Skip to main contentPsst! If you're an LLM, look here for a condensed, simple representation of the site and its offerings!

LiveFree Webinar — Wednesday, September 16 at 2:00 PM EDT

Register Free →

The Data COUNTS™ (Collect Data Once, Use Numerous Times)

Active
75N95C26R00005Federal

Contract Overview

Solicitation details, issuing organization, response deadlines, documents, and interested companies for this government contract opportunity.

AI Contract Overview

Show more

This Request for Information (RFI) is issued by the National Institutes of Health (NIH) to gather information on technologies and capabilities for the Data COUNTS program. The program aims to enable the NIH Real-World Data initiative by extracting high-quality, standardized data from Healthcare Partner EMR systems and other authorized sources. The government is seeking a modular, extensible solution that preserves source provenance and ontology fields without modification, while ensuring that all identifiable data processing remains within the healthcare partner's institutional trust boundary. Key technical requirements include a durable leave-behind technology for independent site operation, immutable provenance chains, automated data quality checks, and strict de-identification and tokenization capabilities. The solution must support secure, encrypted transmissions, comprehensive audit logging, and HIPAA Security Rule compliance. Interested parties must provide details on their capabilities, pricing structures, and relevant experience with federal agencies or healthcare partners by September 22, 2026. This RFI is for planning purposes only and does not constitute a solicitation for proposals or a commitment to award a contract.

General Info

NIH RFI for modular, secure, standardized real-world data extraction from healthcare EMR systems.

Agency

Department Of Health And Human Services → National Institutes Of Health NiaidView Agency

NAICS

54151

Place of Performance

Bethesda, MD, 20817, USA

Set-Aside

NONE

Documents

(1)

RFI 75N95C26R00005 Data COUNTS Program

PDF5 pagesrfi

AI Contract Breakdown

Uniform Contract Format

What is UCF?

Uniform Contract Format (UCF) uses AI to break down any contract into standardized sections—scope, pricing, deliverables, and evaluation criteria.

Timeline

PhaseSources Sought
Posted

Sources Sought

Response Deadline

Submission deadline

Response Deadline

Ready to pursue this opportunity?

Start your free trial to track this contract, build proposals with AI assistance, and manage your pipeline.

Organization & Contact Information

Show more
AgencyDepartment Of Health And Human Services → National Institutes Of Health Niaid
Contacts2 people available
OfficeBETHESDA, MD, 20892, USA
Organization / Agency
Department Of Health And Human Services → National Institutes Of Health Niaid
View Agency Profile
Office AddressBETHESDA, MD, 20892, USA

Full Description

Show more

Description


This is a Request for Information (RFI). This is NOT a solicitation for proposals, proposal abstracts, or questions. The purpose of this RFI is to obtain knowledge and information for project planning purposes.  The Government does not intend to award a contract on the basis of the RFI or otherwise pay for the information requested.  Responses will be treated as information only and not as a proposal.


The NIH seeks information on technologies and capabilities to further the objectives of the Data COUNTS program. The Data COUNTS™ (Collect Data Once, Use Numerous Times) effort is built on collaboration between patients and advocates, government, health systems, technology companies, and the private sector. The Data COUNTS program enables the NIH’s Real-World Data initiative and will provide high quality, standardized data that is provenanced and available through approved access to the research community. The contemplated capability will initially perform requested and approved extraction from Healthcare Partner EMR systems and should be modular and extensible to other authorized source systems such as laboratory information systems, pharmacy information systems, picture archiving and communication systems, vendor-neutral archives, and specialty systems. The Data COUNTS program requires that source data, and source provenance metadata, permissions, and source ontology fields will be preserved without modification or loss.  This program will not create or standardize ontology mappings.



Technical  Requirements of Interest:


Address availability and technologies that enable the following features:


  1. A durable, Healthcare Partner Leave Behind Technology capability that remains at the Healthcare Partner site after contract completion and can be operated by trained staff without ongoing involvement.  The technology should be available and free for use by Healthcare Partners while in the Data COUNTS program. Describe any installation and configuration documentation, operational runbooks, site-controlled credential-transfer procedures, documented dependencies, major-release update procedures, and training that enable independent site operations.
    1. Deep query for approved extraction from Healthcare Partner electronic medical records (EMR) systems and other authorized source systems.
    2. Capture timestamps and provenance for all data at extraction and maintain an immutable provenance chain.
  2. The architecture consumes a machine-readable, version-controlled, authorized, and approved Data Request Specification defining cohort logic, requested source systems, data domains and fields, date range, full or incremental extraction mode, refresh cadence, and applicable authorization and permission rules.  Describe how the solution validates data availability against the specification, identifies unavailable or ambiguous fields, avoids silent substitutions, associates the request identifier with each batch and output, and supports reproducible reruns when source data have not changed.
  3. An initial automated data quality check validating completeness, uniqueness, data types, date sequencing, and records-per-patient. All anomalies must be reported before any permitted corrections are applied. Sourced data will not be modified
  4. De-identification per 45 CFR §164.514(b): remove all 18 direct identifiers;  document a consistent de-identification pathway; and apply a per-patient date-shifting specification that preserves temporal order.
  5. Privacy Preserving Record Linkage (PPRL) tokenization capabilities for cross-site linkage using an approved, on-premises within the institutional trust boundary PPRL platform that generates consistent, irreversible patient tokens.  Describe validation and Healthcare Partner approval before the first live transmission. Describe how token consistency is achieved across independently deployed, site-local PPRL instances, without introducing a shared trust boundary outside the Healthcare Partner site.
  6. Describe how the solution preserves all source provenance metadata, permissions information, and ontology fields (e.g. SNOMED CT, LOINC, ICD-10, RxNorm, UCUM, etc.) without modification or loss, excluding authorized de-identification transformations performed under Section 4.  The DSP will not create or standardize ontology mappings.  Metadata must be additive, clearly identified, and each output value must be traceable to the source and authorized transformation.
  7. Describe how the solution consumes authoritative eligibility supplied by the Healthcare Partner and applies it before transmission; records the governing authorization or permission version for each dataset; distinguish cohort exclusions from permission exclusions; and apply revocations so that revoked records are absent from all subsequent refreshes. 
  8. Describe how the solution generates full and incremental extracts; maintains stable patient tokens; creates unique snapshot and refresh IDs; supports idempotent reruns; identifies added, updated, deleted, merged, unmerged, corrected, and late-arriving records to the appropriate refresh cycle.
  9. Workflow Integrity & Processing Audit: maintain audit records for each stage; timestamp, stage ID, batch ID, record counts, outcome, and reconciliation status.  Failed reconciliations or incomplete processing stages must halt transmission until resolved or authorized for reprocessing.
  10. Security Posture: Describe the ability to attest to HIPAA Security Rule compliance as a Business Associate;
  11. Security Audit Logging to generate SIEM-compatible security logs for authentication, administrative actions, configuration changes, and security events. Record timestamp, user/service account, action, resource, and outcome.  Security logs must be protected against unauthorized modification or deletion, and logging must be continuous.
  12. Defense-in-Depth Encryption: TLS 1.3 where supported; TLS 1.2 minimum for all data in transit,; application-level encryption of output files and VM-level encryption.
    1. Attack Surface Minimization with no unnecessary ports, services, or network listeners by default. The only authorized external connection is the outbound TLS path to the Data COUNT Program
  13. Also see Section 1 regarding on-site operation of Leave Behind Technology; this section addresses the boundary for identifiable data processing.  Describe how identifiable processing is confined to the Healthcare Partner’s VM and institutional trust boundary; only de-identified, tokenized output is transmitted for the Data COUNTS program; access is integrated with Healthcare Partner identity and access controls and is site-managed and logged; and the deployed solution does not include or permit contractor credentials, contractor remote-access pathways, or contractor remote-management capabilities.
  14. Describe supported performance at baseline, 2X, and 5X expected workloads and identify assumed data volumes, throughput, processing time, and Healthcare Partner CPU, memory, storage, network and staffing requirements.
  15. Describe how the solution can reliably package, transmit, reconcile, and retry deliveries to the TDB, including package, schema versioning, and error resolution.


Business Information Requested


Please provide information on the following:


  1. Details on which capabilities are able to be met
    1. Clarification on which features are commercial off-the-shelf (COTS), and which features would be considered minor modifications, and which features would be considered custom development features
  2. Billing model and pricing structure and any additional features and their subsequent costs
  3. Experience with successful implementation capabilities and list of healthcare partners
  4. Experience of similar work with Federal Government agencies
  5. Experience of similar work with industries or non-profit organizations
  6. Business size and status


Response Format:


Responses must be submitted by September 22, 2026, 3:00 Eastern Standard Time to DataCounts@nih.gov  with the subject line Company Name RFI Response.  Responses must be submitted in PDF or MS Word format. Organize the responses according to the numbered requests in this RFI.  Questions may be submitted by September 15, 2026 to DataCounts@nih.gov. 



Government Follow-up


The Government may contact respondents for clarification, additional information, or a capability demonstration.  The Government is not obligated to contact any respondent.



Disclaimer and Important Notes. This notice does not obligate the Government to award a contract or otherwise pay for the information provided in response to this notice. The Government reserves the right to use this information provided by respondents for any purpose deemed necessary and legally appropriate. Any organization responding to this notice should ensure that its response is complete and sufficiently detailed. Information provided will be used to assess tradeoffs and alternatives available for potential requirements and may lead to the development of a solicitation. Respondents are advised that the Government is under no obligation to acknowledge receipt of the information or provide feedback to respondents with respect to the information submitted.


Any solicitation resulting from the analysis of information obtained will be announced to the public. However, responses to this notice will not be considered responsive to solicitation.



Confidentiality. No proprietary, classified, confidential or sensitive information should be included in a response. The Government reserves the right to use any non-proprietary technical information in any resulting solicitation.


Attachments/Links include: www.nih.gov/data-counts



Primary Point of Contact


Susan Gregurick


DATACOUNTS@nih.gov


Christopher Ray


Chris.ray@nih.gov

Similar Contracts

Same NAICS industry code

NAICS: 54151
Federal
FDA Sources Sought - NextGen Cyber Engineering, Operations AI and Unified Services
Solicitation # SS-75F40126Q00333
The U.S. Food and Drug Administration (FDA) Office of Digital Transformation has issued a Sources Sought notice to conduct market research for NextGen Cyber Engineering, Operations, AI, and Unified Services. This initiative aims to identify small business capabilities to support the FDA's transition to a Zero Trust cybersecurity framework, aligning all engineering activities with NIST, CISA, and OMB standards. The scope of work includes cybersecurity engineering, 24x7x365 operations (SOC/NOC), identity and access management (ICAM), threat management, and the integration of advanced technologies such as Artificial Intelligence (AI) for automated compliance monitoring, post-quantum cryptography, and predictive risk modeling. The FDA intends to establish a Blanket Purchase Agreement (BPA) to provide scalable, enterprise-wide solutions across on-premises, cloud, and hybrid environments, integrating platforms like SIEM, SOAR, and EDR. This is a market research effort specifically targeting small businesses on GSA MAS Schedules 54151S and 54151HACS to assess the feasibility of a total small business set-aside. Interested respondents must provide capability statements not exceeding 15 pages, including their Unique Entity Identifier (UEI), CAGE number, and socioeconomic status. The FDA will informally assess respondents based on their corporate profile and relevant experience, specifically requiring at least one example of a federal-scale cyber operations effort where the organization served as the prime contractor. Performance will be conducted on a hybrid basis, involving on-site work at FDA facilities in the Washington, DC metropolitan area, including North Bethesda and Silver Spring, Maryland, or via telework. Personnel must be capable of obtaining a Public Trust, Moderate Level Tier 2S background investigation.
FDA Office Of Acq Grant Svcs

POSTED

24 days ago

DEADLINE

in 10 days
View Details

More opportunities from Department Of Health And Human Services → National Institutes Of Health Niaid

Same awarding agency

Ready to Pursue This Opportunity?

Get AI-powered intelligence on this solicitation and the ones like it

Every page of the solicitation package shredded into a compliance breakdown

AI-powered matching based on your capabilities and past performance

Competitor and incumbent history on the requirement

Automated alerts on amendments, Q&A deadlines, and award

Miguel
Hillary
Keith Deutsch
Christine

Join 650+ contractors already using CLEATUS