report shall immediately notify the site identified POC(s) of any highly pathogenic microorganisms identified.

3.4.7.4. The identification of highly pathogenic microorganisms will be highlighted in the report.

3.4.7.5. Medial lots used for samples

3.4.7.6. Comments indicating when dynamic conditions were used

3.4.7.7. Certificates of analysis of media used

3.4.7.8. Results of quality assurance media plates

3.4.7.9. Calibration of equipment used

3.4.7.10. Sketch identifying location of each sample obtained

3.5. Environmental Quality and Control:The Contractor must perform environmental wipe sampling for hazardous drug surface residue every 12 months or more frequently as needed to verify containment.

3.5.1. The kits used to complete wipe sampling must be verified prior to use to ensure the method and reagent used have been tested to recover a specific percentage of known marker drugs. The drugs required for testing include: cyclophosphamide, ifosfamide, methotrexate, fluorouracil, and platinum-containing drugs.

3.5.2. Additional drugs may be requested based upon identified need per site. Upon identified need, the applicable site will work directly with the contractor where additional cost will be clarified and agreed upon by both parties prior to testing.

3.5.3. A total of 6 surface samples in each designated area will be completed per certification. Surface sampling will include the following areas:

3.5.3.1. Interior of the C-PEC and equipment contained in it

3.5.3.2. Pass-through chambers

3.5.3.3. Surfaces in staging or work areas near the C-PEC

3.5.3.4. Areas adjacent to C-PECs (e.g., floors directly under C-PEC, staging, and dispensing area)

3.5.3.5. Areas immediately outside the hazardous drug buffer room or the C-SCA

3.5.4. If any measurable contamination is found, the Contractor must report the results directly to the site identified point(s) of contact (POC) as soon as practicable and no later than 48 hours of receiving results. The Contractor must repeat the wipe sampling within 5 business days to validate that the facility’s corrective action has been effective.

3.6. Personnel Testing: All compounding personnel must perform gloved fingertip and thumb testing and media-fill testing to assess their sterile technique and related practices initially and every 6 months thereafter.

3.6.1. The Contractor will schedule subsequent personnel testing after completing initial testing and recertification testing.

3.6.2. The Contractor will perform personnel testing within five business days of being notified of a new employee requirement.

3.6.3. The ALM Memorial VA Hospital will be responsible for notifying the Contractor when an employee no longer requires recertification testing.

3.6.4. Media Fill Testing

3.6.4.1. Media Fill Testing will occur in Laminar Horizontal Flow Workstation and simulate the most difficult and challenging compounding procedures and processing conditions encountered by the person replacing all the components used in the CSPs with soybean–casein digest media.

3.6.4.2. A certificate of analysis (COA) must be provided for commercial sterile microbial growth media is used for the media fill testing

3.6.4.3. Media Fill Testing will occur after acceptable gloved fingertip and thumb testing for initial certification.

3.6.4.4. Media Fill Testing will occur prior to gloved fingertip and thumb testing for recertification.

3.6.4.5. The Contractor shall incubate media fill tests in controlled temperature environments in accordance with USP <797> and <800> guidance.

3.6.4.6. Documentation of the media fill test will include the name of the person evaluated, evaluation date/time, media and components used, including manufacturer, expiration date and lot number, starting temperature for each interval of incubation, dates of incubation, the results, and the identification of the observer and the person who reads and documents the results.

3.6.4.7. If an employee does not pass, the Contractor will return for retesting within three business days after receiving negative results.

3.6.5. Gloved Fingertip and Thumb Testing

3.6.5.1. The Contractor shall perform three separate gloved fingertip and thumb tests during initial testing (one sampling device per hand) for each designated employee.

3.6.5.2. The Contractor shall perform one gloved fingertip and thumb tests for recertification testing (one sampling device per hand) for each designated employee.

3.6.5.3. Recertification sampling shall occur every 6 months.

3.6.5.4. A certificate of analysis (COA) must be provided for commercial sterile microbial growth media is used for the media fill testing

3.6.5.5. Gloved fingertip and thumb samples shall be performed in controlled temperature environments and incubated in accordance with USP <797> and

<800> guidance.

3.6.5.6. Each sample shall be labeled with a personnel identifier, whether it was from the right or left hand, and the date and time of sampling.

3.6.5.7. Documentation results for gloved fingertip and thumb sampling will include the name of the person evaluated, evaluation date/time, media and components used, including manufacturer, expiration date and lot number, starting temperature for each interval of incubation, dates of incubation, the results, and the identification of the observer and the person who reads and documents the number of colony forming units (CFU) for the left and right hand.

3.6.5.8. If an employee does not pass, the Contractor will return for retesting within three business days after receiving negative results.

4. REPORTING REQUIREMENTS: The results of each sampling and testing shall be recorded and submitted as a comprehensive report, along with a statement of compliance or non-compliance with the specified tests. A written report of certification for all primary engineering controls, with statement of Pass/Fail, will be furnished on the day of certification. The

Contractor must provide the full report, to include all items as listed above in Section 3, to the

Chief of Pharmacy Service and other designated facility staff timely upon completion of all analyses, including identification of viables, not to exceed two weeks from the certification date. If choosing to subcontract microbiology services and reporting, consistency of reporting must be achieved with at least 90% or greater issuance of microbiology reports from the primary laboratory and 10% or less of issuance from a secondary laboratory.

4.1. All of the following information should be included in the report for clean room certification. Pass/Fail notifications should be included on a per-test basis where applicable.

4.1.1. Executive summary or summary of findings.

4.1.2. Room number and/or location

4.1.3. Room type (e.g. non-hazardous buffer room)

4.1.4. Date of testing

4.1.5. Date of next required certification

4.1.6. Standards used to test room

4.1.7. Notes

4.1.8. Room sketch (location of supply/exhaust diffusers, equipment, room dimensions)

4.1.9. Total room area and volume

4.1.10. Room humidity and temp

4.1.11. Air changes per hour

4.1.12. Pressure differential

4.1.13. Nonviable particle counts

4.1.14. Viable particle count analysis

4.1.15. Picture of viable particle test location in room

5. CONTRACTOR QUALIFICATIONS: The Contractor will provide all parts, labor, equipment, material, travel expenses to test and certify the operation and performance of equipment systems and personnel per the Statement of Work listed in Section 3. All inspections, testing and certifications must be performed by properly trained and appropriately accredited on-site field certification technicians. that are also certified technicians must be trained on all of the types of equipment listed in this SOW. Documentation shall be provided to the VA certifying that each field certification technician has been trained and certified in the work required by this SOW as follows:

5.1. Contractor must have a working knowledge of most recent publications of USP<797>

Pharmaceutical Compounding-Sterile Preparations and USP Chapter <800> Hazardous

Drugs-Handling in Healthcare Settings.

5.2. Contractor must have a working knowledge of NSF/ANSI 49-2016 Biosafety Cabinetry:

Design, Construction, Performance and Field Certification.

5.3. Contractor must be able to provide a technician with current certification as a

Registered Cleanroom Certified Professional for Sterile Compounding Facilities by the

CNBT for cleanroom certification. Proof of current CETA-accredited certification for a specific individual must be provided to facility’s POC prior to performing any work.

5.4. Contractor must provide a technician with current certification as an NSF Class II

Biosafety Cabinet Field Certifier for Class II BSC testing and certification. Proof of current certification for an NSF-accredited certifier must be provided to facility’s POC prior to performing any work.

5.5. Contractor must provide Certified Environmental Microbiology Laboratory - ISO/IEC

17025:2005 Accreditation

5.6. Contractor must have documented competencies for any technicians sent to perform testing and for any technicians who read the media tests. Copies of each technician’s current competencies must be provided to facility’s POC prior to performing any work.

5.7. Note: A Certified Industrial Hygienist (CIH) credential does not waive any of the above certification requirements.

5.8. Contractor must have standard operating procedures (SOPs) for testing, troubleshooting, repair, and certification including documentation of certification equipment calibration to National Institute of Standards and Technology (NIST)-traceable primary standards, a safety plan to include job hazard analysis, respiratory protection program, hazard communication and safety data sheets (SDS) for all chemical products that will be used during the course of this contract. Copies of the

SOPs must be provided to facility’s POC prior to performing any work.

5.9. Contractor must have a specific SOP for changing out biologically contaminated HEPA filters in Class II BSCs, and a specific SOP for changing out HEPA filters contaminated with hazardous drugs in Class II BSCs. Copies of the SOPs must be provided to facility’s POC prior to performing any work.

5.10. Technicians must successfully demonstrate competency in garbing and hand hygiene when performing work in classified areas.

5.11. Due to the sensitive nature of the work area, prior to entering sterile compounding areas (buffer room, ante room), the Contractor will maintain a clean work area at all times by wearing appropriate personal protective equipment (set forth by USP <797> standards) and cleaning any equipment with 70% sterile isopropyl alcohol.

5.12. Contractor must have working knowledge of the following CETA Documents referenced by USP <797> and USP <800>:

5.12.1. CAG-001-2005 Applications Guide For The Use Of Compounding Isolators In

Compounding Sterile Preparations In Healthcare Facilities (Revised December

2008)

5.12.2. CAG-002-2006 Compounding Isolator Testing Guide (Revised December 2008)

5.12.3. CAG-003-2006 Sterile Compounding Facilities (Revised May 2015)

5.12.4. CAG-004-2007 Application Guide for the use of Surface Decontaminants in

Biosafety Cabinets

5.12.5. CAG-005-2007 Servicing Hazardous Drug Compounding Primary Engineering

Controls

5.12.6. CAG-006-2010 CETA High Efficiency Filter Application Guide

5.12.7. CAG-007-2010 Application Guide for Exhaust System Requirements of Class II, Type B Biosafety Cabinets

5.12.8. CAG-008-2010 CETA Certification Matrix for Sterile Compounding Facilities

(Updated January 2012)

5.12.9. CAG-009-2011v3 CETA Certification Application Guide USP <797> Viable

Environmental Sampling & Gowning Evaluation

5.12.10. CAG-010-2011 CETA Application Guide for Informational Notes to Meet the

NSF/ANSI 49:2010a Standard Requirements

5.13. Contractor must have working knowledge of the following ISO standards:

5.13.1. 14644-1:2015 Cleanrooms and associated controlled environments -- Part 1:

Classification of air cleanliness by particle concentration

5.13.2. 14644-2:2015 - Cleanrooms and associated controlled environments -- Part 2:

Monitoring to provide evidence of cleanroom performance related to air cleanliness by particle concentration

5.13.3. 14644-3:2005 Cleanrooms and associated controlled environments -- Part 3:

Test methods

5.13.4. 14644-9:2012 Cleanrooms and associated controlled environments -- Part 9:

Classification of surface cleanliness by particle concentration

5.13.5. 14698-2:2003 - Cleanrooms and associated controlled environments --

Biocontamination control -- Part 2: Evaluation and interpretation of biocontamination data

6. PLACE OF PERFORMANCE: Audie L. Murphy Memorial VA Hospital, 7400 Merton Minter

Blvd, San Antonio, Texas 78229

6.1. Audie L. Murphy Memorial VA Hospital has one SCA, which has the following:

6.1.1. One or more ISO 5 Horizontal LAFW (no more than three LAFWs)

6.2. Audie L. Murphy Memorial VA Hospital has a Hazardous cleanroom suite, which has the following:

6.2.1. ISO 7 Ante Room

6.2.2. ISO 7 Hazardous Buffer Room

6.2.3. Non-Classified Hazardous Drug Storage Room

6.2.4. One or more Class II Type B2 Biological Safety Cabinets (no more than two

BSCs)

6.2.5. Four pass-through chambers

6.3. Audie L. Murphy Memorial VA Hospital anticipates having one cleanroom suite pending completion of construction in 2023. The cleanroom suite will have the following:

6.3.1. ISO 7 Ante Room

6.3.2. ISO 7 Non-Hazardous Buffer Room

6.3.3. ISO 7 Hazardous Buffer Room

6.3.4. Non-Classified Hazardous Drug Storage Room

6.3.5. One or more ISO 5 Horizontal LAFW (no more than two LAFWs)

6.3.6. One or more Class II Type B2 Biological Safety Cabinets (no more than two

BSCs)

6.3.7. Four pass-through chambers

7. TERM OF CONTRACT AND PRICING: Firm Fixed Price

8. PERFORMANCE PERIOD: The contract term is for 12 months with four options of 12 months each beginning upon signature of the contract. ALM Memorial VA Hospital will issue a delivery order only for the current fiscal year. The VA's obligation under this contract shall terminate at the end of each fiscal year. ALM Memorial VA Hospital shall unilaterally renew by issuing a renewal delivery order that shall be effective on the first day of each succeeding fiscal year

9. HOURS OF WORK: Work required in the performance of the contract shall be performed during hours agreed upon between the Contractor and ALM Memorial VA Hospital Pharmacy

Supervisors. Certifications and samplings shall be scheduled with the COR and an ALM

Memorial VA Hospital Pharmacy Supervisor a minimum of three (3) working days in advance.

Close coordination with the COR and Pharmacy Supervisor is necessary. Contractor will be responsible for ensuring all certifications and samplings are completed within the required timeframes for all Pharmacy cleanrooms, equipment, and personnel.

10. GOVERNMENT RESPONSIBILITIES: The government will work in concert with the Contractor to help enable completion of the work of the contract.

11. CONFIDENTIALITY AND NONDISCLOSURE: It is agreed that:

11.1. The preliminary and final deliverables, and all associated working papers, application source code, and other material deemed relevant by VA which have been generated by the contractor in the performance of this task order, are the exclusive property of the

U.S. Government and shall be submitted to the CO at the conclusion of the task order.

11.2. The CO will be the sole authorized official to release, verbally or in writing, any data, draft deliverables, final deliverables, or any other written or printed materials pertaining to this task order. No information shall be released by the contractor. Any request for information relating to this task order, presented to the contractor, shall be submitted to the CO for response.

11.3. Press releases, marketing material, or any other printed or electronic documentation related to this project, shall not be publicized without the written approval of the CO.

VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY language FOR

Inclusion into CONTRACTS, as appropriate

1. GENERAL: Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and

Handbooks as VA and VA personnel regarding information and information system security.

2. ACCESS to VA INFORMATION AND VA INFORMATION SYSTEMS

2.1. A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.

2.2. All contractors, subcontractors, and third-party servicers and associates working with

VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The

Office for Operations, Security, and Preparedness is responsible for these policies and procedures.

2.3. Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by

Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of

Veterans Affairs does not have a Memorandum of Agreement with Defense Security

Service (DSS). Verification of a Security Clearance must be processed through the

Special Security Officer located in the Planning and National Security Service within the

Office of Operations, Security, and Preparedness.

2.4. Custom software development and outsourced operations must be located in the U.S.

to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor.

2.5. The C & A requirements do not apply, and that a Security Accreditation Package is not required. The contractor generated data is NOT VA sensitive information.

3. INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE

3.1. For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor's security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the

COTR and approved by VA Privacy Service prior to operational approval. All external

Internet connections to VA's network involving VA information must be reviewed and approved by VA prior to implementation. Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.

3.2. Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor's systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA

OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements

(MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks.

3.3. The contractor/subcontractor's system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the

VA contracting officer and the ISO for entry into VA's POA&M management process.

The contractor/subcontractor must use VA's POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per

VA Handbook 6500.3. This may require reviewing and updating all of the documentation

(PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.

3.4. The contractor/subcontractor must conduct an annual self-assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COTR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.

3.5. VA prohibits the installation and use of personally-owned or contractor/subcontractor-owned equipment or software on VA's network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.

3.6. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.

3.7. Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:

3.7.1. Vendor must accept the system without the drive;

3.7.2. VA's initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or

3.7.3. VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.

3.8. Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;

3.8.1. The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and

3.8.2. Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the purchase order or contract. A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed. The ISO needs to maintain the documentation.

4. SECURITY INCIDENT INVESTIGATION

4.1. The term "security incident" means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy

Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.

4.2. To the extent known by the contractor/subcontractor, the contractor/subcontractor's notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.

4.3. With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.

4.4. In instances of theft or break-in or other criminal activity, the contractor/ subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.

5. LIQUIDATED DAMAGES FOR DATA BREACH

5.1. Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.

5.2. The contractor/subcontractor shall provide notice to VA of a "security incident" as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.

5.3. Each risk analysis shall address all relevant information concerning the data breach, including the following:

5.3.1. Nature of the event (loss, theft, unauthorized access);

5.3.2. Description of the event, including:

5.3.3. date of occurrence;

5.3.4. data elements involved, including any PII, such as full name, social security number, date of birth, home address, account number, disability code;

5.3.5. Number of individuals affected or potentially affected;

5.3.6. Names of individuals or groups affected or potentially affected;

5.3.7. Ease of logical data access to the lost, stolen or improperly accessed data in light of the degree of protection for the data, e.g., unencrypted, plain text;

5.3.8. Amount of time the data has been out of VA control;

5.3.9. The likelihood that the sensitive personal information will or has been compromised (made accessible to and usable by unauthorized persons);

5.3.10. Known misuses of data containing sensitive personal information, if any;

5.3.11. Assessment of the potential harm to the affected individuals;

5.3.12. Data breach analysis as outlined in 6500.2 Handbook, Management of Security and Privacy Incidents, as appropriate; and

5.3.13. Whether credit protection services may assist record subjects in avoiding or mitigating the results of identity theft based on the sensitive personal information that may have been compromised.

5.4. Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $_37.50 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:

5.4.1. Notification;

5.4.2. One year of credit monitoring services consisting of automatic daily monitoring of at least 3 relevant credit bureau reports;

5.4.3. Data breach analysis;

5.4.4. Fraud resolution services, including writing dispute letters, initiating fraud alerts and credit freezes, to assist affected individuals to bring matters to resolution;

5.4.5. One year of identity theft insurance with $20,000.00 coverage at $0 deductible;

and

5.4.6. Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.

6. TRAINING

6.1. All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:

6.1.1. Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;

6.1.2. Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;

6.1.3. Successfully complete the appropriate VA privacy training and annually complete required privacy training; and

6.1.4. Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document — e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology

Security Training Requirements.]

6.2. The contractor shall provide to the contracting officer and/or the COR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

6.3. Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.

6.4. The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor's employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.

File details come from the government source that posted it. Updated .