Acceptable Risk Controls for ARC-AMPE 3rd Party Attestation

This opportunity is closed, click here to see similar open opportunities.

Title:  

Acceptable Risk Controls for ARC-AMPE 3rd Party Attestation

Agency:  

State of Idaho Department of Health

State:  

Idaho

NAICS Code:  

541513

Industry:  

Information Technology and Software Development

Solicitation Type:  

Request for Proposal

Solicitation ID:  

1077

Open Date:  

9/23/2025

Questions Due Date:  

10/10/2025

Close Date:  

11/14/2025

Last Updated:  

Description:
The State of Idaho Department of Health is seeking a vendor to perform third-party attestation and web application testing for the Acceptable Risk Controls for Affordable Care Act, Medicaid, and Partner Entities (ARC-AMPE) program. The vendor will be responsible for testing five specific web applications, which handle sensitive data including PII, PHI, and FTI. The testing will be conducted using a Grey Box approach and will include vulnerability and penetration testing. The vendor will be required to provide a fully burdened rate for the entire year of services and will be expected to work with the Department to develop a work plan and budget for any additional services required. • The vendor must have prior experience with ARC-AMPE attestation, but does not need to be certified or authorized by CMS or any federal body. • The vendor will be provided with test credentials, staging environments, and sandbox access for the five web applications. • The vendor will be required to provide a narrative description of their prior experience with ARC-AMPE or MARS-E attestation. • The vendor will be required to provide named resumes for key personnel. • The vendor will be expected to emulate a siloed pen test approach and will not be permitted to conduct destructive tests. • The vendor will be required to provide deliverables including attestation letters, Letters of Assessment, and auditor-ready appendices.
Attached Files:

Please visit the bid source via the “Link to Bid Source” button below for documentation.

Contact Information:

There is no contact information available at this time.

Budget Estimate (AI):

$200,000 – $500,000

The budget for this opportunity is likely to be in the range of $200,000 to $500,000, based on the scope of work and the requirements for the vendor. The vendor will be required to provide a fully burdened rate for the entire year of services, which will likely be in the range of $100 to $250 per hour, depending on the level of expertise and the location. The total budget will depend on the number of hours worked and the level of expertise required. Factors that may influence the likely payment range include the complexity of the web applications, the level of security required, and the level of expertise of the vendor.

Similar Opportunities powered by Bid Banana AI

The Bid Lab’s Experts Are Ready To Help You Win RFPs

The Bid Lab is the only RFP consulting firm of its kind, specializing in guiding small and medium-sized businesses through the proposal response process. We have RFP experts ready to help you respond to that perfect opportunity you discover in Bid Banana.

  • Trusted by 100s of small business owners
  • Experience working on 1000s of RFP responses
  • Success stories in virtually every industry you can check out by clicking here.