Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 16 at 2:00 PM EDT

Register Free →

This Sources Sought opportunity from Department Of Veterans Affairs was posted on July 14, 2026. The submission period has ended. Browse the details below for market research, or find similar active opportunities.

AN11--Kaiser Permanente R&D Statistical Expertise EHR Evaluation

Closed
36C26026Q0835Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

Active Opportunities Like This One

NAICS: 541720
New
Federal
A Study on Vessel Design Challenge
Solicitation # 693JF726R000016
The U.S. Maritime Administration (MARAD) is issuing a Request for Proposals under the Maritime Environmental and Technical Assistance (META) program for a Vessel Design Challenge. This initiative seeks to fund multiple design teams to develop integrated vessel designs that prioritize a 30% improvement in fuel efficiency and a reduction in underwater radiated noise (URN). The program is open to domestic applicants other than individuals, with a preference for U.S.-based companies operating under the U.S. flag. Eligible designs include the redesign of existing projects, new design specifications, or theoretical and experimental approaches for commercially useful vessels, excluding small watercraft, recreational, or fisheries vessels. Funding is provided through cooperative agreements, with individual awards ranging from $150,000 to $450,000 and a total available funding pool of $1.25 million. The project timeline is 12 to 18 months. Successful applicants must deliver a preliminary vessel design including hull forms, propulsion and power system selections, stability and load analyses, and a comprehensive economic analysis detailing the return on investment compared to conventional designs. Proposals are limited to 20 pages and must be submitted in PDF format via email to the designated contract specialists. Evaluation will be based on the design integration plan, methodology, team capabilities, project timeline, and budget justification. All applicants must maintain active registration in the System for Award Management (SAM).
693JF7 DOT Maritime Administration

POSTED

2 days ago

DEADLINE

in 4 months
NAICS: 541720
New
Federal
USACE History Office (CEHO) Historical Support Services BPA
Solicitation # W912HQ26QA023
Solicitation W912HQ26QA023 is a total small business set-aside under NAICS 541720 to establish a pool of Blanket Purchase Agreement (BPA) holders to provide historical support services for the USACE Office of History (CEHO). The scope of work includes research, writing, archival management, museum and curatorial support, and the conservation and digitization of historical materials for CEHO, all USACE organizations, and the U.S. Army Engineer School at Ft. Leonard Wood, Missouri. The agreement features a five-year ordering period from September 18, 2026, to September 17, 2031, with a total ceiling of 7.5 million dollars. Individual BPA calls are limited to a maximum of 350,000 dollars, with a minimum order amount of 2,500 dollars. The government intends to award the BPA to all responsible and responsive offerors who meet the minimum technical and qualification requirements. Evaluation is based on technical resources, key personnel, and past performance, with a requirement for small business holders to perform at least 50 percent of the labor. Proposals must be submitted by 12:00 PM EST on September 21, 2026, and should include a technical approach, representative resumes, and samples as specified in Appendix A. Performance is governed by Army Regulations 870-5 and 870-20, and contractors must adhere to strict security and training requirements, including OPSEC and CUI training, as well as ADA standards for exhibit work.
W4LD USA Hecsa

POSTED

2 days ago

DEADLINE

in 9 days
NAICS: 541720
New
Federal
Household Consumer Food Purchase Panel
Solicitation # 1232SA26Q1153
Solicitation 1232SA26Q1153 is an unrestricted, combined synopsis and request for quote issued by the USDA Agricultural Research Service for the procurement of the Household Consumer Food Purchase Panel. The objective is to obtain high-quality, nationally representative food purchase panel data from 2019 through 2031 to support economic and policy research, with a specific focus on SNAP and WIC participants. The contractor will be required to provide detailed purchase data, including item-level identifiers like GTINs or UPCs, payment method tracking for EBT, and household demographic characteristics. Deliverables include initial data spanning 2019 to September 30, 2026, by November 1, 2026, followed by quarterly updates through June 2027 and biannual updates thereafter. The contract is a firm-fixed-price award with an estimated period of performance from September 15, 2026, to September 14, 2031, consisting of one base year and four option years. Award will be based on the best value, evaluating technical approach, past performance—requiring two to three relevant projects from the last three years—and fair and reasonable pricing. To be considered, vendors must submit a priced SF-1449, a firm-fixed-price quotation on company letterhead, a Sam.gov Unique Entity ID, a capability statement, and past performance references by September 21, 2026, at 9:00 AM PT. All quotes must remain firm for 60 calendar days following the deadline.
USDA Ars Afm Apd

POSTED

2 days ago

DEADLINE

in 9 days
NAICS: 541720
New
Federal
COMBINED SYNOPSIS/RFQ FOR GEOPOLITICAL ANALYSIS SUBJECT MATTER EXPERT (SME) SERVICES
Solicitation # N00244-26-Q-0108
Solicitation N00244-26-Q-0108 is a small business set-aside request for quotation issued by the Naval Supply Systems Command Fleet Logistics Center San Diego. The contract seeks specialized professional research, technical-advisory services, and geopolitical analysis to support the Naval Postgraduate School, OPNAV N7 for Force Design, and the Deputy Assistant Secretary of the Navy for Operational Energy. The primary focus is on integrated deterrence strategies, specifically addressing contested logistics and vulnerabilities in the Indo-Pacific regarding China-Taiwan issues. The award will be a firm-fixed-price contract consisting of a 12-month base period from September 30, 2026, to September 29, 2027, with two subsequent 12-month option periods, for a total duration not to exceed three years. The scope of work requires up to two subject matter experts who must hold a PhD in geopolitics or a related field obtained within the last five years and possess a Secret security clearance. Key deliverables include the development of value models, geopolitical analysis of wargames and simulations, and technical advisory services. The base period includes 450 hours of SME services and seven travel events, with option periods providing for 300 hours of service and four travel events each. Proposals will be evaluated based on a best-value trade-off, prioritizing the technical narrative and past performance over price. Submissions must be delivered electronically to the contract specialist by 5:00 PM PST on September 16, 2026, following extensions provided in Amendment 0002.
Navsup Flt Logistics Ctr San Diego

POSTED

2 days ago

DEADLINE

in 5 days

AI Contract Overview

Show more

The Department of Veterans Affairs, through its Network Contract Office 20, is conducting market research via a Sources Sought notice to identify qualified service providers capable of delivering statistical expertise in measurement error and missing data analysis to support the evaluation of the Veterans Health Administration’s immersive virtual reality program. The intended contract is a firm-fixed price R&D services agreement with a base year and two option years, set to begin September 15, 2026, and primarily performed remotely with in-person meetings at the VA Puget Sound Health Care System in Seattle, WA. The agency seeks to engage Kaiser Permanente Washington Health Research Institute to leverage the specialized skills of Dr. Pamela Shaw, a leading biostatistician with extensive experience in electronic health records analysis, study design, and statistical methods for mitigating bias in observational data. Her role will include developing and reviewing study protocols aligned with STRATOS/STROBE guidelines, validating EHR outcome definitions, guiding prospective data collection to supplement incomplete patient-reported outcomes, conducting code reviews for analytic reproducibility, and co-authoring technical reports and peer-reviewed publications. The work spans three fiscal years and requires rigorous methodological oversight to ensure accurate assessment of VR therapy impact, including patient health outcomes, healthcare utilization, and cost implications. The contract imposes stringent information security, privacy, and records management obligations consistent with federal regulations and VA directives, including compliance with FISMA, HIPAA, the Privacy Act of 1974, and NIST standards. Contractors must implement VA-approved encryption, conduct annual security control assessments, adhere to strict data handling procedures, and immediately report any security incidents or breaches involving sensitive personal information. Failure to comply may result in liquidated damages of $42 per affected individual to cover credit monitoring and identity theft protection services. Contractors and their personnel must complete mandatory cybersecurity and privacy training, sign the Contractor Rules of Behavior, and obtain necessary clearances before accessing VA systems. All deliverables become U.S. Government property with unlimited rights, and no records created under the contract may be retained, sold, or disseminated without authorization. Only authorized Kaiser Permanente service providers may respond, and interested parties must submit company details, socioeconomic status certifications via SBA, and a courtesy quote by the July 20, 2026 deadline to inform potential set-aside determinations under NAICS code 541720. Participation in this sources sought notice carries no obligation for the government to issue a solicitation or award a contract.

General Info

VA seeks Kaiser Permanente to provide biostatistical expertise for VR program evaluation under firm-fixed price R&D contract starting September 2026.

Agency

Department Of Veterans Affairs → 260-NETWORK Contract Office 20 (36C260)View Agency

NAICS

541720 - Research and Development in the Social Sciences and HumanitiesView NAICS

Place of Performance

Puget Sound VA Health Care System 1660 South Columbian Way, Seattle, WA, 98108, USA

Set-Aside

NONE

Documents

(1)

36C26026Q0835.docx

DOCX

AI Contract Breakdown

Uniform Contract Format

What is UCF?

Uniform Contract Format (UCF) uses AI to break down any contract into standardized sections—scope, pricing, deliverables, and evaluation criteria.

Timeline

PhaseClosed
Posted

Sources Sought

Response Deadline

Deadline has passed

Submission Closed

Find active opportunities like this

Start your free trial to discover similar active contracts, track opportunities, and build proposals with AI assistance.

Organization & Contact Information

Show more
AgencyDepartment Of Veterans Affairs → 260-NETWORK Contract Office 20 (36C260)
Contacts1 person available
OfficeVANCOUVER, WA, 98661, USA
Organization / Agency
Department Of Veterans Affairs → 260-NETWORK Contract Office 20 (36C260)
View Agency Profile
Office AddressVANCOUVER, WA, 98661, USA
Contacts
Peter ParkContracting Officer

Full Description

Show more

2 Notice of Sources Sought
The purpose of this Sources Sought Announcement is for market research to make appropriate acquisition decisions and to gain knowledge of potential qualified Service-Disabled Veteran Owned Small Businesses (SDVOSB), Veteran Owned Small Businesses (VOSB), Women Owned Small Businesses (WOSB) and Small Businesses interested and capable of providing the services requested, as well as any large businesses. The results from this source sought notice will be used to determine the appropriate set-aside.
The intended contract is a firm-fixed price R&D service contract.
The SBA Non-Manufacturer Rule is not applicable as the intended contract is for services.
The Department of Veterans Affairs, NCO 20 is looking for Kaiser Permanente s authorized service providers that can provide below R&D services.
Statement of Work: Contract Title Expertise in Measurement Error to Support VHA Digital Health Office Immersive Program Evaluation Project: VHA Digital Health Office Immersive Program Evaluation
Background Virtual reality (VR) is an emerging technology that has been used as a treatment in diverse pain populations and for diverse indications. VA's Digital Health Office is exploring offering Veterans a variety of VR therapies through conducting multiple pilot initiatives. To date over 8,000 Veterans have engaged in VR activities through engaging in headset technologies in clinics and at home. Quantifying the potential benefit of disseminating VR technologies requires careful assessment of the VR activities, how they are being used in combination with other therapies such as mental health treatment and physical therapy, and monitoring of outcomes including patient reported changes in health, pain and well-being, healthcare utilization changes and overall costs. The Digital Health Office is providing tools to measure VR engagement and has requested evaluation of the VHA Immersive Program and to generate insights about how to best support further XR implementation. The evaluation activities will leverage data collected as part of VHA Immersive Program activities, data about participants linked to VHA administrative data, and primary data collected by the evaluation team. The evaluation will span three fiscal years, and will be comprised of retrospective analyses, mixed-methods evaluation design, and prospective data collection. To understand how population-level coding and documentation of VR engagement reflect true exposure levels, fidelity, and overall VR dose we require a statistical expert. We are requesting a contract with Kaiser Permanente Washington Health Research Institute (KPWHRI) in order for Pamela Shaw, PhD to work with this project and provide expertise in statistical methods and study design. Dr. Shaw is a Senior Investigator in the Division of Biostatistics at KPWHRI and also Affiliate Professor in the Department of Biostatistics at the University of Washington School of Public Health. Dr. Shaw s research focuses on the design and analysis of studies leveraging electronic health records (EHR) data to support rigorous, cost-effective, clinical and epidemiologic research to improve the health and guide treatment decisions for US citizens. Dr. Shaw brings expertise in complex survey design, statistical methods and study design to address measurement error and outcome misclassification, and the evaluations of interventions using clinical trial and observational data across a variety of health care settings and populations. Her work integrates methodological rigor with practical relevance, advancing the use of electronic health records data to public health and clinical decision making. Selected research projects done under Dr. Shaw s leadership: Williamson B, Krakauer C, Johnson E, Gruber S, Shepherd BE, van der Laan MJ, Lumley T, Lee H, Hernandez Munoz JJ, Zhao F, Dutcher SK, Desai, R, Simon GE, Shortreed SM, Nelson JC, Shaw PA. Assessing treatment effects in observational data with missing confounders: A comparative study of practical doubly-robust and traditional missing data methods. Statistics in Medicine, 2026 Feb;45(3-5):e70366 Shepherd BE, Han K, Chen T, Bian A, Pugh S, Duda SN, Lumley T, Heerman WJ, Shaw PA. Multiwave validation sampling for error-prone electronic health records. Biometrics. 2023 Sep;79(3):2649-2663. PubMed Central PMCID: PMC10525037. Shaw PA, Yang JB, Mowery DL, Schriver ER, Mahoney KB, Bar KJ, Ellenberg SS. Determinants of hospital outcomes for COVID-19 infections in a large Pennsylvania Health System. PLoS ONE, 2022 May 19; 17(5): e0268528. Shaw PA, Gustafson P, Carroll RJ, Deffner V, Dodd KW, Keogh RH, Kipnis V, Tooze JA, Wallace MP, Kuchenhoff H, Freedman LS. STRATOS guidance document on measurement error and misclassification of variables in observational epidemiology: Part II -more complex methods of adjustment and advanced topics.  Statistics in Medicine 2020 Jul 20;39(16):2232-2263.   Han K, Lumley T, Shepherd BE, Shaw PA. Two-phase analysis and study design for survival models with error-prone exposures. Stat Methods Med Res. 2020 Dec 16; PubMed Central PMCID: PMC8715910. Shaw PA. Use of composite outcomes to assess risk-benefit in clinical trials. Clin Trials. 2018 Aug;15(4):352-358. PubMed PMID: 30021496.
Scope Dr. Shaw will provide expertise in measurement error and missing data in studies of longitudinal EHR outcomes following the rigorous frameworks for designing and analyzing observations studies as outlined in the international STRATOS guidance about statistical methods to minimize measurement error and her previous work on two-phase analyses and study designs to address error-prone electronic health records data. This will include reviewing study protocols and statistical analysis plans that rely on EHR data that are subject to missingness and measurement error, especially about use of VR/Immersive technologies that are utilized through a combination of in-clinic and at-home sessions. Dr. Shaw will also provide specific expertise in designing future prospective study protocols and data collection strategies for future evaluations of VR/Immerstive technologies that address potential residual sources of bias associated with measurement error and missing data. Dr. Shaw will work with the analytics team to review available covariate information for patients engaging in VR therapies. Based on observed patterns, she will support two efforts: 1) Provide guidance for prospective data collection efforts to improve precision in specific sub-populations about factors most likely to influence the causal quantities of interest. 2) Provide guidance regarding robust and efficient analytic approaches that leverage auxiliary EHR data with outcome data only available on a subset (e.g. patent reported outcomes). This contract will strengthen analytic accuracy, efficiency, and the credibility of evaluation outcomes. Tasks and Deliverables Task 1: Collaborate with VA Puget Sound study team to develop study protocols and statistical analysis plans. Ensure development of any necessary statistical analysis plans are in line with STRATOS/STROBE guidelines. Task 2: Review EHR outcome definitions, data extraction algorithms, and subset of patient reported outcome data available from specific immersive pilot Task 3: Guide sampling procedures for future prospective data collection efforts among patient subgroups for specific immersive pilot initiatives to supplement EHR outcomes with supplementally collected patient reported outcomes. Task 4: Code review of VA Puget Sound study analysts and replication of analytic findings to ensure reproducibility and quality control.
Task 5: Feedback and review of VA Puget Sound analytic team technical reports detailing internal evaluation findings. Some internal reports may be of interest to broader healthcare community and, if appropriate, will be prepared for peer-review and dissemination through journal publications. Dr. Shaw will serve as a methodologic expert and co-author in manuscript preparation. Deliverable Description Delivery Date 1 Development of study protocols and statistical analysis plans in accordance with STRATOS/STROBE guidelines. As needed 2 Review of EHR outcome definitions, data extraction algorithms, and available patient-reported outcome data from immersive pilot initiatives. As needed 3 Provide sampling recommendations for prospective patient subgroup data collection efforts to supplement EHR outcomes with patient-reported outcomes. As needed 4 Code review and independent replication of analytic findings with written documentation of review outcomes. As needed 5 Review of and feedback on internal technical reports; co-authorship of manuscripts prepared for peer-review submission, as appropriate. As needed 6 Virtual and in-person meeting attendance. As needed
Performance Monitoring Dr. Zeliadt will provide oversight of the work, which will be measured by meeting project deadlines in a timely fashion and regularly assessed quality of the work in achieving the stated project goals. This regular performance evaluation will be recorded in minutes that will be available to the Station POC/COR for review.
The Station POC/COR will work with Dr. Zeliadt and the evaluation team to complete the required annual performance evaluation. Place of Performance The work will be conducted remotely. Dr. Shaw will also attend in-person meetings at the VA Puget Sound Health Care System.
Period of Performance Base year plus two option years. The anticipated start date is September 15, 2026.
VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE FOR INCLUSION INTO CONTRACTS, AS APPROPRIATE
GENERAL
Contractors, contractor personnel, subcontractors, and subcontractor personnel shall be subject to the same Federal laws, regulations, standards, and VA Directives and Handbooks as VA and VA personnel regarding information and information system security.
ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS
A contractor/subcontractor shall request logical (technical) or physical access to VA information and VA information systems for their employees, subcontractors, and affiliates only to the extent necessary to perform the services specified in the contract, agreement, or task order.
All contractors, subcontractors, and third-party servicers and associates working with VA information are subject to the same investigative requirements as those of VA appointees or employees who have access to the same types of information. The level and process of background security investigations for contractors must be in accordance with VA Directive and Handbook 0710, Personnel Suitability and Security Program. The Office for Operations, Security, and Preparedness is responsible for these policies and procedures.
Contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry contract personnel safeguard the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. The Department of Veterans Affairs does not have a Memorandum of Agreement with Defense Security Service (DSS). Verification of a Security Clearance must be processed through the Special Security Officer located in the Planning and National Security Service within the Office of Operations, Security, and Preparedness.
Custom software development and outsourced operations must be located in the U.S. to the maximum extent practical. If such services are proposed to be performed abroad and are not disallowed by other VA policy or mandates, the contractor/subcontractor must state where all non-U.S. services are provided and detail a security plan, deemed to be acceptable by VA, specifically to address mitigation of the resulting problems of communication, control, data protection, and so forth. Location within the U.S. may be an evaluation factor. 3
The contractor or subcontractor must notify the Contracting Officer immediately when an employee working on a VA system or with access to VA information is reassigned or leaves the contractor or subcontractor s employ. The Contracting Officer must also be notified immediately by the contractor or subcontractor prior to an unfriendly termination.
VA INFORMATION CUSTODIAL LANGUAGE
Information made available to the contractor or subcontractor by VA for the performance or administration of this contract or information developed by the contractor/subcontractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the VA. This clause expressly limits the contractor/subcontractor's rights to use data as described in Rights in Data - General, FAR 52.227-14(d) (1).
VA information should not be co-mingled, if possible, with any other data on the contractors/subcontractor s information systems or media storage systems in order to ensure VA requirements related to data protection and media sanitization can be met. If co-mingling must be allowed to meet the requirements of the business need, the contractor must ensure that VA s information is returned to the VA or destroyed in accordance with VA s sanitization requirements. VA reserves the right to conduct on site inspections of contractor and subcontractor IT resources to ensure data security controls, separation of data and job duties, and destruction/media sanitization procedures are in compliance with VA directive requirements.
Prior to termination or completion of this contract, contractor/subcontractor must not destroy information received from VA, or gathered/created by the contractor in the course of performing this contract without prior written approval by the VA. Any data destruction done on behalf of VA by a contractor/subcontractor must be done in accordance with National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records and Information Management and its Handbook 6300.1 Records Management Procedures, applicable VA Records Control Schedules, and VA Handbook 6500.1, Electronic Media Sanitization. Self-certification by the contractor that the data destruction requirements above have been met must be sent to the VA Contracting Officer within 30 days of termination of the contract.
The contractor/subcontractor must receive, gather, store, back up, maintain, use, disclose and dispose of VA information only in compliance with the terms of the contract and applicable Federal and VA information confidentiality and security laws, regulations and policies. If Federal or VA information confidentiality and security laws, regulations and policies become applicable to the VA information or information systems after execution of the contract, or if NIST issues or updates applicable FIPS or Special Publications (SP) after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies in this contract.
The contractor/subcontractor shall not make copies of VA information except as authorized and necessary to perform the terms of the agreement or to preserve electronic information stored on contractor/subcontractor electronic storage media for restoration in case any electronic equipment or data used by the contractor/subcontractor needs to be restored to an operating state. If copies are made for restoration purposes, after the restoration is complete, the copies must be appropriately destroyed.
If VA determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for VA to withhold payment to the contractor or third party or terminate the contract for default or terminate for cause under Federal Acquisition Regulation (FAR) part 12.
If a VHA contract is terminated for cause, the associated BAA must also be terminated and appropriate actions taken in accordance with VHA Handbook 1600.01, Business Associate Agreements. Absent an agreement to use or disclose protected health information, there is no business associate relationship.
The contractor/subcontractor must store, transport, or transmit VA sensitive information in an encrypted form, using VA-approved encryption tools that are, at a minimum, FIPS 140-2 validated.
The contractor/subcontractor s firewall and Web services security controls, if applicable, shall meet or exceed VA s minimum requirements. VA Configuration Guidelines are available upon request.
Except for uses and disclosures of VA information authorized by this contract for performance of the contract, the contractor/subcontractor may use and disclose VA information only in two other situations: (i) in response to a qualifying order of a court of competent jurisdiction, or (ii) with VA s prior written approval. The contractor/subcontractor must refer all requests for, demands for production of, or inquiries about, VA information and information systems to the VA contracting officer for response.
Notwithstanding the provision above, the contractor/subcontractor shall not release VA records protected by Title 38 U.S.C. 5705, confidentiality of medical quality assurance records and/or Title 38 U.S.C. 7332, confidentiality of certain health records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol abuse, or infection with human immunodeficiency virus. If the contractor/subcontractor is in receipt of a court order or other requests for the above mentioned information, that contractor/subcontractor shall immediately refer such court orders or other requests to the VA contracting officer for response. 5 4 For service that involves the storage, generating, transmitting, or exchanging of VA sensitive information but does not require C&A or an MOU-ISA for system interconnection, the contractor/subcontractor must complete a Contractor Security Control Assessment (CSCA) on a yearly basis and provide it to the COTR.
INFORMATION SYSTEM DESIGN AND DEVELOPMENT
Information systems that are designed or developed for or on behalf of VA at non-VA facilities shall comply with all VA directives developed in accordance with FISMA, HIPAA, NIST, and related VA security and privacy control requirements for Federal information systems. This includes standards for the protection of electronic PHI, outlined in 45 C.F.R. Part 164, Subpart C, information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization (reference Appendix D of VA Handbook 6500, VA Information Security Program). During the development cycle a Privacy Impact Assessment (PIA) must be completed, provided to the COTR, and approved by the VA Privacy Service in accordance with Directive 6507, VA Privacy Impact Assessment.
The contractor/subcontractor shall certify to the COTR that applications are fully functional and operate correctly as intended on systems using the VA Federal Desktop Core Configuration (FDCC), and the common security configuration guidelines provided by NIST or the VA. This includes Internet Explorer 7 configured to operate on Windows XP and Vista (in Protected Mode on Vista) and future versions, as required.
The standard installation, operation, maintenance, updating, and patching of software shall not alter the configuration settings from the VA approved and FDCC configuration. Information technology staff must also use the Windows Installer Service for installation to the default program files directory and silently install and uninstall.
Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
The security controls must be designed, developed, approved by VA, and implemented in accordance with the provisions of VA security system development life cycle as outlined in NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, VA Handbook 6500, Information Security Program and VA Handbook 6500.5, Incorporating Security and Privacy in System Development Lifecycle.
The contractor/subcontractor is required to design, develop, or operate a System of Records Notice (SOR) on individuals to accomplish an agency function subject to the Privacy Act of 1974, (as amended), Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Privacy Act may involve the imposition of criminal and civil penalties.
The contractor/subcontractor agrees to:
Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:
(a) The Systems of Records (SOR); and
(b) The design, development, or operation work that the contractor/subcontractor is to perform;
Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a SOR on individuals that is subject to the Privacy Act; and
Include this Privacy Act clause, including this subparagraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a SOR.
In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a SOR on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a SOR on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a SOR on individuals to accomplish an agency function, the contractor/subcontractor is considered to be an employee of the agency.
Operation of a System of Records means performance of any of the activities associated with maintaining the SOR, including the collection, use, maintenance, and dissemination of records.
Record means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and contains the person s name, or identifying number, symbol, or any other identifying particular assigned to the individual, such as a fingerprint or voiceprint, or a photograph.
System of Records means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
7 6 The vendor shall ensure the security of all procured or developed systems and technologies, including their subcomponents (hereinafter referred to as Systems ), throughout the life of this contract and any extension, warranty, or maintenance periods. This includes, but is not limited to workarounds, patches, hotfixes, upgrades, and any physical components (hereafter referred to as Security Fixes) which may be necessary to fix all security vulnerabilities published or known to the vendor anywhere in the Systems, including Operating Systems and firmware. The vendor shall ensure that Security Fixes shall not negatively impact the Systems.
The vendor shall notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the Systems (including the confidentiality or integrity of its data and operations, or the availability of the system). Such issues shall be remediated as quickly as is practical, but in no event longer than 10 days.
When the Security Fixes involve installing third party patches (such as Microsoft OS patches or Adobe Acrobat), the vendor will provide written notice to the VA that the patch has been validated as not affecting the Systems within 10 working days. When the vendor is responsible for operations or maintenance of the Systems, they shall apply the Security Fixes within 10 days.
All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. Exceptions to this paragraph (e.g. for the convenience of VA) shall only be granted with approval of the contracting officer and the VA Assistant Secretary for Office of Information and Technology.
INFORMATION SYSTEM HOSTING, OPERATION, MAINTENANCE, OR USE
For information systems that are hosted, operated, maintained, or used on behalf of VA at non-VA facilities, contractors/subcontractors are fully responsible and accountable for ensuring compliance with all HIPAA, Privacy Act, FISMA, NIST, FIPS, and VA security and privacy directives and handbooks. This includes conducting compliant risk assessments, routine vulnerability scanning, system patching and change management procedures, and the completion of an acceptable contingency plan for each system. The contractor s security control procedures must be equivalent, to those procedures used to secure VA systems. A Privacy Impact Assessment (PIA) must also be provided to the COTR and approved by VA Privacy Service prior to operational approval. All external Internet connections to VA s network involving VA information must be reviewed and approved by VA prior to implementation.
8 7 Adequate security controls for collecting, processing, transmitting, and storing of Personally Identifiable Information (PII), as determined by the VA Privacy Service, must be in place, tested, and approved by VA prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of VA. These security controls are to be assessed and stated within the PIA and if these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.
Outsourcing (contractor facility, contractor equipment or contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (authorization) (C&A) of the contractor s systems in accordance with VA Handbook 6500.3, Certification and Accreditation and/or the VA OCS Certification Program Office. Government-owned (government facility or government equipment) contractor-operated systems, third party or business partner networks require memorandums of understanding and interconnection agreements (MOU-ISA) which detail what data types are shared, who has access, and the appropriate level of security controls for all systems connected to VA networks. The contractor/subcontractor s system must adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the VA contracting officer and the ISO for entry into VA s POA&M management process. The contractor/subcontractor must use VA s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the government. Contractor/subcontractor procedures are subject to periodic, unannounced assessments by VA officials, including the VA Office of Inspector General. The physical security aspects associated with contractor/subcontractor activities must also be subject to such assessments. If major changes to the system occur that may affect the privacy or security of the data or the system, the C&A of the system may need to be reviewed, retested and re-authorized per VA Handbook 6500.3. This may require reviewing and updating all of the documentation (PIA, System Security Plan, Contingency Plan). The Certification Program Office can provide guidance on whether a new C&A would be necessary.
The contractor/subcontractor must conduct an annual self assessment on all systems and outsourced services as required. Both hard copy and electronic copies of the assessment must be provided to the COTR. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action (this can be specified in the contract) to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost.
VA prohibits the installation and use of personally-owned or contractor/subcontractor-owned equipment or software on VA s network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, SOW or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal (host-based or enclave based) firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the anti-viral software and the firewall on the non-VA owned OE.
All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA Handbook 6500.1, Electronic Media Sanitization upon: (i) completion or termination of the contract or (ii) disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media (hard drives, optical disks, CDs, back-up tapes, etc.) used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per 6500.1 requirements. This must be completed within 30 days of termination of the contract.
Bio-Medical devices and other equipment or systems containing media (hard drives, optical disks, etc.) with VA sensitive information must not be returned to the vendor at the end of lease, for trade-in, or other purposes. The options are:
Vendor must accept the system without the drive;
VA s initial medical device purchase includes a spare drive which must be installed in place of the original drive at time of turn-in; or
VA must reimburse the company for media at a reasonable open market replacement cost at time of purchase.
Due to the highly specialized and sometimes proprietary hardware and software associated with medical equipment/systems, if it is not possible for the VA to retain the hard drive, then;
The equipment vendor must have an existing BAA if the device being traded in has sensitive information stored on it and hard drive(s) from the system are being returned physically intact; and
Any fixed hard drive on the device must be non-destructively sanitized to the greatest extent possible without negatively impacting system operation. Selective clearing down to patient data folder level is recommended using VA approved and validated overwriting technologies/methods/tools. Applicable media sanitization specifications need to be pre-approved and described in the purchase order or contract. 10 9 A statement needs to be signed by the Director (System Owner) that states that the drive could not be removed and that (a) and (b) controls above are in place and completed.  The ISO needs to maintain the documentation.
SECURITY INCIDENT INVESTIGATION
The term security incident means an event that has, or could have, resulted in unauthorized access to, loss or damage to VA assets, or sensitive information, or an action that breaches VA security procedures. The contractor/subcontractor shall immediately notify the COTR and simultaneously, the designated ISO and Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in system(s) to which the contractor/subcontractor has access.
To the extent known by the contractor/subcontractor, the contractor/subcontractor s notice to VA shall identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA information or assets were placed at risk or compromised), and any other information that the contractor/subcontractor considers relevant.
With respect to unsecured protected health information, the business associate is deemed to have discovered a data breach when the business associate knew or should have known of a breach of such information. Upon discovery, the business associate must notify the covered entity of the breach. Notifications need to be made in accordance with the executed business associate agreement.
In instances of theft or break-in or other criminal activity, the contractor/subcontractor must concurrently report the incident to the appropriate law enforcement entity (or entities) of jurisdiction, including the VA OIG and Security and Law Enforcement. The contractor, its employees, and its subcontractors and their employees shall cooperate with VA and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law violation(s) associated with any incident. The contractor/subcontractor shall cooperate with VA in any civil litigation to recover VA information, obtain monetary or other compensation from a third party for damages arising from any incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
LIQUIDATED DAMAGES FOR DATA BREACH
Consistent with the requirements of 38 U.S.C. §5725, a contract may require access to sensitive personal information. If so, the contractor is liable to VA for liquidated damages in the event of a data breach or privacy incident involving any SPI the contractor/subcontractor processes or maintains under this contract.
The contractor/subcontractor shall provide notice to VA of a security incident as set forth in the Security Incident Investigation section above. Upon such notification, VA must secure from a non-Department entity or the VA Office of Inspector General an independent risk analysis of the data breach to determine the level of risk associated with the data breach for the potential misuse of any sensitive personal information involved in the data breach. The term 'data breach' means the loss, theft, or other unauthorized access, or any access other than that incidental to the scope of employment, to data containing sensitive personal information, in electronic or printed form, that results in the potential compromise of the confidentiality or integrity of the data. Contractor shall fully cooperate with the entity performing the risk analysis. Failure to cooperate may be deemed a material breach and grounds for contract termination.
Each risk analysis shall address all relevant information concerning the data breach, including the following:
NATURE OF THE EVENT (LOSS, THEFT, UNAUTHORIZED ACCESS);
DESCRIPTION OF THE EVENT, INCLUDING:
(A) DATE OF OCCURRENCE; (B) DATA ELEMENTS INVOLVED, INCLUDING ANY PII, SUCH AS FULL NAME, SOCIAL SECURITY NUMBER, DATE OF BIRTH, HOME ADDRESS, ACCOUNT NUMBER, DISABILITY CODE;
(3) NUMBER OF INDIVIDUALS AFFECTED OR POTENTIALLY AFFECTED; (4) NAMES OF INDIVIDUALS OR GROUPS AFFECTED OR POTENTIALLY AFFECTED;
(5) EASE OF LOGICAL DATA ACCESS TO THE LOST, STOLEN OR IMPROPERLY ACCESSED DATA IN LIGHT OF THE DEGREE OF PROTECTION FOR THE DATA, E.G., UNENCRYPTED, PLAIN TEXT; (6) AMOUNT OF TIME THE DATA HAS BEEN OUT OF VA CONTROL;
(7) THE LIKELIHOOD THAT THE SENSITIVE PERSONAL INFORMATION WILL OR HAS BEEN COMPROMISED (MADE ACCESSIBLE TO AND USABLE BY UNAUTHORIZED PERSONS); (8) KNOWN MISUSES OF DATA CONTAINING SENSITIVE PERSONAL INFORMATION, IF ANY; (9) ASSESSMENT OF THE POTENTIAL HARM TO THE AFFECTED INDIVIDUALS; (10) DATA BREACH ANALYSIS AS OUTLINED IN 6500.2 HANDBOOK, MANAGEMENT OF SECURITY AND PRIVACY INCIDENTS, AS APPROPRIATE; AND (11) WHETHER CREDIT PROTECTION SERVICES MAY ASSIST RECORD SUBJECTS IN AVOIDING OR MITIGATING THE RESULTS OF IDENTITY THEFT BASED ON THE SENSITIVE PERSONAL INFORMATION THAT MAY HAVE BEEN COMPROMISED.
Based on the determinations of the independent risk analysis, the contractor shall be responsible for paying to the VA liquidated damages in the amount of $ 42.00 per affected individual to cover the cost of providing credit protection services to affected individuals consisting of the following:
(1) NOTIFICATION; (2) ONE YEAR OF CREDIT MONITORING SERVICES CONSISTING OF AUTOMATIC DAILY MONITORING OF AT LEAST 3 RELEVANT CREDIT BUREAU REPORTS; (3) DATA BREACH ANALYSIS; (4) FRAUD RESOLUTION SERVICES, INCLUDING WRITING DISPUTE LETTERS, INITIATING FRAUD ALERTS AND CREDIT FREEZES, TO ASSIST AFFECTED INDIVIDUALS TO BRING MATTERS TO RESOLUTION; (5) ONE YEAR OF IDENTITY THEFT INSURANCE WITH $20,000.00 COVERAGE AT $0 DEDUCTIBLE; AND
(6) Necessary legal expenses the subjects may incur to repair falsified or damaged credit records, histories, or financial affairs.
SECURITY CONTROLS COMPLIANCE TESTING
On a periodic basis, VA, including the Office of Inspector General, reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract. With 10 working-day s notice, at the request of the government, the contractor must fully cooperate and assist in a government-sponsored security controls assessment at each location wherein VA information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of VA, including those initiated by the Office of Inspector General. The government may conduct a security control assessment on shorter notice (to include unannounced assessments) as determined by VA in the event of a security incident or at any other time.
TRAINING
All contractor employees and subcontractor employees requiring access to VA information and VA information systems shall complete the following before being granted access to VA information and its systems:
Sign and acknowledge (either manually or electronically) understanding of and responsibilities for compliance with the Contractor Rules of Behavior, Appendix E relating to access to VA information and information systems;
Successfully complete the VA Cyber Security Awareness and Rules of Behavior training and annually complete required security training;
Successfully complete the appropriate VA privacy training and annually complete required privacy training; and
Successfully complete any additional cyber security or privacy training, as required for VA personnel with equivalent information system access [to be defined by the VA program official and provided to the contracting officer for inclusion in the solicitation document e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirements.]
The contractor shall provide to the contracting officer and/or the COTR a copy of the training certificates and certification of signing the Contractor Rules of Behavior for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.
Failure to complete the mandatory annual training and sign the Rules of Behavior annually, within the timeframe required, is grounds for suspension or termination of all physical or electronic access privileges and removal from work on the contract until such time as the training and documents are complete.
Records Management The following standard items relate to records generated in executing the contract and should be included in a typical Electronic Information Systems (EIS) procurement contract: Citations to pertinent laws, codes and regulations such as 44 U.S.C chapters 21, 29, 31 and 33; Freedom of Information Act (5 U.S.C. 552); Privacy Act (5 U.S.C. 552a); 36 CFR Part 1222 and Part 1228. Contractor shall treat all deliverables under the contract as the property of the U.S. Government for which the Government Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Contractor shall not create or maintain any records that are not specifically tied to or authorized by the contract using Government IT equipment and/or Government records. Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected by the Freedom of Information Act. Contractor shall not create or maintain any records containing any Government Agency records that are not specifically tied to or authorized by the contract. The Government Agency owns the rights to all data/records produced as part of this contract. The Government Agency owns the rights to all electronic information (electronic data, electronic information systems, electronic databases, etc.) and all supporting documentation created as part of this contract. Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data. Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format [paper, electronic, etc.] or mode of transmission [e-mail, fax, etc.] or state of completion [draft, final, etc.]. No disposition of documents will be allowed without the prior written consent of the Contracting Officer. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the agency records schedules. Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, this contract. The Contractor (and any sub-contractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.
Required Information in Your Response to Sources Sought: In order to be considered a valid source that can impact the set-aside determination of a possible future solicitation, potential contractors shall provide, at a minimum, the following information to peter.park2@va.gov by below response deadline:
1) Company name, address, and point of contact, phone number, e-mail address, and UEI.
2) Please identify your company s size in comparison to the anticipated North American Industry Classification System (NAICS) code 541720 Research and Development in the Social Sciences and Humanities. To be considered a small business your company must have less than 28 million dollars in average annual receipts. This notice is to determine the marketplace for this specific requirement. Please check one of the following:
[ ] yes [ ] no Service Disabled Veteran Owned Small Business (SDVOSB) [ ] yes [ ] no Veteran Owned Small Business (VOSB) [ ] yes [ ] no Women Owned Small Business (WOSB) [ ] yes [ ] no HUBZone [ ] yes [ ] no Small Business Manufacturers [ ] yes [ ] no All other Small Business (SB) [ ] yes [ ] no Other than Small Business
3) Any socioeconomic business must have a SBA certification at https://search.certifications.sba.gov/.
4) Only authorized service representatives/providers of Kaiser Permanente that can provide this specific service will be considered.
5) Please provide a courtesy quote in response to this request to evaluate price reasonableness for any set-aside determination.
The Government is not obligated to nor will it pay for or reimburse any costs associated with responding to this sources sought notice. This notice shall not be construed as a commitment by the Government to issue a solicitation or ultimately award a contract, nor does it restrict the Government to a particular acquisition approach. The Government will in no way be bound to this information if any solicitation is issued.
Notice to Potential Offerors: All Offerors who provide goods or services to the United States Federal Government must be registered in the System Award Management (SAM located on the web at www.sam.gov). It is desirable that any Offeror to have completed their business Online Representations and Certifications Application in the System for Award Management (SAM).
Service Address: Puget Sound VA Health Care System 1660 South Columbian Way Seattle, WA 98108
Point of Contact: Peter Park Contracting Officer peter.park2@va.gov
Response Deadline: 07/20/2026 by 3:00pm Pacific Time

More opportunities from Department Of Veterans Affairs → 260-NETWORK Contract Office 20 (36C260)

Same awarding agency

NAICS: 332510
New
Federal
648 VA Portland OR Home Sleep Testing Services Requirement RFQ
Solicitation # 36C26026Q1021
The Department of Veterans Affairs Network Contracting Office 20 is soliciting an Indefinite Delivery, Indefinite Quantity IDIQ contract for Home Sleep Apnea Testing HSAT supplies and services to support the VA Portland Health Care System and other facilities within VISN20. This five-year firm-fixed price contract, consisting of a base year and four one-year option periods, is set aside for Service-Disabled Veteran-Owned Small Businesses SDVOSB under NAICS 332510. The objective is to transition from in-person laboratory polysomnography to a mail-order, direct-to-home disposable testing model to increase patient access and reduce clinical staff burden. The contractor must provide a comprehensive HSAT solution that includes preparing kits based on provider instructions, shipping them directly to Veterans, and providing 24/7 phone support for troubleshooting and instruction. The required devices must be FDA-cleared, lightweight, and capable of monitoring respiratory airflow, chest and abdominal effort, blood oxygen saturation, heart rate variability, and body positioning. Technical requirements include wireless data transmission to a HIPAA-compliant cloud platform for VA physician review, the ability to score obstructive and central sleep apnea events, and the provision of alternative devices for patients without smartphones or internet access. The system must also integrate questionnaires for Epworth sleepiness data and BMI calculations.
Hardware Manufacturing

POSTED

2 days ago

DEADLINE

in 6 days
View Details
NAICS: 541519
New
Federal
OFL (LMS) Lab Management Software
Solicitation # 36C26026Q0472
Solicitation 36C26026Q0472 is a Total Small Business Set-Aside request for quote issued by the Department of Veterans Affairs Network Contracting Office to procure Lab Management Software (LMS) and IOT digital lens calculation data for the VISN 20 Optical Fabrication Laboratory at the Boise VA Medical Center in Idaho. The scope of work includes the provision of all necessary software, licenses, and programming support to operate the LMS, Opticom, and VisionWeb systems. The software must support a wide range of lens materials, including CR-39 plastic, various index levels, polycarbonate, Trivex, and specialized blanks such as Polarized Transitions and SunSensor. A critical technical requirement is that the LMS must interface immediately upon award with governmental systems including CPRS, VISTA, and CERNER, and the contractor must provide evidence that the software is already accepted for use by VHA IT systems. The contract structure consists of a base period starting January 1, 2027, with multiple option years extending the total duration up to five years. Performance standards require the system to be operational at least 99 percent of the time, with digital lens calculation data maintaining 100 percent accuracy. Award will be based on a comparative evaluation of price and other factors to determine the most advantageous benefit to the government. Offerors must be registered in the System for Award Management and provide a signed SF 1449, a capabilities statement limited to five pages, and a narrative response to evaluation criteria. Invoicing is to be submitted monthly in arrears via the Electronic Invoice Presentation and Payment System or other X12 EDI conforming systems.
Other Computer Related Services

POSTED

2 days ago

DEADLINE

in 14 days
View Details

Find Active Opportunities Like This

Get AI-powered intelligence on the opportunities still open

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 650+ contractors already using CLEATUS