The contract involves providing
mobile MRI services at the Dublin VA Medical Center. Performance standards, monitoring mechanisms (direct observation, periodic inspection, complaint review), payment terms (monthly, in arrears), contract administration procedures, conflict of interest clauses, and security and privacy requirements for handling VA information are outlined. The contract period includes a base year and potential option periods. Hours of operation are specified, as well as holidays observed. The contractor is responsible for ensuring the security of all procured or developed systems and technologies, including their subcomponents, throughout the life of the contract and any extension, warranty, or maintenance periods. The contractor must notify VA within 24 hours of the discovery or disclosure of successful exploits of the vulnerability which can compromise the security of the systems. The vendor shall ensure that security fixes shall not negatively impact the systems. All other vulnerabilities shall be remediated as specified in this paragraph in a timely manner based on risk, but within 60 days of discovery or disclosure. The government reserves the right to conduct such an assessment using government personnel or another contractor/subcontractor. The contractor/subcontractor must take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, generally at no additional cost. VA prohibits the installation and use of personally owned or contractor/subcontractor-owned equipment or software on VA's network. If non-VA owned equipment must be used to fulfill the requirements of a contract, it must be stated in the service agreement, sow or contract. All of the security controls required for government furnished equipment (GFE) must be utilized in approved other equipment (OE) and must be funded by the owner of the equipment. All remote systems must be equipped with, and use, a VA-approved antivirus (AV) software and a personal host-based or enclave-based firewall that is configured with a VA-approved configuration. Software must be kept current, including all critical updates and patches. Owners of approved OE are responsible for providing and maintaining the antiviral software and the firewall on the non-VA owned OE. All electronic storage media used on non-VA leased or non-VA owned IT equipment that is used to store, process, or access VA information must be handled in adherence with VA handbook ****, electronic media sanitization upon completion or termination of the contract or disposal or return of the IT equipment by the contractor/subcontractor or any person acting on behalf of the contractor/subcontractor, whichever is earlier. Media hard drives, optical disks, CDs, backup tapes, etc. used by the contractors/subcontractors that contain VA information must be returned to the VA for sanitization or destruction or the contractor/subcontractor must self-certify that the media has been disposed of per **** requirements. This must be completed within 30 days of termination of the contract. Liquidated damages for data breaches are also specified.