Opportunity

SAM #36C26126Q1068

VA Central California seeks comprehensive on-site document and data shredding services for multiple facilities

Buyer

VA Network Contracting Office 21

Posted

July 30, 2026

Respond By

August 06, 2026

Identifier

36C26126Q1068

NAICS

561990, 562112, 562920

The Department of Veterans Affairs Central California Health Care System is seeking a contractor for comprehensive on-site data and document shredding services across its main facility in Fresno and five outpatient clinics. - Government Buyer: - Department of Veterans Affairs, Network Contracting Office 21, Central California Health Care System - Scope of Services: - On-site commercial destruction of confidential waste including administrative papers, sensitive documents, hardbound journals, magazines, white and mixed paper, and non-paper media (CDs, DVDs, computer media) - Contractor must provide all labor, equipment (including confidential containers/bins), supplies, secured vehicles, and supervision - Services required at multiple locations with specific schedules and quantities of containers per site - Product Line Items: - Large 32" containers: 820 units (summed across locations) - Medium 26" containers: 200 units (summed across locations) - Small 16" containers: 78 units (summed across locations) - Unique Requirements: - Contractor must be National Association for Information Destruction (NAID) certified - Compliance with VA Directive 6371 and strict security/privacy standards - Certificates of Destruction and detailed monthly reporting required - Interim and final destruction procedures must be followed - No specific OEMs or brands are named; focus is on service capability and compliance - Estimated contract value likely ranges from $250,000 to $600,000 based on scope and industry pricing - Potential competitors include major NAID-certified shredding service providers

Description

1. STATEMENT OF WORK DOCUMENT AND RECORDS SHREDDING AND DESTRUCTION VACCHCS 1. Scope of Work 1.1 The contractor shall provide all labor, personnel, equipment including confidential containers (consoles/bins), supplies, secured vehicles, materials, supervision, and other related services necessary to provide on-site commercial document destruction services for confidential waste (administrative papers, sensitive documents, hard bound journals, magazines, white and mixed paper) at the Veterans Affairs Central California Health Care System (VACCHCS) and Five Outpatient Clinics. Large amounts of non-paper CD, DVD, computer media will be separated and quoted separately. 1.2 VACCHCS personnel in all locations are in the practice of putting all confidential, sensitive or administrative documents, as well as other paper, in locked containers located throughout all the VACCHCS facilities and clinics. 2. Place of Performance VA Fresno Medical Facility 2615 E. Clinton Ave Fresno, CA 93703 VA Visalia Clinic 5300 W. Tulare St, Ste 106 Visalia, CA 93277 Oakhurst CBOC 40597 Westlake Drive Oakhurst, CA 93644 Merced CBOC 340 E. Yosemite Ave. Merced, CA 95340 Federal Building 855 M Street, Suite 970 Fresno, CA 93721 Visalia CBOC 500 N Santa Fe St Visalia, CA 93292 3. Security Waste Pick up Schedule Locations and Quantities of Containers 3.1 Pick-up of security waste shall be accomplished in accordance with the pick-up schedule listed in paragraph 3.2 and 3.3. 3.2 Location and Time (Monday through Friday during Normal duty hours 8:00AM-3:30PM) VA Central California HCS See schedule below Section 3.2.1 Oakhurst CBOC Bi-weekly Merced CBOC Bi-weekly Federal Building, Suite 970 Weekly Visalia CBOC Bi-weekly Visalia Admin Building Monthly VA Central California facility requests service of all regular scheduled date of containers or consoles, to be emptied. Schedule for VA Central California locations: Main Hospital, Bldg. 1, Trailer LC2, and outer Buildings to be Serviced once a week. High volume areas are: HAS, Bldg. 24, 1st floor (8 Lg bins & 1 small) Emergency Area, Basement (5 Med bins) Pharmacy Area, 1st Floor, 1B061 (7 Lg bins) Primary Care, 1st floor, Charting room (1 Lg & 1 med) Laboratory Area, 2nd Floor, 2B24 (3 Lg bins) 4th Floor (West & East stations) (2 Lg bins) 5th Floor (West & East stations) (5 Lg bins) CLC, Bldg. 31, Main Nurse area (2 Lg bins) 3.3 When regular delivery/pick up days occur on one of the Federal holidays listed below, the regular delivery/pick up shall automatically shift to the following business days or within same work week (Monday through Friday). The 11 national holidays observed by the Federal Government are: New Years Day 1 January Martin Luther King Jr Day Third Monday in January Presidents Day Third Monday in February Memorial Day Last Monday in May Juneteenth National Independence 19 June Independence Day 4 July Labor Day First Monday in September Columbus Day Second Monday in October Veterans Day 11 November Thanksgiving Day Fourth Thursday in November Christmas Day 25 December 3.3.1 Any other day specifically declared by the President of the United States to be a national holiday. If a holiday falls on Sunday, the following Monday will be observed as the legal holiday. If a holiday falls on Saturday, the preceding Friday is observed as a legal holiday by U.S. Agencies. 3.4 In the event of schedule changes and prior to any changes made to the schedule, the Contracting Officer Representative (COR) will notify the Contracting Officer (CO) in writing of the revised pick-up schedule. A revised pick-up schedule will be provided to the contractor in writing along with the contract modification from the CO. 3.4.2 In the event, the contractor fails to empty a container, the contractor will have one week once notified to empty the container. The COR will have the authority to change bin sizes, as needed. 3.4.3 The contractor will provide two additional 95-gallon containers to the VA Facility to service customers on days that the contractor is not scheduled for pick up, or bins that are missed by the driver. 3.4.4 The contractor shall provide a list of bins, identified by alpha numeric numbering system (or similar) and barcode, with location and bin type. These identifiers will be used in reporting and data tracking. 3.5 Quantity of Containers per location Service site Large, 32 Medium, 26 Small, 16 VA Fresno 119 29 17 Oakhurst CBOC 3 0 0 Merced CBOC 3 0 0 Federal Bldg. 9th Flr, Suite 970 7 0 1 Visalia CBOC 8 0 0 Visalia Admin Building 2 1 3.6 Shredding Specifications 3.6.1 The Contractor shall be a National Association for Information Destruction Certified (NAID). 3.6.2 Interim Destruction- The Contractor shall provide shredding document destruction services for all secure waste that are collected in locked containers: (administrative papers, sensitive documents, and CDs). The Contractor shall conduct the Interim destruction on site, as a reasonable safeguard that affords an additional layer of security of temporary paper records. Interim destruction (temporary records) will be transferred to the Contractor's secured location, pending transport for Final destruction (pulping). The Contractor shall provide Certificates of Destruction (CODs) for all locations covered on section 3.5 on the day of interim destruction. The Contractor representative will be considered the witness to the destruction and provide an interim Certificate of Destruction per Directive 6371. Prior to departing the VA location, the witness shall provide the designated VA representative documentation acknowledging receipt of the temporary paper records. Not Practicable Documentation. If interim destruction is not reasonably practicable, VACCHCS will create and maintain documentation explaining why it was not practicable. In such cases, the Contractor must provide sufficient reasonable physical safeguards to protect temporary paper records until final destruction is completed and shall provide receipt documentation to the designated VA representative prior to departing the VA location. 3.6.3 Final destruction- shredding of all documents must meet or exceed the following criteria based on VACCHCS requirements and the requirements set forth by NAID (National Association of Information Destruction), and VA Directive 6371. Final destruction ensures temporary paper records are not readable or constructible to any degree upon final destruction, known as pulping. The Contractor shall provide CODs on a monthly basis to the COR, in addition to sampling of shredded material on a quarterly basis. The certification shall contain sufficient information to attest to the final destruction of the temporary paper records, what temporary records were destroyed, the date when they were sent for destruction, what destruction method was used, where they were destroyed, and who was responsible for their final destruction. If the final destruction is completed by a subcontractor to the information destruction contractor, then the written certification of destruction is completed by this third party or by the information destruction contractor with assurance from the third party that final destruction was completed. If the final destruction is completed by a subcontractor to the information destruction contractor, then the written certification of destruction is completed by this third party or by the information destruction contractor with assurance from the third party that final destruction was completed. 3.6.4 Long-Term Storage Approval. Any storage of temporary paper records for more than thirty (30) days prior to final destruction requires advance written approval from VACCHCS (the VA organization that generated the records). 3.6.5 Contractor shall provide monthly data reports providing quantities destroyed, facility location and bin identifier. The quantity will be by total weight and/or volume by facility, with the ability to drill down to each bin type and quantity of each bin total for the month. 3.6.6 Definitively destroying the records means final destruction ensures temporary paper records are not readable or constructible to any degree upon final destruction. The material cannot be reassembled and used in an inappropriate manner in violation of laws and regulations. Sensitive records are records that are national security classified or exempted from disclosure by statute, including the Privacy Act, or regulation. Information protection, destruction precautions, the documents (paper data), VACCHCS information containing social security number and other information covered by the privacy act shall be destroyed. 3.6.7 Sensitive VA temporary paper records that have not been destroyed to the standard of final destruction shall never be placed with trash, recycling, or other refuse. 3.7 Contingency Plan 3.7.1 Contractor shall have a contingency plan in place to address any access or service issues, such as elevator out of service, facility or room inaccessible, disabled vehicle, plant outages etc. 3.8 Quality Control 3.8.1 The contractor shall develop and maintain quality programs to ensure recycling services are performed in accordance with commonly accepted commercial practices and comply with VACCHCS requirements. The contractor and COR will conduct quarterly inspections, in order to meet VA Environmental of Care Inspection. 100% of the containers/ consoles/bins must be emptied and shredded at each location per the schedule provided by the COR. If a container, console/bin is not emptied and shredded, the contractor shall notify the COR, of the reason that a console/bin could not be emptied and shredded. The contractor shall only be invoicing and receive payment for containers/consoles/bins that are 100% emptied. The contractor shall remove bins from Facility, after service is complete before 3:30pm. The Contractor shall allow the VA Representatives to conduct inspection, upon request of their facility. 3.8.2 Contractor shall provide recommendations throughout the performance of the contract for pickup schedule, pickup frequency, bin sizes and other items to improve program efficiency and cost savings. 3.9 Safety 3.9.1 The contractor shall have in place a documented and comprehensive Health and Safety program to ensure all shredding activities are provided in a safe and secure manner and responsible for maintaining OSHA standards for occupational safety. 3.10 Contractor Vehicles 3.10.1 All contractor vehicles utilized in the performance of this contract shall maintain insurance (up to the minimum coverage required by the respective state) and shall maintain current state vehicle registration. 3.10.2 All contractor employees shall possess a valid California state driver’s license and have a clean driving record. The contractor or his/her employee’s while performing under this contract shall use no personal vehicles to transport containers to and from the government and contractor site. 3.10.3 The contractor shall ensure that all contractor vehicles utilized for this performance contract are kept in proper working condition. The contractor vehicles shall always be locked and properly secured while at the government site or in route to and from contractor site. Vehicles used in the performance of the contract shall not be left unattended and unlocked at any time while transporting VACCHCS security waste. 3.11 Contractor Facilities 3.11.1 All security waste shall be shredded onsite at the VACCHCS premises. In the event that onsite shredding is not available due to unforeseen mechanical issues, the confidential materials are to be left on VACCHCS premises, and COR is to be notified. The contractor must schedule an onsite vehicle within one week. 3.11.2 Prior to beginning performance of the contract, the designated contractor facility site will be inspected and approved by COR and the VACCHCS s Privacy Officer. 3.12 Security Waste Collection Containers and Phase-Out for Follow-On Contracts 3.12.1 The size of the containers provided is referenced in paragraph 3.5. 3.12.2 The lockable containers shall be kept locked at all times. The contractor shall provide two sets of keys for each lockable security waste container. One set of keys shall remain in the possession of the contractor or his employees at all times while at the Contractor’s site. One set of keys shall be provided to the VACCHCS COR. 3.12.3 In the event the Government awards a follow-on contract to other than the incumbent contractor, the contractor will cooperate to the extent required to allow for an orderly changeover to the successor contractor. This transition shall be as smooth and transparent as possible to ensure no interruption in the services currently being provided. 3.12.4 In the event the Government awards a follow-on contract to other than the incumbent contractor, the incumbent contractor shall schedule a time with the COR to remove containers/consoles/bins throughout the VACCHCS facilities at no additional cost to the government. 3.12.5 The contractor shall deliver the required number of lockable security waste containers (Joint Commission compliant) with keys to the VACCHCS site specified in the contract within 5 calendar days after contract award and approval of VACCHCS security suitability. The confidential waste containers shall be placed at the designated locations directed by the COR or the local VACCHCS site point of contact (POC). The VACCHCS site POC will be provided to the contractor by the COR. All containers must have a baffle preventing anyone from pulling documents out of the containers. 3.12.6 The contractor shall submit one point of contact for all locations to the COTR within 5 days of contract award. 3.13 VACCHCS Clearance Requirements The contractor shall be required to comply with all security requirements of VACCHCS. All security requirements must be met, and the employees must be cleared prior to the contractor performing work under the contract. Employees that cannot meet the security requirements and clearance requirements will not be allowed to perform work under this contract. This also includes any required training for contract personnel (e.g. VA Cyber Security Awareness, VHA Privacy Policy, etc.) including Compliance and Business Integrity (CBI) Training. 3.14 Handling of Records 3.14.1 Information or records accessed and/or created by the Contractor in the course of performing services under this contract are the property of the VA and shall not be accessed, released, transferred, or destroyed except in accordance with applicable federal law, regulations, and/or VA/VHA policy. The Contractor will not copy information contained in VA information systems, either by printing to paper or by copying to another digital format, without the explicit instruction and written approval from the officials listed in paragraph a., above, except as is necessary to make single copies in the ordinary course of providing patient care. The Contractor will not commingle the data from VA information systems with information from other sources. Contractor shall report any unauthorized disclosure of VA information to the Contracting Officers Representative (COR). 3.14.2 The Logistics Management Service will follow VACCHCS procedures to assure VA sensitive information is protected. 3.14.3 The contractor is responsible for securing any unattended vehicle on site, including locking all doors, removing keys, and safeguarding any sensitive materials stored within. 3.15 Minimum Standards for Information Destruction Information destruction contractors and subcontractors must be able to meet the following standards: Physical and Operational Security Monitored Alarm System(s) that include the following: Motion Detectors; Door Contacts; Battery Back-Up; and Monitoring Service. Taped Closed Circuit TV (CCTV) monitors with the following: Fully Functional Cameras; Recording Devices; and Secure Recording Tape Library. Sufficient Lighting to allow CCTV Locks and Key Controls Visitor Logs Visitor In/Out Logs; and Visitor ID Badges. Documentation and Control of Resources Documentation and control of employees: Documentation of who has access to materials (minimum necessary access only is allowed); Documentation of background investigations (types and frequency); Documentation of citizenship, naturalization (no non-US citizens); Documentation of drug screen; and Documentation of re-evaluation of above items (at least every two years). Documentation and control of destruction equipment: Type (Mobile or Plant-Based); Manufacturer and Model; Serial Number; and Dates of non-operational downtime for repair. Documentation and control of destruction and collection vehicles: Vehicle make and model; License plate number; State/County of registration; Acceptable overnight storage address and location; Acceptable roadworthiness of vehicles; Locks and security of vehicles; and Driver logs to show who has control of vehicle at any given time. Documentation and control of all recipients of materials: Name of individual/company; Address where received; Method of final disposition; and Certifications of destruction (general documentation acceptable as long as it is attributable to VA's data (e.g., bails shipped on were pulped on )). Other Operational Requirements All destruction will take place within the enclosure of the destruction facility, which consists of four solid walls and a ceiling, and meets all criteria related to physical building security. The only permissible uses of a mobile destruction vehicle will be within the enclosure of the destruction facility, on-site at the VA's premises, or at an off-site location if approved of in advance by VA and is located within walking distance of the VA premises. A log is kept to record the dates and times that the mobile destruction vehicle is operating within the destruction facility, which shall be made available to VA during an audit, by means of review of CCTV images. The mobile destruction vehicle will be made available to VA for audit, within the enclosure of the destruction facility, during the initial audit and during all scheduled re-audits, for demonstration purposes. 4. DEFINITIONS a. Certification of Destruction. Written documentation that attests to the completion of the destruction process after the final destruction, as defined by this policy, of VA temporary paper records have taken place. Certification documentation can be in the form of a letter, memo, or any format attesting to its complete destruction. This certification is not considered a valid certification of destruction if completed and submitted prior to the final destruction of the records. The certification should contain sufficient information to attest to the final destruction of the temporary paper records — what temporary records were destroyed, the date when they were destroyed, what destruction method was used, where they were destroyed, and who was responsible for their final destruction. b. Final Destruction. The process through which temporary paper records are pulped, macerated, shredded or otherwise destroyed to a degree that definitively ensures that they are not readable or reconstructable to any degree. If this final destruction is performed away from a VA facility it must be performed by an information destruction contractor (or its subcontractor of third party) who has demonstrated that. c. Interim Destruction: Any physical destruction process that substantially reduces the risk that PII, PHI, or other VA sensitive information will be disclosed during transport and short-term storage (i.e., less than 30 days) of temporary paper records but does not meet the requirement of final destruction as defined in this Directive. Interim destruction is a reasonable physical safeguard that affords an additional layer of security for temporary paper records once they are identified for destruction. This may be while they are stored at a VA location awaiting final destruction or when they are removed from VA custody until final destruction is completed at an off-site location. It is generally accomplished through maceration, chopping, pulverization, or shredding where these processes do not render the material unreadable or where the material could be reconstructed. Interim destruction is not required but is strongly recommended to reduce risk; it will be a consideration as to whether a facility has completed due diligence in the event of a data breach. d. Permanent records. As defined in 36 CFR 1220.18 General Definitions, are those records that have been determined by the Archivist of the United States, National Archives and Records Administration (NARA), to have sufficient value to warrant their preservation in the National Archives of the United States. As such, they may not be destroyed by pulping, shredding, or any other means. An example of permanent records are original hardcopy documents for research and development projects. e. Protected Health Information (PHI). This term applies only to individually-identifiable health information that is under the control of VHA, as VA's only Covered Entity under HIPAA. PHI is health (including demographic) data that is transmitted by, or maintained in, electronic or any other form or medium. PHI excludes employment records held by an employer in its role as employer, records of a person deceased for more than 50 years, and some education records. It includes genetic information. f. Personally Identifiable Information (PII). Any information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother's maiden name, etc. Information does not have to be retrieved by any specific individual or unique identifier (i.e., covered by the Privacy Act) to be personally identifiable information. SOURCE: Office of Management and Budget (OMB) Memorandum 07-16, Safeguarding Against and Responding to Breaches of Personally Identifiable Information (May 22, 2007). g. Readable. Printed data is readable when strategies can be used to assist with decoding (the translation of letters and/or into sounds or visual representations of speech) data and arriving at comprehension through the use of morpheme, semantics, syntax, and contextual clues to integrate the information they have read into their existing framework of knowledge in order to arrive at a meaning. h. Reconstructable. Printed data is reconstructable when methods can be employed to reassemble the various portions of material in such a fashion that data can be decoded as to make it readable so that meaning can be derived from the data found on the media. i. Records. As defined in 44 U.S.C. 3301, records are all books, papers, maps, photographs, machine readable materials, or other documentary materials, regardless of physical form or characteristics, made or received by an agency of the United States Government under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the Government or because of the informational value of the data in them. j. Temporary records. As defined in 36 CFR 1220.18 General Definitions, are those records that have been determined by the Archivist of the United States to have insufficient value to warrant preservation by NARA. Temporary records are eligible for destruction by burning, pulping, or shredding. Examples of temporary records would be copies of hardcopy documents for research and development projects. k. VA Sensitive Information: All Department information and/or data on any storage media or in any form or format, which requires protection due to the risk of harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes not only information that identifies an individual but also other information whose improper use or disclosure could adversely affect the ability of an agency to accomplish its mission; proprietary information; and records about individuals requiring protection under applicable confidentiality provisions. SOURCE: 38 U.S.C. § 5727. For purposes of this Directive, these confidentiality provisions include, but are not limited to, the Privacy Act; 38 U.S.C. 5701, 5705, and 7332; the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule; and information that can be withheld under the Freedom of Information Act. 5. SECURITY INFORMATION Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security. 6. VA INFORAMTION CUSTODIAL LANGUAGE a. The Government shall receive unlimited rights to data/intellectual property first produced and delivered in the performance of this contract or order (hereinafter contract ) unless expressly stated otherwise in this contract. This includes all rights to source code and all documentation created in support thereof. The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data General. The primary clause used to define computer software license (not data/intellectual property first produced under this contractor or order) is FAR 52.227-19, Commercial Computer Software License. b. Information made available to the contractor by VA for the performance or administration of this contract will be used only for the purposes specified in the service agreement, SOW, PWS, PD, and/or contract. The contractor shall not use VA information in any other manner without prior written approval from a VA Contracting Officer (CO). The primary clause used to define Government and Contractor data rights is FAR 52.227-14 Rights in Data General. c. VA information will not be co-mingled with any other data on the contractor s information systems or media storage systems. The contractor shall ensure compliance with Federal and VA requirements related to data protection, data encryption, physical data segregation, logical data segregation, classification requirements and media sanitization. d. VA reserves the right to conduct scheduled or unscheduled audits, assessments, or investigations of contractor Information Technology (IT) resources to ensure information security is compliant with Federal and VA requirements. The contractor shall provide all necessary access to records (including electronic and documentary materials related to the contracts and subcontracts) and support (including access to contractor and subcontractor staff associated with the contract) to VA, VA's Office Inspector General (OIG), and/or Government Accountability Office (GAO) staff during periodic control assessments, audits, or investigations. e. The contractor may only use VA information within the terms of the contract and applicable Federal law, regulations, and VA policies. If new Federal information security laws, regulations or VA policies become applicable after execution of the contract, the parties agree to negotiate contract modification and adjustment necessary to implement the new laws, regulations, and/or policies. f. The contractor shall not make copies of VA information except as specifically authorized and necessary to perform the terms of the contract. If copies are made for restoration purposes, after the restoration is complete, the copies shall be destroyed in accordance with VA Directive 6500, VA Cybersecurity Program and VA Information Security Knowledge Service. g. If a Veterans Health Administration (VHA) contract is terminated for default or cause with a business associate, the related local Business Associate Agreement (BAA) shall also be terminated and actions taken in accordance with VHA Directive 1605.05, Business Associate Agreements. If there is an executed national BAA associated with the contract, VA will determine what actions are appropriate and notify the contactor. h. The contractor shall store and transmit VA sensitive information in an encrypted form, using VA-approved encryption tools which are, at a minimum, Federal Information Processing Standards (FIPS) 140-2, Security Requirements for Cryptographic Modules (or its successor) validated and in conformance with VA Information Security Knowledge Service requirements. The contractor shall transmit VA sensitive information using VA approved Transport Layer Security (TLS) configured with FIPS based cipher suites in conformance with National Institute of Standards and Technology (NIST) 800-52, Guidelines for the Selection, Configuration and Use of Transport Layer Security (TLS) Implementations. i. The contractor s firewall and web services security controls, as applicable, shall meet or exceed VA s minimum requirements. j. Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor may use and disclose VA information only in two situations: (i) in response to a qualifying order of a court of competent jurisdiction after notification to VA CO (ii) with written approval from the VA CO. The contractor shall refer all requests for, demands for production of or inquiries about, VA information and information systems to the VA CO for response. k. Notwithstanding the provision above, the contractor shall not release VA records protected by Title 38 U.S.C. § 5705, Confidentiality of medical quality-assurance records and/or Title 38 U.S.C. § 7332, Confidentiality of certain medical records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse or infection with Human Immunodeficiency Virus (HIV). If the contractor is in receipt of a court order or other requests for the above-mentioned information, the contractor shall immediately refer such court order or other requests to the VA CO for response. l. Information made available to the contractor by VA for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract will be protected and secured in accordance with VA Directive 6500 and Identity and Access Management (IAM) Security processes specified in the VA Information Security Knowledge Service. m. Any data destruction done on behalf of VA by a contractor shall be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management, VA Handbook 6300.1, Records Management Procedures, and applicable VA Records Control Schedules. n. The contractor shall provide its plan for destruction of all VA data in its possession according to VA Directive 6500 and NIST 800-88, Guidelines for Media Sanitization prior to termination or completion of this contract. If directed by the COR/CO, the contractor shall return all Federal Records to VA for disposition. o. Any media, such as paper, magnetic tape, magnetic disks, solid state devices or optical discs that is used to store, process, or access VA information that cannot be destroyed shall be returned to VA. The contractor shall hold the appropriate material until otherwise directed by the Contracting Officer s Representative (COR) or CO. Items shall be returned securely via VA-approved methods. VA sensitive information must be transmitted utilizing VA-approved encryption tools which are validated under FIPS 140-2 (or its successor) and NIST 800-52. If mailed, the contractor shall send via a trackable method (USPS, UPS, FedEx, etc.) and immediately provide the COR/CO with the tracking information. Self-certification by the contractor that the data destruction requirements above have been met shall be sent to the COR/CO within 30 business days of termination of the contract. p. All electronic storage media (hard drives, optical disks, CDs, back-up tapes, etc.) used to store, process or access VA information will not be returned to the contractor at the end of lease, loan, or trade-in. Exceptions to this paragraph will only be granted with the written approval of the VA CO. 7. ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS 7.1 A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees and subcontractors only to the extent necessary to perform the services specified in the solicitation or contract. This includes indirect entities, both affiliate of contractor/subcontractor and agent of contractor/subcontractor. 7.2 Contractors and subcontractors shall sign the VA Information Security Rule of Behavior (ROB) before access is provided to VA information and information systems (see Section 4, Training, below). The ROB contains the minimum user compliance requirements and does not supersede any policies of VA facilities or other agency components which provide higher levels of protection to VA's information or information systems. Users who require privileged access shall complete the VA elevated privilege access request processes before privileged access is granted. 7.3 All contractors and subcontractors working with VA information are subject to the same security investigative and clearance requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors shall be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office of Human Resources and Administration/Operations, Security and Preparedness (HRA/OSP) is responsible for these policies and procedures. Contract personnel who require access to classified information or information systems shall have an appropriate security clearance. Verification of a. Security Clearance shall be processed through the Special Security Officer located in HRA/OSP. Contractors shall conform to all requirements stated in the National Industrial Security Program Operating Manual (NISPOM). 7.4 All contractors and subcontractors shall comply with conditions specified in VAAR 852.204-71(d); Contractor operations required to be in United States. All contractors and subcontractors working with VA information must be permanently located within a jurisdiction subject to the law of the United States or its Territories to the maximum extent feasible. If services are proposed to be performed abroad the contractor must state where all non-U.S. services are provided. The contractor shall deliver to VA a detailed plan specifically addressing communications, personnel control, data protection and potential legal issues. The plan shall be approved by the COR/CO in writing prior to access being granted. 7.5 The contractor shall notify the COR/CO in writing immediately (no later than 24 hours) after personnel separation or occurrence of other causes. Causes may include the following: Contractor/subcontractor personnel no longer has a need for access to VA information or VA information systems. Contractor/subcontractor personnel are terminated, suspended, or otherwise has their work on a VA project discontinued for any reason. Contractor believes their own personnel or subcontractor personnel may pose a threat to their company’s working environment or to any company-owned property. This includes contractor-owned assets, buildings, confidential data, customers, employees, networks, systems, trade secrets and/or VA data. Any previously undisclosed changes to contractor/subcontractor background history are brought to light, including but not limited to changes to background investigation or employee record. Contractor/subcontractor personnel have their authorization to work in the United States revoked. Agreement by which contractor provides products and services to VA has either been fulfilled or terminated, such that VA can cut off electronic and/or physical access for contractor personnel 7.6 In such cases of contract fulfillment, termination, or other causes; the contractor shall take the necessary measures to immediately revoke access to VA network, property, information, and information systems (logical and physical) by contractor/subcontractor personnel. These measures include (but are not limited to): removing and then securing Personal Identity Verification (PIV) badges and PIV Interoperable (PIV-I) access badges, VA-issued photo badges, credentials for VA facilities and devices, VA-issued laptops, and authentication tokens. Contractors shall notify the appropriate VA COR/CO immediately to initiate access removal. 7.7 Contractors/subcontractors who no longer require VA accesses will return VA-issued property to VA. This property includes (but is not limited to): documents, electronic equipment, keys, and parking passes. PIV and PIV-I access badges shall be returned to the nearest VA PIV Badge Issuance Office. Once they have had access to VA information, information systems, networks and VA property in their possessions removed, contractors shall notify the appropriate VA COR/CO. 8. TRAINING 8.1 All contractors and subcontractors requiring access to VA information and VA information systems shall successfully complete the following before being granted access to VA information and its systems: VA Privacy and Information Security Awareness and Rules of Behavior course (Talent Management System (TMS) #10176) initially and annually thereafter. Sign and acknowledge (electronically through TMS #10176) understanding of and responsibilities for compliance with the Organizational Rules of Behavior, relating to access to VA information and information systems initially and annually thereafter; and Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system or information access (to be defined by the VA program official and provided to the VA CO for inclusion in the solicitation document — i.e., any role-based information security training). 8.2 The contractor shall provide to the COR/CO a copy of the training certificates and certification of signing the Organizational Rules of Behavior for each applicable employee within five days of the initiation of the contract and annually thereafter, as required. 8.3 Failure to complete the mandatory annual training is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the required training is complete. 9. SECURITY INCIDENT INVESTIGATION 9.1 The contractor, subcontractor, their employees, or business associates shall immediately (within one hour) report suspected security / privacy incidents to the VA OIT’s Enterprise Service Desk (ESD) by calling (855) 673-4357 (TTY: 711). The ESD is OIT’s 24/7/365 single point of contact for IT-related issues. After reporting to the ESD, the contractor, subcontractor, their employees, or business associates shall, within one hour, provide the COR/CO the incident number received from the ESD. 9.2 To the extent known by the contractor/subcontractor, the contractor/subcontractor's notice to VA shall identify the information involved and the circumstances surrounding the incident, including the following: The date and time (or approximation of) the Security Incident occurred. The names of individuals involved (when applicable). The physical and logical (if applicable) location of the incident. Why the Security Incident took place (i.e., catalyst for the failure). The amount of data belonging to VA believed to have been compromised. The remediation measures the contractor is taking to ensure no future incidents of a similar nature. 9.3 After the contractor has provided the initial detailed incident summary to VA, they will continue to provide written updates on any new and relevant circumstances or facts they discover. The contractor, subcontractor, and their employees shall fully cooperate with VA or third-party entity performing an independent risk analysis on behalf of VA. Failure to cooperate may be deemed a material breach and grounds for contract termination. 9.4 VA IT contractors shall follow VA Handbook 6500, Risk Management Framework for VA Information Systems VA Information Security Program, and VA Information Security Knowledge Service guidance for implementing an Incident Response Plan or integrating with an existing VA implementation. 9.5 In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG, and the VA Office of Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident. 9.6 The contractor shall comply with VA Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, which establishes the breach management policies and assigns responsibilities for the oversight, management and reporting procedures associated with managing of breaches. 9.7 With respect to unsecured Protected Health Information (PHI), the contractor is deemed to have discovered a data breach when the contractor knew or should have known of breach of such information. When a business associate is part of VHA contract, notification to the covered entity (VHA) shall be made in accordance with the executed BAA. 9.8 If the contractor or any of its agents fails to protect VA sensitive personal information or otherwise engages in conduct which results in a data breach involving any VA sensitive personal information the contractor/subcontractor processes or maintains under the contract; the contractor shall pay liquidated damages to the VA as set forth in clause 852.211-76, Liquidated Damages Reimbursement for Data Breach Costs. VA ACQUISITION REGULATION SOLICITATION PROVISION AND CONTRACT CLAUSE NOTE: This clause will undergo official rule making by the Office of Acquisitions and Logistics. The below language will be submitted for public review through the Federal Register. The final wording of the clause may be changed from what is outlined below based on public review and comment. Once approved, the final language in the clause can be obtained from the Office of Acquisitions and Logistics Programs and Policy. 1. SUBPART 839.2 INFORMATION AND INFORMATION TECHNOLOGY SECURITY REQUIREMENTS 839.201 Contract clause for Information and Information Technology Security: a. Due to the threat of data breach, compromise or loss of information that resides on either VA-owned or contractor-owned systems, and to comply with Federal laws and regulations, VA has developed an Information and Information Technology Security clause to be used when VA sensitive information is accessed, used, stored, generated, transmitted, or exchanged by and between VA and a contractor, subcontractor or a third party in any format (e.g., paper, microfiche, electronic or magnetic portable media). b. In solicitations and contracts where VA Sensitive Information or Information Technology will be accessed or utilized, the CO shall insert the clause found at 852.273-75, Security Requirements for Unclassified Information Technology Resources. 2. 852.273-75 - SECURITY REQUIREMENTS FOR UNCLASSIFIED INFORMATION TECHNOLOGY RESOURCES (INTERIM- OCTOBER 2008) As prescribed in 839.201, insert the following clause: The contractor, their personnel, and their subcontractors shall be subject to the Federal laws, regulations, standards, and VA Directives and Handbooks regarding information and information system security as delineated in this contract. (END OF CLAUSE) It has been determined that protected health information (PHI) may be used, disclosed, accessed, transmitted, created, stored/maintained, and/or destroyed (providing appropriate proof of destruction in compliance with VA Directive 6371) by the Contractor, and a signed Business Associate Agreement (BAA) will be required. The Contractor will adhere to the requirements set forth within the BAA, referenced in the solicitation, and will comply with all applicable VA/VHA Directives. Once awarded, Contractor and Contracting Officer will collaborate with the Facility Privacy Officer Roy Martinez [Rogelio.MartinezJr@va.gov] to implement the appropriate BAA.

View original listing