| Location: | Federal |
|---|---|
| Posted: | Mar 24, 2026 |
| Due: | Apr 7, 2026 |
| Agency: | U.S. Government Publishing Office |
| Type of Government: | State & Local |
| Category: |
|
| Publication URL: | To access bid details, please log in. |
Program/Jacket Number: 2529-S
Title: Veterans "High Risk Flag" (HRF) Mailings.
Bid Opening Date: April 7, 2026
Contract Type: Term Contract
Scope: These specifications cover the secure (PII/PHI) production of envelopes and notecards, requiring such operations as pickup of furnished materials, electronic prepress, proofs, address list processing, printing in black and two additional colors (dark red and dark blue ), variable data personalization, trimming, envelope construction, collating, inserting, addressing, mailing and sample delivery.
Quantity: Approximately 56 orders will be placed per year,
GPO Team: Northcentral Team
Files:
2529-S
Program 2529-S Page 1 of 35
Specifications by; TF
Reviewed by; TN
U.S. GOVERNMENT PUBLISHING OFFICE
Government Publishing & Print Procurement
GENERAL TERMS, CONDITIONS, AND SPECIFICATIONS
For the Procurement of
Veterans "High Risk Flag" (HRF) Mailings
as requisitioned from the U.S. Government Publishing Office (GPO) by the
Department of Veterans Affairs
Single Award
TERM OF CONTRACT: The term of this contract is for the period beginning May 1, 2026 and ending April 30,
2027, plus up to four (4) optional 12-month extension periods that may be added in accordance with the
"OPTION TO EXTEND THE TERM OF THE CONTRACT" clause in SECTION 1 of this contract.
BID OPENING: Bids shall be opened virtually at 11:00 a.m., Eastern Time (ET), on April 07, 2026 at the U.S.
Government Publishing Office. All parties interested in attending the bid opening shall email bids@gpo.gov one
(1) hour prior to the bid opening date and time to request a Microsoft Teams live stream link. This must be a
separate email from the bid submission. The link will be emailed prior to the bid opening.
BID SUBMISSION: Bidders must email bids to bids@gpo.gov for this solicitation. No other method of bid
submission will be accepted at this time. The program number and bid opening date must be specified in the
subject line of the emailed bid submission. Bids received after the bid opening date and time specified above
will not be considered for award.
BIDDERS, PLEASE NOTE: These specifications have been extensively revised; therefore, all bidders are
cautioned to familiarize themselves with all provisions of these specifications before bidding.
Abstracts of contract prices are available at: https://www.gpo.gov/how-to-work-with-us/vendors/contract-pricing.
ADDITIONAL EMAILED BID SUBMISSION PROVISIONS: The Government will not be responsible for
any failure attributable to the transmission or receipt of the emailed bid including, but not limited to, the
following -
1. Illegibility of bid.
2. Emails over 75 MB may not be received by GPO due to size limitations for receiving emails.
3. The bidder's email provider may have different size limitations for sending email; however, bidders are
advised not to exceed GPO's stated limit.
4. When the email bid is received by GPO, it will remain unopened until the specified bid opening time.
Government personnel will not validate receipt of the emailed bid prior to bid opening. GPO will use
the prevailing time (specified as the local time zone) and the exact time that the email is received by
GPO's email server as the official time stamp for bid receipt at the specified location. For information
of a technical nature, contact Thomas Ferguson at (312) 353-5783 or email tferguson@gpo.gov
Veterans "High Risk Flag" (HRF) Mailings Page 2 of 35
Program 2529-S
SECTION 1. - GENERAL TERMS AND CONDITIONS
GPO CONTRACT TERMS: Any contract which results from this Invitation for Bid will be subject to the
applicable provisions, clauses, and supplemental specifications of GPO Contract Terms (GPO Publication 310.2,
effective December 1, 1987 (Rev. 1-18) and GPO Contract Terms, Quality Assurance Through Attributes
Program for Printing and Binding (GPO Publication 310.1, effective May 1979 (revised September 2019).
Contract Terms, Forms and Standards information for contractors can be found on the GPO website at
http://www.gpo.gov/how-to-work-with-us/vendors/programs-for-vendors. The Contract Terms publication noted
above can be downloaded at http://www.gpo.gov/docs/default-source/forms-and-standards-files-for-
vendors/qatap.pdf.
DOING BUSINESS WITH GPO: Contractors wishing to do business with the GPO are referred to the GPO
web site http://www.gpo.gov/how-to-work-with-us/vendors/programs-for-vendors, where one can register as a
GPO contractor using the 'GPO Publish information' link in accordance with the furnished instructions on this
page.
PREDOMINANT PRODUCTION FUNCTION: The predominant production function is printing and mailing.
Bidders who must subcontract this operation will be determined to be non-responsible for award. Subcontracting
is allowed for manufacturing of the envelopes only.
QUALITY ASSURANCE LEVELS AND STANDARDS: The following levels and standards shall apply to
these specifications:
Product Quality Levels:
(a) Printing Attributes - Level III.
(b) Finishing Attributes - Level III.
Inspection Levels (from ANSI/ASQC Z1.4):
(a) Non-destructive Tests - General Inspection Level I.
(b) Destructive Tests - Special Inspection Level S-2.
Specified Standards: The specified standards for the attributes requiring them shall be:
Attribute Specified Standard
P-7. Type Quality and Uniformity Approved Priors/ Average type dimension per publication
P-10. Process Color Match Approved Priors/ Approved Proofs
PREAWARD SURVEY: In order to determine the responsibility of the prime contractor or any subcontractor,
the Government reserves the right to conduct an on-site preaward survey at the contractor's/subcontractor's
facility or to require other evidence of technical, production, managerial, financial, and similar abilities to
perform, prior to the award of a contract. As part of the financial determination, the contractor in line for award
may be required to provide one or more of the following financial documents:
1) Most recent profit and loss statement
2) Most recent Balance Sheet
3) Statement of cash flows
4) Current official bank statement
5) Current lines of credit (with amounts available)
6) Letter of commitment from paper supplier(s)
7) Letter of commitment from any subcontractor
Veterans "High Risk Flag" (HRF) Mailings Page 3 of 35
Program 2529-S
The documents will be reviewed to validate that adequate financial resources are available to perform the contract
requirements. Documents submitted will be kept confidential and used only for the determination of responsibility
by the Government. Failure to provide the requested information in the time specified by the Government may
result in the Contracting Officer not having adequate information to reach an affirmative determination of
responsibility.
ADDITIONAL PREAWARD SURVEY REQUIREMENTS: Any contractor being considered for award of
this program must submit the following detailed plans during the preaward survey (due diligence) process, prior
to award of this contract. These proposed plans are subject to review and approval by the Government, and award
will not be made prior to approval of same.
The contractor MUST NOT provide this information with their submitted bid, but must instead provide this
information only upon request from the GPO contract administrator.
All requested materials and documentation must be provided within 2 workdays of request.
Production Plan: The contractor will be required to provide documentation to demonstrate how orders placed
against this program will be produced. Information required must include, but is not limited to, an equipment list,
breakdown of production steps and required labor, cost breakdowns, subcontractor information, sample invoice,
shippers to be utilized, etc.
a. A listing of all production equipment and equipment capacities to be utilized on this contract.
b. The production capacity currently being utilized on this equipment.
c. The capacity that is available for managing and producing the volume of work products identified within this
contract.
d. If new equipment is to be utilized, the documentation of the purchase order, source, delivery schedule and
installation dates are required.
Security Control Plan: The contractor will be required to provide documentation to demonstrate compliance with
the "Security and Privacy" section of these specifications. The contractor shall provide a security plan that
addresses all aspects of physical and logical data file handling, processing and transfer, including publication and
all associated mail handling as required. The security plan will address employee requirements for security
training, background investigations, and credit checks. The security plan will address inventory controls, network
security, visitor controls and applicable miscellaneous aspects of production. The security plan shall meet or
exceed the mandated VA security requirements and be approved by a designated VA Information Security Officer
and the Privacy Officer.
The contractor shall review the security plan at least quarterly and update it as soon as changes are indicated.
The security plan will be maintained throughout the life of the contract. After acceptance of the security plan, the
contractor shall inform the VA representative in writing, within seven (7) calendar days of changes made to the
document.
See Attachment B: In addition to the above, the contractor is also required to complete the Contractor Security
Control Assessment (Attachment B) annually and keep a copy with the Security Control Plan.
BAA: The contractor shall enter into a Business Associate Agreement (BAA), see below.
The proposed Security Control Plan must address the following:
Materials - The way that all accountable materials will be handled throughout all phases of production. This plan
shall also include the method of disposal of all production waste materials in accordance with VA directive 6371
and the NIST publication 800-88.
Veterans "High Risk Flag" (HRF) Mailings Page 4 of 35
Program 2529-S
Disposal of Waste Materials - The contractor is required to demonstrate how all waste materials used in the
production of sensitive VA records will be definitively destroyed (ex. burning, pulping, shredding, macerating, or
other suitable similar means). Electronic Records must be definitively destroyed in a manner that prevents
reconstruction. Definitively destroying the records means the material cannot be reassembled and used in an
appropriate manner in violation of law and regulations. Sensitive records are records that are national security
classified or exempted from disclosure by statute, including the Privacy Act or regulation.
If the contractor selects shredding as a means of disposal, it is preferred that a cross cut shredder be used. If a strip
shredder is used, the strips must not exceed one-quarter inch. The contractor must provide the location and
method planned to dispose of the material. The plan must include the names of all contract officials responsible
for the plan and describe their duties in relationship to the waste material plan.
Production Area - The contractor must provide a secure area(s) for the processing and storage of data for the
mailer items, either a separate facility dedicated to this product, or a walled-in limited access area within the
contractor's existing facility. Access to the area(s) shall be limited to security-trained employees involved in the
production of the postcards and mailers.
Part of the Security Control Plan shall include a floor plan detailing the area(s) to be used, showing existing walls,
equipment to be used, and the printing and finishing locations.
Quality Control Plan: The contractor shall provide and maintain, within his own organization, an independent
quality assurance organization of sufficient size and expertise to monitor the operations performed, and inspect
the products of each operation to a degree and extent that will ensure the Government's quality assurance,
inspection, and acceptance provisions are met. The contractor shall perform, or have performed, the process
controls, inspections and tests required to substantiate that the products provided under this contract conform to
the specifications and contract requirements. The contractor shall describe in detail their quality control/quality
assurance plan describing how, when, and by whom the plans will be performed.
The plan must provide for periodic samplings to be taken during the production run, a control system that will
detect defective, missing, or mutilated pieces, and the actions to be taken by the contractor when
defective/missing/mutilated pieces are discovered. These actions must be consistent with the requirements found
in GPO Contract Terms (GPO Publication 310.2, effective December 1, 1987, (Rev. 1-18)) and any updates
thereafter. A recovery system is required to replace all defective, missing, or mutilated pieces. This control system
may use a unique sequential number to aid in the recovery program which has to be maintained in order to recover
any missing or damaged pieces. These pieces must be reprinted and 100% accountability must be maintained
throughout the run. The contractor must ensure that there are no missing or duplicated pieces.
The plan must include examples and a detailed description of all quality control samples and their corresponding
inspection reports or logs the contractor will keep to document the quality control inspections performed on each
run. The plan must provide for a complete audit trail (i.e., it must be possible to locate any piece of mail at any
time from the point it leaves the press, up to and including the point at which the mail is delivered to a USPS
facility). An explanation of the contractor's sequential numbering system is required to understand the audit trail
required for each and every piece.
Note: The Government will not, as a routine matter, request that the contractor produce individual pieces in transit
within the plant, however, the contractor must demonstrate that they have an audit trail established that has the
ability to comply with this type of request if and when the need arises.
The quality control plan must also include examples of the documentation and a detailed description of the
random samples that document all of the contractor's activities. Furthermore, the plan must include the names of
all quality assurance officials and describe their duties in relationship to the quality control plan. The plan must
include a detailed description of the number and types of inspections that will be performed as well as the records
maintained documenting these activities.
Veterans "High Risk Flag" (HRF) Mailings Page 5 of 35
Program 2529-S
The quality control plan must account for the number of pieces mailed for each order, including days when no
pieces are mailed.
The Government will periodically verify that the contractor is complying with the approved quality control plan
through on-site examinations and/or requiring copies of the contractor's quality assurance records and quality
assurance random copies.
See Attachment A: Contractor Rules of Behavior. The contractor will be bound by these requirements upon
award.
Quality Control Sample Plan: The plan must provide a description of how the contractor will create quality
control samples for periodic samplings to be taken during the production run and provide for backup and
rerunning in the event of an unsatisfactory sample. The plan shall contain control systems that will detect
defective, missing, or mutilated pieces.
The plan should include the sampling interval the contractor intends to utilize. The contractor will be required to
create a quality control sample from each file, to be drawn from the production stream. Mailers samples should be
in unsealed envelopes with contents inserted. Mailer number and file date must be indicated on each sample. The
contractor must maintain samples as indicated in the contract specifications.
The plan shall detail the actions to be taken by the contractor when defective/missing/mutilated items are
discovered. These actions must be consistent with the requirements found in GPO Contract Terms (GPO
Publication 310.2, effective December 1, 1987, (Rev. 1-18)) or any updates thereafter.
Verification of Production and Mailing Plan: Contractor will be responsible for validating the integrity of every
item produced in all phases of printing, packaging, and mailing and to ensure all mailpieces were correctly
entered into the United States Postal System.
Mailpiece Integrity shall be defined as follows: Each mailpiece shall include all components (and only those
components) intended for the designated recipient as contained in the print files received from VA.
The contractor is responsible for providing the automated print integrity control systems and processes required to
prevent the commingling of mailer items intended for different recipients into a completed package. The
contractor's printing process must have automated systems that include coding & scanning technology capable of
-
1. Validating the count of items in a set.
2. Validating the sequence of items in a set.
3. Validating the sequence of sets in a production batch.
4. Interrupting production if variances are detected.
Mailing integrity shall be defined as follows: All records received from the VA that are designated for printing
were printed, inserted (if applicable) and entered correctly into the U.S. Postal System.
The contractor is responsible for providing the automated inserted mailpiece tracking/reporting systems and
processes required to validate that 100% of all records received from VA which are designated for printing were
printed, inserted (if applicable), and mailed correctly. The contractor's inserting equipment must have automated
systems that include coding and scanning technology capable of -
1. Reconciling letter counts and quantity counts from VA provided files to print order control totals provided by
VA; reporting variances.
2. Uniquely identifying each Product Types within a print order.
3. Unique identifier to be scanned after insertion to ensure all products are present and accounted for.
4. Tracking and reporting all products produced and mailed within a print order at the Product Type level.
5. Identifying and reporting all missing products that were lost or spoiled during production within a print order.
Veterans "High Risk Flag" (HRF) Mailings Page 6 of 35
Program 2529-S
6. Generating a new production file for all missing products.
7. Tracking and reporting all products that were reproduced and mailed within a print order at the Product Type
level.
8. Reconciling the total of all products produced and mailed within a print order to the control totals provided by
VA; reporting all variances.
9. Reconciling the total of all products mailed to mailing totals contained on Postal Entry Forms within a print
order; reporting all variances.
10. Generating a final automated summary report which provides information that all mail pieces have been
scanned, after insertion, verifying that all pieces for each mail package and file date are accounted for after
contents are inserted, and event information on any spoiled or missing pieces verifying that they were scanned
and accounted for. A copy of the summary report must be submitted with the matching GPO 712 form(s).
The contractor must generate an automated audit report when necessary showing the tracking of all products
throughout all phases of production for each mailpiece. This audit report will contain all information identified
above for each phase of printing, packaging, and mailing.
All product tracking/reporting data must be retained in electronic form for 120 calendar days after mailing, and
must be made available to VA for auditing of contractor performance upon request. The contractor must maintain
quality control samples, inspection reports, and records for a period of no less than 120 calendar days subsequent
to the date of the check tendered for final payment by the GPO. The Government will periodically verify that the
contractor is complying with the approved quality control plan through on-site examinations and/or requesting
copies of the contractor's quality assurance records and quality assurance random copies.
Unique Identification Number Plan: Unique identifying numbers will be used to track each individual product,
thereby providing 100% accountability. This enables the contractor to track each product through completion of
the project. The contractor may create their own sequence number and run date to facilitate their presorting and
inserting process but must maintain the original Unique ID (UID) for Management Information (MI) reporting.
Recovery System: A recovery system will be required to ensure all defective, missing, or mutilated pieces
detected are identified, reprinted, and replaced. The contractor's recovery system must use unique sequential
alpha/numeric identifiers assigned to each piece (including quality control samples) to aid in the recovery and
replacement of any defective/missing/mutilated pieces, and must be capable of tracking and/or locating any
individual piece of mail from the time it leaves the press, up to and including when it is off-loaded to the USPS
facility. An explanation of the contractor's sequential numbering system is required to understand the audit trail
required for each and every piece.
Note: The Government will not, as a routine matter, request that the contractor produce individual pieces in transit
within the plant, however, the contractor must demonstrate they will have an audit trail established that has the
ability to comply with this type of request if and when the need arises.
Material Handling and Inventory Control: This plan should explain in detail how the following materials will be
handled: incoming raw materials; work-in-progress materials; quality control inspection materials; USPS
inspection materials; and all outgoing materials cleared for USPS pickup/delivery.
Personnel Plan: This plan should include a description of the training programs employees will be given to
familiarize them with the requirements of this program. If employees have current and adequate security
clearances, please notate.
Postage Plan: Contractor must provide a postage cost breakout during the certification. The VA will pay the
postage and furnish the permit information to the contractor. The mail class will be First Class Mail rate.
VA Business Associate Agreement: During the Preaward Survey, the contractor being considered for award will
receive a PDF file of the VA Business Associate Agreement and must sign and return.
Veterans "High Risk Flag" (HRF) Mailings Page 7 of 35
Program 2529-S
Contractors who are unable to provide the above documentation within 2 workdays may be declared non-
responsible.
POST-AWARD REQUIREMENTS:
After award, the contractor may be required to have a post-award phone conference call with Government
personnel from the VA and/or GPO, and additionally will be required to produce various proofs and samples for
approval prior to beginning production of the first GPO Form 2511 Print Order.
Actual print production begins upon completion of these certifications.
Required post-award implementation and certification of VA security requirements (shown below) must be
completed within 10 workdays after Date of Award, or completed by another documented VA-approved date.
* All applicable contractor employees must successfully complete VA Cyber Security Awareness training and
annual refresher training as required.
* Contractor shall provide to the VA points of contact and the GPO contract administrator a copy of the
training certificates produced at the completion of each training session, for each applicable employee
within ten (10) workdays of notification of contract award and annually thereafter, as required.
* All applicable contractor employees must successfully complete any additional cyber security or privacy
training, as required.
GOVERNMENT IN PLANT INSPECTIONS: The Government reserves the right to have Government
representative(s) inspect any operation, including the security controls and privacy practices implemented by the
contractor under this contract at the start of production, and/or at any time during production. The Government
may conduct an inspection with 10 workdays notice, or on short notice, or unannounced, in the event of a security
incident or at any other time. The contractor's full cooperation is required.
SECURITY AND PRIVACY REQUIREMENTS:
Confidentiality of Information: Information regarding any individual is of a confidential nature and may be used
only for the purposes of producing the requirements of this contract. All materials containing confidential
information, including but not exclusive to Government furnished data, imaged forms, and scrap, must be handled
so that information does not have any unauthorized use. All scrap generated with any information regarding any
individual person must be shredded, incinerated, otherwise destroyed beyond recognition. Any media (files, disks,
etc.) produced by the VA and sent to the contractor MUST be returned to the VA upon completion of the specific
order. Contractor must return this material via an overnight delivery service to prevent theft or accidental use.
All contractors and contractor personnel shall be subject to the Federal laws, regulations, standards and VA
Directives and Handbooks, regarding information system security as delineated in this contract. Contractors must
follow policies and procedures outlined in VA Directive 6500, Information Security Program and its handbooks
to ensure appropriate security controls are in place.
Veterans "High Risk Flag" (HRF) Mailings Page 8 of 35
Program 2529-S
Protection of Confidential Information:
(a) The contractor shall restrict access to all confidential information obtained from the Department of Veterans
Affairs in the performance of this contract to those employees and officials who need it to perform the contract.
Employees and officials who need access to confidential information for performance of the contract will be
determined at the Post-Award Conference between the Contracting Officer and the responsible contractor
representative.
(b) The contractor shall process all confidential information obtained from VA in the performance of this contract
under the immediate supervision and control of authorized personnel, and in a manner that will protect the
confidentiality of the records in such a way that unauthorized persons cannot retrieve any such records.
(c) The contractor shall inform all personnel with access to the confidential information obtained from VA in the
performance of this contract of the confidential nature of the information and the safeguards required to protect
this information from improper disclosure.
(d) For knowingly disclosing information in violation of the Privacy Act, the contractor and the contractor
employees may be subject to the criminal penalties as set forth in 5 U.S.C Section 552a (i)(1), which is made
applicable to contractors by 5 U.S.C. 552a (m)(1) to the same extent as employees of the VA. For knowingly
disclosing confidential information as described in section 1106 of the Social Security Act (42 U.S.C. 1306), the
contractor and contractor's employees may also be subject to the criminal penalties as set forth in that provision.
(e) The contractor shall assure that each contractor employee with access to confidential information knows the
prescribed rules of conduct, and that each contractor employee is aware that he/she may be subject to criminal
penalties for violations of the Privacy Act.
(f) All confidential information obtained from VA for use in the performance of this contract shall, at all times, be
stored in an area that is physically safe from unauthorized access.
(g) The Government reserves the right to conduct on-site visits to review the contractor's documentation and in-
house procedures for protection of confidential information.
VA Information Custodial Requirements:
1. Information made available to the contractor by VA for the performance and/or administration of this contract
or information developed by the contractor in performance and/or administration of the contract shall be used
only for those purposes and shall not be used in any other way without the prior written agreement of the
Contracting Officer. This clause expressly limits the contractor's rights to use data as described in Rights in Data
- General, Federal Acquisition Regulation (FAR) 52.227-14(d) (1).
2. Information generated by a contractor as a part of the contractor's normal business operations, such as medical
records created in the course of providing treatment, is subject to a review by the Office of General Counsel
(OGC) to determine if the information is the property of VA and subject to VA policy. If the information is
determined by OGC to not be the property of VA, the restrictions required for VA information will not apply.
3. VA information will NOT be commingled with any other data on the contractor's information systems/media
storage systems in order to ensure VA requirements related to data protection and media sanitization can be met.
VA also reserves the right to conduct IT resource inspections to ensure data separation and on-site inspection of
information destruction/media sanitization procedures to ensure they are in compliance with VA policy
requirements.
4. Prior to termination or completion of this contract, the contractor will not destroy information received from
VA or gathered or created by the contractor in the course of performing this contract without prior written
approval by VA. Any data destruction done on behalf of VA by a contractor must be done in accordance with
National Archives and Records Administration (NARA) requirements as outlined in VA Directive 6300, Records
and Information Management and its Handbook 6300.1 Records Management Procedures, and applicable VA
Records Control Schedules. These Directives are available at: http://www1.va.gov/vapubs/.
Veterans "High Risk Flag" (HRF) Mailings Page 9 of 35
Program 2529-S
5. The contractor will receive, gather, store, back up, maintain, use, disclose and dispose of VA information only
in compliance with the terms of the contract and applicable Federal and VA information confidentiality and
security laws, regulations and policies. Applicable Federal information security regulations include all Federal
Information Processing Standards (FIPS) and Special Publications (SP) issued by the National Institute of
Standards and Technology (NIST). If Federal or VA information confidentiality and security laws, regulations
and policies become applicable to the VA information or information systems after execution of the contract, or if
NIST issues or updates applicable FIPS after execution of this contract, the parties agree to negotiate in good faith
to implement the information confidentiality and security laws, regulations and policies, including FIPS or SP, in
this contract.
6. Contractors collecting, storing, or disseminating personal identifiable information (PII) or protected health
information (PHI) data must conform to all pertinent regulations, laws, and VA directives related to privacy.
Contractors must provide access for VA privacy reviews and assessments and provide appropriate documentation
as directed.
Note: Personally identifiable information is defined as any information which can be used to distinguish or trace
and individual's identity, such as their name, social security number, Veterans identification number, biometric
records, etc., alone or when combined with other personal or identifying information which is linked or linkable
to a specific individual, such as date and place of birth, mother's maiden name, etc.
7. The contractor shall not make copies of VA information except as necessary to perform the terms of the
agreement or to preserve electronic information stored on contractor electronic storage media for restoration in
case any electronic equipment or data used by the contractor needs to be restored to an operating state.
8. If VA determines that the contractor has violated any of the information confidentiality, privacy, and security
provisions of the contract, it shall be sufficient grounds for the Government to terminate the contract for default or
terminate for cause under the GPO Printing Procurement Regulations (GPO Publication 305.3).
9. If a Veterans Health Administration (VHA) contract is terminated for cause, the associated business associate
agreement (BAA) will also be terminated and appropriate actions taken in accordance with VHA Handbook
1600.01 Business Associates.
10. Contractor will store, transport or transmit VA sensitive information in an encrypted form, using a VA-
approved encryption application that meets the requirements of NIST's FIPS 140-2 standard.
11. The contractor's firewall and Web services security controls, if applicable, shall meet or exceed VA's
minimum requirements. VA directives are available on the VA directives Web site at
http://www1.va.gov/vapubs/.
12. Except for uses and disclosures of VA information authorized by this contract for performance of the contract,
the contractor may use and disclose VA information only in two other situations: (1) in response to a qualifying
order of a court of competent jurisdiction; or, (2) with VA's prior written approval. The contractor will refer all
requests for, demands for production of, or inquiries about, VA information and information systems to VA for
response.
13. Notwithstanding the provision above, the contractor shall NOT release medical quality assurance records
protected by 38 U.S.C. 5705 or records pertaining to drug addiction, sickle cell anemia, alcoholism or alcohol
abuse, or infection with human immunodeficiency virus protected under 38 U.S.C. 7332 under any circumstances,
including in response to a court order, and shall immediately refer such court orders or other inquiries to VA for
response.
14. The contractor will not use technologies banned in VA in meeting the requirements of the contract (e.g.,
Bluetooth enabled devices).
Security Incident Investigation:
1. The term "security incident" means an event that has, or could have, resulted in unauthorized access to, loss of,
or damage to VA assets or sensitive information, or an action that breaches VA security procedures. The
contractor shall immediately notify the GPO and VA representative and simultaneously, the designated
ISO/Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized
disclosure of sensitive information, including that contained in system(s) to which the contractor has access.
Veterans "High Risk Flag" (HRF) Mailings Page 10 of 35
Program 2529-S
2. To the extent known by the contractor, the contractor's notice to GPO and VA will identify the information
involved, the circumstances surrounding the incident (including to whom, how, when, and where the VA
information/assets were placed at risk or compromised), and any other information that the contractor considers
relevant.
3. The contractor will simultaneously report the incident to the appropriate law enforcement entity(ies) of
jurisdiction, including the GPO and VA Offices of the Inspector General and Security and Law Enforcement, in
instances of theft or break-in or other criminal activity. The contractor and its employees will cooperate with VA
and any law enforcement authority responsible for the investigation and prosecution of any possible criminal law
violation(s) associated with any incident. The contractor will cooperate with VA in any civil litigation to recover
VA information, obtain monetary, or other compensation from a third party for damages arising from any
incident, or obtain injunctive relief against any third party arising from, or related to, the incident.
4. To the extent practicable, the contractor shall mitigate any harmful effects on individuals whose VA
Information was accessed or disclosed in a security incident. In the event of a data breach with respect to any VA
sensitive information processed or maintained by the contractor under the contract, the contractor is responsible
for liquidated damages to be paid to VA.
5. If a security incident (as described above) occurs at the contractor's facility, the actual damage to the
Government for the incident will be difficult or impossible to determine. Therefore, pursuant to the "Liquidated
Damages" clause (GPO Contract Terms, Publication 310.2), in lieu of actual damages, the contractor shall pay to
the Government as fixed, agreed, and liquidated damages for each record, or part thereof, involved in the
incident, the amount set forth below. Liquidated damages will be assessed against that record, or part thereof,
which has been compromised. Liquidated damages will not be assessed against that record or part thereof that has
not been compromised. The amount of damages will be computed at $37.50 per record, or part thereof,
compromised; provided that the minimum amount of liquidated damages shall not be less than $5.00 for the entire
order and not more than 50% of the total value of the entire order. The total damages assessed against a contractor
shall in no case exceed 50% of the total value of the entire order. Payment of an order will be withheld until
evidence of steps taken to prevent the recurrence of a security incident has been taken.
Security Training:
1. All contractor employees requiring access to VA sensitive information shall complete the following before
being granted access to VA sensitive information:
* Sign and acknowledge understanding of, and responsibilities for, compliance with the Contractor Rules of
Behavior (Attachment A) relating to access to VA information and information systems;
* Successfully complete VA Cyber Security Awareness training and annual refresher training as required
including return of completion certificates for the Government record;
* Successfully complete any additional cyber security or privacy training, as required for VA personnel
with equivalent information system access.
2. The contractor shall provide to the GPO contract and VA points of contact a copy of the training certificates for
each applicable employee (for the required training as stated above) within ten (10) workdays of notification of
contract award and annually thereafter, as required. These online courses are located at the following web site:
https://www.tms.va.gov.
3. Failure to complete this mandatory training within the timeframe required will be grounds for suspension or
termination of all physical and/or electronic access privileges and removal from work on the contract until such
time as the training is completed.
SAFEGUARD MEASURES FOR PERSONALLY IDENTIFIABLE INFORMATION (PII) DATA:
VA policies require documentation that PII data sent to contractor remains secure while projects are in progress
and is eventually destroyed in such a way that it cannot be retrieved or restored after being deleted from the
contractor's hard drives/systems.

With GovernmentContracts, you can:
...Follow 45--JACKET ASSY,H20 HEA Active Contract Opportunity Notice ID SPE8E826T5589 Related Notice... of ...
DEPT OF DEFENSE
Bid Due: 9/25/2026
...Program/Jacket Number: 451-829/830 Title: Jacket 451-829: Form 1041-ES (OCR) (2026) Payment... Vouchers; Jacket ...
U.S. Government Publishing Office
Bid Due: 9/17/2026
...Program/Jacket Number: 741-837 Title: Document Scanning (New Orleans Project) Bid Opening Date... Specifications ...
U.S. Government Publishing Office
Bid Due: 9/17/2026
...Program/Jacket Number: 1215-S Title: Litigation Support Services Bid Opening Date: September 29...
U.S. Government Publishing Office
Bid Due: 9/29/2026