PWS_GCSS-Army_Integration_V1.13.pdf

PDF 188 KB Posted

Attached to
Systems Integration into Global Combat Support System Army (GCSS-Army) Federal contract opportunity
Solicitation number
W9124J-17-R-GCSS
Issued by
Department of the Army Materiel Command Mission and Installation Contracting Command Fort Sam Houston

About this file

Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to Systems Integration into Global Combat Support System Army (GCSS-Army), newest first.
File Type Posted
Sources_Sought_Questions_with_Reponses.docx DOCX document
Exhibit_A_PRS.pdf PDF
Attachment_2_DOD_Requirements_Validation_Instructions_and_Template.pdf PDF
Attachment_1_Health_Readiness_Center_of_Excellence_(HRCoE)_Problem_Statement_v2_(11_J....pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

FOR NON-PERSONAL SERVICES

1. GENERAL. This is a non-personal services contract to provide support to Medical Logistics (MEDLOG) systems integration into Global Combat Support System –Army (GCSS-Army), at the Defense Medical Logistics Center, Fort Detrick, MD and Defense Health Headquarters, Falls Church, VA. The government will not exercise any supervision or control over the contract service providers (CSPs) performing the services herein. Such CSPs shall be accountable solely to the contractor who in turn is responsible to the government.

1.1. Background.

1.1.1. The United States Army has been fielding GCSS-Army to units since FY14. GCSS-Army will replace the Property Book Unit Supply Enhanced (PBUSE) System, the Standard Army Maintenance System-Enhanced (SAMS-E), the Standard Army Maintenance System Installation Enhanced (SAMS-IE), Materiel Management Workstation (MMWS) and the Fleet Logistics Management System (FLMS) and bring all functionality into a single, integrated common operating picture. All medical maintenance operations within the operating force depend on SAMS-E and will be directly impacted by conversion to GCSS-Army. This will not impact the Generating Force Medical Supply Support Activity and medical maintenance systems, which will continue to use the current systems.

1.1.2 The Army’s current automated information systems environment is comprised of many non-integrated systems that operate in a stand-alone capacity. A majority of the Army’s legacy Sustainment Information Systems (SIS) are being replaced with an integrated, commercial-off-the-shelf (COTS) Enterprise Resource Planning (ERP) solution. The solution, at the tactical and installation levels, is the Global Combat Support System-Army (GCSS-Army). GCSS-Army provides commanders and staffs, at all levels, with near real-time logistics and financial data, for more timely and sound decision-making. GCSS-Army will enable auditability of financial operations, as mandated by Congress. GCSS-Army began fielding Wave 1 in 1st Quarter of FY13, and is replacing the Standard Army Retail Supply System (SARSS) in Supply Support Activities (SSAs), to include the SSAs’ materiel and financial management systems.

1.1.3 GCSS-Army Wave 2 will impact every Command, unit supply room, field maintenance activity and property book office in the Army, totaling 140,000 users. GCSS-Army will replace the Property Book Unit Supply Enhanced (PBUSE) System, the Standard Army Maintenance

System-Enhanced (SAMS-E), the Standard Army Maintenance System Installation Enhanced (SAMS-IE), Materiel Management Workstation (MMWS) and the Fleet Logistics Management System (FLMS) and bring all functionality into a single, integrated common operating picture.

Army Logistics business processes and supporting Information Technology (IT) are designed for enterprise management and represent an Operating Company Model.

1.1.4. MEDLOG business processes and supporting Information Technology (IT) are designed for local management at each Military Treatment Facilities (MTF)and in a Holding Company Model. The associated management processes are redundant. The efforts to optimize standardization and materiel sourcing are decentralized. The requirements and performance data must be collected from multiple sources (DMLSS, TEWLS, and JMAR).

1.1.5. Our supply chain medical materiel management processes are replicated at every post, camp and station. Decisions on sourcing materiel are done locally. Although some master data is centralized, most of the data is managed locally, which causes many errors and man hours.

1.1.6. Our Installation Medical Supply Activity (IMSA) customers do not have a seamless IT support structure to deploy and integrate with Army operation processes.

1.1.7. The Defense Medical Logistics – Enterprise Solution (DML-ES) automated information systems (AIS’s) support the management of retail and wholesale medical logistics business processes in Military Treatment Facilities (MTFs), warehouses and in field environments. The end-users are military logistics personnel, medical planners and health care providers (including physicians, nurses, ancillary services personnel, dental/optical personnel, occupational/environmental health staff, and biomedical equipment and facilities maintenance technicians). DML AIS’s enable health care providers to deliver cost-effective, state-of-the-art healthcare to patients worldwide. DML AIS’s have been rebranded under the descriptor of Defense Medical Logistics - Enterprise Solution (DML-ES) for the MED LOG enterprise system which takes proven applications that have strong business processes and makes them simpler to use.

1.1.8. Using IT integration, the Defense Medical Logistics - Enterprise Solution (DML-ES) forms a tailored, end-to-end business framework for medical logistics supply chain management. The DML-ES employs strategies to migrate from Medical Treatment Facility (MTF) Centric to Enterprise Centric Capability to reduce variation, increase supply chain agility and be a key enabler for Patient safety, Standardization and committed volume purchasing. The following applications are components of Defense Medical Logistics - Enterprise Solution (DML-ES):

1.1.8.1 Defense Medical Logistics Standard Support (DMLSS) component is migrating to a thin client technical structure and is highly leveraged to provide functions such as Asset Management, Materiel Management, Assemblage Maintenance, Equipment and Biomedical Maintenance Management, and Facility/Environment of Care Management. DMLSS serves in the distinct role of providing integrated medical logistics support for the full spectrum of health care facilities business needs to support prevention, primary, secondary and tertiary medical care. DMLSS brings together an integrated suite of logistics modules to support the continental United States and Overseas medical treatment facilities. The use of DMLSS allows Service members to train on the IT system they will use in theater environments. DMLSS has a robust acquisition capability, and interfaces financial processes with all Service Components. DMLSS partners with Defense Logistics Agency –Troop Support (DLA-TS) as the CLASS VIII Executive Agency and Prime Vendors (PV) to obtain materiel (Consumables, Equipment, Services) to provide Department of Defense (DOD) medical professionals with the tools for the delivery of medical care. Key Attributes:

1.1.8.1.1. Supports in-garrison and deployed Active Duty and Reserve medical logisticians across a joint environment.

1.1.8.1.2. Fully integrated medical logistics functionality. Supports medical supply, equipment maintenance, facility management, and assemblage management.

1.1.8.1.3. Enables compliance with DoD, federal regulations and Food And Drug Administration (FDA) and Joint Commission standards.

1.1.8.1.4. Full supply chain management for Class VIII supplies.

1.1.8.1.5. Fully capable DMLSS Remote Support/Sustainment Concept of Operations (CONOPS) and model.

1.1.8.1.6. Tiered help desk support.

1.1.8.1.7. Federal Financial Management Improvement Act (FFMIA) of 1996 compliant.

1.1.8.2. Theater Enterprise Wide Logistics System (TEWLS) component is highly leveraged to fulfill centralized business level functions such as Depot Operations, Assembly Build and Management, Combat Developer Planning, Supply Chain Distribution, and Lifecycle Management. TEWLS is a centralized solution within an enterprise resource planning SAP-based, net centric service oriented architecture. It supports joint and coalition forces and provides support to U.S. Embassies. TEWLS reduces complexity; uses industry standards and best practices. The central functionality significantly improves information standardization and visibility, and relieves tactical units from complex processes of inventory management and supplier relationships and keeps to a minimum the number of levels for materiel management within Theater.

1.1.8.3. Joint Medical Asset Repository (JMAR) component is highly leveraged as the DML-ES Data Warehouse to provide functions such as Business Intelligence (BI) and Decision Support (DS), and to fulfill enterprise level business functions that are best optimized in the Data Warehouse (DW) component. JMAR is a web-enabled repository that captures inventory and transactions from distributed medical logistics systems to provide visibility, business intelligence and flexible reporting on materiel inventory, status and location to support Defense Health Agency (DHA) Medical Logistics (MEDLOG) Shared Services. JMAR is a key source of data used for DHA MEDLOG Shared Services Performance Metrics for medical materiel standardization and purchasing optimization as well as Planning, Procurement and Sustainment of Equipment. JMAR collects medical logistics data from 31 DOD source systems and provides external data interfaces to facilitate critical logistics programs such as the FDA shelf life extension, Defense Logistics Agency (DLA), MMC for Theater Lead Agent for Medical Materiel

(TLAMM) inventories and MEDLOG Common Operating pictures. JMAR is designated as the authoritative source for aggregated Medical Logistics data provided to the DoD Asset Visibility program. This capability facilitates Enterprise historical trending and analysis to enable proactive forecasting and data driven decisions. JMAR provides clinical views of high visibility inventories to support pandemic influenza and Chemical, Biological, Radiological, and Nuclear CBRN contingencies.

1.1.8.4. DMLSS Customer Assistance Module (DCAM) and Patient Movement Items Tracking System (PMITS) are niche products designed to fulfill specific business needs of the DML-ES and are integrated into the enterprise system specifically for their niche business processes.

DCAM provides the far forward continuum of care a laptop-based simplified automated tool for clinicians and other non-logisticians to electronically download catalog data from their supporting MEDLOG unit, place orders and view order status.

1.1.8.5. The DML-ES suite of applications are interoperable and forms a tailored, end-to-end business framework for medical logistics supply chain management. This framework provides a set of business process and IT solutions for total life cycle management of the medical products and services required to deliver the joint Medical Logistics capability. It supports the materiel needs of the Defense Health Agency (DHA) for delivery of cost-effective, state-of-the-art healthcare worldwide. This framework provides a “continuum of IT capability" that overcomes the challenges of global operations.

1.2. Scope of work.

1.2.1. The contractor shall provide qualified personnel, services, materials, equipment, supplies and facilities necessary to perform an Enterprise Architecture Analysis for MEDLOG integration with GCSS-Army and assist the Army Medical Logistics Enterprise (AMLE) and Combined Arms Support Command (CASCOM) with implementation of the future state of MEDLOG in GCSS- Army as described in the EAA.

1.2.1.1. The contractor shall perform the services listed in paragraph 5 for the operating force and programs that support the operating force such as Army Prepositioned Stock (APS) and the Theater Lead Agent for Medical Materiel (TLAMM).

1.2.2. The contractor shall comply with all applicable laws, rules and regulations, including but not limited to those listed in paragraph 6 of the PWS.

1.3. Safety Requirements. The contractor shall maintain safety and health standards compliant with requirements of the Occupational Safety and Health Administration (OSHA).

1.3.1. All CSPs shall comply with the installation vehicle registration policies and procedures, and all safety procedures and practices associated with the facility.

1.4. Security Requirements. The contractor shall be responsible for the security of all Soldier information.

1.4.1. Neither the contractor nor any of its CSPs shall disclose or cause to disseminate any information concerning operations of military activities. Such action(s) could result in violation of the contract and possible legal actions.

1.4.2. All inquiries, comments or complaints arising from any matter observed, experienced, or learned of as a result of or in connection with the performance of this contract, the resolution of which may require the dissemination of official information, shall be directed to the contracting officer representative (COR) and the contracting officer (KO).

1.4.3. The contractor shall only conduct business with designated government personnel listed as points of contact (POCs). Names of authorized personnel will be provided to the contractor by the government, in writing, within three days after contract award, and will be updated as necessary throughout the contract period.

1.4.4. US Government records, copies of original results and reports, verified original data, corrected data, and corrected supporting final reports are maintained by the contractor, but remain the property of the US Government. These files/results shall be surrendered to the COR.

1.4.5. TRUSTED ASSOCIATED SPONSORSHIP SYSTEM (TASS).

1.4.5.1. The contractor shall comply with agency personal identity verification procedures that implement Homeland Security Presidential Directive-12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201.

1.4.5.2. The contractor shall comply with agency personal identity verification procedures in all subcontracts when the subcontractor is required to have physical access to a federally controlled facility or access to a Federal information system.

1.4.5.3. The contractor shall ensure compliance with the provisions set forth below. For purposes of the Federal Acquisition Regulation (FAR) Clause 52.204-9, the government will designate a Trusted Agent (TA) for this contract. The government reserves the right to amend or supplement these provisions pursuant to the Changes clause in the contract.

1.4.5.4. The contractor is responsible for absences of CSPs due to expired identification and access documents. Such absences shall not relieve the contractor of its obligation to perform the services required under this contract.

1.4.5.5. In-processing Requirements. The CSPs are prohibited from performing services under this contract absent compliance with the in-processing requirements set forth below.

1.4.5.6. The government will sponsor the contract CSPs for an Army Knowledge Online (AKO) account. All CSP e-mail addresses will identify them as a contractor and use the format firstname.lastname.ctr@us.army.mil. The AKO account will be discontinued by the government when the CSPs no longer require access.

1.4.5.7. The government TA will send a notice through the TASS to the AKO e-mail address provided IAW the above requirement. The CSP’s user ID and password will be provided in the e-mail and will be require a change at first log-in. In the event the e-mail message is not received, the contractor may request the username and password from the TA and proceed to the website https://www.dmdc.osd.mil/tass to complete the process.

1.4.5.8. The CSP shall log into the TASS and complete the verification process by submitting the application back to the TA for approval.

https://www.dmdc.osd.mil/tass

1.4.5.9. The application will be accepted, returned, or rejected by the TA. Notice as to whether the application has been accepted, returned, or rejected will be provided to the CSP’s e-mail address within 48 hours after submission. If the application is returned or rejected, the CSP shall contact the TA and comply with the TA’s guidance to attempt to correct and resolve the issue(s).

1.4.5.10. Upon approval of the application, the CSP will receive an e-mail stating the CAC application was approved. The applicant must then go to a RAPIDS Issuing Facility to have the government credential issued. To make an appointment, the CSP shall follow the instructions provided by the TA and contact the COR for instructions. The CSP shall present two acceptable forms of ID which may include: Driver's License, Military ID, Contractor Company ID with picture and expiration date, charge card with picture imprinted, or passport.

1.4.5.11. Revalidation Requirements. The TA is required to revalidate all CSPs, in the TASS, every 6 months. In the event revalidation is denied, the CAC credentials shall be revoked and the CAC will not be useable to log in.

1.4.5.12. Out-processing Requirements. When a CSP’s performance under this contract ceases, the CSP shall physically bring the CAC to the TA and complete the DA Form 2962. The TA will revoke the CAC from the TASS.

1.4.6. Physical Security. The contractor shall safeguard all government equipment, information and property provided for contractor use.

1.4.6.1. Key Control. (Note: all references to keys include key cards.) The contractor shall ensure keys issued to CSPs are not lost or misplaced and are not used by unauthorized persons. The contractor shall develop written procedures covering key control. Such procedures shall include turn-in of any issued keys by CSPs who no longer require access to work areas. The contractor shall immediately report to the KO any occurrences of lost keys. The contractor shall not duplicate government-issued keys.

1.4.6.2. If the contractor loses keys, other than master keys, the government may replace or re-key the affected locks and deduct the cost of such remediation from the monthly payment due the contractor. If the contractor loses a master key, the government may replace all locks and keys for that master key system and deduct the replacement costs from the monthly payment due the contractor.

1.4.6.3. The contractor shall prohibit the use of government issued keys/key cards by any persons other than the CSPs. The contractor shall prohibit the opening of locked areas by CSPs to permit entrance of persons other than CSPs engaged in the performance of assigned work in those areas, or personnel authorized entrance by the KO.

1.5. Quality Control (QC). The contractor is responsible for quality control. The contractor shall establish and maintain a complete Quality Control Plan (QCP) that shall ensure the requirements of the contract are provided as specified in this PWS. At a minimum, the QCP shall include a self-inspection plan, an internal staffing plan, and an outline of the procedures that the Contractor will use to maintain quality, timeliness, responsiveness, customer satisfaction, and any other requirements set forth in this PWS. The contractor shall provide copies of the QCP to the KO and COR no later than 30 days after contract award, and within 5 days when changes are made thereafter.

1.6. Quality Assurance (QA). The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). The QASP is the government’s internal plan for performing QA, and does not become part of the resultant contract.

1.7. Identification of Privacy Act. This contract requires the development of a system of records in accordance with the Privacy Act of 1974.

1.8. Travel. The contractor may be required to travel during the performance of this contract to attend meetings, conferences, and training to off-site locations in support of this PWS to include various CONUS Medical Brigades (e.g. Fort Bragg, NC, Fort Lewis, WA, Fort Hood, TX) and OCONUS Theater Lead Agent for Medical Materiel (TLAMM) such as Germany and Korea (i.e.

USAMMCE and USAMMC-K). The contractor will be authorized travel expenses consistent with the Joint Travel Regulation (JTR) and the limitation of funds specified in this contract. All travel requires prior government approval/authorization by the COR.

1.9. Place of Performance. The place of performance is at the Defense Medical Logistics Center 693 Neiman Street, Fort Detrick, MD 21702 and the Defense Health Headquarters 7700 Arlington BLVD, Falls Church, VA 22042.

1.9.1. Telecommuting. IAW FAR 7.108, Additional Requirement for Telecommuting. Contractor personnel are permitted to telecommute with prior coordination and approval from the Procurement Contracting Officer (PCO) and COR. However, if telecommuting may adversely impact the Medical Research and Materiel Command (MRMC)/AMLE mission readiness and Operations Security Training (OPSEC) requirements, it may be limited and subjected to security requirements.

1.10. Hours of Operation. The contractor is responsible for providing services between the hours of 0800 to 1700 hours, Eastern Time, Monday through Friday, except federal holidays or when the government facility is closed due to emergencies, administrative closings, or similar government-directed closings. For other than firm fixed price contracts, the contractor will not be reimbursed when the government facility is closed.

1.11. Recognized Holidays. The contractor shall not perform services on the holidays listed:

New Year’s Day, January 1st Martin Luther King’s Birthday, 3rd Monday in January Presidents’ Day, 3rd Monday in February Memorial Day, last Monday in May Independence Day, July 4th Labor Day, 1st Monday in September Columbus Day, 2nd Monday in October Veteran’s Day, November 11th

Thanksgiving Day, 4th Thursday in November Christmas, December 25th

1.11.1. Any of the above holidays falling on a Saturday will be observed on the preceding Friday; holidays falling on a Sunday will be observed on the following Monday.

1.12. Personnel.

1.12.1. Key Personnel. The contractor shall provide a contractor representative. The name of this person shall act for the contractor in its absence shall be designated, in writing, and submitted to the KO prior to contract performance start date. The contractor representative shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contractor representative shall be available between the hours of 0800 to 1700 hours, Eastern Time, Monday through Friday except federal holidays or when the government facility is closed for administrative reasons.

1.12.2. Personnel Qualifications. The contractor shall accomplish the assigned tasks by employing and utilizing qualified personnel with appropriate combinations of education, training, and experience. The contractor shall match personnel skills to the task with a minimum of under or over employment of resources. The contractor shall apply personnel skills appropriate to the provisioning of respective contract deliverables.

1.12.3. Appropriate Conduct. Contractor personnel shall conform to standards of conduct and code of ethics, which are consistent with those applicable to government employees as provided for in the Joint Ethics Regulation 5500.7.R.

1.12.4. Personal Appearance. The CSPs shall present a neat and clean appearance. The CSPs shall wear a contractor furnished, visible identifying badge (name tag) on the right front of the outer clothing while performing services under this contract. The name tag shall have the name of the contractor as well as the full name and professional title of the individual CSP.

1.14. Removal of CSPs.

1.14.1. At any time during the performance of this contract, the KO or COR may direct the contractor to immediately remove from the workplace any CSP whose actions or conduct raises reasonable suspicion that clear and present danger of physical harm exists to the CSP, a patient, other contract CSPs, or government personnel.

1.14.2. If the need for a removal occurs, the COR will contact the contractor and direct the contractor to remove that CSP from the medical facility and to not use that individual to perform any services required under this contract until the issue has been resolved by the KO. The contractor shall formally meet with the COR to discuss further action in accordance with the MTF Quality Assurance and Inspection (QA&I) Plan and AR 40-68. A review of the basis for removal will be made by the KO within 3 working days after the COR directed the removal.

1.14.3. If, after any investigation deemed necessary by the KO and discussions with the contractor's representative, the KO concludes that the contract CSP’s conduct requires permanent removal from performance under the contract, the KO will notify the contractor that permanent removal is required. In the event of disagreements between the government and the contractor's representative concerning matters of impaired CSPs, the decision of the KO will be final. Within 10 working days between the removal and the final decision of the KO, the contractor shall provide a backup/replacement CSP in accordance with the terms and conditions of this contract. Removal of CSPs does not relieve the contractor of the requirement to perform contract services.

1.15. Crime Control Act of 1990. No performance under this contract will be allowed without full compliance with the Crime Control Act of 1990 and Department of Defense Instruction 1402.5 dated 19 January 1993. All CSPs having access to government computer systems must be subjected to a background investigation and have favorable background investigation.

Background checks will be based on fingerprints of individuals obtained by a law enforcement officer and inquiries will be made, based on the Standard Form 85-P completed by the CSP, through the Federal Bureau of Investigation (FBI) and state criminal history repositories.

1.16. The contractor shall not employ active duty military or government civilian employees to perform services under this contract.

1.17. HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (June 2012) In accordance with DoD 6025.18-R “Department of Defense Health Information Privacy Regulation,” January 24, 2003, the Contractor meets the definition of Business Associate.

Therefore, a Business Associate Agreement is required to comply with both the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security regulations. This clause serves as that agreement whereby the Contractor agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause, and in DoD 6025.18-R and DoD 8580.02-R, as amended. Additional requirements will be addressed when implemented.

(a) Definitions. As used in this clause generally refer to the Code of Federal Regulations (CFR) definition unless a more specific provision exists in DoD 6025.18-R or DoD 8580.02-R.

Individual has the same meaning as the term “individual” in 45 CFR 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g).

Privacy Rule means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR part 160 and part 164, subparts A and E.

Protected Health Information has the same meaning as the term “protected health information” in 45 CFR 160.103, limited to the information created or received by the Contractor from or on behalf of the Government pursuant to the Contract.

Electronic Protected Health Information has the same meaning as the term “electronic protected health information” in 45 CFR 160.103.

Required by Law has the same meaning as the term “required by law” in 45 CFR 164.103.

Secretary means the Secretary of the Department of Health and Human Services or his/her designee.

Security Rule means the Health Insurance Reform: Security Standards at 45 CFR part 160, 162 and part 164, subpart C.

Terms used, but not otherwise defined, in this Clause shall have the same meaning as those terms in 45 CFR 160.103, 160.502, 164.103, 164.304, and 164.501.

(b) The Contractor shall not use or further disclose Protected Health Information other than as permitted or required by the Contract or as Required by Law.

(c) The Contractor shall use appropriate safeguards to prevent use or disclosure of the Protected Health Information other than as provided for by this Contract.

(d) The Contractor agrees to use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits in the execution of this Contract.

(e) The Contractor shall, at their own expense, take action to mitigate, to the extent practicable, any harmful effect that is known to the Contractor of a use or disclosure of Protected Health Information by the Contractor in violation of the requirements of this Clause. These mitigation actions will include as a minimum those listed in the TMA Breach Notification Standard Operating Procedure (SOP), which is available at:

http://www.tricare.mil/tma/privacy/breach.aspx.

(f) The Contractor shall report to the Government any security incident involving protected health information of which it becomes aware.

(g) The Contractor shall report to the Government any use or disclosure of the Protected Health Information not provided for by this Contract of which the Contractor becomes aware.

(h) The Contractor shall ensure that any agent, including a subcontractor, to whom it provides Protected Health Information received from, or created or received by the Contractor, on behalf of the Government, agrees to the same restrictions and conditions that apply through this Contract to the Contractor with respect to such information.

(i) The Contractor shall ensure that any agent, including a subcontractor, to whom it provides electronic Protected Health Information, agrees to implement reasonable and appropriate safeguards to protect it.

(j) The Contractor shall provide access, at the request of the Government, and in the time and manner reasonably designated by the Government to Protected Health Information in a Designated Record Set, to the Government or, as directed by the Government, to an Individual in order to meet the requirements under 45 CFR 164.524.

(k) The Contractor shall make any amendment(s) to Protected Health Information in a Designated Record Set that the Government directs or agrees to pursuant to 45 CFR 164.526 at the request of the Government, and in the time and manner reasonably designated by the Government.

(l) The Contractor shall make internal practices, books, and records relating to the use and disclosure of Protected Health Information received from, or created or received by the Contractor, on behalf of the Government, available to the Government, or at the request of the Government to the Secretary, in a time and manner reasonably designated by the Government or the Secretary, for purposes of the Secretary determining the Government’s compliance with the Privacy Rule.

(m) The Contractor shall document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.

http://www.tricare.mil/tma/privacy/breach.aspx

(n) The Contractor shall provide to the Government or an Individual, in time and manner reasonably designated by the Government, information collected in accordance with this Clause of the Contract, to permit the Government to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR 164.528.

General Use and Disclosure Provisions

Except as otherwise limited in this Clause, the Contractor may use or disclose Protected Health Information on behalf of, or to provide services to, the Government for treatment, payment, or healthcare operations purposes, in accordance with the specific use and disclosure provisions below, if such use or disclosure of Protected Health Information would not violate the HIPAA Privacy Rule, the HIPAA Security Rule, DoD 6025.18-R or DoD 8580.02-R if done by the Government.

Specific Use and Disclosure Provisions

(a) Except as otherwise limited in this Clause, the Contractor may use Protected Health Information for the proper management and administration of the Contractor or to carry out the legal responsibilities of the Contractor.

(b) Except as otherwise limited in this Clause, the Contractor may disclose Protected Health Information for the proper management and administration of the Contractor, provided that disclosures are required by law, or the Contractor obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies the Contractor of any instances of which it is aware in which the confidentiality of the information has been breached.

(c) Except as otherwise limited in this Clause, the Contractor may use Protected Health Information to provide Data Aggregation services to the Government as permitted by 45 CFR 164.504(e)(2)(i)(B).

(d) Contractor may use Protected Health Information to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).

Obligations of the Government

Provisions for the Government to Inform the Contractor of Privacy Practices and Restrictions

(a) The Government will provide the Contractor with the notice of privacy practices that the Government produces in accordance with 45 CFR 164.520.

(b) The Government will provide the Contractor with any changes in, or revocation of, permission by Individual to use or disclose Protected Health Information, if such changes affect the Contractor’s permitted or required uses and disclosures.

(c) The Government will notify the Contractor of any restriction to the use or disclosure of Protected Health Information that the Government has agreed to in accordance with 45 CFR 164.522.

Permissible Requests by the Government

The Government will not request the Contractor to use or disclose Protected Health Information in any manner that would not be permissible under the HIPAA Privacy Rule, the HIPAA Security Rule, or any applicable Government regulations (including without limitation, DoD 6025.18-R and DoD 8580.02-R) if done by the Government, except for providing Data Aggregation services to the Government and for management and administrative activities of the Contractor as otherwise permitted by this clause.

Termination

(a) Termination. A breach by the Contractor of this clause, may subject the Contractor to termination under any applicable default or termination provision of this Contract.

(b) Effect of Termination.

(1) If this contract has records management requirements, the records subject to the Clause should be handled in accordance with the records management requirements. If this contract does not have records management requirements, the records should be handled in accordance with paragraphs (2) and (3) below

(2) If this contract does not have records management requirements, except as provided in paragraph (3) of this section, upon termination of this Contract, for any reason, the Contractor shall return or destroy all Protected Health Information received from the Government, or created or received by the Contractor on behalf of the Government. This provision shall apply to Protected Health Information that is in the possession of subcontractors or agents of the Contractor. The Contractor shall retain no copies of the Protected Health Information.

(3) If this contract does not have records management provisions and the Contractor determines that returning or destroying the Protected Health Information is infeasible, the Contractor shall provide to the Government notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Government and the Contractor that return or destruction of Protected Health Information is infeasible, the Contractor shall extend the protections of this Contract to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as the Contractor maintains such Protected Health Information.

Miscellaneous

(a) Regulatory References. A reference in this Clause to a section in DoD 6025.18-R, DoD 8580.02-R, Privacy Rule or Security Rule means the section currently in effect or as amended, and for which compliance is required.

(b) Survival. The respective rights and obligations of Business Associate under the “Effect of Termination” provision of this Clause shall survive the termination of this Contract.

(c) Interpretation. Any ambiguity in this Clause shall be resolved in favor of a meaning that permits the Government to comply with DoD 6025.18-R, DoD 8580.02-R, the HIPAA Privacy Rule or the HIPAA Security Rule.

1.18. Personally Identifiable Information (PII) Requirements

1.18.1. Sections 1.2 of this PWS require the contractor to design, develop, or operate a system of records on individuals, to accomplish an agency function subject to the Privacy Act of 1974, Public Law 93-579, December 31, 1974 (5 U.S.C. 5521). The contractor shall comply with the Privacy Act and all applicable agency regulations on individual privacy, to include DoD Directive 5400.11, “Department of Defense Privacy Program” and DoD 5400.11-R, “Department of Defense Privacy Program.”

1.18.2. Systems Access. When requested by the government, the contractor shall provide access to and information regarding the systems that the contractor operates or maintains on behalf of the government under this contract.

1.18.3. Systems Security. The contractor shall encrypt all contractor-owned laptops or other portable media storage devices that process or store PII, IAW NIST Federal Information Processing Standard (FIPS) 140-2 (or successor). The contractor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the internet or other public networks.

1.18.4. Data Security. The contractor, unless otherwise authorized by the government, shall limit access to PII to those employees and subcontractors who require the information in order to perform their official duties under this contract. The contractor, contractor employees, and subcontractors shall physically or electronically protect PII when not in use and/or under the control of an authorized individual. During the course of contract performance, when PII is no longer needed or required to be retained under applicable government records retention policies, the contractor shall coordinate with the contracting officer to either turn over the PII to the government, or destroy it through means that will make the PII irretrievable (i.e., permanently unavailable for access by any person). The contractor shall only use PII obtained under this contract for purposes of the contract, and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer. At expiration or termination of this contract, the contractor shall coordinate with the contracting officer to either turn over all PII managed under the contract that is in its possession to the government or successor contractor, or, if the government so directs, destroy the PII.

1.19. Data Breach Response and Notification

1.19.1. The contractor shall adhere to the reporting and response requirements for PII set forth in Memorandum, Office of the Secretary of Defense, Subject: Safeguarding Against and Responding to the Breach of Personally identifiable Information (PII), June 5, 2009, ALARACT 050/2009, DoD 5400.11-R, and any amendments.

1.19.2. The contractor or its subcontractor shall immediately notify MAJ Daniel O’Neill, 301-619- 9760, daniel.j.oneill34.mil@mail.mil upon discovery that a suspected or actual breach of PII has occurred. The notification shall include, to the greatest extent possible, the identification of each individual whose PII has been or possibly has been breached. In addition, the contractor or its subcontractor shall provide MAJ Daniel O’Neill, 301-619-9760, daniel.j.oneill34.mil@mail.mil with any other available information that must be included in required breach reporting and mailto:daniel.j.oneill34.mil@mail.mil mailto:daniel.j.oneill34.mil@mail.mil notifications. The contractor shall provide this information at the time of the initial notification to the government or promptly thereafter as information becomes available.

1.19.3. The government will determine whether a breach of PII has occurred, and whether breach notification to affected individuals is required. If breach notification to affected individuals is required, the government will determine if the contractor shall make the required notification. If the contractor is to notify the impacted population, it shall submit the notification letters to Health Care Operations Directorate, 703-681-8052/5095, for review and approval.

2. DEFINITIONS AND ACRONYMS

2.1. Definitions.

2.1.1. Contractor. The term as used in this contract refers to the prime.

2.1.2. Contracting Officer. A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings. The KO is the only individual who can legally bind the government.

2.1.3. Contracting Officer's Representative (COR). An individual designated and authorized in writing by the contracting officer to perform specific technical or administrative functions. Only an employee of the US Government may be appointed as a COR. A COR does NOT have authority to change any terms or conditions of the contract or task order(s).

2.1.4. Physical Security. Actions that prevent the loss or damage of government property.

2.1.5. Quality Assurance. The various functions, including inspection, performed by the Government to determine whether a contractor has fulfilled the contract obligations pertaining to quality and quantity.

2.1.6. Quality Control. All necessary measures taken by the contractor to assure that the quality of an end product or service shall meet contract requirements.

2.1.7. Subcontractor. One that enters into a subcontract and assumes some of the obligations of the primary contractor.

2.2. Acronyms.

AAR After Action Report ACOR Alternate Contracting Officer's Representative ADMIN Administrative Assistant AESIP Army Enterprise Systems Integration Program AFARS Army Federal Acquisition Regulation Supplement AKO Army Knowledge Online AMC Army Materiel Command AMEDD Army Medical Department AMEDDCS Army Medical Department Center and School AMLE Army Medical Logistics Enterprise AO Area of Responsibility

APS Army Pre-positioned Stocks AR Army Regulation AT Anti-Terrorism ATCTS Army Training Certification Tracking System BCA Business Case Analysis BPC Business Process Council BPR Business Process Reengineering BSO Business Support Office C&A Certification and Accreditation CAC Common Access Card CASCOM Combined Arms Support Command CCE Contracting Center of Excellence CDRLs Contract Data Requirements Lists CFR Code of Federal Regulations CLSI Clinical and Laboratory Standards Institute CM-3 Centralized Medical Materiel Management CMD Contracts Management Division CMR Contractor Manpower Reporting CONOPS Concept of Operations CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTS Commercial-Off-the-Shelf CPARS Contractor Performance Assessment Reporting System CSP Contract Service Provider CTA Contract Technical Advisor CTIP Combat Trafficking in Persons General Awareness Course CVS Contractor Verification System CW Chief Warrant Officer DA Department of the Army DCAA Defense Contract Audit Agency DCAM DMLSS Customer Assistance Module DD Department of Defense DD254 Department of Defense Contract Security Requirement List DEERS Defense Enrollment Eligibility Reporting System DFARS Defense Federal Acquisition Regulation Supplement DHA Defense Health Agency DLA Defense Logistics Agency DMDC Defense Manpower Data Center DMLSS Defense Medical Logistics Standard Support DOD Department of Defense DODDAC Department of Defense Activity Address Codes DOL Director of Logistics DTS Defense Travel System

E Electronic ENAC Expanded National Agency Check ERP Enterprise Resource Planning FAR Federal Acquisition Regulation FFP Firm Fixed Price Type Contract FIPS PUB Federal Information Processing Standards Publication FORSCOM United States Army Forces Command FSC Federal Supply Services FSD Force Sustainment Directorate FSS Federal Supply Schedule G&A General and Administrative charges GCSS-A Global Combat Support System - Army GFE Government Furnished Equipment GFI Government Furnished Information GFM Government Furnished Materials GMP Good Manufacturing Practices GSA General Services Administration H Hard Copy HIPAA Health Insurance Portability and Accountability Act of 1996 HQ Head Quarters HQDA Headquarters Department of the Army HRCoE Health Readiness Center of Excellence HSM Hydration Status Monitor HSM PDE Hydration Status Monitor Product Development Effort IAW In Accordance With ICT Information and Communication Technology ID Identification ID/IQ Indefinite Delivery, Indefinite Quantity Contracts ILS Integrated Logistic Support INC Incorporated IPT Integrated Product Team ISO International Organization for Standardization IT Information Technology JMLFDC Joint Medical Logistics Functional Development Center JTR Joint Travel Regulation KO Contracting Officer LD BMET Lead Biomedical Equipment Technician LLC Limited Liability Company LMP Logistics Modernization Program LOA Letter of Authorization LOGSA Logistics Support Activity MACOM Major Command MD Maryland

MDD Materiel Development Decision MEDCOM US Army Medical Command MEDLOG Medical Logistics MES Medical Equipment Sets MMQC Medical Materiel Quality Control MOD Military of Defense MOS Military Occupational Specialty MRMC Medical Research and Materiel Command MTF Medical Treatment Facility NAC National Agency Check NMP National Maintenance Program OCI Organizational Conflict of Interest OCONUS Outside Continental United States (includes Alaska and Hawaii) ODC Other Direct Costs OEM Original Equipment Manufacturer OH Over Head OMB Office of Management and Budget OPSEC Operations Security Training OSHA Occupational Safety and Health Administration OTSG Office of The Surgeon General, US Army PASS Professional and Administrative Support Services PCO Procuring Contracting Officer PDE Product Development Effort PE Program Element PIPO Phase In/Phase Out PM Program Manager PMA Pre-Market Approval PMCS Preventive Maintenance Check Service PO Purchase Order POC Point of Contact POI Point of Information POM Program Objective Memoranda PRS Performance Requirements Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Plan R&D Research and Development RAPIDS Real-Time Automated Personnel Identification System RFI Request for Information RFP Request for Proposal

ROI Return on Investment SAMS-E Standard Army Maintenance System-Enhanced SBIR Small Business Innovation Research SBU Sensitive But Unclassified SF Standard Form SKO Sets, Kits and Outfits SME Subject Matter Expert SOFA Status of Force Agreement SOP Standard Operating Procedure ST Special Text STD Standard TA Trusted Agent TARP Threat Awareness and Response Program TASS Trusted Associate Sponsorship System TBD To Be Determined TDA Training and Development Agency TDY Travel Temporary Duty TEWLS Theater Enterprise-Wide Logistics System THREATCONS Threat Conditions TLAMM Theater Lead Agent for Medical Materiel TOE Table of Organization and Equipment TRADOC Training and Doctrine Command UAMMC-K United States Army Medical Materiel Center - Korea UIC Unique Identification Code USAMAA United States Army Medical Materiel Agency USAMMCE United States Army Medical Materiel Center – Europe USAMRAA United States Army Medical Research Acquisition Activity USAMRMC United States Army Medical Research and Materiel Command USARC United States Army Reserve Command VO Verifying Office

3. GOVERNMENT FURNISHED ITEMS AND SERVICES.

3.1. Materials.

3.1.1. The Government will make available the materials, office space, communications capability and information for use by the contractor in the performance of this contract.

3.2. Facilities. The government will provide the necessary workspace for CSPs to support the tasks outlined in this PWS. The government will provide access to office equipment such as telephones, computers, printers, scanners, fax machines and other items necessary to accomplish the PWS.

3.3. Government Services. The government will provide office-related services such as telephone, internet and network access services.

3.4. Utilities. The government will provide all standard facility utilities such as electricity, water, etc., for the contractor’s use in the performance of this PWS. The contractor shall ensure prudent utilities conservation practices, such as turning off lights when not in use, and closing water faucets after using the required amount to accomplish cleaning vehicles or equipment.

3.5. Government unique training. The government may elect to provide unique government training to contract CSPs who are performing services under this contract. If the government elects to provide such training, the government will provide such training at no additional expense to the contractor or to the CSP. When directed by the KO, CSPs shall attend all such training in a paid status as part of the normal services required and billed under the contract.

Contractor personnel with an area of performance within an Army-controlled installation, facility or area shall complete training requirements listed below within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever applies.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .