DRAFT_Performance_Work_Statement.docx
DOCX document 32 KB Posted
- Attached to
- Notice of Award Federal contract opportunity
- Solicitation number
- W81K0018Q0130
- Issued by
- Department of the Army Medical Command
About this file
DRAFT Performance Work Statement
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ATTACHMENT_A.xlsx | XLSX spreadsheet | |
| W81K0018Q0130-0005.pdf | ||
| W81K0018Q0130-0004.pdf | ||
| W81K0018Q0130-0003.pdf | ||
| W81K0018Q0130-0002.pdf | ||
| REVISED_SOLICITATION_INSTRUCTIONS.docx | DOCX document | |
| W81K0018Q0130-0001.pdf | ||
| W81K0018Q0130.pdf | ||
| SOLICITATION_INSTRUCTIONS.docx | DOCX document | |
| Sources_Sought_Notice.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement
General: The Industrial Hygiene Service (IHS) at Carl R. Darnall Army Medical Center (CRDAMC), Fort Hood, Texas conducts evaluations for exposure to a multitude of environmental, chemical and biological hazards in worksites, medical facilities, and family housing. The exposures may occur to Soldiers, Civilian personnel, family members’ and visitors. A function of these evaluations may require sampling for exposure to molds and fungi. In order to identify these potential hazards, IHS requires the non-personal services of an un-biased, third party laboratory.
Performance Requirements:
1.0. The laboratory shall be accredited by the American Industrial Hygiene Association (AIHA).
1.1. The laboratory must be a participant in the AIHA Environmental Microbiology Laboratory Accreditation Program (EMLAP) testing program.
1.2. The laboratory shall provide current accreditation certificates and renewals.
1.3. The laboratory shall provide all personnel, equipment, and supplies required for the analysis of the submitted samples.
1.3.1. The laboratory personnel are not required to perform contract activities on the military installation. All activities will be performed in the contractor’s laboratory.
1.4. The laboratory shall provide analysis as requested by the IHS department at CRDAMC.
1.5. The laboratory shall provide an immediate (within one business day) E-mail report of requested analytical results.
1.6. The laboratory shall provide corrected reports as required/requested.
1.7. The laboratory shall provide free next day shipment of all samples to laboratory for analysis.
Analysis Requested:
2.0. The samples may be submitted in separate project batches on a daily basis.
2.1. There shall be NO set number of samples will be sent per project.
2.2. There shall be NO guarantee as to the number of samples submitted per month. Evaluation projects vary and the determination of sample collection and quantity is based on the individual project.
2.3. A three (3) [72-hour] day turnaround time is required as a routine minimum. However, customer may request an analysis be performed within a shorter period with appropriate increase to the individual sample pricing. Examples are 4-hour, same day, or next day (24-hour).
2.4. Common samples submitted for analysis are outlined in the following table.
2.5. The samples submitted for analysis are not limited to the below requests as outlined in the table. Additional non-common samples from vendors Directory of Service may be requested.
Common Sample Analysis Requested
Analysis Description
| Turn Around Time |
| Routinely done |
| Standard |
| Air, Non-Viable Spore Trap Analysis |
| Standard |
| Supplemental Particle Screen |
Includes (Synthetic, Cotton, and Glass Fibers, Skin Cells, Insect Parts, Plant Parts, Pollen)
| Standard |
| Surface Tape, Quantitative Direct Spore Count Direct Exam |
| Standard |
| Bulk, Quantitative Direct Spore Count Direct Exam |
| Standard |
| Carpet Check Bulk, Quantitative Spore Count Direct Exam |
Occasionally Requested Tests
| Standard |
| Cat Allergens Analysis |
| Standard |
| Dog Allergens Analysis |
| Standard |
| Cockroach Allergen Level |
| Standard |
| Polyclonal Dust Mites (Der-p1 & Der-f1) |
| Standard |
| Mouse-Mus m1 Allergen |
| Standard |
| Rat-Rat n1 Allergen |
| Standard |
| Allergen Panel, (Cat, Dog, Cockroach, and Dust Mites [Der-pl/Der-fl]) |
| Standard |
| Complete Allergen Panel (Cat, Dog, Cockroach, Dust Mites [Der-pl/Der-fl], Mouse [Mus m1], and Rat [Rat n1]) |
| Tests not listed on common sample sheet but listed in vendor’s current Directory of Services to be priced with stated discount of: |
| Discount of: |
| 24-hr |
| Common Price increase for non-standard TAT not otherwise stated: |
(Applied after appropriate discount to Directory of Service pricing) % increase
| Same Day |
| Common Price increase for non-standard TAT not otherwise stated: |
(Applied after appropriate discount to Directory of Service pricing) % increase
| 4-hr |
| Common Price increase for non-standard TAT not otherwise stated: |
(Applied after appropriate discount to Directory of Service pricing) % increase
Analysis Pricing:
3.0. The vendor's current pricing will be basis for all quotes and pricing.
3.1. The common sample analysis requests will be priced as quoted.
3.2. Any analysis requests for samples that are not listed on the common sample sheet but that are listed in the vendor current Directory of Services to be priced with stated standard discount. (See Above Table of Common Tests).
3.3. Any pricing rate increase for non-routine turn-around time will be as stated above. (See Above Table of Common Tests).
Performance Requirement Statement:
4.0. The following minimum Performance Requirement Statement applies.
4.1. The Government may modify assessment methods as deemed necessary through the term of the contract.
Performance Requirement Statement (PRS)
| PERFORMANCE OBJECTIVE |
| PERFORMANCE STANDARD |
| METHOD ASSESSMENT |
| Analysis performed as requested |
| Comply with request time |
98% of the time IHS to maintain request log
| Analytical results immediately as required |
| Comply with reporting time |
98% of the time IHS to maintain request log
| Provided corrected analytical reports as requested if required |
| Comply 100% of time |
| IHS to maintain request log |
Standards Criteria
| STANDARD ASSESSMENT |
| MEASUREMENT |
| PAST PERFORMANCE |
| 99% to 100% |
| Excellent |
| Document Past Performance Assessment Report |
(Paying particular attention to performance that exceeds the standard)
| 96% to 98% |
| Very Good |
| 95% |
| Satisfactory |
| 91 to 94% |
| Marginal |
| 90% or less |
| Unsatisfactory |
CONTRACTOR MANPOWER REPORTING
"ACCOUNTING FOR CONTRACT SERVICES-The Office of the Assistant Secretary of the Army (Manpower & Reserve Affairs) operates and maintains a secure Army data collection site where the contractor will report ALL contractor manpower (including subcontractor manpower) required for performance of this contract. The contractor is required to completely fill in all the information in the format using the following web address “https://cmra.army.mil.” The required information includes: (1) Contracting Office, Contracting Officer, Contracting Officer’s Technical Representative; (2) Contract number, including task and delivery order number; (3) Beginning and ending dates covered by reporting period; (4) Contractor name, address, phone number, e-mail address, identity of contractor employee entering data; (5) Estimated direct labor hours (including sub-contractor); (6) Estimated direct labor dollars paid this reporting period (including sub-contractor); (7) Total payments (including sub-contractor); (8) Predominant Federal Service Code (FSC) reflecting services provided by contractor (and separate predominant FSC for each sub-contractor if different); (9) Organizational title associated with the Unit Identification Code (UIC) for the Army Requiring Activity (the Army Requiring Activity is responsible for providing the contractor with its UIC for the purposes of reporting this information); (10) Locations where contractor and sub-contractors perform the work (specified by zip code in the United States and nearest City, Country, when in an overseas location, using standardized nomenclature provided on website); (11) Presence of deployment or contingency contract language, and, (12) Number of contractor and sub-contractor employees deployed in theater this reporting period (by country). (13) As part of its submission, the contractor will also provide the estimated total cost (if any) incurred to comply with this reporting requirement. Reporting period will be the period of performance not to exceed 12 months ending September 30 of each government fiscal year and must be reported by 31 October of each calendar year. The contractor shall notify the Contracting Officer’s Representative (COR) by the 5th working day of November whether or not they have completed this report. If the COR is unavailable, the contractor will notify the Contracting Officer."
End of the Performance Work Statement
SUPPLEMENT TO PERFORMANCE WORK STATEMENT
1. GOVERNMENT HOLIDAYS
The following Government Holidays are observed:
New Year’s Day, January 1 Martin Luther King, Jr.’s Birthday, 3rd Monday in January President’s Day, 3rd Monday in February Memorial Day, Last Monday in May Independence Day, July 4 Labor Day, 1st Monday in September Columbus Day, 2nd Monday in October Veteran’s Day, November 11 Thanksgiving Day, 4th Thursday in November Christmas Day, December 25
Note: Any of the above holidays falling on a Saturday will be observed on the preceding Friday; holidays falling on a Sunday will be observed on the following Monday. Any holidays that are declared by Presidential Executive Order shall be observed in the same manner as the holidays listed above. If the area in which a contract employee is scheduled to work is closed due to a holiday declared by an Executive Order and the employee is not required to report in, payment will not be made for those hours. Closures of the installation due to inclement weather or other such acts of God shall be handled in the same manner.
2. INVOICING AND PAYMENT MONTHLY
The vendor shall submit monthly, in arrears, itemized invoices in accordance with DFARS 252.232-7003, for services rendered under this contract. Information regarding IRAPT is available on the Internet at https://wawf.eb.mil/.
3. ANTITERRORISM/OPERATIONS SECURITY:
3.1. Access and general protection/security policy and procedures. This standard language is for contractor employees with an area of performance within Army controlled installation, facility, or area. Contractor and all associated sub-contractors employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.
3.2. For contractors that do not require CAC, but require access to a DoD facility or installation. Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
3.3. iWATCH Training. This standard language is for contractor employees with an area of performance within an Army controlled installation, facility or area. The contractor and all associated sub-contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This local developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the GPOC. This training shall be completed within 90 calendar days of contract award and within 120 calendar days of new employees commencing performance with the results reported to the GPOC NLT 90 calendar days after contract award.
3.4. All Personnel entering a military reservation are subject to background screening and search at any time. Contractor and all associated sub-contractor’s employees shall comply with applicable installation, CRDAMC and area commander installation/facility access and local security policies and procedures. The contractor shall also provide all information required for background checks to meet installation and CRDAMC access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or CRDAMC Provost Marshal’s Office. Contractor workforce must comply with all personal identity verification requirements as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes. The contractor is responsible for absence of contract personnel due to expired identification and access documents. A criminal history background check shall be required for all personnel entering a military installation under this contract. The contractor is responsible for those personnel that are denied installation access because of derogatory information discovered during a background check. Provided personnel must agree to sign documentation allowing the government to conduct such checks as deemed required by the Installation Provost Marshal or CRDAMC Security Office. If issuance of a DOD Common Access card is required, no person can be issued a DoD Common Access Card (CAC) until an FBI fingerprint check is sent out by the CRDAMC Personnel Security Office and satisfactory results have been returned.
4. SEXUAL ASSAULT PREVENTION AND RESPONSE PROGRAM (SHARP): The vendor shall comply with OTSG/MEDCOM Policy Memo 13-062, Policy for Reporting Incidents of Sexual Assault and Sexual Harassment under the Sexual Assault Prevention and Response Program (SHARP), 12 Nov 2013. The SHARP reporting requirements apply only to knowledge obtained by vendor personnel while performing services under this contract. The vendor shall require all Contract Service Providers (CSP) with knowledge of an incident of sexual assault occurring on a Government facility, to include a Government leased facility, where the vendor is providing services under this contract, to report the incident to the vendor who shall immediately (within 24 hours) report the incident in writing to the government's COR. All incidents shall be reported whether they involve vendor personnel or Government personnel, or other individuals. The vendor shall require all CSPs with knowledge of an incident of sexual harassment occurring on a Government facility, to include a Government leased facility, where the vendor is providing services under this contract, to report the incident to the vendor who shall immediately (within 24 hours) report the incident in writing to the government's COR. All incidents shall be reported whether they involve vendor personnel or Government personnel, or other individuals.
4.1 Government Unique Training: The vendor shall ensure all service providers receive Sexual Harassment/Assault Response and Prevention (SHARP) training not later than 60 calendar days after vendor personnel begins performance under this contract. Training can be obtained either online or in person. Vendor personnel can attend SHARP training provided by Carl R. Darnall Army Medical Center, Fort Hood, Texas If the employee has an AKO account, they can access online the Team Bound Self Study course through Army Learning Management System (ALMS) at http://www.atsc.army.mil/tadlp/delivery/alms.asp
4.2 Advisory Publications: Army Regulation 600-20, Army Command Policy, 20 Sep 2012 4.3 Advisory Publications Army Regulation 600-20, Army Command Policy, 20 Sep 2012 OTSG/MEDCOM Policy Memo 13-062, Policy for Reporting Incidents of Sexual Assault and Sexual Harassment under the Sexual Assault Prevention and Responses Program (SHARP), 12 Nov 2013
5. HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) NON-DEFENSE HEALTH AGENCY (NON-DHA) BUSINESS ASSOCIATE AGREEMENT (BAA) (7 JULY 2014)
Introduction In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health Information Privacy Regulation,” January 24, 2003, this document serves as a BAA between the signatory parties for purposes of the HIPAA and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD vendor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties. (a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subvendor, Unsecured Protected Health Information, and Use. —Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act Issuances as defined herein. —Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [insert name of Business Associate signatory to this BAA]. —Agreement means this BAA together with the documents and/or other arrangements under which the Business Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this BAA. —Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [insert name of MHS component signatory to this BAA]. —DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate (NCRMD). —DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007). —DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (2007) and DoD 5400.11-R (2007). —HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402. —HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the 2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.
—Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance. I. Obligations and Activities of Business Associate (a) The Business Associate shall not use or disclose PHI other than as permitted or required by the Agreement or as required by law. (b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Agreement. (c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business Associate shall also respond to any security incident of which it becomes aware in accordance with any Information Assurance provisions of the Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the Business Associate shall immediately initiate breach response as required by part V of this BAA. (d) In accordance with 45 CFR 164.502(e)(1)(ii)) and 164.308(b)(2), respectively), as applicable, the Business Associate shall ensure that any subvendors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such PHI. (e) The Business Associate shall make available PHI in a Designated Record Set, to the Covered Entity or, as directed by the Covered Entity, to an Individual, as necessary to satisfy the Covered Entity obligations under 45 CFR 164.524. (f) The Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526. (g) The Business Associate shall maintain and make available the information required to provide an accounting of disclosures to the Covered Entity or an individual as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.528. (h) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under the HIPAA Privacy Rule, the Business Associate shall comply with the requirements of HIPAA Privacy Rule that apply to the Covered Entity in the performance of such obligation(s); and (i) The Business Associate shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules. II. Permitted Uses and Disclosures by Business Associate (a) The Business Associate may only use or disclose PHI as necessary to perform the services set forth in the Agreement or as required by law. The Business Associate is not permitted to de-identify PHI under DoD HIPAA issuances or the corresponding 45 CFR 164.514(a)-(c), nor is it permitted to use or disclose de-identified PHI, except as provided by the Agreement or directed by the Covered Entity. (b) The Business Associate agrees to use, disclose and request PHI only in accordance with the HIPAA Privacy Rule “minimum necessary” standard and corresponding DHA policies and procedures as stated in the DoD HIPAA Issuances. (c) The Business Associate shall not use or disclose PHI in a manner that would violate the DoD HIPAA Issuances or HIPAA Privacy Rules if done by the Covered Entity, except uses and disclosures for the Business Associate’s own management and administration and legal responsibilities or for data aggregation services as set forth in the following three paragraphs. (d) Except as otherwise limited in the Agreement, the Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. The foregoing authority to use PHI does not apply to disclosure of PHI, which is covered in the next paragraph.
(e) Except as otherwise limited in the Agreement, the Business Associate may disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that disclosures are required by law, or the Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(f) Except as otherwise limited in the Agreement, the Business Associate may use PHI to provide Data Aggregation services relating to the Covered Entity’s health care operations.
III. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
(a) The Covered Entity shall provide the Business Associate with the notice of privacy practices that the Covered Entity produces in accordance with 45 CFR 164.520 and the corresponding provision of the DoD HIPAA Issuances.
(b) The Covered Entity shall notify the Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes affect the Business Associate’s use or disclosure of PHI.
(c) The Covered Entity shall notify the Business Associate of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such changes may affect the Business Associate’s use or disclosure of PHI.
IV. Permissible Requests by Covered Entity The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule or any applicable Government regulations (including without limitation, DoD HIPAA Issuances) if done by the Covered Entity, except for providing Data Aggregation services to the Covered Entity and for management and administrative activities of the Business Associate as otherwise permitted by this BAA.
V. Breach Response
(a) In general.
In the event of a breach of PII/PHI held by the Business Associate, the Business Associate shall follow the breach response requirements set forth in this Part V, which is designed to satisfy both the Privacy Act and HIPAA as applicable. If a breach involves PII without PHI, then the Business Associate shall comply with DoD Privacy Act Issuance breach response requirements only; if a breach involves PHI (a subset of PII), then the Business Associate shall comply with both Privacy Act and HIPAA breach response requirements. A breach involving PHI may or may not constitute an HHS Breach. If a breach is not an HHS Breach, then the Business Associate has no HIPAA breach response obligations. In such cases, the Business Associate must still comply with breach response requirements under the DoD Privacy Act Issuances.
If the DHA Privacy Office determines that a breach is an HHS Breach, then the Business Associate shall comply with both the HIPAA Breach Rule and DoD Privacy Act Issuances, as directed by the DHA Privacy Office, regardless of whether the breach occurs at DHA or at one of the Service components. If the DHA Privacy Office determines that the breach does not constitute an HHS Breach, then the Business Associate shall comply with DoD Privacy Act Issuances, as directed by the applicable Service-Level Privacy Office. The Business Associate shall contact the Covered Entity for guidance when the incident is not an HHS Breach.
This Part V is designed to satisfy the DoD Privacy Act Issuances and the HIPAA Breach Rule as implemented by the DoD HIPAA Issuances. In general, for breach response, the Business Associate shall report the breach to the Covered Entity, assess the breach incident, notify affected individuals, and take mitigation actions as applicable. Because DoD defines “breach” to include possible (suspected) as well as actual (confirmed) breaches, the Business Associate shall implement these breach response requirements immediately upon the Business Associate’s discovery of a possible breach.
(b) Government Reporting Provisions The Business Associate shall report the breach within one hour of discovery to the Covered Entity and to the US Computer Emergency Readiness Team (US CERT) -the other parties as deemed appropriate by the Covered Entity. The Business Associate is deemed to have discovered a breach as of the time a breach (suspected or confirmed) is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing it) who is an employee, officer or other agent of the Business Associate.
The Business Associate shall submit the US-CERT report using the online form at https://forms.us-cert.gov/report/. Before submission to US-CERT, the Business Associate shall save a copy of the on-line report. After submission, the Business Associate shall record the US-CERT Reporting Number. Although only limited information about the breach may be available as of the one hour deadline for submission, the Business Associate shall submit the US-CERT report by the deadline. The Business Associate shall e-mail updated information as it is obtained, following the instructions at http://www.us-cert.gov/pgp/email.html. The Business Associate shall provide a copy of the initial or updated US-CERT report to the -Covered Entity and the applicable Service-Level Privacy Office, if requested by either. Business Associate questions about US-CERT reporting shall be directed to the Covered Entity or Service-Level Privacy Office, not the US-CERT office.
The additional US Army and the US Army Medical Command (MEDCOM) reporting requirements are addressed in the PII Breach Reporting and Notification Policy. The latest version of this policy can be obtained from the Covered Entity or the MEDCOM Privacy Act/Freedom of Information Act (FOIA) Office at: usarmy.jbsa.medcom.list.medcom-foia-users@mail.mil. If multiple beneficiaries are affected by a single event or related set of events, then a single reportable breach may be deemed to have occurred, depending on the circumstances. The Business Associate shall inform the Covered Entity as soon as possible if it believes that “single event” breach response is appropriate; the Covered Entity will determine how the Business Associate shall proceed and, if appropriate, consolidate separately reported breaches for purposes of Business Associate report updates, beneficiary notification, and mitigation.
When a Breach Report initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Business Associate shall submit a revised form or forms, stating the updated status and previous report date(s) and showing any revisions or additions in red text. Examples of updated information the Business Associate shall report include, but are not limited to: confirmation on the exact data elements involved, the root cause of the incident, and any mitigation actions to include, sanctions, training, incident containment, follow-up, etc. The Business Associate shall submit these report updates promptly after the new information becomes available. Prompt reporting of updates is required to allow the Covered Entity to make timely final determinations on any subsequent notifications or reports. The Business Associate shall provide updates to the same parties as required for the initial Breach Report. The Business Associate is responsible for reporting all information needed by the Covered Entity to make timely and accurate determinations on reports to HHS as required by the HHS Breach Rule and reports to the Defense Privacy and Civil Liberties Office as required by DoD Privacy Act Issuances.
In the event the Business Associate is uncertain on how to apply the above requirements, the Business Associate shall consult with the Covered Entity (or the Service-Level Privacy Office, which will consult with the DHA Privacy Office as appropriate) when determinations on applying the above requirements are needed.
(c) Individual Notification Provisions If the DHA Privacy Office determines that individual notification is required, the Business Associate shall provide written notification to individuals affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities of the individuals are ascertained. The 10 day period begins when the Business Associate is able to determine the identities (including addresses) of the individuals whose records were impacted.
The Business Associate’s proposed notification to be issued to the affected individuals shall be submitted to the parties to which reports are submitted under paragraph V (a) for their review, and for approval by the DHA Privacy Office. Upon request, the Business Associate shall provide the DHA Privacy Office with the final text of the notification letter sent to the affected individuals. If different groups of affected individuals receive different notification letters, then the Business Associate shall provide the text of the letter for each group. (PII shall not be included with the text of the letter(s) provided.) Copies of further correspondence with affected individuals need not be provided unless requested by the Privacy Office. The Business Associate’s notification to the individuals, at a minimum, shall include the following:
—The individual(s) must be advised of what specific data was involved. It is insufficient to simply state that PII has been lost. Where names, Social Security Numbers (SSNs) or truncated SSNs, and Dates of Birth (DOBs) are involved, it is critical to advise the individual that these data elements potentially have been breached.
—The individual(s) must be informed of the facts and circumstances surrounding the breach. The description should be sufficiently detailed so that the individual clearly understands how the breach occurred.
—The individual(s) must be informed of what protective actions the Business Associate is taking or the individual can take to mitigate against potential future harm. The notice must refer the individual to the current Federal Trade Commission (FTC) web site pages on identity theft and the FTC’s Identity Theft Hotline, toll-free: 1-877-ID-THEFT (438-4338); TTY: 1-866-653-4261.
—The individual(s) must also be informed of any mitigation support services (e.g., one year of free credit monitoring, identification of fraud expense coverage for affected individuals, provision of credit freezes, etc.) that the Business Associate may offer affected individuals, the process to follow to obtain those services and the period of time the services will be made available, and contact information (including a phone number, either direct or toll-free, e-mail address and postal address) for obtaining more information.
Business Associates shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Business Associate and/or subvendor organization that suffered the breach. The letter must also include contact information for a designated POC to include, phone number, email address, and postal address.
If the Business Associate determines that it cannot readily identify, or will be unable to reach, some affected individuals within the 10 day period after discovering the breach, the Business Associate shall so indicate in the initial or updated Breach Report. Within the 10 day period, the Business Associate shall provide the approved notification to those individuals who can be reached. Other individuals must be notified within 10 days after their identities and addresses are ascertained. The Business Associate shall consult with the DHA Privacy Office, which will determine which media notice is most likely to reach the population not otherwise identified or reached. The Business Associate shall issue a generalized media notice(s) to that population in accordance with Privacy Office approval.
The Business Associate shall, at no cost to the government, bear any costs associated with a breach of PII/PHI that the Business Associate has caused or is otherwise responsible for addressing.
Breaches are not to be confused with security incidents (often referred to as cyber security incidents when electronic information is involved), which may or may not involve a breach of PII/PHI. In the event of a security incident not involving a PII/PHI breach, the Business Associate shall follow applicable DoD Information Assurance requirements under its Agreement. If at any point the Business Associate finds that a cyber-security incident involves a PII/PHI breach (suspected or confirmed), the Business Associate shall immediately initiate the breach response procedures set forth here. The Business Associate shall also continue to follow any required cyber security incident response procedures to the extent needed to address security issues, as determined by DoD/DHA.
VI. Termination
(a) Termination. Noncompliance by the Business Associate (or any of its staff, agents, or subvendors) with any requirement in this BAA may subject the Business Associate to termination under any applicable default or other termination provision of the Agreement. (b) Effect of Termination.
(1) If the Agreement has records management requirements, the Business Associate shall handle such records in accordance with the records management requirements. If the Agreement does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below. If the Agreement has provisions for transfer of records and PII/PHI to a successor Business Associate, or if DHA gives directions for such transfer, the Business Associate shall handle such records and information in accordance with such Agreement provisions or DHA direction.
(2) If the Agreement does not have records management requirements, except as provided in the following paragraph (3), upon termination of the Agreement, for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity that the Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of subvendors or agents of the Business Associate. The Business Associate shall retain no copies of the PHI.
(3) If the Agreement does not have records management provisions and the Business Associate determines that returning or destroying the PHI is infeasible, the Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Covered Entity and the Business Associate that return or destruction of PHI is infeasible, the Business Associate shall extend the protections of the Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI.
VII. Miscellaneous
(a) Survival. The obligations of Business Associate under the “Effect of Termination” provision of this BAA shall survive the termination of the Agreement.
(b) Interpretation. Any ambiguity in the Agreement shall be resolved in favor of a meaning that permits the Covered Entity and the Business Associate to comply with the HIPAA Rules and the DoD HIPAA Rules.
6. LIST OF EXCLUDED INDIVIDUALS/ENTITIES
1. The Vendor shall not employ or contract with any individual or entity (hereinafter collectively referred to as “person”) to provide items or services that will be included in invoices submitted to the Government under this contract if such person is listed on the Department of Health and Human Services (HHS) Office of the Inspector General (OIG) List of Excluded Individuals and Entities (LEIE) or the TRICARE Sanctioned Provider List. The Government is legally prohibited from paying for provision of items or services by such persons. The prohibition extends to services beyond direct patient care, such as services of persons in executive or leadership roles and administrative and management services, whether or not such services are billed separately. The LEIE may be found at http://oig.hhs.gov/fraud/exclusions.asp, and the TRICARE Sanctioned Provider list at http://www.health.mil/Military-Health-Topics/Access-Cost-Quality-and-Safety/Quality-And-Safety-of-Healthcare/Program-Integrity/Sanctioned-Providers. The LEIE and TRICARE Sanctioned Provider List are hereinafter collectively referred to as “the Lists.” 2. Prior to start of contract performance, the vendor shall (a) query the Lists to determine whether the name of any person the Vendor employs or contracts with to provide services or items for which payment may be made under this contract appears on the Lists, and (b) certify to the Contracting Officer that the Vendor has queried the Lists and no such names appear on either of the Lists.
3. During performance of the contract, and prior to persons other than those whose names were queried in accordance with paragraph 2, above, (hereinafter “new persons”) providing services or items under the contract, the vendor shall (a) query the Lists as in paragraph 2, and (b) certify to the Contracting Officer that the names of such new persons do not appear on either of the Lists.
4. The vendor is advised that during performance of the contract, MTF personnel will perform a recurrent recheck of the names of vendor personnel working in the MTF against the Lists, as specified in OTSG/MEDCOM Policy Memo 15-037. The Government will notify the vendor in the event any vendor personnel working in the MTF appear on either of the Lists.
5. Should any person providing items or services under the contract appear on either of the Lists at any time during contract performance, the vendor shall (a) in cases where the vendor identified the person, notify the Contracting Officer, and (b) promptly remove that person from the contract.
6. Violation of any aspect of the above paragraphs shall be considered a material breach of the contract and may result in termination of the contract.
7. The vendor is further advised that, in accordance with Civil Monetary Penalties Law [CMP] (codified at 42 USC § 1320a-7a):
a. There are steep civil monetary penalties associated with billing the Government for providing items or services by a person on either of the Lists, and with failing to return to the Government any overpayments received for provision of such items or services.
b. Billing under the contract for provision of items or services by a person on either List may also result in exclusion of the person that employs or contracts with such person.
8. HHS OIG has issued a Special Advisory Bulletin on the Effect of Exclusion from Participation in Federal Health Care Programs with additional information on the CMP. The Special Advisory Bulletin may be found at http://oig.hhs.gov/exclusions/files/sab-05092013.pdf (End of Clause)
7. TOBACCO FREE MEDICAL CAMPUS (TFMC)
The vendor shall ensure that all employees comply with the U.S. Army Medical Command and MTF smoking policies while performing services under this contract. Smoking restrictions will apply at any location or building where health care activities are performed under this contract.
In accordance with Army Regulation 600-63, paragraph 7-3, 14 April 2015; Operations Order 15-48 (Army Medical Command (MEDCOM) Tobacco Free Living – USAMEDCOM), 8 May 2015; and any Operations Order, regulation or other instruction implementing, defining or otherwise addressing the Tobacco Free Medical Campus (TFMC) on any military installation or DoD-controlled location, vendor personnel are prohibited from using any tobacco product on or within any TFMC while performing under this contract. TFMCs are established at each installation or DoD-controlled location and include: (1) any property or non-residential building that is operated, maintained or assigned to support medical activities, including but not limited to, hospitals, medical laboratories, outpatient clinics (including medical, dental, and veterinary facilities), or aid stations operating for the primary purpose of delivering medical care and services for DOD eligible beneficiaries and /or meeting the mission of the Army Medical Command; (2) all other facilities in which medical activities or administration take place, to include HQ MEDCOM and Defense Health Headquarters; (3) all internal roadways, sidewalks and parking lots; and (4) all sidewalks, parking lots and grounds external but adjacent to the building or related to the migratory corridors surrounding the medical facility. The vendor shall obtain from the GPOC any orders, regulations, instructions or other documents implementing, defining or otherwise addressing the TFMC for any given installation or DoD-controlled location where vendor personnel may perform under this contract and shall instruct vendor personnel on the TFMC limitations for installations or DoD-controlled locations where they may perform under this contract.
File details come from the government source that posted it.