USA | AZ | PIMA COUNTY | TUCSON | 85701
The University Of Arizona-AZ
Request for Proposals for Point of Sale and eCommerce Solution
AI helper
The provided text details various appendices and clauses related to a contract, primarily focusing on cloud software services and payment card industry compliance. For cloud software, vendor obligations include continuous service availability (99. 9%), 24/7/365 telephone and online support, quarterly updates, semiannual reports, and specific response times for priority one issues (within 1 hour). Scheduled and unscheduled maintenance procedures are outlined, with at least 72 hours' notice for unscheduled maintenance unless it's an emergency. The vendor is responsible for vulnerability management and any damage to university data. For payment card transactions, the vendor must comply with PCI DSS, P2DSS, and PCI PTS standards, providing annual attestation of compliance. A Business Associate Agreement (BAA) is also included, outlining the vendor's responsibilities regarding Protected Health Information (PHI) under HIPAA and HITECH, including permitted uses and disclosures, security safeguards, reporting of breaches, and subcontractor requirements. The vendor must maintain a comprehensive information privacy and security program and comply with HHS guidance. The BAA also details the handling of designated record sets, including access and amendment procedures. The vendor indemnifies the university against losses arising from breaches of the agreement or negligence. The BAA survives termination of the agreement indefinitely for retained PHI. The governing law is Arizona, with disputes resolved in Arizona state or federal courts.
The bid notice states that the vendor warrants that the services will be fully available 99. 9% of each month, except for scheduled maintenance for which written notice has been provided to the university at least thirty 30 calendar days in advance.
The bid notice states that any person who makes expenditure prohibited under this provision or who fails to file or amend the disclosure form to be filed or amended by this provision, shall be subject to a civil penalty of not less than 10,000, and not more than 100,000, for each such failure.
Bid Close Date: