Holy Family University respectfully submits the following corrective action plan for the year ended June 30, 2022. Name and address of independent public accounting firm: Baker Tilly US, LLP 1650 Market Street, Suite 4500 Philadelphia, Pennsylvania 19103 Audit period: June 30, 2022 The findings from...
Holy Family University respectfully submits the following corrective action plan for the year ended June 30, 2022. Name and address of independent public accounting firm: Baker Tilly US, LLP 1650 Market Street, Suite 4500 Philadelphia, Pennsylvania 19103 Audit period: June 30, 2022 The findings from the June 30, 2022 schedule of findings and questioned costs are discussed below. Finding 2022-001: Special Tests and Provisions - Gramm-Leach Bliley Act (?GLBA?) 84.268 Federal Direct Loan Program; 84.063 Federal Pell Grant Program, 84.033 Federal Work Study Program, 84.007 Federal Supplemental Education Opportunity Grant; 84.038 Federal Perkins Loan Program Recommendation: The University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the University should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Action Taken: The institution acknowledges and understands the requirements set forth by the Gramm-Leach-Bliley Act (GLBA) and is in the process of selecting a qualified individual for the partner role. Our team is actively developing a timeline to ensure full compliance with GLBA by June 9, 2023. In order to prioritize our efforts, we have identified areas of risk and implemented risk-based priorities to strengthen our network security, including firewalls, email access with Multi-Factor Authentication (MFA), applications, and policies/procedures. As part of our compliance efforts, our team will conduct a risk assessment to address three areas of concern, including 1. employee training and management 2. information systems (including network and software design 3. as well as information processing, storage, transmission, and disposal), and detecting, preventing and responding to attacks, intrusions, or other systems failures. We will document safeguards for identified risks by June 30, 2023. Name(s) of Contact Person(s) Responsible for Corrective Action: Mark Green, Associate Vice President Institutional Effectiveness, IT, and Innovation Anticipated Completion Date: June 9, 2023 If there are any questions regarding this corrective action plan please contact Eric Nelson, Vice President for Finance & Administration, at enelson@holyfamily.edu.