INFORMATION TECHNOLOGY SECURITY ASSESSMENT AS A SERVICE: HITRUST CSF CERTIFICATION

INVITATION TO NEGOTIATE ITN # 2021-01

2002 Old St. Augustine Rd. Suite E45 Tallahassee, FL 32301

HEALTHY START MOMCARE NETWORK, INC. INVITATION TO NEGOTIATE # 2021-01

SECTION I: Purpose

The Healthy Start MomCare Network, Inc. (“Organization”) invites qualified vendors to submit proposals and remain open to negotiations to provide assessment and related services as required in connection with Organization obtaining certification from the HITRUST Common Security Framework (CSF) under the HITRUST CSF Assurance Program (“CSF Assessor Services”)

OBJECTIVE

The Healthy Start MomCare Network, Inc. is a 501(c)3 organization that serves as the administrative service organization for all Florida Healthy Start Coalitions. It is the primary contract representative with the Florida Agency for Health Care Administration (“AHCA”) to provide risk appropriate care coordination and other services to pregnant women, infants and children who are identified as at-risk for poor birth, health and developmental outcomes, and any other program or purpose permitted by law pursuant to Sections 409.975(4)(a) and 409.906(11) of the Florida Statutes (2015) and in accordance with a federal Medicaid waiver.

The Organization invites qualified vendors to submit proposals to provide CSF Assessor Services. It is the intent of the Organization to contract with a qualified vendor with healthcare experience and whose services can facilitate incorporating the regulatory compliance requirements of the HIPAA Privacy and Security Rule. The CSF Assessor will provide assessment services to assist the Organization in demonstrating compliance with the requirements of existing standards and regulations including federal (HIPAA, HITECH), third party (PCI, COBIT) and government (NIST, FTC) limited to the scope applicable to the Organization based on its current activities. The CSF Assessor shall provide trained resources to Organization to assess how well Organization is managing its privacy and security infrastructure, ongoing management of Information Security policies, procedures and technical systems in order to maintain the confidentiality, integrity and availability of all Organization information systems in compliance with security control requirements of the HITRUST CSF. If needed, the CSF Assessor shall document corrective action plans that align with the CSF, and assist Organization with its interim assessment within twelve months following its initial attainment of HITRUST CSF Certification, to evaluate whether Organization has made improvements on the corrective action plan, and assist Organization in that effort.

The Organization reserves the right to modify the Scope and Specifications, as circumstances require. The obligations of the Organization under this award are subject to the terms and conditions established by the Legislature of the State of Florida and contract approval by the Healthy Start MomCare Network, Inc. Board of Directors.

ITN documents are posted on Healthy Start MomCare Network website www.healthystartmomcarenetwork.org in the “News” section and may also be requested via email.

Download Full HITRUST ITN Document