Cybersecurity Assessment

Solicitation # 25RFP250901005012
Posted 2/3/25, 10:01 AM
No Updates
Due 2/17/25, 6:00 PM
Similar Opportunities
The South Dakota Department of Social Services (DSS) is seeking proposals for a comprehensive stakeholder engagement and project management contract focused on juvenile justice transitional healthcare services. The primary objective is to identify barriers and develop recommendations for implementing Division FF, Title V, section 5121 of the Consolidated Appropriations Act, 2023, which provides limited Medicaid coverage for eligible juveniles in pre-release settings. The contract requires...
The Alaska Department of Health (DOH), Division of Public Health (DPH) is seeking a contractor to provide a data clearinghouse service for the Health Facility Data Reporting Program through Request for Proposals (RFP 2025-1600-0053). The selected contractor will collect and manage inpatient and outpatient discharge data from approximately 40-50 healthcare facilities in Alaska, including hospitals, ambulatory surgical centers, and diagnostic testing facilities. Key deliverables include...
The South Carolina Office of State Procurement, on behalf of the South Carolina Department of Public Health (DPH), is seeking a contractor to conduct the South Carolina Pregnancy Risk Assessment Monitoring System (SCPRAMS) surveillance/survey project. The selected vendor will be responsible for executing mail and telephone survey phases, targeting approximately 140-160 infant cases per month through sampling from the state's live birth registry. Key deliverables include sending pre-letters,...
The South Carolina Department of Public Health (DPH) is seeking a vendor to provide a comprehensive Video Directly Observed Therapy (VDOT) software system for Richland County. The procurement, identified by solicitation number 5400027854, requires an asynchronous video conferencing platform with patient-facing mobile applications, provider-facing web portals, and mobile applications that support healthcare providers in remotely monitoring patient medication adherence. The system must...

The South Dakota Department of Health (SD DOH) is seeking a qualified vendor to conduct a comprehensive cybersecurity assessment of the South Dakota Health Care Coalition (SD HCC) partners across healthcare, long-term care, and public health sectors. The assessment will target approximately 180 healthcare facilities statewide, evaluating current cybersecurity practices, identifying vulnerabilities, assessing disaster risks, and examining mitigation and recovery capabilities for potential cyberattacks. Key deliverables include a detailed assessment of existing cybersecurity capabilities, identification of operational gaps, and actionable recommendations to enhance preparedness and resilience. The ideal contractor must demonstrate expertise in healthcare cybersecurity, including knowledge of medical operating systems, equipment, healthcare coalitions, public health, emergency management, and facility operations. Proposal submissions are due by February 17, 2025, with a contract period running from March 1, 2025, through June 30, 2025. The RFP indicates that questions must be submitted by January 23, 2025, with state responses provided by February 3, 2025, and an anticipated award decision and contract negotiation date of February 27, 2025.

The solicitation does not explicitly mention specific set-aside designations or restrictions for disadvantaged enterprises. Bidders are required to maintain various insurance coverages, including commercial general liability, professional liability, business automobile liability, and worker's compensation insurance, with minimum coverage of $1,000,000 per occurrence. The state notes a companion RFP (#25-0901005-013 for Extended Downtime Health Care Delivery Impact Assessment) with overlapping elements, encouraging respondents to submit proposals for both if appropriate. While no specific budget cap is detailed, the RFP requires comprehensive cost proposals that will be evaluated independently from technical proposals. The assessment will not involve penetration or vulnerability testing but will focus on evaluating general cybersecurity capabilities across facilities that independently manage their IT and cybersecurity frameworks. Each facility must comply with HIPAA and Joint Commission standards, with additional considerations for NIST Cybersecurity Framework (CSF) compliance. The state plans to select a single vendor and will not consider offshore hybrid staffing models.

Generated 2/17/25, 7:15 PM