Data Analysis for Quality, Safety & Oversight of the End Stage Renal Disease (ESRD), Transplant, and Organ Procurement Organization (OPO) Programs
HEALTH AND HUMAN SERVICES, DEPARTMENT OF
Notice type
Solicitation
Solicitation #
75FCMC26R0057
NAICS
541720
PSC
R499
Posted
July 22, 2026
Response due
August 13, 2026
Description
Statement of Work
Security and Privacy Requirements
CMS Security & Privacy Requirements
This section provides an overview of general CMS Security policies and outlines requirements applicable
to all CMS contractors and subcontractors. The CMS Information Security and Privacy Program website
provides additional details of CMS security policies and procedures across CMS, and is referenced
throughout this document.
The Contractor must adhere to all CMS and Federal IT Security and Privacy standards, policies, statutes,
and reporting requirements, as well as all National Institute of Standards and Technology (NIST)
standards and guidelines, and other Government-wide laws and regulations for the protection and security
of Government Information.
The Contractor must also adhere to the guidance and requirements provided within the CMS Information
Systems Security and Privacy Policy (IS2P2). The IS2P2 consolidates existing information security and
privacy policy documents into a single volume and directly integrates the enforcement of information
security and privacy through the CMS CIO, Chief Information Security Officer, and Senior Official for
Privacy.
The CMS/HHS Security and Privacy requirements are based on the policies within the “CMS Security
and Privacy Language for Information and Information Technology Procurements”. The areas listed
below were selected by CMS based on the specific security and privacy requirements identified for this
project. Additional information security and privacy considerations may be identified for individual task
orders, depending on the contract structure.
2. Information Security and/or Physical Access Security
3. Privacy Act Records
☐ 4. Government Information Processed on GOCO or COCO Systems
☐ 5. Cloud Services
☐ 6. Other IT Procurements
a.
☐ Hardware
b.
☐ Software
c.
☐ IT Application Design, Development and Support
d.
☐ Physical Access to Government Controlled Facilities
Information Security and/or Physical Access Security
1. Baseline Security Requirements
a. Applicability. The requirements herein apply whether the entire contract or modification
(hereafter "contract"), or portion thereof, includes either or both of the following:
-- 1 of 14 --
Statement of Work
Security and Privacy Requirements
i. Access (Physical or Logical) to Government Information: A Contractor
(and/or any subcontractor) will have or will be given the ability to have, routine
physical (entry) or logical (electronic) access to government information.
ii. Operate a Federal System Containing Information: A Contractor (and/or any
subcontractor) will operate a federal system and information technology
containing data that supports the HHS mission. In addition to the Federal
Acquisition Regulation (FAR) Subpart 2.1 definition of "information
technology" (IT), the term as used in this section includes computers, ancillary
equipment (including imaging peripherals, input, output, and storage devices
necessary for security and surveillance), peripheral equipment designed to be
controlled by the central processing unit of a computer, software, firmware and
similar procedures, services (including support services), and related resources.
b. Safeguarding Information and Information Systems. All government information and
information systems must be protected in accordance with HHS/ CMS policies and level
of risk. At a minimum, the Contractor (and/or any subcontractor) must:
i. Protect the:
Confidentiality, which means preserving authorized restrictions on
access and disclosure, based on the security terms found in this contract,
including means for protecting personal privacy and proprietary
information;
Integrity, which means guarding against improper information
modification or destruction, and ensuring information non-repudiation
and authenticity; and
Availability, which means ensuring timely and reliable access to and use
of information.
ii. Categorize all information owned and/or collected/managed on behalf of
HHS/CMS and information systems that store, process, and/or transmit HHS
information in accordance with FIPS 199 and National Institute of Standards and
Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to
Guide for Mapping Types of Information and Information Systems to Security
Categories. Based on information provided by the ISSO, CISO, CMS SOP, or
other representative, the impact level for each Security Objective
(Confidentiality, Integrity, and Availability) and the Overall Impact Level, which
is the highest watermark of the three factors of the information or information
system are the following:
Confidentiality:
☐ Low
Moderate
☐ High
Integrity:
☐ Low
Moderate
☐ High
Availability:
☐ Low
Moderate
☐ High
Overall Impact Level:
☐ Low
Moderate
☐ High
iii. Based on the agreed-upon level of impact, implement the necessary safeguards to
protect all information systems and information collected and/or managed on
behalf of HHS/CMS regardless of location or purpose.
iv. Report any discovered or unanticipated threats or hazards by either the agency or
contractor, or if existing safeguards have ceased to function immediately after
discovery, within one (1) hour or less, to the government representative(s).
-- 2 of 14 --
Statement of Work
Security and Privacy Requirements
v. Adopt and implement all applicable policies, procedures, controls, and standards
required by the HHS/CMS Information Security Program to ensure the
confidentiality, integrity, and availability of government information and
government information systems for which the Contractor is responsible under
this contract or to which the Contractor may otherwise have access under this
contract. Obtain all applicable security and privacy policies by contacting the
CO/COR or HHS/CMS security and/or privacy officials.
c. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor
FAR and HHSAR clauses as needed.
d. Privacy Com…
Source: SAM.gov, as posted. Verify the current solicitation before responding.
Pursue this opportunity with Mindy
See who holds it now, who else is bidding, and draft your response — grounded in real government data, not generic AI.
View the original notice on SAM.gov ↗Similar Active Opportunities (NAICS 541720)
B--TWIN CREEK ROCK ART INVENTORY SURVEY
INTERIOR, DEPARTMENT OF THE · Solicitation · due July 29, 2026
Intent to Sole Source: Research Services for Advanced Bladder Cancer
VETERANS AFFAIRS, DEPARTMENT OF · Special Notice · due July 24, 2026
Notice of Intent to Award a BPA Call Order against The Land Management Integrated Resources BPA (LMIR), Mark Twain N.F.
AGRICULTURE, DEPARTMENT OF · Special Notice · due August 6, 2026
AF12--Vetchange System Services- Intent to Sole Source
VETERANS AFFAIRS, DEPARTMENT OF · Special Notice · due July 24, 2026
Cultural Resource Surveys on the Monongahela National Forest.
AGRICULTURE, DEPARTMENT OF · Combined Synopsis/Solicitation · due August 7, 2026
Request for Information Army Research Institute for the Behavioral and Social Sciences (ARI)
DEPT OF DEFENSE · Sources Sought · due July 31, 2026