The South Dakota Department of Health (SD DOH) is seeking a qualified vendor to conduct a comprehensive cybersecurity assessment of the South Dakota Health Care Coalition (SD HCC) partners across healthcare, long-term care, and public health sectors. The assessment will target approximately 180 healthcare facilities statewide, evaluating current cybersecurity practices, identifying vulnerabilities, assessing disaster risks, and examining mitigation and recovery capabilities for potential cyberattacks. Key deliverables include a detailed assessment of existing cybersecurity capabilities, identification of operational gaps, and actionable recommendations to enhance preparedness and resilience. The ideal contractor must demonstrate expertise in healthcare cybersecurity, including knowledge of medical operating systems, equipment, healthcare coalitions, public health, emergency management, and facility operations. Proposal submissions are due by February 17, 2025, with a contract period running from March 1, 2025, through June 30, 2025. The RFP indicates that questions must be submitted by January 23, 2025, with state responses provided by February 3, 2025, and an anticipated award decision and contract negotiation date of February 27, 2025. The solicitation does not explicitly mention specific set-aside designations or restrictions for disadvantaged enterprises. Bidders are required to maintain various insurance coverages, including commercial general liability, professional liability, business automobile liability, and worker's compensation insurance, with minimum coverage of $1,000,000 per occurrence. The state notes a companion RFP (#25-0901005-013 for Extended Downtime Health Care Delivery Impact Assessment) with overlapping elements, encouraging respondents to submit proposals for both if appropriate. While no specific budget cap is detailed, the RFP requires comprehensive cost proposals that will be evaluated independently from technical proposals. The assessment will not involve penetration or vulnerability testing but will focus on evaluating general cybersecurity capabilities across facilities that independently manage their IT and cybersecurity frameworks. Each facility must comply with HIPAA and Joint Commission standards, with additional considerations for NIST Cybersecurity Framework (CSF) compliance. The state plans to select a single vendor and will not consider offshore hybrid staffing models.
A Portfolio Platform of GovExec © 2025