A.09.03_Solicitation_Amendment_SF30_0004.pdf

PDF 430 KB Posted

Attached to
Enterprise (Off-Site) Remote Medical Coding Services Federal contract opportunity
Solicitation number
W81K04-17-R-0001
Issued by
Department of the Army Medical Command

About this file

Solicitation Amendment 0004

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise (Off-Site) Remote Medical Coding Services, newest first.
File Type Posted
A.09.03_Clarification_Response_071017.pdf PDF
A.09.03_Clarification_Response_070517.pdf PDF
A.09.03_Clarification_Response_062917.docx DOCX document
A.09.03_Government_Responses_062817_W81K04-17-R-0001.pdf PDF
A.09.03_Solicitation_Amendment_Conformed.pdf PDF
A.09.03_Solicitation_Amendment_SF30_0007.pdf PDF
A.09.03_Attachment_6_-_Price_Spreadsheet.xlsx XLSX spreadsheet
A.09.03_Solicitation_Amendment_SF30_0006.pdf PDF
A.09.03_Solicitation_Amendment_Conformed_0006.pdf PDF
A.09.03_Soliciation_Comformed_Copy_W81K04-17-R-0001_0005_06.07.17.pdf PDF
Copy_of_Contractor_Questions_June_7_2017_Mindseeker_Solicitation_W81K04-17-R-0001.pdf PDF
A.09.03_Soliciation_Amendment_W81K04-17-R-0001_0005_06.07.17.pdf PDF
A.09.03_Government_Respones_W81K04-17-R-0001_060617.pdf PDF
A.09.03_Solicitation_Amendment_Conformed_0002.pdf PDF
A.09.03_Solicitation_Amendment_SF30_0002.pdf PDF
A.09.03_Solicitation_Amendment_W81K04-17-R-0001-0001.pdf PDF
A.09.01_Presolicitation_Questions_-_Government_Responses_051817.pdf PDF
A.09.03_Solicitation_-_W81K04-17-R-0001_Amend_01.pdf PDF
A.09.03_Solicitation_-_W81K04-17-R-0001.pdf PDF
A.09.03_W81K04-17-R-0001_Preproposal_Conference.pdf PDF
A.09.04_Pre-Proposal_Sign_In_17-R-0001.pdf PDF
A.09.03_W81K04-17-R-0001_Preproposal_Conference.pptx PPTX presentation
A.09.03_Draft_Solicitation_W81K04-17-R-0001_050217.pdf PDF
A.09.01_Presolicitation_Questions_-_Government_Responses_041717.pdf PDF
A.09.01_Presolicitation_Questions_-_Government_Responses_041717.pdf PDF
Draft_Solicitation_W81K04-17-R-0001_07Apr2017.pdf PDF
W81K04-17-R-0001_Q&A_03Apr2017.pdf PDF
A.09.01_W81K04-17-R-0001_Questions_and_Answers_032317.pdf PDF
Questions_and_Answers_032217_17-R-0001_Remote_Coding_Draft_Solicitation.xlsx XLSX spreadsheet
A.09.03_Draft_Solicitation.pdf PDF
Contractor_Questions_Template.xlsx XLSX spreadsheet
Show all 31

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print)

30-105-04EXCEPTION TO SF 30

APPROVED BY OIRM 11-84

STANDARD FORM 30 (Rev. 10-83)

Prescribed by GSA

FAR (48 CFR) 53.243

The purpose of this Amendment is to update the PWS to reflect the changes made on Amendment 0002 w hich included the addition of

Regional Health Command - Atlantic. FAR Clause 52.217-9 w as also amended to reflect the correct number of anticipated months (60) for the duration of this contract.

Note: There w ere no changes made to Attachment 05.

1. CONTRACT ID CODE PAGE OF PAGES

S 1 28

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)

16C. DATE SIGNED

BY 06-Jun-2017

16B. UNITED STATES OF AMERICA15C. DATE SIGNED15B. CONTRACTOR/OFFEROR

(Signature of Contracting Officer)(Signature of person authorized to sign)

8. NAME AND ADDRESS OF CONTRACTOR (No., Street, County, State and Zip Code) X W81K04-17-R-0001

X 9B. DATED (SEE ITEM 11)

18-May-2017

10B. DATED (SEE ITEM 13)

9A. AMENDMENT OF SOLICITATION NO.

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offer is extended, X is not extended.

Offer must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:

(a) By completing Items 8 and 15, and returning 1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;

or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE

RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN

REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

12. ACCOUNTING AND APPROPRIATION DATA (If required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE

CONTRACT ORDER NO. IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(B).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor is not, is required to sign this document and return copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

10A. MOD. OF CONTRACT/ORDER NO.

2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO.(If applicable)

6. ISSUED BY

3. EFFECTIVE DATE

06-Jun-2017

CODE

W40M USA HLTH CONTRACTING ACT

CTR FOR HEALTH CARE CONTR

2199 STORAGE ST BLDG 4197 STE 68

JBSA FT SAM HOUSTON TX 78234-5074

W81K04 7. ADMINISTERED BY (If other than item 6)

4. REQUISITION/PURCHASE REQ. NO.

CODE

See Item 6

FACILITY CODECODE

EMAIL:TEL:

W81K04-17-R-0001

SECTION SF 30 BLOCK 14 CONTINUATION PAGE

SUMMARY OF CHANGES

SECTION SF 1449 - CONTINUATION SHEET

The following have been modified:

ATTACHMENT 5

Attachment 5 - Estimated Workload Data - ED

Item MTF

Estimated

ED Year 1

Estimated

ED Year 2

Estimated

ED Year 3

Estimated

ED Year 4

Estimated ED

Year 5 Total 5 Years

0005 - BASSETT ACH-

FT. WAINWRIGHT* 6,182 6,182 6,182 6,182 6,182 30,910

0032 - EVANS ACH-FT.

CARSON 25,662 25,662 25,662 25,662 25,662 128,311

0047 - EISENHOWER

AMC-FT. GORDON 10,616 10,616 10,616 10,616 10,616 53,079

0048 - MARTIN ACH-

FT. BENNING 16,005 16,005 16,005 16,005 16,005 80,024

0049 - WINN ACH-FT.

STEWART 9,605 9,605 9,605 9,605 9,605 48,025

0052 - TRIPLER AMC-

FT SHAFTER 15,954 15,954 15,954 15,954 15,954 79,770

0057 - IRWIN ACH-FT.

RILEY 8,445 8,445 8,445 8,445 8,445 42,224

0060 - BLANCHFIELD

ACH-FT. CAMPBELL 14,492 59,289 59,289 59,289 59,289 251,648

0064 - BAYNE-JONES

ACH-FT. POLK 15,525 15,525 15,525 15,525 15,525 77,625

0075 - L. WOOD ACH-

FT. LEONARD WOOD 6,460 6,460 6,460 6,460 6,460 32,299

0086 - KELLER ACH-

WEST POINT 1,348 1,348 1,348 1,348 1,348 6,740

0089 - WOMACK AMC-

FT. BRAGG 64,359 64,359 64,359 64,359 64,359 321,793

0108 - WILLIAM

BEAUMONT AMC-FT.

BLISS 1,473 1,473 1,473 1,473 1,473 7,366

0109 - BAMC-SAMMC

JBSA FSH 2,949 2,949 2,949 2,949 2,949 14,745

0110 - DARNALL AMC-

FT. HOOD 21,575 21,575 21,575 21,575 21,575 107,873

0125 - MADIGAN AMC-

FT. LEWIS 16,188 16,188 16,188 16,188 16,188 80,940

0131 - WEED ACH-FT.

IRWIN 5,681 5,681 5,681 5,681 5,681 28,405

0607-LANDSTUHL

REGIONAL MEDCEN 5,965 5,965 5,965 5,965 5,965 29,825

0612 - BRIAN

ALLGOOD ACH-SEOUL 3,792 3,792 3,792 3,792 3,792 18,958

252,274 297,071 297,071 297,071 297,071 1,440,558

PERFORMANCE WORK STATEMENT

PERFORMANCE WORK STATEMENT

Enterprise-Wide Remote Medical Records Coding Services

Patient Administration and Biostatistics Activity (PASBA)

United States Army Medical Command (MEDCOM)

06 June 2017

1. GENERAL: This is a non-personal services contract to provide enterprise-wide, remote (off-site) medical coding services throughout the United States Army Medical Command (MEDCOM). The Government will neither supervise Contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances will the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor's responsibility to notify the Contracting Officer immediately.

1.1 BACKGROUND.

1.1.1 The MEDCOM Patient Administration Systems and Biostatistics Activity (PASBA) has identified approximately ten (10) million medical records annually that go beyond the coding capability of the of MEDCOM

Medical Treatment Facilities’ (MTFs) coding staff. These medical records are retained from all services (Army, Air Force, Navy and Marines) for active duty service members, family members and beneficiaries, retirees, civilian trauma, and other categories of patients. The outpatient medical records include Outpatient Clinic (OP) Records, Emergency Department (ED), Ambulatory Procedure Visits (APVs), and Inpatient Professional Service Rounds

(IPSR), and other outpatient records within MHS Genesis (DoD electronic health record being implemented at

Madigan Army Medical Center, Fort Lewis, Washington).

1.1.2 Per the Military Health System (MHS), Professional Services and Specialty Medical Coding Guidelines, Version 5.0, “Medical coding is the alphanumeric representation of clinical documentation. It allows standardized, efficient data gathering for a variety of purposes. While it can provide a detailed clinical picture of a patient population, it can also be useful in overseeing population health, anticipating demand, assessing quality outcomes and standards of care, managing business activities, and receiving reimbursements for services.” As such, the

MEDCOM MTFs coding staffs are responsible for transposing documented medical care into an alphanumeric format.

1.2 SCOPE.

1.2.1 The contractor shall provide all personnel, management, administration, facilities, materials, equipment, and services except as identified in Paragraph 3, Government-furnished equipment, necessary to perform non-personal, remote medical record outpatient coding services and related medical record coding functions in support of 32

MTFs located in four (4) Regional Health Commands (RHC): Atlantic, Central, Pacific, and Europe (See Exhibit B for listing of MTFs by Region and Attachments 2 – 4 for Estimated Annual Workload Data by MTF by OP Clinic

Records, ED, APVs, and IPSRs).

1.2.2 The scope is also inclusive of any related medical record coding functions or tasks, such as physician queries, data entry, and abstracting coding information into the Coding Compliance Editor (CCE), Composite Health Care

System (CHCS), and MHS Genesis that leads to the remote coding of clinical records.

1.2.3. Place of Performance. The services provided under this contract will be performed remotely (off-site) at contractor facilities. For purposes of off-site remote coding, a contractor facility is inclusive of CSP performing services at home.

1.3 COMMERCIAL STANDARDS. Performance shall be in accordance with the standards contained in the

Performance of Work (PWS) and all pertinent Department of Defense (DoD) Directives to include the Military

Health System (MHS) Coding Guidelines and DoD Instruction 6040.42, Management Standards for Medical coding of DoD Health Records. These guidelines are accessible on the Health.mil website at http://health.mil/Military-

Health-Topics/Technology/Support-Areas/MHS-Specific-Coding-Guidelines.

1.3.1. Commercial Industry References.

1.3.1.1 International Classification of Diseases, 10

th

Revision, Clinical Modification/ (ICD-10-CM);

1.3.1.2 Current Procedural Terminology (CPT

), 4th Edition or most current edition; and

1.3.1.3 Healthcare Common Procedure Coding System (HCPCS).

1.4 KEY PERSONNEL. The following personnel are considered key personnel by the Government: Contract

Manager and Alternate Contract Manager or equivalents. The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the Contracting Officer (KO). The Contract

Manager and Alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. For key personnel qualifications, see PWS 4.0, Contractor-Furnished Material, Equipment, and Qualifications.

1.4.1 The contractor shall designate key personnel, in writing, and submit to the Contracting Officer (KO) prior to contract performance start date.

1.4.2 The key personnel shall be available for government contact via email and telephone, during designated business hours for each medical treatment facility (MTF). Any changes to the key personnel shall be submitted to the KO in writing not later than five (5) business days prior to change of key personnel.

1.5 APPLICATION VIRTUALIZATION HOSTING ENVIRONMENT (AVHE)/MHS Genesis.

1.5.1 AVHE Guidelines. The contractor shall comply with the AVHE (most current version) guidelines. The

AVHE is a public domain and is the framework for providing DoD-medical user’s access to a list of client applications (Essentris, Armed Forces Health Longitudinal Technology Application (AHLTA), CHCS, and CCE) and delivering these applications through a web browser. AVHE is a Citrix-based capability that is hosted worldwide at each regional MHS Application Access Gateway (MAAG) sites. Each MAAG site represents a centrally-managed, standard, integrated, and robust computing infrastructure to support the regional delivery of applications and services to the entire MHS community. The AVHE Users Guide may be obtained at https://avhe-support.health.mil/. Other Citrix-based capability may be used to access MHS Genesis. The DHA Service Center will manage account provisioning processes for AVHE and the Citrix-based platform to access MHS Genesis.

1.5.1.1 The current uptime for AVHE is 99.6%. This uptime is calculated based on any outages caused by the

WAN, network, JAD authentication, SVHE hosting platform and the AVHE platform itself.

1.5.1.2 The contractor may experience AVHE network latency for different reasons (home wifi/ISP, DISA WAN routing changes, etc); however, the Independent Computing Architecture (ICA) protocol that Citrix uses for AVHE connections is distinguished as reasonably latency tolerant compared to most application protocols.

http://health.mil/Military-Health-Topics/Technology/Support-Areas/MHS-Specific-Coding-Guidelines http://health.mil/Military-Health-Topics/Technology/Support-Areas/MHS-Specific-Coding-Guidelines https://avhe-support.health.mil/ https://avhe-support.health.mil/

1.5.1.3 The AVHE has two maintenance windows per month (on Saturdays) that are coordinated through the

Defense Health Agency Global Service Center (DHAGSC) Change Management and Notification processes. The

AVHE maintenance is considered non-impactful and does not result in an outage at an AVHE site as all of the

AVHE components (servers, etc.) are highly available so a single server can be patched while the other takes on the load.

1.5.2 AVHE System Requirements. The contractor shall comply with and maintain the following system requirements for each Contract Service Provider (CSP) not later than (NLT) 60 calendar days after task order (TO) award and throughout the duration of contract:

1.5.2.1 Army Training Certification Tracking System (ATCTS). All CSPs requiring network access to the hosted applications shall successfully register in the Army Training Certification Tracking System (ATCTS). The

ATCTS website for registration is located at https://atc.us.army.mil/iastar/registration.php. The contractor is responsible for maintaining an active database of CSPs ATCTS status and providing status to the MTF-specific

COR, as requested. All CSPs are identified as general users and should be annotated on the DD Form 2875, System Authorization Access Request (SAAR) as IT Level 3.

1.5.2.1.1 Contractor personnel do not require access to classified data. Per the National Industrial Security Program

Operating Manual (NISPOM) and AR 25-2, in order to gain access to and fully utilize the Army Medical

Department (AMEDD) electronic network and to gain access to patient data as protected by the Health Insurance

Portability and Accountability Act (HIPAA), all contract personnel must have an IT-III (formerly ADP-III)

Clearance. Prior to the start of the contract period, the contractor shall ensure necessary actions have been taken such that the person performing work contained herein has an IT-III clearance.

1.5.2.2 DoD Information Assurance (IA) Awareness Training. All CSPs requiring a DoD Common Access Card

(CAC) (e.g., smart card) and network access to the hosted applications shall successfully complete the DoD

Information Assurance Awareness before issuance of network access. Successful completion of the current version of this training must be accomplished annually thereafter. All contractor employees working IA/IT functions must comply with DoD and Army training requirements in DoDD 8570.01, DoD 8570.01-M, and AR 25-2 within six months of employment. Each CSP shall access DoD Information Assurance Awareness Training at the Cyber

Security Training Center website, “DoD Cyber Awareness Challenge Training at https://ia.signal.army.mil/dodiaa.

The contractor is responsible for maintaining an active database of CSPs IA training status and providing initial and annual training certificates to the MTF-specific COR, as requested.

1.5.2.3 DoD Common Access Card (CAC). The government will provide a DoD CAC smart card to each contract service provider performing medical record coding services. The AVHE requires the use of a CAC to gain access to published applications. See PWS 1.6 for Trusted Associated Sponsorship System (TASS)) for instructions regarding CAC issuance.

1.5.2.4 Medical Joint Active Directory Account. Each CSP requiring access to AVHE shall have an account in the medical Joint Active Directory Environment. The contractor shall contact the DHA Global Service Center at https://support-gsc.health.mil to create a Joint Active Directory account for each CSP requiring access to AVHE.

1.5.2.5 Citrix Client and End User Device Configuration Settings. Each end user device (EUD) that is used to access AVHE shall meet the following system requirements:

1.5.2.5.1 Citrix Receiver Client. Citrix Receiver 4.2.100 client is the minimum recommended client and can be downloaded from the following URL: https://io.dha.health.mil/fls/fls_avh/CitrixRecieverWeb.zip.

1.5.2.5.2 DoD Root Certificates. DoD Root Certificates allow the web browser to trust the identity of the AVHE websites that deliver published applications. The DoD Root Certificates may be obtained from http://iasecontent.disa.mil/pki-pke/InstallRoot_NonAdmin_4.1.msi or http://iase.disa.mil/pki-pke/Pages/tools.aspx under “Trust Store.”

1.5.2.5.3 Smartcard Reader and Associated Middleware. In order to access published applications from AVHE, https://ia.signal.army.mil/dodiaa https://support-gsc.health.mil/ https://io.dha.health.mil/fls/fls_avh/CitrixRecieverWeb.zip http://iasecontent.disa.mil/pki-pke/InstallRoot_NonAdmin_4.1.msi http://iase.disa.mil/pki-pke/Pages/tools.aspx each EUD shall include a smartcard reader and associated or required middleware (e.g., Active Client.).

1.5.2.5.4 For any issues regarding the accessing of applications on AVHE, the contractor shall contact the DHA

Global Service Center (DHAGSC) at (800) 600-9332 (or by using the appropriate country access code for

OCONUS) or via email at servicecenter@dha.mil. To submit a support ticket via the web, log on to the DHAGSC

Remedy Service Request Management module at https://servicecenter.dha.health.mil/ and search for “AVHE”

(requires an active Remedy account).

1.5.3. Accessing Published (Hosted) Applications on AVHE. For each CSP, the contractor shall comply with and maintain the following MHS application access requirements not later than 30 calendar days after initial CAC issuance and throughout the contract duration:

1.5.3.1 HIPAA and Privacy Act Training. All CSPs requiring network access to the hosted applications shall successfully complete the MHS Privacy Act and Health Insurance Portability and Accountability Act (HIPAA)

Privacy and Security training prior to access to the hosted applications and then annually thereafter. The contractor shall submit a copy of the Privacy Act and HIPAA course certificate along with the completed SAAR and DoD IA

Awareness training certificate to the MTF-specific COR for each affected CSP. The contractor is responsible for maintaining an active database of CSPs HIPAA and Privacy Act training status and providing initial and annual training certificates to the MTF-specific COR, as requested. The course is accessible via Joint Knowledge Online

(JKO). Please refer to the Joint Knowledge Online (JKO) Instructions on accessing JKO.

1.5.3.2 In order to gain network access to given applications (e.g., AHLTA, Essentris, CCE, and CHCS), the contractor shall complete a SAAR, DA Form 2875. The contractor shall submit a completed SAAR to the MTF-specific COR for all hosted applications required for the CSP to perform medical records coding. The MTF-specific

COR shall coordinate the review/approval of the SAAR for contractor access for all requested hosted applications.

The fillable PDF form is located http://www.dtic.mil/whs/directives/forms/eforms/dd2875.pdf.

1.5.3.3 Upon government approval of the SAAR for the hosted applications, the CSP shall access the applications on site-specific AVHE URLs. The CSP shall open its web browser and enter the site specific AVHE URL into the address bar. The list of AVHE site specific URLs are located in the AVHE Users Guide.

1.5.3.4 The Government will provide unique training for Essentris, AHLTA, CCE, and CHCS (see PWS 3.0, Government-Furnished Services) on a MTF-specific basis.

1.6 TRUSTED ASSOCIATED SPONSORSHIP SYSTEM (TASS).

1.6.1 The contractor shall comply with agency personal identity verification procedures that implement Homeland

Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and

Federal Information Processing Standards Publication (FIPS PUB) Number 201.

1.6.1.1 The contractor shall comply with agency personal identity verification procedures in all subcontracts when the subcontractor is required to have physical access to a federally-controlled facility or access to a Federal information system.

1.6.1.2 The contractor shall ensure compliance with the provisions set forth below. For purposes of Federal

Acquisition Regulation (FAR) 52.204-9, the government will designate MTF-specific Trusted Agents (TAs) for each location listed in the contract. The government reserves the right to amend or supplement these provisions pursuant to the changes clause in the contract.

1.6.1.3 The contractor is responsible for absences of CSPs due to expired identification and access documents. Such absences shall not relieve the contractor of its obligation to perform the services required under this contract.

1.6.1.4 The government will sponsor the CSPs for an Army Knowledge Online (AKO) account. All CSP email addresses will identify them as a contractor and use the format firstname.lastname.ctr@ mail.mil. AKO will be discontinued by the government when the CSPs no longer require access.

https://io.dha.health.mil/cm/user_support.cfm mailto:servicecenter@dha.mil?subject=AVHE%20Support%20Request&body=**%20PLEASE%20ANSWER%20THE%20FOLLOWING%20QUESTIONS%20**%0A%0A1.%20%20User%20Contact%20Information%20%3A%20%20(Name%2FE-mail%2FPhone%2FSite)%0A%0A2.%20%20AVHE%20URL%20being%20accessed%20%3A%20%20(https%3A%2F%2Favhe-xxxx.health.mil)%0A%0A3.%20%20Which%20application%20are%20you%20trying%20to%20reach%20through%20AVHE%2FCitrix%3A%20(Name%20of%20Application)%20%20%0A%0A4.%20%20Please%20describe%20your%20problem%20or%20nature%20of%20your%20support%20request%3A%0A https://servicecenter.dha.health.mil/ http://jko.jten.mil/mhs http://jko.jten.mil/mhs https://jkodirect.jten.mil/pdf/DHA%20Accounts_tip%20sheet_Mar%202015.pdf http://www.dtic.mil/whs/directives/forms/eforms/dd2875.pdf

1.6.1.5 The Government TA will send a notice through the TASS to the AKO e-mail address provided IAW the above requirement. The CSPs user ID and password will be provided in the email and shall require a change at first log-in. In the event the e-mail message is not received the contractor may request the username and password from the TA and proceed to the website https://www.dmdc.osd.mil/tass to complete the process.

1.6.1.6 The CSP shall log into the TASS and complete the verification process by submitting the application back to the TA for approval.

1.6.1.7 The application will be accepted, returned, or rejected by the TA. Notice as to whether the application has been accepted, returned or rejected will be provided to the individual's e-mail address provided within 48 hours after submission. If the application is returned or rejected, the CSP shall contact the TA and comply with the TA's guidance to attempt to correct and resolve the issues.

1.6.1.8 Upon approval of the application, the CSP shall receive an e-mail sent to the address provided stating the

CAC application was approved. The applicant must then go to a RAPIDS Issuing Facility to have the government credential issued. The CSP must present two acceptable forms of ID which include: Driver's License, Military ID, Contractor Company ID with picture and expiration date, charge card with picture imprinted, or passport. RAPIDS site locations may be found at https://rapids-appointments.dmdc.osd.mil/(S(05n5pqao5euc01oaodj3isk3))/appointment/default.aspx.

1.6.1.9 Revalidation Requirements. The TA is required to revalidate all CSPs, in the TASS, every 180 calendar days. In the event revalidation is denied, the CAC credentials shall be revoked and the CAC will not be useable to login.

1.6.1.10 Out-processing Requirements. When a CSPs performance under this contract ceases, the CSP shall personally bring the CAC to the TA and complete the DA Form 2962. The TA will revoke the CAC from the TASS.

1.7 ACCESS AND GENERAL PROTECTION/SECURITY POLICY AND PROCEDURES.

1.7.1 Contractor and all associated sub-contractor employees shall provide all information required for background checks to meet MTF-specific installation access requirements to be accomplished by installation Provost Marshal

Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel) as directed by DOD, Headquarters, Department of the Army and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.

1.7.2 Contractor and all associated sub‐contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index and Terrorist Screening

Database (Army Directive 2014‐05/AR 190‐13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at

OCONUS locations, in accordance with status of forces agreements and other theater regulations.

1.7.2.1 For contractors requiring Common Access Card (CAC). The contractor shall coordinate with the MEDCOM

COR for adjudication procedures for Tier 1 background investigations for each CSP. Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated Tier 1 investigation in accordance with Army

Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1)

Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled Tier 1 at the Office of Personnel

Management.

https://www.dmdc.osd.mil/appj/cvs/login https://rapids-appointments.dmdc.osd.mil/(S(05n5pqao5euc01oaodj3isk3))/appointment/default.aspx https://rapids-appointments.dmdc.osd.mil/(S(05n5pqao5euc01oaodj3isk3))/appointment/default.aspx

1.7.2.1.1 Army Federal Investigative Standards (FIS). In accordance with FIS, the Office of Personnel Management

(OPM) implemented Tier 1 background investigations and discontinued the National Agency Check with Inquiries

(NACI) on 1 October 2014. A Tier 1 (T1) represents the type of background investigation to be conducted for this effort. A Tier 1 is required for each CSP to access the DOD computer network.

1.7.2.1.2 The preferred method for the submission of fingerprints is via digital fingerprint machine through the

Defense Manpower Data Center (DMDC) Secure Web Fingerprint Transaction (SWFT +) System. Digital fingerprints may be submitted at Army security offices. If digital fingerprints are not possible, a candidate must submit ink prints on the Standard Form 87 Finger Print Card. The use of hard copy fingerprint cards will delay the security review. The preparation and submission of the Tier 1 shall be at the expense of the Government, upon commencement of services. The contractor shall advise their employees that a positive report is needed as a condition of employment under this contract. If the results of the Tier 1 investigation result in derogatory findings, the Contractor shall be responsible for and pay all costs associated with the Tier 1 investigation. The Government will not reimburse these costs.

1.7.3 OPSEC Training.

1.7.3.1 Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within

30 calendar days of reporting for duty. All contractor employees must complete annual OPSEC awareness training.

(Compliance is required for all task orders.) The contractor is responsible for maintaining an active database of

CSPs OPSEC training status and providing initial and annual training certificates to the MTF-specific COR, as requested.

1.7.3.2 OPSEC Standing Operating Procedure/Plan. If required via individual task order, the contractor shall develop an OPSEC Standing Operating Procedure (SOP)/Plan within 90 calendar days of contract award, to be reviewed and approved by the responsible Government OPSEC Officer, per AR 530-1, Operations Security. This

SOP/Plan will specify the government's critical information, why it needs to be protected, where it is located, who is responsible for it, and how to protect it. In addition, the contractor shall identify an individual who will be an

OPSEC Coordinator. The contractor will ensure that this individual becomes OPSEC Level II certified in accordance with AR 530-1.

1.7.4 The contractor shall ensure that its CSPs entering government-controlled installations or facilities have in advance obtained access badges, passes or related equivalent documentation in accordance with facility regulations, so as not to delay the accomplishment of contracted services.

1.7.5 The CSPs operating contractor or personal vehicles on Federal property shall possess an operator's license for the category of vehicle being operated and automobile insurance as required by regulations/laws governing said

Federal property. Privately owned and contractor vehicles are subject to being searched pursuant to applicable regulations.

1.7.6 Force Protection Condition (FPCON) impact on work levels. During FPCONs Charlie and Delta all services at

Army-controlled installations or facilities are discontinued; therefore these contract services will be suspended accordingly. The MTF-specific COR will notify the contractor when services will resume when the FPCON level is reduced to level Bravo or lower. This contract and its CSPs are not considered mission essential.

1.8 INFORMATION ASSURANCE, SECURITY, AND CONFIDENTIALITY

1.8.1 Contract service providers will be issued a Common Access Card (CAC) which is required for access to

AVHE hosted applications and MHS Genesis.

1.8.2 The processing of records shall require utilization of Essentris, Essentris ED module, T-System, Health

Artifact and Image Management Solution (HAIMS), AHLTA, CHCS, CCE, via the AVHE platform. MHS Genesis will be accessed through a Citrix-based capability. The DHA Service Center will manage account provisioning processes for this Citrix-based platform to access MHS Genesis.

1.8.3 The contractor shall be responsible for safeguarding all medical information provided for contractor use. The contractor shall not retain any copies, paper or electronic information once the work is completed and approved by the MEDCOM-level COR. The contractor and contract employees shall be aware that proven violation of confidentiality of patient information shall be cause for termination of employment on contract performance.

Neither the contractor nor its staff shall release patient medical information or account data, except for the purposes of this contract, without the expressed written authorization from the MEDCOM-level COR. The contractor shall be responsible for its employees in release of confidentiality and/or proprietary information. All contractor personnel shall observe the requirements imposed on sensitive data by law, Federal Regulation, and DoD/AR policies and procedures. Contract employees shall be responsible for maintaining patient confidentiality at all times. All individually identifiable health records shall be treated with the strictest confidentiality. The contractor shall comply with the Privacy Act, 38, USC 5701, and 38 USC 7332.

1.8.4 The contractor shall comply with all applicable DoD security regulation and procedures during the performance of this contract. The contractor shall not disclose and must safeguard procurement sensitive information, computer systems and data, Privacy Act data, and Government personnel work products obtained or generated in the performance of this contract.

1.8.5 Certain data may be collected and analyzed as a component of the requirement. Such data shall be stored electronically in a secure manner to prevent disclosure to unauthorized parties, and for the purpose of making such data available by the government as needed.

1.9 QUALITY CONTROL (QC).

1.9.1 The contractor shall maintain an Industry quality standard-compliant process for quality control.

1.9.2 The contractor shall maintain a complete Quality Control Plan (QCP) that shall ensure the requirements of the contract are provided as specified in this PWS. The contractor shall provide copies of the QCP to the KO and

MEDCOM-level COR/ACOR no later than 30 calendar days after contract award. The QCP shall demonstrate how the contractor intends to ensure quality performance during the contract period of performance. The contractor shall maintain a QCP that includes performance metrics. As necessary, the contractor shall update/revise the QCP and submit updates/revisions to the KO and MEDCOM-level COR, for review prior to implementation. The final updated/revised QCP shall be incorporated into the contract by reference as a compliance document. The contractor shall update/revise the QCP, as necessary, and submit the updated/ revised QCP to the KO and MEDCOM-level

COR not later than seven (7) calendar days for review/comments prior to implementation.

1.9.3 Quality Control Inspection Report. The contractor shall submit a monthly written report to the KO and

MEDCOM-level COR not later than the 5 th calendar day of each month for the previous month of contractor inspection results and actions in process to improve quality.

1.10 QUALITY ASSURANCE (QA). The government shall evaluate the contractor’s performance under this contract in accordance with (IAW) the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government must do to ensure that the contractor has performed IAW the performance standards and contract quality requirements are met. The term “contract quality requirements” means the technical requirements in the contract relating to the quality of the service and those contract clauses prescribing inspection and other quality controls incumbent on the contractor to ensure the service conforms to the contractual requirements. It defines how the performance standards will be applied, the frequency of surveillance, and the performance thresholds.

1.11 CONTRACTORS IN THE GOVERNMENT WORK AREAS.

1.11.1 Contract Service Providers (to include subcontractors) shall identify themselves as contractor employees while performing their tasks in government work areas. The CSPs shall wear a contractor furnished, visible identifying badge (name tag) in a prominent location, on the front of the outer clothing above the waist, while performing services under this contract. The name tag shall have the name of the contractor as well as the full name and professional title of the individual CSP. CSPs shall ensure that their presence or participation does not construe the appearance or impression as a government employee.

1.11.2 Contract Service Providers attending meetings and/or working in other situations, or providing services where their contractor status is not obvious to third parties (such as phone, internet, or other distance methods) are required to identify themselves as such to avoid creating an impression in the minds of members of the public, government employees, or members of Congress that they are government officials or employees.

1.12 POST AWARD CONFERENCE/PERIODIC/QUARTERLY MEETINGS. The contractor shall attend the post award conference convened by the contracting activity or contract administration office in accordance with Federal

Acquisition Regulation Subpart 42.5. The contracting officer, contracting officer representative, and other government personnel, as appropriate, may meet periodically with the contractor to review the contractor’s performance. At these meetings, the contracting officer will apprise the contractor of how the government views the contractor’s performance and the contractor shall apprise the government of issues/concerns, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues.

1.13 CONTRACTING OFFICER REPRESENTATIVE (COR). A MEDCOM-level COR and Alternate COR

(ACOR) will be assigned to the basic contract and each task order issued will be assigned an individual COR (MTF-specific) by the Contracting Officer (KO). The CORs will monitor all technical aspects of the contract/task order and assist in contract/task order administration. A letter of designation will be issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, or changes in delivery dates. The COR is not authorized to change any terms or conditions of the resulting order. The contractor shall only conduct business with KO, MEDCOM-level COR, ACOR, and MTF-specific

CORs.

1.13.1 All inquiries, comments or complaints arising from any matter observed, experienced, or learned of as a result of or in connection with the performance of this contract, the resolution of which may require the dissemination of official information, shall be directed to the MEDCOM-level COR and the KO.

1.14 ADVERTISEMENT AND SOCIAL MEDIA. The contractor shall not post information to public website or social media locations, personal or professional, that in any way disclose names, locations, discussions, pictures before, during, or after contract period of performance without the express consent of the Government.

1.15 PHASE OUT PERIOD. As an incumbent, the contractor shall ensure a smooth transition with the successor during the phase-out period prior to completion of contractual performance. The contractor will provide an orderly transition of work acceptance and accomplishment so that full control by the successor is achieved by the end of the phase-out period.

1.16 TRAVEL. The contractor may be required to travel during the performance of this contract to attend meetings, training or other functions to provide services in support of this PWS. The COR will provide designated locations and facilities to the contractor not later than (NLT) 21 calendar days prior to the event.

1.16.1 Although the Joint Travel Regulation (JTR) is not applicable to Contractors, it may be used to determine the reasonableness and allowability of reimbursable costs under this contract. All reimbursable costs shall be considered to be reasonable and allowable only to the extent that they do not exceed on a daily basis the maximum rates in effect at the time of travel as set forth in the JTR. There may be circumstances when the JTR authorizes a discretionary travel and transportation expense, but the contract remains silent. In such circumstances, the expense is not allowable under this contract and will not be reimbursed. The contractor shall not include profit and G&A overheads in their travel cost reimbursement.

1.17 SEXUAL HARASSMENT AND ASSAULT RESPONSE PROGRAM (SHARP).

1.17.1 The contractor shall comply with OTSG/MEDCOM Policy Memo 13-062, Policy for Reporting Incidents of

Sexual Assault and Sexual Harassment under the Sexual Assault Prevention and Response Program (SHARP), 12

Nov 2013. The SHARP reporting requirements apply only to knowledge obtained by contractor personnel while performing services under this contract.

1.17.2 The contractor shall require all CSPs with knowledge of an incident of sexual assault occurring on a

Government facility, to include a Government leased facility, where the contractor is providing services under this contract, to report the incident to the contractor who shall immediately (within 24 hours) report the incident in writing to the government's COR. This reporting policy also applies to sexual assault incidents involving

MEDCOM personnel that occur on the contractor’s owned or leased facility under this contract. All incidents shall be reported whether they involve contractor personnel or Government personnel, or other individuals, when the incidents occur on a Government facility or a Government leased facility.

1.17.3 The contractor shall require all CSPs with knowledge of an incident of sexual harassment occurring on a

Government facility, to include a Government leased facility, where the contractor is providing services under this contract, to report the incident to the contractor who shall immediately (within 24 hours) report the incident in writing to the government's COR. This reporting policy also applies to sexual harassment incidents involving

MEDCOM personnel that occur on the contractor’s owned or leased facility under this contract. All incidents shall be reported whether they involve contractor personnel or Government personnel, or other individuals, when the incidents occur on a Government facility or a Government leased facility.

1.18 EXCLUSION FROM PARTICIPATION IN FEDERAL HEALTH CARE PROGRAMS.

1.18.1 The Contractor shall not employ or contract with any individual or entity (hereinafter collectively referred to as “person”) to provide items or services that will be included in invoices submitted to the Government under this contract if such person is listed on the Department of Health and Human Services (HHS) Office of the Inspector

General (OIG) List of Excluded Individuals and Entities (LEIE) or the TRICARE Sanctioned Provider List. The

Government is legally prohibited from paying for provision of items or services by such persons. The prohibition extends to services beyond direct patient care, such as services of persons in executive or leadership roles and administrative and management services, whether or not such services are billed separately. The LEIE may be found at http://oig.hhs.gov/fraud/exclusions.asp, and the TRICARE Sanctioned Provider list at http://www.health.mil/Military-Health-Topics/Access-Cost-Quality-and-Safety/Quality-And-Safety-of-

Healthcare/Program-Integrity/Sanctioned-Providers. The LEIE and TRICARE Sanctioned Provider List are hereinafter collectively referred to as “the Lists.”

1.18.1.1 Prior to start of contract performance, the Contractor shall (a) query the Lists to determine whether the name of any person the Contractor employs or contracts with to provide services or items for which payment may be made under this contract appears on the Lists, and (b) certify to the Contracting Officer that the Contractor has queried the Lists and no such names appear on either of the Lists.

1.18.1.2 During performance of the contract, and prior to persons other than those whose names were queried in accordance with paragraph 2, above, (hereinafter “new persons”) providing services or items under the contract, the

Contractor shall (a) query the Lists as in paragraph 2, and (b) certify to the Contracting Officer that the names of such new persons do not appear on either of the Lists.

1.18.1.3 The Contractor is advised that during performance of the contract, MTF personnel will perform a recurrent recheck of the names of contractor personnel working in the MTF against the Lists, as specified in

OTSG/MEDCOM Policy Memo 15-037. The Government will notify the Contractor in the event any contractor personnel working in the MTF appear on either of the Lists.

1.18.1.4 Should any person providing items or services under the contract appear on either of the Lists at any time during contract performance, the Contractor shall (a) in cases where the Contractor identified the person, notify the

Contracting Officer, and (b) promptly remove that person from the contract.

1.18.2 Violation of any aspect of the above paragraphs shall be considered a material breach of the contract and may result in termination of the contract.

1.18.3 The Contractor is further advised that, in accordance with Civil Monetary Penalties Law [CMP] (codified at

42 USC § 1320a-7a):

1.18.3.1 There are steep civil monetary penalties associated with billing the Government for providing items or services by a person on either of the Lists, and with failing to return to the Government any overpayments received for provision of such items or services.

1.18.3.2 Billing under the contract for provision of items or services by a person on either List may also result in exclusion of the person that employs or contracts with such person.

1.18.3.3 HHS OIG has issued a Special Advisory Bulletin on the Effect of Exclusion from Participation in Federal

Health Care Programs with additional information on the CMP. The Special Advisory Bulletin may be found at http://oig.hhs.gov/exclusions/files/sab-05092013.pdf.

1.19 Non-Defense Health Agency (Non-DHA) Health Insurance Portability and Accountability Act (HIPAA)

Business Associate Agreement (BAA) (7 July 2014)

Introduction

In accordance with 45 CFR 164.502(e)(2) and 164.504(e) and paragraph C.3.4.1.3 of DoD 6025.18-R, “DoD Health

Information Privacy Regulation,” January 24, 2003, this document serves as a BAA between the signatory parties for purposes of the HIPAA and the “HITECH Act” amendments thereof, as implemented by the HIPAA Rules and

DoD HIPAA Issuances (both defined below). The parties are a DoD Military Health System (MHS) component, acting as a HIPAA covered entity, and a DoD contractor, acting as a HIPAA business associate. The HIPAA Rules require BAAs between covered entities and business associates. Implementing this BAA requirement, the applicable DoD HIPAA Issuance (DoD 6025.18-R, paragraph C3.4.1.3) provides that requirements applicable to business associates must be incorporated (or incorporated by reference) into the contract or agreement between the parties.

(a) Catchall Definition. Except as provided otherwise in this BAA, the following terms used in this BAA shall have the same meaning as those terms in the DoD HIPAA Rules: Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices (NoPP), Protected Health

Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health

Information, and Use.

—Breach means actual or possible loss of control, unauthorized disclosure of or unauthorized access to PHI or other

PII (which may include, but is not limited to PHI), where persons other than authorized users gain access or potential access to such information for any purpose other than authorized purposes, where one or more individuals will be adversely affected. The foregoing definition is based on the definition of breach in DoD Privacy Act

Issuances as defined herein.

—Business Associate shall generally have the same meaning as the term “business associate” in the DoD HIPAA

Issuances, and in reference to this BAA, shall mean [insert name of Business Associate signatory to this BAA].

—Agreement means this BAA together with the documents and/or other arrangements under which the Business

Associate signatory performs services involving access to PHI on behalf of the MHS component signatory to this

BAA.

—Covered Entity shall generally have the same meaning as the term “covered entity” in the DoD HIPAA Issuances, and in reference to this BAA, shall mean [insert name of MHS component signatory to this BAA].

—DHA Privacy Office means the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Director is the

HIPAA Privacy and Security Officer for DHA, including the National Capital Region Medical Directorate

(NCRMD).

—DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health

System (MHS). These issuances are DoD 6025.18-R (2003), DoDI 6025.18 (2009), and DoD 8580.02-R (2007).

—DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11

(2007) and DoD 5400.11-R (2007).

—HHS Breach means a breach that satisfies the HIPAA Breach Rule definition of breach in 45 CFR 164.402.

—HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the

U.S. Department of Health and Human Services (HHS) and codified at 45 CFR Part 160 and Part 164, Subpart E

(Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-D (Enforcement), as amended by the

2013 modifications to those Rules, implementing the “HITECH Act” provisions of Pub. L. 111-5. See 78 FR 5566-

5702 (Jan. 25, 2013) (with corrections at 78 FR 32464 (June 7, 2013)). Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this BAA and are not included in the term HIPAA Rules.

—Service-Level Privacy Office means one or more offices within the military services (Army, Navy, or Air Force) with oversight authority over Privacy Act and HIPAA privacy compliance.

I. Obligations and Activities of Business Associate

(a) The Business Associate shall not use or disclose PHI other than as permitted or required by the Agreement or as required by law.

(b) The Business Associate shall use appropriate safeguards, and comply with the DoD HIPAA Rules with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by the Agreement.

(c) The Business Associate shall report to Covered Entity any Breach of which it becomes aware, and shall proceed with breach response steps as required by Part V of this BAA. With respect to electronic PHI, the Business

Associate shall also respond to any security incident of which it becomes aware in accordance with any Information

Assurance provisions of the Agreement. If at any point the Business Associate becomes aware that a security incident involves a Breach, the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .