Data Analysis for Quality, Safety & Oversight of the End Stage Renal Disease (ESRD), Transplant, and Organ Procurement Organization (OPO) Programs

HEALTH AND HUMAN SERVICES, DEPARTMENT OF

Notice type
Solicitation
Solicitation #
75FCMC26R0057
NAICS
541720
PSC
R499
Posted
July 22, 2026
Response due
August 13, 2026

Description

Statement of Work Security and Privacy Requirements CMS Security & Privacy Requirements This section provides an overview of general CMS Security policies and outlines requirements applicable to all CMS contractors and subcontractors. The CMS Information Security and Privacy Program website provides additional details of CMS security policies and procedures across CMS, and is referenced throughout this document. The Contractor must adhere to all CMS and Federal IT Security and Privacy standards, policies, statutes, and reporting requirements, as well as all National Institute of Standards and Technology (NIST) standards and guidelines, and other Government-wide laws and regulations for the protection and security of Government Information. The Contractor must also adhere to the guidance and requirements provided within the CMS Information Systems Security and Privacy Policy (IS2P2). The IS2P2 consolidates existing information security and privacy policy documents into a single volume and directly integrates the enforcement of information security and privacy through the CMS CIO, Chief Information Security Officer, and Senior Official for Privacy. The CMS/HHS Security and Privacy requirements are based on the policies within the “CMS Security and Privacy Language for Information and Information Technology Procurements”. The areas listed below were selected by CMS based on the specific security and privacy requirements identified for this project. Additional information security and privacy considerations may be identified for individual task orders, depending on the contract structure.  2. Information Security and/or Physical Access Security  3. Privacy Act Records ☐ 4. Government Information Processed on GOCO or COCO Systems ☐ 5. Cloud Services ☐ 6. Other IT Procurements a. ☐ Hardware b. ☐ Software c. ☐ IT Application Design, Development and Support d. ☐ Physical Access to Government Controlled Facilities Information Security and/or Physical Access Security 1. Baseline Security Requirements a. Applicability. The requirements herein apply whether the entire contract or modification (hereafter "contract"), or portion thereof, includes either or both of the following: -- 1 of 14 -- Statement of Work Security and Privacy Requirements i. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information. ii. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of "information technology" (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources. b. Safeguarding Information and Information Systems. All government information and information systems must be protected in accordance with HHS/ CMS policies and level of risk. At a minimum, the Contractor (and/or any subcontractor) must: i. Protect the:  Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;  Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and  Availability, which means ensuring timely and reliable access to and use of information. ii. Categorize all information owned and/or collected/managed on behalf of HHS/CMS and information systems that store, process, and/or transmit HHS information in accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. Based on information provided by the ISSO, CISO, CMS SOP, or other representative, the impact level for each Security Objective (Confidentiality, Integrity, and Availability) and the Overall Impact Level, which is the highest watermark of the three factors of the information or information system are the following:  Confidentiality: ☐ Low  Moderate ☐ High  Integrity: ☐ Low  Moderate ☐ High  Availability: ☐ Low  Moderate ☐ High  Overall Impact Level: ☐ Low  Moderate ☐ High iii. Based on the agreed-upon level of impact, implement the necessary safeguards to protect all information systems and information collected and/or managed on behalf of HHS/CMS regardless of location or purpose. iv. Report any discovered or unanticipated threats or hazards by either the agency or contractor, or if existing safeguards have ceased to function immediately after discovery, within one (1) hour or less, to the government representative(s). -- 2 of 14 -- Statement of Work Security and Privacy Requirements v. Adopt and implement all applicable policies, procedures, controls, and standards required by the HHS/CMS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain all applicable security and privacy policies by contacting the CO/COR or HHS/CMS security and/or privacy officials. c. Privacy Act. Comply with the Privacy Act requirements (when applicable), and tailor FAR and HHSAR clauses as needed. d. Privacy Com

Source: SAM.gov, as posted. Verify the current solicitation before responding.

Pursue this opportunity with Mindy

See who holds it now, who else is bidding, and draft your response — grounded in real government data, not generic AI.

View the original notice on SAM.gov ↗

Similar Active Opportunities (NAICS 541720)