As of February 10, 2020, the World Health Organization (WHO) reported that 40,554 cases of the Novel Coronavirus (2019-nCoV) have been confirmed globally, with twelve cases confirmed in the United States.  The WHO has been issuing situation reports on a daily basis since January 21, and each report in February alone has identified more than 2,000 to 3,000 new cases each day.

Due to the lack of approved therapeutics, vaccines, and diagnostics for this threat, developing new products and testing products already approved for other uses is a high priority for the U.S. interagency response effort—the Medical Countermeasure (MCM) Task Force.  The Biomedical Advanced Research and Development Authority (BARDA), under the Office of the Assistant Secretary for Preparedness and Response (ASPR) in the U.S. Department of Health and Human Services (HHS), is leading this Task Force in partnership with U.S. Department of Defense, Food and Drug Administration, Centers for Disease Control and Prevention, and National Institutes of Health.

BARDA is currently looking at the effectiveness of existing countermeasures for similar viruses, as well as potential new responsive technologies, including vaccines, diagnostics, therapeutics, and medical supplies.  BARDA is serving as the sole point of entry for product and technology submissions to ensure there is an expedited process for receipt and review of proposed solutions for 2019-nCoV.  In this capacity, BARDA has released two opportunities to submit potential solutions for the 2019-nCoV response discussed below: (1) the EZ-BAA for 2019-nCoV diagnostics and (2) market research packages for any and all potential products and supplies.  Covington encourages those with technology that could be potentially useful to respond.Continue Reading U.S. Government Seeks Industry Solutions in Novel Coronavirus Response

On Friday January 31, 2020, Ellen Lord, Under Secretary of Defense for Acquisition and Sustainment, Kevin Fahey, Assistant Secretary of Defense for Acquisition, and Katie Arrington, the Chief Information Security Officer for the Department of Defense (“DoD”), briefed reporters on the release of the Cybersecurity Maturity Model Certification (“CMMC”) Version
Continue Reading DoD Announces the Release of CMMC Version 1.0

The Trump Administration has declared this month National Slavery and Human Trafficking Prevention Month, calling on industry associations, law enforcement, private businesses, and others to work toward ending modern slavery and human trafficking. This proclamation follows the Administration’s efforts to combat human trafficking, which we have previously discussed here, and comes on the heels of an OMB memorandum released last fall aimed at “enhanc[ing] the effectiveness of anti-trafficking requirements in Federal acquisition while helping contractors manage and reduce the burden associated with meeting these responsibilities.”
Continue Reading Trump Administration Renews Focus on Anti-Human Trafficking Efforts

Late last week, House Democrats passed Speaker Nancy Pelosi’s Elijah E. Cummings Lower Drug Costs Now Act. This bill would, among other things, permit the Department of Health and Human Services (“HHS”) to negotiate lower prices for 250 of the costliest drugs on behalf of Medicare beneficiaries and other consumers.
Continue Reading Momentum In Drug Pricing Reform: House Passes New Legislation on the Heels of Presidential Candidates’ Drug Pricing Proposals

On December 13, the Department of Defense (“DoD”) released the latest version of its Cybersecurity Maturity Model Certification (“CMMC”).  This is the third iteration of the draft model that DoD has publicly released since it issued the first draft in October.  (We previously discussed Version 0.4 and Version 0.6 of the CMMC in prior blog posts.)

DoD describes the CMMC as “a DoD certification process that measures a DIB sector company’s ability to protect FCI [Federal Contract Information] and CUI [Controlled Unclassified Information].”  DoD has stated publicly that it intends to begin incorporating certification requirements into solicitations starting in Fall 2020, with compliance audits beginning in late 2020 or early 2021.  Depending the sensitivity of the information that contractors will receive in the course of performing work for DoD, they will be expected to demonstrate compliance through third party audits with the requirements set forth under one of five certification levels.  This applies even where contractors will not be handling FCI or CUI in the course of performing their contracts.[1]

The two most significant updates to the model in this version of the draft are (i) the addition of “Practices” for obtaining Level 4 and 5 certifications, and (ii) an expansion of “clarifications” section, which now covers the requirements of Levels 2 and 3 of the model, in addition to Level 1.  These changes and others are discussed in more detail below.  Given the expected release in late January 2020, it is likely that the requirements in this draft will closely resemble those that will be set forth in Version 1.0 of the CMMC framework, which is anticipated to serve as the basis for the first contractor audits.Continue Reading DoD Releases Version 0.7 of Its Cybersecurity Maturity Model Certification

On November 27, 2019, the Department of Commerce issued a proposed rule to implement the May 15, 2019 Executive Order entitled “Securing the Information and Communications Technology and Services Supply Chain.”  Once finalized and effective, the regulations will govern the process and procedures that the Secretary of Commerce will use to determine whether certain transactions involving information and communications technology or services (“ICTS”) should be prohibited or otherwise restricted.  As currently drafted, the proposed rule goes further than many other legal authorities, in that it allows the government to prohibit or otherwise restrict a broad range of wholly commercial transactions that the Secretary determines present national security risks.

Details on key aspects of the proposed rule are in a Client Alert that we published on November 27, available here.  The public comment period remains open until December 27.  Given the breadth of the proposed rule and the significant number of open questions, thoughtful comments will be critically important in scoping a final rule.
Continue Reading Commerce Department Proposes Rule Impacting Information and Communications Technology Supply Chains

Last week, the FAR Council issued a Final Rule, setting forth new FAR provisions that require the reporting of certain counterfeit and suspect counterfeit parts and certain major or critical nonconformances to the Government – Industry Data Exchange Program (“GIDEP”).[1]  This Final Rule comes more than five years after the rule was first proposed in the Federal Register in June 2014.  The FAR Council describes the Final Rule as “significantly de-scoped” from the version proposed in 2014, but it nonetheless constitutes a significant expansion of the existing counterfeit part reporting obligations, which to date have applied only to electronic parts under DOD contracts.
Continue Reading New FAR Rule Expands Counterfeit Reporting Obligations

On November 6, 2019, the Department of Labor’s Office of Federal Contract Compliance Programs (“OFCCP”) issued a Notice of Proposed Rulemaking (“NPRM”) aimed at resolving what OFCCP describes as a “decade of confusion.”[1] At issue is a long-standing question concerning the scope of OFCCP’s enforcement authority over health care providers participating in TRICARE, a federal health care program covering millions of military personnel, veterans, and their families. In particular, the NPRM requests comments on proposed regulations that would amend OFCCP’s definition of “subcontractor” and thereby remove TRICARE providers–and potentially other categories of providers–from OFCCP’s regulatory authority entirely. The deadline for filing comments is December 6, 2019.
Continue Reading OFCCP Proposes Rule Removing TRICARE Health Care Providers from Its Regulatory Authority

As previously discussed on this blog, the National Defense Authorization Act for Fiscal Year 2017 and the NDAA for Fiscal Year 2018 imposed new limitations on when the Department of Defense can use Lowest Price Technically Acceptable source selection methods.  Just last month, the Department of Defense issued a final rule amending the Defense Federal Acquisition Regulation Supplement to implement those provisions.  Now, in Inserso Corp., B-417791, B-417791.3, Nov. 4, 2019, GAO has weighed in on what counts as LPTA for purposes of those restrictions.  This decision may indicate a potentially significant limitation on the reach of the NDAA provisions, new DFARS rule, and proposed FAR rule.
Continue Reading What Is Lowest Priced Technically Acceptable? GAO Clarifies Reach of New LPTA Restrictions

On November 7, the Office of the Assistant Secretary of Defense for Acquisition released Version 0.6 of its draft Cybersecurity Maturity Model Certification (CMMC) for public comment. The CMMC was created in response to growing concerns by Congress and within DoD over the increased presence of cyber threats and intrusions aimed at the Defense Industrial Base (DIB) and its supply chains.

The model updates Version 0.4, which DoD released on September 4, 2019, and which we wrote about here. The CMMC establishes the framework necessary for contractors to obtain one of five certification levels necessary to perform work on certain DoD contracts, including those that require the handling of Controlled Unclassified Information. Whereas Version 0.4 merely listed the capabilities, controls, and processes that were expected to apply to each certification level, this version provides some additional discussion and clarification to assist contractors with meeting Level 1 certifications.

DoD has not explicitly asked for comment on this version of the CMMC, and has stated that the updated model is being released “so that the public can review the draft model and begin to prepare for the eventual CMMC roll out.” For this reason, although additional changes are to be expected to the model, contractors should review the general requirements closely to ensure that they are positioned to continue bidding on DoD contracts once DoD begins including a requirement to obtain a specific certification level in Requests for Proposal in Fall 2020.
Continue Reading DoD Releases Version 0.6 of its Cybersecurity Maturity Model Certification