W9114F-25-Q-0024.pdf
PDF 508 KB Posted
- Attached to
- Hematology Testing - Cost Per Reportable Result Federal contract opportunity
- Solicitation number
- W9114F25Q0024
- Issued by
- Department of the Army Medical Command
About this file
This is a Request for Quote (RFQ) solicitation document for automated hematology testing services at the U.S. Army Health Clinic in Vicenza, Italy. The solicitation (W9114F25Q0024) requires one automated hematology analyzer system with installation, maintenance, repair, reagents, supplies, and consumables to be provided under a Cost Per Reportable Result (CPRR) contract structure.
The contract will be awarded as a Firm-Fixed-Price contract using Simplified Acquisition Procedures and Lowest Price Technically Acceptable evaluation criteria. The period of performance runs from May 1, 2025 through September 30, 2029, with a base period and four one-year options. Key requirements include providing FDA-approved equipment compatible with MHS Genesis, 5-part differential testing capabilities, throughput of at least 45 CBCs per hour, and platelet count capabilities from 7x10^3/μL up to 2,000,000/μL. Questions are due by March 12, 2025 at 15:00 Italy time, with quotes due March 21, 2025 at 15:00. The NAICS code is 325413 with a size standard of 1,250 employees. The contract includes specific requirements for onsite training, method verification, and ongoing service/maintenance support with 24-hour emergency response capabilities.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| W9114F-25-Q-0024-0001.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
W9114F25Q0024
b. TELEPHONE NUMBER
314-590-5252
8. OFFER DUE DATE/LOCAL TIME
03:00 PM 21 Mar 2025
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
26-Feb-2025
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA X ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
W9114F9. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
ELENA M. RASPITHA
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
1 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.X
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED ORX
SMALL BUSINESS
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
W40M MRCO EUROPE
MEDICAL READINESS CONTR OFC EUROPE
CMR 402
APO AE 09180-0402
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE HT0891 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
AHC VICENZA - PA
GOVERNMENT REPRESENTATIVE
BLDG 2310 - CASERMA EDERLE
VICENZA 09630
TEL: FAX:
FAX:
TEL: 011 49 6371 86 113 SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
1,250
NAICS:
325413
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF52
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
W9114F25Q0024
Section SF 1449 - CONTINUATION SHEET
CONTRACT MINIMUM/MAXIMUM QUANTITY AND CONTRACT VALUE
The minimum quantity and contract value for all orders issued against this contract shall not be less than the minimum quantity and contract value stated in the following table. The maximum quantity and contract value for all orders issued against this contract shall not exceed the maximum quantity and contract value stated in the following table.
MINIMUM
QUANTITY
MINIMUM
AMOUNT
MAXIMUM
QUANTITY
MAXIMUM
AMOUNT
$1,000.00
CLIN DELIVERY/TASK ORDER MINIMUM/MAXIMUM QUANTITY AND CLIN ORDER VALUE
The minimum quantity and order value for the given Delivery/Task Order issued for this CLIN shall not be less than the minimum quantity and order value stated in the following table. The maximum quantity and order value for the given Delivery/Task Order issued for this CLIN shall not exceed the maximum quantity and order value stated in the following table.
CLIN
MINIMUM
QUANTITY
MINIMUM
AMOUNT
MAXIMUM
QUANTITY
MAXIMUM
AMOUNT
0001 $ $
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 13,750 Each Hematology Reportable Results
FFP
Cost Per Reportable Result (CPRR)
The Contractor shall provide testing capabilities for the U.S. Army Health Clinic- Vicenza (USAHC-V) to include a hematology analyzer system with installation, maintenance and repair, and the necessary reagents, supplies, and consumables in accordance with the Contract Requirements.
Ordering Period: 01 May 2025 to 30 September 2029 FOB: Destination
PSC CD: 6550
NET AMT
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 POP 01-MAY-2025 TO
30-SEP-2029
N/A AHC VICENZA - PA
GOVERNMENT REPRESENTATIVE
BLDG 2310 - CASERMA EDERLE
VICENZA 09630
FOB: Destination
HT0891
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government
PROJECTED IMPLEMENTATION PLAN
Projected Implementation Plan
Date / Timeline Action
30 APR 2025 Contract award within first 10 business days from contract award
Order instruments and conduct on-site walk through or virtual meeting with each site
31 MAY 2025* Instrument Delivery
1 - 15 JUNE 2025* Instrument Verification Completed
30 JUNE 2025 Go-Live with Patient Testing
*These are no later than dates. Milestones can be completed earlier then the dates specified.
CONTRACT REQUIREMENTS
Contract Requirements
1. Scope
1.1. The Contractor shall provide one (1) automated hematology analyzer and reagents in support of the hematology mission at Vicenza Army Health Clinic in Vicenza, Italy. The successful offeror shall furnish all equipment, reagents, consumables, controls, and any necessary maintenance to the respective laboratories for the purpose of hematology testing under a Cost Per Reportable Result (CPRR). All parts, equipment and reagents/consumables shall be supplied and serviced through the Contractor.
Medical Treatment Facility (MTF) Location Vicenza Army Health Clinic Caserma Carlo Ederle Building 2310, Room F14.1 36100, Vicenza, Italy
1.2. All costs integrated into this contract shall be calculated based on annual test volume.
1.3. All supplies and equipment to include connections between equipment shall be approved by the US Food and Drug Administration (FDA).
1.4. Period of Performance
* Complete blood count (CBC)
Period Period of Performance Analyzer
(Per location) Test
53 Months 1 May 2025 – 30 September 2029 1 CBC with
Reticulocyte
1.5. Government Points of Contact
1.6. The Contractor will provide two copies of the operating manual in English, one of which must be a hard copy and the other another hard copy or digital file.
1.7. Contractor provides for delivery and installation, all required maintenance, and final removal of equipment upon termination of contract.
1.8. Printer cartridges (laser or ink jet), ribbons, or special printer paper (thermal etc.) will be provided by the contractor.
2. Analyzer Requirements
2.1. Reagents/consumables shall meet the requirements of the clinic missions, workload, and test menu. All
CBC tests shall have FDA approval for immature granulocyte providing a five-part differential, reticulocyte count, and platelet count tests.
2.2. Fully automated/integrated analyzers comprised of one (1) independently operating analyzer for the location. Capable of performing a full test profile using <200 μL of sample with a throughput of at least 45 CBCs per hour. Analyzers shall include a pre-diluted sample access mode for the sample volume of <100 μL to perform full hematology test profile.
2.3. Platelet counts shall be able to read down to at least 7 × 10^3/μL. Must be able to accurately count platelets in platelet-rich plasma (PRP) samples, without the need for dilution, in concentrations of up to 2,000,000 platelets per microliter.
2.4. Individual analyzers shall have fully automated capabilities. There shall be a single point of specimen entry for the routine analysis of all required tests.
2.5. Able to process without operator intervention once the run time has started: 100% walk-away. Instrument shall have above 95% uptime, with a 5% or less downtime per month. Contractor shall provide information to support this requirement. Contractor provides a service guarantee that if both analyzers are down and unable to perform a CBC, the Contractor shall provide emergency on site repair regardless of the time of day, at no additional charge.
2.6. Shall have a single aspiration pathway for open and closed tube sampling to eliminate the need for mode-to-mode correlation.
2.7. Shall be capable of achieving WBC linearity range of 1-100.0 x 10^3/μL and directly measure MCV with a linearity of 50-150 fL or HCT with a linearity and reportable range of 0.0-75.0%.
2.8. Daily shutdown and start up time should be less than 20 minutes.
2.9. The Contractor must have an established driver compatible for interfacing the equipment with the military hospital computer system, MHS Genesis.
2.10. Recognize MHS Genesis generated bar-code labels on primary sample tubes.
Government Points of Contact (POCs)
Location POC Name Contact Information
US Army Health Clinic Vicenza Jundi, Gemma +39 0444619523
2.11. Analyzer will provide onboard quality control (QC) statistics, to include QC lot numbers, means, ranges, standard deviations, and coefficients of variation.
2.12. Analyzer flags results that indicate abnormal cells or activities.
2.13. Analyzer provides histograms for WBC, RBC, and PLT counts.
2.14. Provide uninterruptible power supply capable of sustaining the analyzers for 15 minutes.
2.15. Printer cartridges (laser or ink jet), ribbons, or special printer paper (thermal etc.) will be provided by the contractor.
2.16. All waste products produced by the analyzer are able to be contained and/or disposed of in accordance with host nation hazardous waste regulations.
2.17. Analyzer must possess QC management software with built in/customizable Levey Jennings and Westgard rules.
2.18. Analyzer must be able to back up patient results for later retrieval (specify # of patient results and length of time of storage capacity).
2.19. Analyzer software interface/monitor must be touch-screen.
3. Reagent Requirements
3.1. The Contractor shall provide all quality control and test reagent materials acceptable to the section
Medical Director. This includes third-party controls when requested/required by the laboratory.
3.2. Contractor shall set up a monthly standing order based upon test volume and reagent needs, so no emergency orders are anticipated. If test volumes dramatically change, the standing order may be adjusted through a contract modification.
3.3. Any required emergency orders shall be delivered within 24 hours after the order is placed.
3.4. Reagents used for troubleshooting analytical systems shall be replaced by the Contractor at no additional cost.
3.5. In determining reagent requirements, the Contractor shall consider requirements for routine quality control runs (as defined by the Laboratory Director), routine calibration, periodic calibration/calibration verification in accordance with departmental quality assurance policies and standard operating procedures and troubleshooting of out-of-control assays when calculating the yearly requirements.
3.6. The contractor shall provide safety data sheets (SDS) in English for each reagent delivered under this contract.
3.7. Routine services and reagent delivery for all locations will not be required on U.S. Federal and Italian National Holidays. If a U.S. federal holiday falls on a Saturday, then the official holiday is the preceding Friday.
If a U.S. federal holiday falls on a Sunday, then the official holiday is the following Monday.
3.7.1. US Federal Holidays
1st January New Year’s Day 3rd Monday in January Martin Luther King Day 3rd Monday in February Washington’s Birthday Last Monday in May Memorial Day
19th June Juneteenth 4th July Independence Day 1st Monday in September Labor Day 2nd Monday in October Columbus Day 11th November Veteran’s Day 4th Thursday in November Thanksgivings Day 25th December Christmas Day
3.7.2. Italian National Holidays
New Years Day, January 1st Day of Epiphany, January 6th Easter Monday, First Monday after Easter Liberation Day, 25 April Labor Day, 1 May Republic Day, 2 June Assumption Day, 15 August Feast of Virgin Mary (Vicenza Only), 8 September All Saints’ Day, 1 November National Unity Day, 3 November Immaculate Conception, 8 December Christmas Day, 25 December Saint Stephen’s Day, 26 December
4. Onsite Training
4.1. The Contractor shall provide the following for all testing locations:
4.1.1. The Contractor shall provide initial on-site operator training in English to all technicians assigned to the Government site and normally assigned to perform the associated testing prior to implementation of the analyzer for patient testing.
4.1.2. All on-site training shall include basic analyzer operation, troubleshooting procedures, performance of operator-level periodic preventive maintenance procedures, and use of any data management/quality control software.
4.1.3. The Contractor shall provide off-site training in English for one person from each clinic for each delivery order, if available.
5. Method Verification
5.1. The Contractor shall provide a qualified technical specialist to perform verification studies, in accordance with the College of American Pathologist (CAP) accreditation standards and Laboratory Director requirements, that includes but is not limited to, reference range, linearity (to include WBC, RBC, HGB, PLT and reticulocyte as required), instrument comparison, and decision rules. Technical specialist compiles necessary data for Laboratory Director review. The assigned TSR shall be responsible for the entire method validation/verification.
5.2. The method validation/verification shall be completed and approved by the Laboratory Director prior to reporting of patient results.
5.3. All instrument reagents, calibrators, linearity materials and other required reagents/materials used in the method validation/verification study shall be provided by the Contractor at no additional cost to the Government. These materials shall not be used in the analysis of specimens for patient care.
6. Service and Maintenance
6.1. The Contractor shall meet the following service and maintenance requirements for testing at the location:
6.1.1. The Contractor shall provide direct customer service and support, during normal duty hours, local
European time to include hotline telephone service (provided in English) and on-call emergency repair, to assist operators in correcting equipment problems.
6.1.2. The Contractor shall maintain all equipment installed under this contract except for repairs necessitated by willful damage or negligence on the part of the Government. This includes emergency repairs as well as routine Preventive Maintenance Services safety tests, calibrations/calibration verifications, and unscheduled repair services in accordance with procedures and practices prescribed by the manufacturer of the equipment.
6.1.3. The Contractor shall provide calibration/verification of all analyzers at least every six (6) months in accordance with manufacturer’s specifications and Collage of American Pathologists (CAP) accreditation standards. All materials used during calibration/ verifications shall be at no cost to the Government.
6.1.4. The Contractor shall provide all personnel, equipment, tools, materials, supervision, parts, transportation, and other items and services necessary to perform all required repairs and scheduled preventive maintenance/safety inspections and calibrations of equipment. The performance of scheduled periodic preventive maintenance, safety checks, and calibrations that are not normally performed at the operator level shall be performed by Contractor service personnel in accordance with requirements as specified in the Contractor’s instrument maintenance manual. Completion of analyzer installation shall establish time-zero for determining the time frame for performance of periodic services.
6.1.5. Any service technician provided by the Contractor shall adhere to all required reporting procedures for the respective laboratory prior to reporting to the laboratory for work. Current procedures will be available through the COR.
6.1.6. In all cases, the Contractor shall provide all reagents, calibrators, controls, and any other materials necessary to troubleshoot instrument failure. Replacement parts used, as necessary, claimed from local operator-level maintenance kits as well as any reagents that may have been used shall be replaced at no cost to the Government.
6.1.7. The Contractor shall notify the COR or designee of the exact date and time for performance of a preventive maintenance service no later than ten (10) calendar days prior to the scheduled preventive maintenance services.
6.1.8. Upon notification of equipment failure, the Contractor shall respond to telephonic requests for unscheduled repair within one (1) business day. A repair service engineer should be available on-site to repair the equipment failure within two (2) business days of the initial contact from laboratory personnel. If the equipment is designated inoperable and out of service for longer than three (3) business days (from the time-of-service technician’s arrival on site), the Contractor shall notify the COR, in writing, as to the reason(s) (i.e. non-availability of parts, etc.) for non-compliance. If the equipment cannot be repaired, a replacement instrument shall be provided within seven (7) business days. If the equipment cannot be replaced within seven (7) business days, the Government may seek remedies for damages in accordance with FAR 52.212-4(a), “Contract Terms and Conditions – Commercial Items, Inspection/Acceptance”.
6.1.9. Software add-ons and updates, as they become available, will be included.
7. RISK MANAGEMENT FRAMEWORK (RMF) for DOD IT
7.1. Risk Management Framework (RMF) for DoD IT: All IS, Platform Information Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data shall be accredited in accordance with DoDI 8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal Information Security Modernization Act (FISMA) security control testing. IS and PIT systems shall be categorized in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.
7.1.1. All systems subject to RMF shall present evidence of authorization in the System Security Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of Contracting Officer request. Evidence of FISMA compliance shall be presented in the form of a POA&M. Systems shall have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions (ATO-C) by contract award.
7.1.2. The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework (RMF) and DoDI 8510.01, Risk Management Framework (RMF).
7.1.3. The contractor shall configure the information system in accordance with Defense Information
Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).
7.1.4. The contractor shall ensure that the information system conforms to the requirements of DoDI
8551.01 “Ports, Protocols, and Services Management (PPSM)”.
7.1.5. The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.
7.1.6. The contractor shall Public Key (PK) enable the information system, implementing digital signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK) Enabling”.
7.1.7. The contractor will be responsible for compliance with the Joint Force Head Quarters – Department of Defense Information Network issuances and IA Vulnerability Management (IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.
7.1.8. The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.
7.1.9. The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA Cybersecurity Architectures.
7.1.10. Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.
7.1.11. Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The
Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP 800-137.
7.1.12. The contractor shall mitigate supply chain risk to the government by complying with DFARS
252.239-7018 and only utilizing unified capability equipment identified on the DODIN Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).
8. PERSONALLY IDENTIFIABLE INFORMATION, PROTECTED HEALTH INFORMATION, AND
FEDERAL INFORMATION REQUIREMENTS (REVISED 10/27/2020)
8.1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information
(PHI) and Federal Information Laws
This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances.
In general, the Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.
This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.
For purposes of this Section, the following definitions apply.
DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDI 5400.11, DoD Privacy and Civil Liberties Programs, January 29, 2019 and DoDI 5400.11- R, Department of Defense Privacy Program, May 14, 2007.
HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E (Enforcement), as amended.
Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.
DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoDM 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, DoDI 6025.18, Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs, March 13, 2019, and DoDI 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs, August. 12, 2015.
Defense Health Agency (DHA) Privacy Office is the DHA Privacy and Civil Liberties Office. The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA.
8.2. Records Management
When creating and maintaining official Government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36
CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records Management requirements outlined in the current TRICARE Operations Manual (TOM).
8.3. Freedom of Information Act (FOIA)
The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:
The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request preferably sent via the National FOIA Portal at: www.FOIA.gov. However, requesters may also submit requests via email at DHA.FOIA@mail.mil; or via postal delivery addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101. All FOIA requests shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Contract and/or Modification numbers shall be included in all FOIA requests seeking DHA procurement records. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible and respond to DHA within ten working days.
In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action.
Direct contact, including interim replies, between TRICARE Contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.
8.4. Systems of Records
In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil Liberties, and Transparency Division, and as required by the DoD Privacy Act Issuances.
Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, OMB Circular A-130, and Privacy Act of 1974 requirements applicable to Contractors operating systems of records on behalf of federal agencies. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.
8.5. Privacy Impact Assessment (PIA)
If DHA data is stored on a Contractor owned system, a PIA is required from the Contractor.
8.6. Data Sharing Agreement (DSA)
8.6.1. (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de-identified data)
The Contractor shall consult with the DHA Privacy Office to determine if the Contractor shall obtain a DSA or Data Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.
The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules and DoD HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.
Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor shall gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA Privacy Board requests for additional documentation.
To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the DHA Privacy Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data involved:
• DSA for De-Identified Data
• DSA for PHI
• DSA for PII Without PHI
• DUA for Limited Data Set
DSAs executed for contract support will expire after 1 year or at the end of the contract option year, whichever comes first. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.
8.6.2. (Applies if contract requirements may include human subject research)
This Contract incorporates by reference the Protection of Human Subject Research clause in the Defense Federal Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235-7004. A separate DFARS provision, 48 CFR 235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR 219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a Contractor participates in a study or demonstration project or other activity that involves human subject research, then the Contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If Contractor activity appears to involve human subject research, then the Contractor shall consult the DHA Privacy Office, which may contact the Research Regulatory Oversight Office in the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)).
8.7. Privacy Act and HIPAA Training
The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of substance use disorder patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a Covered Entity, or Business Associate.
The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.
8.8. HIPAA Business Associate Provisions
8.8.1. Business Associate – General Provisions
The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. The Contractor shall use the DoD BAA, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD Components”, located at, https://www.health.mil/Military-Health-Topics/Privacy-and-Civil-Liberties/Privacy- Contract-Language/HIPAA-Compliant-Business-Associate-Agreement-for-the-MHS. b.i. and (3)b.ii
8.9. Breach Response
8.9.1.1. Definitions Related to Breach response
8.9.1.2. Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The foregoing definition is based on the definition of breach in DoDM 6025.18. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral PII/PHI).
8.9.1.3. A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the Contractor does not initially know whether or not the PII/PHI was encrypted, then the incident shall initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the Contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the Contractor. In determining whether unauthorized access should be suspected, the Contractor shall consider at least the following factors:
• How the event was discovered;
• Did the information stay within the covered entity’s control;
• Was the information actually accessed/viewed; and
• Ability to ensure containment (e.g., recovered, destroyed, or deleted).
8.9.1.4. A confirmed breach is an incident in which it is known that unauthorized access could occur.
For example, if a laptop containing PII/PHI is lost and the Contractor knows that the PII/PHI is unencrypted, then the Contractor should classify and report the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the Contractor knows this even without knowing whether or not unauthorized access to the PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the Contractor should re-classify the incident as a non-breach incident.
8.9.1.5. A HHS breach is an incident that satisfies the definition of breach in Section 164.402 of the
HIPAA Breach Rule. The text of the HHS definition states:
Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.
HHS breach excludes:
Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the HIPAA Privacy Rule.
Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy Rule.
A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.
Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
The unauthorized person who used the PHI or to whom the disclosure was made;
Whether the PHI was actually acquired or viewed; and
The extent to which the risk to the PHI has been mitigated.
8.9.1.6. A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI. A cybersecurity incident may or may not involve a breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI.
However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.
8.9.2. General
8.9.2.1. The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.
8.9.2.2. Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation (which includes individual notification), eradication, recovery, and follow-up.
8.9.2.3. The Contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The Contractor should consult with the DHA Privacy Office where guidance is needed, such as when the Contractor is uncertain whether a discovered breach is the Contractor’s responsibility (e.g., if the Contractor discovers a breach not caused by the Contractor), or how the Contractor is to classify an incident (breach vs. non-breach, confirmed vs. possible, cyber vs. non-cyber). Under no circumstances will a Contractor delay reporting a confirmed or possible breach to the DHA Privacy Office beyond the 24-hour deadline. In conjunction with its initial investigation, the Contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.
8.9.2.4. In the event of a cybersecurity incident not involving a PII/PHI breach, the Contractor shall follow applicable DoD cybersecurity and NIST requirements, which include United States- Computer Emergency Readiness Team (US-CERT) reporting (see paragraph 8.9.3). If at any point a Contractor finds that a cybersecurity incident involves a PII/PHI breach (possible or confirmed), the Contractor shall immediately initiate the reporting procedures set forth below.
The Contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.
8.9.2.5. Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the Contractor immediately after discovery. The time of that report to the Contractor shall trigger the Contractor’s DHA Privacy Office reporting deadline (24 hours) under paragraph 8.9.2.3. If a cybersecurity incident is involved, the Contractor’s deadline for US-CERT reporting (1 hour) runs from the time the incident is confirmed. The Contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the Contractor to complete the breach response requirements herein. Alternatively, the Contractor and subcontractor may agree that the subcontractor shall report directly to US-CERT and the DHA Privacy Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the Contractor of the incident and the subsequent response actions.
8.9.2.6. Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the outcome. Investigations identifying unauthorized disclosures shall be logged for HIPAA and Privacy Act disclosure accounting purposes, whether or not individual notification is required under the HIPAA Breach Rule.
8.9.2.7. Contractors, when acting as HIPAA-covered entities, and not as business associates, are not subject to the breach response requirements herein. However, such Contractors are subject to both the HIPAA Breach Rule (applicable to them in their capacity as covered entities) and DoD cybersecurity requirements (applicable to them in their capacity as DoD Contractors).
8.9.3. Reporting Provisions
8.9.3.1. Immediately upon discovery of a possible or confirmed breach or cybersecurity incident, the
Contractor shall initiate an investigation. If the incident involves electronic PII/PHI, and if the investigation finds a confirmed breach or cybersecurity incident, the Contractor shall report it, within 1 hour of confirmation, to the US-CERT Incident Reporting System at https://forms.us-cert.gov/report/, as required by the Department of Homeland Security (DHS).
Note: DHS no longer requires US-CERT reporting of non-cyber breaches or unconfirmed electronic breaches. However, DHS permits US-CERT reporting of unconfirmed cyber-related incidents on a voluntary basis. Thus, if a Contractor is uncertain whether a possible cyber-related incident should be treated as confirmed and thus reportable, the Contractor may voluntarily report the incident.
Before submission to US-CERT, the Contractor shall save a copy of the on-line report. After submitting the report, the Contractor shall record the US-CERT incident reporting number, which shall be included in the initial report to the DHA Privacy Office as described in paragraph 8.9.3.2.
Note: Regardless of whether or not an incident is confirmed as a breach, the Contractor shall also investigate whether or not the incident impacts data integrity or availability of PII/PHI. If such impact is confirmed, then the incident is reportable to US-CERT as a cybersecurity incident. For guidance on investigating the impact on data integrity and availability, refer to DoD cybersecurity and NIST guidance.
The Contractor shall provide any updates to the initial US-CERT report by email to soc@us-cert.gov, with the Reporting Number in the subject line. The Contractor shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office if requested. Contractor questions about US-CERT reporting shall be directed to the DHA Privacy Office, not the US- CERT office.
8.9.3.2. In addition to US-CERT reporting, the Contractor shall report to the DHA Privacy Office by submitting the form specified below within 24 hours of discovery of a breach (possible or confirmed), unless the breach falls within a category that the Privacy Office has determined to be not reportable (A.006). This 24-hour period runs from the time of discovery, unlike the 1 hour US- CERT reporting period, which runs from the time a cybersecurity incident is confirmed. Thus, depending on the time period needed to confirm, the report to the DHA Privacy Office may be due either before or after the US-CERT report.
The breach report form required within the 24-hour deadline shall be sent by e-mail to:
DHA.PrivacyOfficer@mail.mil. The Contractor shall also e-mail the report to the CO, the COR and its usual point of contact at the applicable Program Office. Encryption is not required, because reports and notices shall not contain PII/PHI. If electronic mail is not available, telephone notification is also acceptable (at 703-275-6363), but all notifications and reports delivered telephonically shall be confirmed in writing as soon as technically feasible.
Contractors shall prepare the breach reports required within the 24-hour deadline by completing the Breach Reporting Department of Defense Form DD 2959 (Breach of PII Report), available at https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf. For non-cyber incidents without a US-CERT number, the Contractor shall assign an internal tracking number and include that number in Box 1.e of the DD Form 2959. The Contractor shall coordinate with the DHA Privacy Office for subsequent action, such as beneficiary notification, and mitigation. The Contractor shall promptly update the DD Form 2959 as new information becomes available.
When a Breach Report Form initially submitted is incomplete or incorrect due to unavailable information, or when significant developments require an update, the Contractor shall submit a revised form or forms promptly after the new information becomes available, stating the updated status and previous report date(s) and showing any revisions or additions in red text.
The Contractor shall provide updates to the same parties as required for the initial Breach Report Form.
8.9.4. Individual Notification Provisions
8.9.4.1. If the DHA Privacy Office determines that individual notification is required, the Contractor shall provide written notification to beneficiaries affected by the breach as soon as possible, but no later than 10 working days after the breach is discovered and the identities and addresses of the beneficiaries are ascertained. The 10 day period begins when the Contractor is able to determine the identities (including addresses) of the beneficiaries whose records were impacted. If notification cannot be accomplished within 10 working days, the Contractor shall notify the DHA Privacy Office.
8.9.4.2. The Contractor’s proposed notification to be issued to the affected beneficiaries shall be submitted to the DHA Privacy Office for approval. The notification to beneficiaries shall include, at a minimum, the following:
• Specific data elements,
• Basic facts and circumstances,
• Recommended precautions the beneficiary can take,
• Federal Trade Commission (FTC) identity theft hotline information, and
• Any mitigation support services offered, such as credit monitoring.
Contractors shall ensure any envelope containing written notifications to affected individuals are clearly labeled to alert the recipient to the importance of its contents, e.g., “Data Breach Information Enclosed,” and that the envelope is marked with the identity of the Contractor and/or subcontractor organization that suffered the breach.
If media notice is required, the Contractor will submit a proposed notice and suggested media outlets for the DHA Privacy Office review and approval (which will include coordination with the DHA Communications Division).
8.9.5. In the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .