Exhibit A - Contract Requirements.pdf

PDF 346 KB Posted

Attached to
Blood Chemistry Testing - Cost Per Reportable Result Federal contract opportunity
Solicitation number
W9114F-26-Q-A010
Issued by
Department of the Army Medical Command

About this file

This document is a contract requirements exhibit for an automated clinical chemistry analyzer and reagents at the Vicenza Army Health Clinic in Italy. The contract requires the contractor to provide one clinical chemistry analyzer and all associated reagents, consumables, controls, and maintenance for chemistry and immunology testing under a Cost Per Reportable Result (CPRR) model. The contract is divided into two periods: a 2-month initial period from January to February 2026, and a 58-month primary period from March 2026 to December 2030.

The analyzer must meet specific technical requirements, including a single point of specimen entry, random access with STAT interrupt capability, ability to handle multiple tube sizes, and FDA approval. The system must perform 27 specific tests including ALT, Albumin, ALP, Cholesterol, Glucose, and others. Additional requirements include providing on-site operator training, method verification studies, full maintenance service, software updates, and compliance with extensive privacy and cybersecurity regulations. The contractor is responsible for all equipment installation, maintenance, calibration, and eventual removal, with strict guidelines around data protection, breach reporting, and individual notification procedures.

View the file

Other files for this federal contract opportunity

Other files attached to Blood Chemistry Testing - Cost Per Reportable Result, newest first.
File Type Posted
Questions and Answers.pdf PDF
W9114F26QA0100002 - RFQ Conformed.pdf PDF
W9114F26QA0100002 - RFQ Amendment .pdf PDF
W9114F26QA0100001 - RFQ Conformed.pdf PDF
Exhibit A - Contract Requirements - 2025.11.14.pdf PDF
W9114F26QA0100001 - RFQ Amendment.pdf PDF
Attachment 1 - Self-Certification for Antimafia.pdf PDF
Exhibit B - Blood Chemistry Estimated Annual Workloads.pdf PDF
Exhibit C - Implementation Plan.pdf PDF
Solicitation_-_W9114F26QA010.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Contract Requirements

1. Scope

1.1. The Contractor shall provide one (1) automated clinical chemistry analyzer and reagents in support of the chemistry mission at Vicenza Army Health Clinic in Vicenza, Italy. The successful offeror shall furnish all equipment, reagents, consumables, controls, and any necessary maintenance to the respective laboratories for the purpose of chemistry/immunology testing under a Cost Per Reportable Result (CPRR). All parts, equipment and reagents/consumables shall be supplied and serviced through the Contractor.

Medical Treatment Facility (MTF) Location Vicenza Army Health Clinic Caserma Carlo Ederle Building 2310, Room F14.1 36100, Vicenza, Italy

1.2. All costs integrated into this contract shall be calculated based on annual test volume.

1.3. All supplies and equipment to include connections between equipment shall be approved by the US Food and Drug Administration (FDA).

1.4. Ordering Periods

Period Dates Analyzer (Per location) Tests

2 Months 1 January 2026 – 28 February 2026 1 Clinical Chemistry

ALT, Albumin, ALP, AST, Bilirubin Direct, Bilirubin Total, BUN, Calcium, CO2, Chloride, Cholesterol, CRP, CK, Creatinine, Ethanol, GGT, Glucose, HDL, HA1C, Iron, LDL, Magnesium, Potassium, Phosphate, Protein Total, Sodium, Transferrin, Triglycerides, UIBC

58 Months 1 MAR 2026 – 31 December 2030 1 Clinical Chemistry

ALT, Albumin, ALP, AST, Bilirubin Direct, Bilirubin Total, BUN, Calcium, CO2, Chloride, Cholesterol, CRP, CK, Creatinine, Ethanol, GGT, Glucose, HDL, HA1C, Iron, LDL, Magnesium, Potassium, Phosphate, Protein Total, Sodium, Exhibit A

Period Dates Analyzer (Per location) Tests

Transferrin, Triglycerides, UIBC

1.5. Government Points of Contact

1.6. The Contractor will provide two copies of the operating manual in English, one of which must be a hard copy and the other another hard copy or digital file.

1.7. Contractor provides for delivery and installation, all required maintenance, and final removal of equipment upon termination of contract.

1.8. Printer cartridges (laser or ink jet), ribbons, or special printer paper (thermal etc.) will be provided by the contractor.

2. Analyzer Requirements

2.1. The analyzer shall have a single point of specimen entry for the routine analysis of all required chemistry and immunoassay tests.

2.2. The analyzer shall include random access, discrete system with STAT interrupt capability and a primary tube sampling system capable of handling 100mm x 16mm, 100mm x 13mm, 75mm x 13mm, and 64mm x 10.25 test tubes. The analyzer shall be capable of accommodating both Becton-Dickinson and Greiner vacutainer tubes. The analyzer shall be capable of directly reading barcode labels applied to primary containers as specified in CLSI standards.

2.3. The analyzer system shall provide users with rapid, reliable test results. These analyzer systems must be capable of performing in low, medium, and high-volume work periods to produce results that are accurate and precise throughout the manufacturer’s stated linearity/analytic measurement range.

2.4. The analyzer shall be able to measure all the requested analytes on an individual sample with a volume of 300 microliters.

2.5. The bilirubin assay must have a range suitable for analyzing neonate specimens and must provide for measuring total bilirubin, direct bilirubin, indirect bilirubin, and neonatal bilirubin

2.6. Albumin, creatinine, and cholesterol assays shall be traceable to nationally recognized reference methodologies.

2.7. The Analyzer initial startup from the shutdown state must not exceed 30 minutes.

2.8. The analyzer system must come equipped with an un-interruptible power supply (UPS) capable of providing all necessary electrical power to each analyzer system, to include the data management system for seven minutes. The UPS must ensure enough power to have seamless, uninterrupted testing for approximately seven minutes in the event of a power outage

2.9. The analyzer systems, connections, and all reagents shall be approved by the Food and Drug Administration (FDA). All analyzers and associated parts and accessories shall be new. No used, refurbished, or like-new equipment shall be provided in support of this contract at any time.

2.10. The Contractor provided analyzer system shall either require no water system or the water system will be provided and maintained by the contractor. Any liquid effluent produced by the analyzer must be capable of disposal according to national Hazardous Waste Regulations.

2.11. The Analyzer provided must have a current Authorization to Operate (ATO) to allow system interface to the Laboratory Information System (LIS). See Paragrah 7; Risk Management Framework (RMF) for DOD IT

2.12. The analyzer will have a large enough College of American Pathologists peer group for proper proficiency testing and data analysis.

3. Reagent Requirements

3.1. The analyzer shall have the on-board ability to maintain reagents at the proper storage temperatures for the assays listed. All assays must be FDA approved.

3.2. The workload listed for the site is an estimate based on historical patient workload. Actual workload may vary. The workload numbers represent patient reportable results, which is less than the test count required to obtain them. Test counts include calibrators, controls, troubleshooting re-runs, and specimen dilutions in addition to the final test reported. However, in order to generate a patient reportable result, all requirements of the laboratories Quality Management Program (QMP) must be met regarding quality control (see Table 1). Daily QC usage, shown below, reflects minimum requirements. The contractor-furnished analyzer system shall not require routine daily quality control more often than once every 24 hours for all analytes specified in this document. Non-routine quality control requirements shall meet or exceed those shown in Table 1.

Table 1: Example of minimum QC usage required by each laboratory’s QMP Routine Daily QC usage (two levels) Once every 24 hours Troubleshooting Yes After calibrations Yes After major maintenance Yes

3.3. The actual workload may fluctuate in the first year of the contract due to changes in the distribution of patient care. In addition, workload may expand or contract in subsequent option years due to fluctuations in patient volume. The workload per site is an estimate for the Base Period of the contract. All workload numbers represent patient reportable/billable results for the indicated year.

3.4. To account for expected fluctuations in workload, the Contractor shall provide a “sliding scale” schedule of reagent cost per test. This schedule shall provide a listing of all available analytes with the cost per reportable patient result for a given workload. As workload increases, the cost per reportable patient result should decrease. The workload will be based on the total number of patient reportable results.

3.5. The analyzer shall be capable of maintaining calibration curves simultaneously for all the assays listed. Calibration curves shall be maintained electronically for the entire period of the calibration validity which shall be a minimum of six months for most of the analytes.

3.6. All the assays must be present on the analyzer at all times.

must have the capability to add/change out reagents/reagent packs with only a minimal calibration/quality control requirement, i.e., must allow the user to calibrate any assay, remove the assay reagent/reagent packs for a period of undetermined time and then reload the reagents/reagent packs to run the assay without the need from recalibrations. Thereby allowing the user to meet work test scheduling requirements specific to the location.

3.8. The Contractor shall optimize the specific arrangement of the reagents/reagent packs for assays that are routinely maintained on the analyzer during the initial installation of the analyzer. The Contractor must ensure that all required reagents/reagents packs are accounted for in the loading plan for the assays that are routinely maintained on the analyzer.

3.9. The Contractor shall provide an estimate of the yearly quantities of reagent/reagent packs, calibrator/standards, and quality control materials required to perform the volume of patient reportable tests for each assay.

3.10. In determining reagent requirements, the Contractor shall consider requirements for routine quality control runs (as defined by the Laboratory Director), routine calibration, periodic calibration/calibration verification in accordance with departmental quality assurance policies and standard operating procedures and troubleshooting of out-of-control assays when calculating the yearly requirements.

3.11. The Contractor shall provide quality control materials IAW requirements outlined in each Laboratory’s QA program and approved the respective Laboratory Director. This includes third-party controls, calibrators, linearity, and verification kits where required/requested by the laboratory.

3.12. The Contractor shall ensure that the following requirements are considered when calculating the yearly requirements: routine quality control runs (as defined by the respective Laboratory Directors and outlined in the Laboratory QA program), routine calibration, periodic calibration/calibration verification (i.e., each assay must be calibrated or have calibration verification performed at intervals not to exceed a 6-month period of time), specimen dilutions, and troubleshooting of out-of-control assays.

3.13. The Contractor shall estimate the volume of user-replaceable maintenance items that will be required to support the analyzer, and any analyzer specific tools/supplies necessary to perform operator-level periodic maintenance tasks, at the level of use specified by the projected workloads. An operator level maintenance tool/spare parts kit shall be provided and replenishment of all expended items shall be made by the contractor at no additional cost to the government. Replenishment shall be made as needed or on a periodic basis not to exceed the normal preventive maintenance cycle.

3.14. All reagents must have a minimum shelf life of six (6) months upon receipt by the Government. If this shelf life requirement cannot be met, the Contractor must identify the guaranteed shelf life after receipt that can be accommodated in their response to the Request for Quotation (RFQ).

3.15. Contractor shall sequester the required quality control materials (to include other manufacturers QC materials) and test reagents and ensure that no more than one (1) lot change for QC material and two (2) lot changes for reagents occurs per contract year. Assays must be stable enough to maintain a single control run (three levels) per 24 hours of testing. The

Exhibit A

3.7. Reagents need not be maintained on the analyzer at the same time, but the analyzers provided

3.16. All reagents provided shall be identical to those used in the FDA 510K approval application. All reagents/reagent packs shall be provided as follows:

Be provided by the manufacturer of the equipment.

Be marked with the required storage temperature.

Be maintained at the proper storage temperature during transportation from the contractor’s storage facility to the Government acceptance site.

Be delivered on time at the appropriate storage temperature.

3.17. The Contractor shall provide the reagents/reagent packs, calibrators/standards, quality control materials, user-replaceable maintenance items, and analyzer specific tools/supplies to assure optimal operating condition, proper design, monitoring and control of equipment, in accordance with the manufacturer regulatory standards.

3.18. The Contractor shall provide reagents/reagent packs, calibrators/standards, quality control materials, user-replaceable maintenance items and analyzer specific tools/supplies to ensure, at a minimum, sustainment of the laboratory’s workloads.

3.19. Emergency orders shall be delivered within 24 hours after the order is placed, excluding weekends, Federal and Local holidays. Emergency orders shall be of the same lot number or calibrators/standards, reagents/reagent packs, or quality control materials currently in use for the assay(s) for which supplies are being requested.

3.20. Preservation and packing shall be performed in accordance with the best commercial practice and in such a manner to afford adequate protection against any damage during shipment from source to destination. All packaging and shipping information shall be clearly marked as to contents on both the shipping documents and the shipping container/box. Deliveries should be made directly to the testing locations during normal business hours, excluding weekends, federal and local holidays.

3.21. Routine services and reagent delivery for all locations will not be required on U.S.

Federal and Italian National Holidays. If a U.S. federal holiday falls on a Saturday, then the official holiday is the preceding Friday. If a U.S. federal holiday falls on a Sunday, then the official holiday is the following Monday.

3.21.1. US Federal Holidays

1st January New Year’s Day 3rd Monday in January Martin Luther King Day 3rd Monday in February Washington’s Birthday Last Monday in May Memorial Day 19th June Juneteenth 4th July Independence Day 1st Monday in September Labor Day 2nd Monday in October Columbus Day

Exhibit A analyzer-reagent system shall provide calibration stability such that calibration is not required upon change of reagent containers/cartridges but rather upon lot change or every six months whichever occurs first. This calibration frequency does not include calibrations required following lot changes, instrument repair or servicing (e.g. field service type maintenance or service, major changes in instrument components that affect readout, QC troubleshooting, etc.)

or other instances as described in the respective Laboratory’s QA program or approved by the respective Laboratory Director.

11th November Veteran’s Day 4th Thursday in November Thanksgivings Day 25th December Christmas Day

3.21.2. Italian National Holidays

New Years Day, January 1st Day of Epiphany, January 6th Easter Monday, First Monday after Easter Liberation Day, 25 April Labor Day, 1 May Republic Day, 2 June Assumption Day, 15 August Feast of Virgin Mary (Vicenza Only), 8 September All Saints’ Day, 1 November National Unity Day, 3 November Immaculate Conception, 8 December Christmas Day, 25 December Saint Stephen’s Day, 26 December

4. Onsite Training

4.1. The Contractor shall provide the following for all testing locations:

4.1.1. The Contractor shall provide initial on-site operator training in English to all technicians assigned to the Government site and normally assigned to perform the associated testing prior to implementation of the analyzer for patient testing.

4.1.2. All on-site training shall include basic analyzer operation, troubleshooting procedures, performance of operator-level periodic preventive maintenance procedures, and use of any data management/quality control software.

4.1.3. The Contractor shall provide off-site training in English for one person from each clinic for each delivery order, if available.

5. Method Verification

5.1. The Contractor shall provide a qualified technical specialist to perform verification studies, in accordance with the College of American Pathologist (CAP) accreditation standards and Laboratory Director requirements, that includes but is not limited to, reference range, linearity, instrument comparison, and decision rules. Technical specialist compiles necessary data for Laboratory Director review. The assigned TSR shall be responsible for the entire method validation/verification.

5.2. The method validation/verification shall be completed and approved by the Laboratory Director prior to reporting of patient results.

5.3. All instrument reagents, calibrators, linearity materials and other required reagents/materials used in the method validation/verification study shall be provided by the Contractor at no additional cost to the Government. These materials shall not be used in the analysis of specimens for patient care.

6. Service and Maintenance

6.1. The Contractor shall meet the following service and maintenance requirements for testing at the location:

6.1.1. The Contractor is required to maintain all equipment installed under this contract except for repairs necessitated by willful damage or negligence on the part of the U.S. Government.

6.1.2. The Contractor shall provide all personnel, equipment, tools, materials, supervision, parts, transportation, and other items and services necessary to perform all required repairs and scheduled preventive maintenance/safety inspections and calibrations of equipment. The performance of scheduled periodic preventive maintenance, safety checks, and calibrations that are not normally performed at the operator level shall be performed by Contractor service personnel in accordance with requirements as specified in the Contractor’s instrument maintenance manual. Completion of installation of the analyzers will establish time zero for determination of time frames for performance of the above periodic services.

6.1.3. The Contractor shall provide a full unscheduled and preventive maintenance service for the lease period at no additional cost. Service shall include repair and replacement of defective parts, complete maintenance program (as required by the manufacturer’s maintenance manuals), and hotline telephone service, to assist operators in troubleshooting problems.

6.1.4. Any service technician provided by the Contractor shall adhere to all required reporting procedures for the respective laboratory prior to reporting to the laboratory for work.

Current procedures will be available through the COR.

6.1.5. In all cases, the Contractor shall provide all reagents, calibrators, controls, and any other materials necessary to troubleshoot instrument failure. Replacement parts used, as necessary, claimed from local operator-level maintenance kits as well as any reagents that may have been used shall be replaced at no cost to the Government.

6.1.6. The Contractor shall notify the COR or designee of the exact date and time for performance of a preventive maintenance service no later than ten (10) calendar days prior to the scheduled preventive maintenance services.

6.1.7. Upon notification of equipment failure, the Contractor shall respond to telephonic requests for unscheduled repair within one (1) business day. A repair service engineer should be available on-site to repair the equipment failure within two (2) business days of the initial contact from laboratory personnel. If the equipment is designated inoperable and out of service for longer than three (3) business days (from the time-of-service technician’s arrival on site), the Contractor shall notify the COR, in writing, as to the reason(s) (i.e. non-availability of parts, etc.) for non-compliance. If the equipment cannot be repaired, a replacement instrument shall be provided within seven (7) business days (from the time-of-service technician’s arrival on site). If the equipment cannot be replaced within seven (7) business days, the Government may seek remedies for damages in accordance with FAR 52.212-4(a), “Contract Terms and Conditions – Commercial Items, Inspection/Acceptance”.

6.1.8. Software add-ons and updates, as they become available, will be included.

6.1.9. All work shall be performed in a professional manner by an authorized service representative. If any deficiencies are found due to negligence of the service representative, the Contractor shall be required to correct the deficiency to a fully operational status in accordance with manufacturer specifications at no additional cost to the U.S. Government.

6.1.10. All correspondence, service reports, safety data sheets and invoicing shall be in the English language.

6.1.11. Preventive maintenance services shall be performed in accordance with the manufacturer’s standards/procedures. A preventive maintenance service shall include, but is not limited to, safety, calibration, complete operational testing, lubrication, adjustments, and cleaning of equipment to which the operator does not have access. This also includes the installation of all non-operator parts required to ensure proper operation. A written record detailing the maintenance performed shall be provided upon completion.

7. RISK MANAGEMENT FRAMEWORK (RMF) for DOD IT

7.1. Risk Management Framework (RMF) for DoD IT: All IS, Platform Information Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data shall be accredited in accordance with DoDI 8510.01, Risk Management Framework (RMF) for DoD IT and comply with annual Federal Information Security Modernization Act (FISMA) security control testing. IS and PIT systems shall be categorized in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, implement a corresponding set of security controls from the NIST SP 800-53, and use assessment procedures from NIST SP 800-53A with additional DoD-specific assignment values, overlays, implementation guidance, and assessment procedures as required.

7.1.1. All systems subject to RMF shall present evidence of authorization in the System Security Plan, Security Assessment Report) a Plan of Action and Milestones (POA&M) and authorization decision document or show that the system has a DoD RMF or equivalent DoD Component PIT system accreditation decision that is current within 3 years within 5 business days of Contracting Officer request. Evidence of FISMA compliance shall be presented in the form of a POA&M. Systems shall have and maintain an Authority to Operate (ATO) or Authority to Operate with Conditions (ATO-C) by contract award.

7.1.2. The contractor shall implement security controls in accordance with NIST implementation and validation requirements specified in the NIST SP 800-37 Risk Management Framework (RMF) and DoDI 8510.01, Risk Management Framework (RMF).

7.1.3. The contractor shall configure the information system in accordance with Defense Information Agency (DISA) Security Requirements Guides (SRGs) and security technical implementation guides (STIGs).

7.1.4. The contractor shall ensure that the information system conforms to the requirements of DoDI 8551.01 “Ports, Protocols, and Services Management (PPSM)”.

7.1.5. The contractor shall ensure that the information system shall authenticate all entities as specified in DoDI 8520.03 “Identity Authentication for Information Systems” prior to granting access.

signature and encryption requirements specified in DoDI 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK) Enabling”.

7.1.7. The contractor will be responsible for compliance with the Joint Force Head Quarters – Department of Defense Information Network issuances and IA Vulnerability Management (IAVM) issuances by ensuring that the issuances are assessed, implemented and maintained throughout development and sustainment in accordance with specified timelines.

7.1.8. The contractor shall support reciprocity, by providing all directed information in NIST security documents to the government.

7.1.9. The contractor shall implement system level protection and detection capabilities that are consistent with their contract for NIST Security requirements that meet DoD and DHA Cybersecurity Architectures.

7.1.10. Cyber Incident Reporting Requirement: The contractor shall comply with the incident management requirements of Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, “Cyber Incident Handling Program”.

7.1.11. Information security continuous monitoring (ISCM): ISCM is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is a critical part of the risk management process to ensure that IS and PIT operations remain within an acceptable level of risk despite any changes that occur. The Contractor shall maintain ongoing monitoring, analysis and incident response procedures for all ARRT and PIT systems under this requirement in accordance with NIST SP 800-137.

7.1.12. The contractor shall mitigate supply chain risk to the government by complying with DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities

(UC).

8. PERSONALLY IDENTIFIABLE INFORMATION, PROTECTED HEALTH INFORMATION, AND

FEDERAL INFORMATION REQUIREMENTS (REVISED 10/27/2020)

8.1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.

This Contract incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures. Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD

Exhibit A

7.1.6. The contractor shall Public Key (PK) enable the information system, implementing digital https://aplits.disa.mil/processAPList implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.

For purposes of this Section, the following definitions apply.

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDI 5400.11, DoD Privacy and Civil Liberties Programs, January 29, 2019 and DoDI 5400.11- R, Department of Defense Privacy Program, May 14, 2007.

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E (Enforcement), as amended.

Additional HIPAA rules regarding electronic transactions and code sets (45 CFR Part 162) are not addressed in this Section and are not included in the term HIPAA Rules.

DoD HIPAA Issuances means the DoD issuances implementing the HIPAA Rules in the DoD Military Health System (MHS). These issuances are DoDM 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in DoD Health Care Programs,” March 13, 2019, DoDI 6025.18, Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs, March 13, 2019, and DoDI 8580.02, Security of Individually Identifiable Health Information in DoD Health Care Programs, August. 12, 2015.

Defense Health Agency (DHA) Privacy Office is the DHA Privacy and Civil Liberties Office.

The DHA Privacy Office Chief is the HIPAA Privacy and Security Officer for DHA.

8.2. Records Management

When creating and maintaining official Government records, the Contractor shall comply with all federal requirements established by 44 United States Code (U.S.C.) Chapters 21, 29, 31, 33 and 35, and by 36 CFR, Chapter XII, Subchapter B – Records Management. The Contractor shall also comply with DoD Administrative Instruction No. 15 (DoD AI-15), “OSD Records and Information Management Program” (May 3, 2013) and Records Management requirements outlined in the current TRICARE Operations Manual (TOM).

8.3. Freedom of Information Act (FOIA)

The Contractor shall comply with the following procedures if it receives a FOIA request and immediately contact the DHA FOIA Officer for evaluation/action:

The Contractor shall inform beneficiaries that DHA FOIA procedures require a written request preferably sent via the National FOIA Portal at: www.FOIA.gov. However, requesters may also submit requests via email at DHA.FOIA@mail.mil; or via postal delivery addressed to the DHA Freedom of Information Service Center, 7700 Arlington Boulevard, Suite 5101, Falls Church, Virginia 22042-5101. All FOIA requests shall describe the desired record as completely as possible to facilitate its retrieval from files and to reduce search fees which may be borne by the requestor. Contract and/or Modification numbers shall be included in all FOIA requests seeking DHA procurement records. Although the administrative time limit to grant or deny a request (ten working days after receipt) does not begin until the request is received by DHA, the Contractor shall act as quickly as possible and respond to DHA within ten working days.

Exhibit A http://www.dtic.mil/whs/directives

In response to requests received by the Contractor for the release of information, unclassified information, documents and forms which were previously provided to the public as part of routine services shall continue to be made available in accordance with previously established criteria. All other requests from the public for release of DHA records and, specifically, all requests that reference FOIA shall be immediately forwarded to DHA, ATTENTION: Freedom of Information Officer, for appropriate action. Direct contact, including interim replies, between TRICARE Contractors and such requestors is not authorized. The Contractor shall process requests by individuals for access to records about themselves in accordance with directions from the DHA Freedom of Information Service Center. If such a requestor specifically makes the request under the Privacy Act or does not make clear whether the request is made under FOIA or the Privacy Act, the Contractor shall process the request in accordance with directions from the DHA Privacy Office. If requestor specifically seeks PHI under HIPAA, the Contractor shall follow paragraph 8.1.6, relating to individual rights of access to PHI.

8.4. Systems of Records

In order to meet the requirements of the Privacy Act and the DoD Privacy Act Issuances, the Contractor shall identify to the DHA Contracting Officer (CO) systems of records that are or will be maintained or operated for DHA where records of PII collected from individuals are maintained and specifically retrieved using a personal identifier. Upon identification of such systems to the CO, and prior to the lawful operation of such systems, the Contractor shall coordinate with the DHA Privacy Office to complete systems of records notices (SORNs) for submission and publication in the Federal Register as coordinated by the Defense Privacy, Civil Liberties, and Transparency Division, and as required by the DoD Privacy Act Issuances.

Following proper SORN publication and Government confirmation of Contractor authority to operate the applicable system(s), the Contractor shall also comply with the additional systems of records and SORN guidance, in coordination with the DHA Privacy Office, regarding periodic system review, amendments, alterations, or deletions set forth by the DoD Privacy Act Issuances, Office of Management and Budget (OMB) Memorandum 99-05, Attachment B, OMB Circular A- 130, and Privacy Act of 1974 requirements applicable to Contractors operating systems of records on behalf of federal agencies. The Contractor shall promptly advise the DHA Privacy Office of changes in systems of records or their use that may require a change in the SORN.

8.5. Privacy Impact Assessment (PIA)

If DHA data is stored on a Contractor owned system, a PIA is required from the Contractor.

8.6. Data Sharing Agreement (DSA)

8.6.1. (Applies if contract requirements involve the use of DHA data (including PII/PHI, a limited data set, or de-identified data)

The Contractor shall consult with the DHA Privacy Office to determine if the Contractor shall obtain a DSA or Data Use Agreement (DUA), when DHA data will be accessed, used, disclosed or stored, to perform the requirements of this Contract.

The Contractor shall comply with the permitted uses established in a DSA/DUA to prevent the unauthorized use and/or disclosure of any PII/PHI, in accordance with the HIPAA Rules

• DSA for De-Identified Data

• DSA for PHI

• DSA for PII Without PHI

• DUA for Limited Data Set

DSAs executed for contract support will expire after 1 year or at the end of the contract option year, whichever comes first. If the contractual use of DHA data will continue after the DSA expiration date, the Contractor shall submit a DSA Renewal Request template to the Privacy Office; however, if the DSA will not be renewed, the Contractor shall close the DSA by providing a Certificate of Data Disposition (CDD) to the DHA Privacy Office.

8.6.2. (Applies if contract requirements may include human subject research)

This Contract incorporates by reference the Protection of Human Subject Research clause in the Defense Federal Acquisition Regulation Supplement (DFARS) at 48 CFR 252.235- 7004. A separate DFARS provision, 48 CFR 235.072(e), requires that the clause be incorporated in contracts that include or may include research involving human subjects in accordance with 32 CFR 219, DoDI 3216.02, and 10 U.S.C. 980, including research that meets exemption criteria under 32 CFR 219.101(b), the clause applies to solicitations and contracts awarded by any DoD component, regardless of mission or funding Program Element Code. Thus, in the event a Contractor participates in a study or demonstration project or other activity that involves human subject research, then the Contractor shall comply with Protection of Human Subject Research clause. COs may not determine whether an activity is exempt from human subject research requirements. If Contractor activity appears to involve human subject research, then the Contractor shall consult the DHA Privacy Office, which may contact the Research Regulatory Oversight Office in the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)).

8.7. Privacy Act and HIPAA Training

The Contractor shall ensure that its entire staff, including subcontractors and consultants that perform work on this Contract receive training on the Privacy Act, HIPAA, and the federal regulations on confidentiality of substance use disorder patient records, 42 CFR Part 2. Refer to FAR 52.224-3 regarding specific requirements for Privacy Training appropriate to the Contractor’s scope of involvement with DHA’s PHI and its regulatory responsibilities as either a Covered Entity, or Business Associate.

The Contractor shall ensure all employees and subcontractors supply a certificate of all training completion to the Contracting Officer’s Representative (COR) within 30 days of being assigned and on an annual basis based on the trainee’s birth month thereafter.

Exhibit A and DoD HIPAA Issuances. Likewise, the Contractor shall comply with the DoD Privacy Act Issuances.

Prior to using any data involving PHI for research purposes, as defined by HIPAA, the Contractor shall gain approval from the DHA Privacy Board. Thus, the Contractor shall comply with DHA Privacy Board requests for additional documentation.

To begin the DSA request process, the Contractor shall submit a DSA Application (DSAA) to the DHA Privacy Office. Upon approval, the requestor shall enter into one of the following agreements, depending on the data involved:

8.8. HIPAA Business Associate Provisions

8.8.1. Business Associate – General Provisions

The Contractor meets the definition of Business Associate, and DHA meets the definition of a covered entity under the HIPAA Rules and the DoD HIPAA Issuances. Therefore, a Business Associate Agreement (BAA) between the Contractor and DHA is required to comply with the HIPAA Rules and the DoD HIPAA Issuances. The Contractor shall use the DoD BAA, which shall be used by all organizational entities within the DoD, referred to collectively as the “DoD Components”, located at, https://www.health.mil/Military-Health- Topics/Privacy-and-Civil-Liberties/Privacy-Contract-Language/HIPAA-Compliant- Business-Associate-Agreement-for-the-MHS. b.i. and (3)b.ii

8.9. Breach Response

[This paragraph 9 is inoperative, and all references herein to “paragraph 9” shall be deemed to refer to the TOM breach responses provisions, if the contract incorporates the TOM by reference

8.9.1.1. Definitions Related to Breach response

8.9.1.2. Breach means a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose. The foregoing definition is based on the definition of breach in DoDM 6025.18. Breaches are classified as either possible or confirmed (see the following two definitions) and as either cyber or non-cyber (i.e., involving either electronic PII/PHI or paper/oral

PII/PHI).

8.9.1.3. A possible breach is an incident where the possibility of unauthorized access is suspected (or should be suspected) and has not been ruled out. For example, if a laptop containing PII/PHI is lost, and the Contractor does not initially know whether or not the PII/PHI was encrypted, then the incident shall initially be classified as a possible breach, because it is impossible to rule out the possibility of unauthorized access to the PII/PHI. In contrast, that possibility can be ruled out immediately, and a possible breach has not occurred, when misdirected postal mail is returned unopened in its original packaging. However, if the intended recipient informs the Contractor that an expected package has not been received, then a possible breach exists until and unless the unopened package is returned to the Contractor. In determining whether unauthorized access should be suspected, the Contractor shall consider at least the following factors:

• How the event was discovered;

• Did the information stay within the covered entity’s control;

• Was the information actually accessed/viewed; and

• Ability to ensure containment (e.g., recovered, destroyed, or deleted).

8.9.1.4. A confirmed breach is an incident in which it is known that unauthorized access could occur. For example, if a laptop containing PII/PHI is lost and the Contractor knows that the PII/PHI is unencrypted, then the Contractor should classify and report

8.9.1.5. A HHS breach is an incident that satisfies the definition of breach in Section

164.402 of the HIPAA Breach Rule. The text of the HHS definition states:

Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under subpart E of this part [i.e. the HIPAA Privacy Rule] which compromises the security or privacy of the PHI.

HHS breach excludes:

Any unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a DoD covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the HIPAA Privacy Rule.

Any inadvertent disclosure by a person who is authorized to access PHI at a DoD covered entity or business associate to another person authorized to access PHI at the same DoD covered entity or business associate, or organized health care arrangement in which the DoD covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted the HIPAA Privacy Rule.

A disclosure of PHI where a DoD covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.

Except as provided in this definition, an acquisition, access, use, or disclosure of PHI in a manner not permitted under this issuance is presumed to be a breach unless the DoD covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;

The unauthorized person who used the PHI or to whom the disclosure was made;

Whether the PHI was actually acquired or viewed; and

The extent to which the risk to the PHI has been mitigated.

8.9.1.6. A cybersecurity incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices, with respect to electronic PII/PHI. A cybersecurity incident may or may not involve a

Exhibit A the incident as a confirmed breach, because unauthorized access could occur due to the lack of encryption (the Contractor knows this even without knowing whether or not unauthorized access to the PII/PHI has actually occurred). If the laptop is subsequently recovered and forensic investigation reveals that files containing PII/PHI were never accessed, then the possibility of unauthorized access can be ruled out, and the Contractor should re-classify the incident as a non-breach incident.

8.9.2. General

8.9.2.1. The breach response requirements shall be followed for all unauthorized use or disclosure of information regardless of whether the information is PHI or solely PII.

8.9.2.2. Because DoD defines “breach” to include possible (suspected), as well as actual (confirmed) breaches, the Contractor shall implement these breach response requirements immediately upon the Contractor’s discovery of a possible breach. These procedures focus on the first two steps (breach identification and reporting) of a comprehensive breach response program, but also require addressing the remaining steps: containment, mitigation (which includes individual notification), eradication, recovery, and follow-up.

8.9.2.3. The Contractor shall establish internal processes for carrying out the procedures set forth below. These processes shall assign responsibility for investigating, classifying, reporting and otherwise responding to breaches and cybersecurity incidents. The Contractor should consult with the DHA Privacy Office where guidance is needed, such as when the Contractor is uncertain whether a discovered breach is the Contractor’s responsibility (e.g., if the Contractor discovers a breach not caused by the Contractor), or how the Contractor is to classify an incident (breach vs.

non-breach, confirmed vs. possible, cyber vs. non-cyber). Under no circumstances will a Contractor delay reporting a confirmed or possible breach to the DHA Privacy Office beyond the 24-hour deadline. In conjunction with its initial investigation, the Contractor shall immediately take steps to minimize any impact from the occurrence, proceed with further investigation of any relevant details (such as root causes, vulnerabilities exploited), and initiate further breach response steps.

8.9.2.4. In the event of a cybersecurity incident not involving a PII/PHI breach, the Contractor shall follow applicable DoD cybersecurity and NIST requirements, which include United States- Computer Emergency Readiness Team (US-CERT) reporting (see paragraph 8.9.3). If at any point a Contractor finds that a cybersecurity incident involves a PII/PHI breach (possible or confirmed), the Contractor shall immediately initiate the reporting procedures set forth below. The Contractor shall also continue to follow any required cybersecurity incident response procedures and other applicable DoD cybersecurity requirements.

8.9.2.5. Contractors shall require subcontractors who discover a possible breach or cybersecurity incident to initiate the incident response requirements herein by reporting the incident to the Contractor immediately after discovery. The time of that report to the Contractor shall trigger the Contractor’s DHA Privacy Office reporting deadline (24 hours) under paragraph 8.9.2.3. If a cybersecurity incident is involved, the Contractor’s deadline for US-CERT reporting (1 hour) runs from the time the incident is confirmed. The Contractor shall require the subcontractor to cooperate as necessary to meet these deadlines, maintain records, and otherwise enable the Contractor to complete the breach response requirements herein. Alternatively, the Contractor and subcontractor may agree that the subcontractor shall report directly to

Exhibit A breach of PII/PHI. For example, a malware infection would be a possible breach if it could cause unauthorized access to PII/PHI. However, if the malware only affects data integrity or availability (not confidentiality), then a non-breach cybersecurity incident has occurred.

8.9.2.6. Contractors shall maintain records of all breach and cybersecurity incident investigations, regardless of the outcome. Investigations identifying unauthorized disclosures shall be logged for HIPAA and Privacy Act disclosure accounting purposes, whether or not individual notification is required under the HIPAA Breach Rule.

8.9.2.7. Contractors, when acting as HIPAA-covered entities, and not as business associates, are not subject to the breach response requirements herein. However, such Contractors are subject to both the HIPAA Breach Rule (applicable to them in their capacity as covered entities) and DoD cybersecurity requirements (applicable to them in their capacity as DoD Contractors).

8.9.3. Reporting Provisions

8.9.3.1. Immediately upon discovery of a possible or confirmed breach or cybersecurity incident, the Contractor shall initiate an investigation. If the incident involves electronic PII/PHI, and if the investigation finds a confirmed breach or cybersecurity incident, the Contractor shall report it, within 1 hour of confirmation, to the US-CERT Incident Reporting System at https://forms.us-cert.gov/report/, as required by the Department of Homeland Security (DHS).

Note: DHS no longer requires US-CERT reporting of non-cyber breaches or unconfirmed electronic breaches. However, DHS permits US-CERT reporting of unconfirmed cyber-related incidents on a voluntary basis. Thus, if a Contractor is uncertain whether a possible cyber-related incident should be treated as confirmed and thus reportable, the Contractor may voluntarily report the incident.

Before submission to US-CERT, the Contractor shall save a copy of the on-line report.

After submitting the report, the Contractor shall record the US-CERT incident reporting number, which shall be included in the initial report to the DHA Privacy Office as described in paragraph 8.9.3.2.

Note: Regardless of whether or not an incident is confirmed as a breach, the Contractor shall also investigate whether or not the incident impacts data integrity or availability of PII/PHI. If such impact is confirmed, then the incident is reportable to US-CERT as a cybersecurity incident. For guidance on investigating the impact on data integrity and availability, refer to DoD cybersecurity and NIST guidance.

The Contractor shall provide any updates to the initial US-CERT report by email to soc@us-cert.gov, with the Reporting Number in the subject line. The Contractor shall provide a copy of the initial or updated US-CERT report to the DHA Privacy Office if requested. Contractor questions about US-CERT reporting shall be directed to the DHA Privacy Office, not the US-CERT office.

8.9.3.2. In addition to US-CERT reporting, the Contractor shall report to the DHA Privacy Office by submitting the form specified below within 24 hours of discovery of

Exhibit A

US-CERT and the DHA Privacy Office, and that the subcontractor shall be responsible for completing the response process, provided that such agreement requires the subcontractor to inform the Contractor of the incident and the subsequent response actions.

mailto:soc@us-cert.gov a breach (possible or confirmed), unless the breach falls within a category that the Privacy Office has determined to be not reportable (A.006). This 24-hour period runs from the time of discovery, unlike the 1 hour US- CERT reporting period, which runs from the time a cybersecurity incident is confirmed. Thus, depending on the time period needed to confirm, the report to the DHA Privacy Office may be due either before or after the US-CERT report.

The breach report form required within the 24-hour deadline shall be sent by e-mail to: DHA.PrivacyOfficer@mail.mil. The Contractor shall also e-mail the report to the CO, the COR and its usual point of contact at the applicable Program Office.

Encryption is not required, because reports and notices shall not contain PII/PHI. If electronic mail is not available, telephone notification is also acceptable (at 703-275- 6363), but all notifications and reports delivered telephonically shall be confirmed in writing as soon as technically feasible.

Contractors shall prepare the breach reports required within the 24-hour deadline by completing the Breach Reporting Department of Defense Form DD 2959 (Breach of PII Report), available at https://www.esd.whs.mil/Portals/54/Documents/DD/forms/dd/dd2959.pdf. For non-cyber incidents without a US-CERT number, the Contractor shall assign an internal tracking number and include that number in Box 1.e of the DD Form 2959. The Contractor shall coordinate with the DHA Privacy Office for subsequent action, such as beneficiary notification, and mitigation. The Contractor shall promptly update the DD Form 2959 as new information becomes available.

When a Breach Report Form initially submitted is incomplete or incorrect due to…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .