2022-024: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Personnel Security; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses found during an audit of IT general controls. The audit performed by an external consultant during the period April 1, 2019, through March 31, 2020, resulted in 71 individual control weaknesses out of 100 controls tested, which the consultant grouped in ten findings. As of the end of fiscal year 2022, Medical Assistance Services resolved one of the ten findings and continues to make progress with nine remaining findings, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency's ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to staffing turnover and shortages as well as organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan in June 2022, stating corrective actions are still ongoing for all nine findings and estimates it will complete corrective action for eight of the findings by the end of calendar year 2022 and the last finding by June 2023. Medical Assistance Services should continue to dedicate the necessary resources to ensure timely completion of its corrective action plans and to comply with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-029: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires implementing certain internal controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services cannot ensure adequate protection of its sensitive and mission- critical data without configuring its sensitive web application in accordance with the Security Standard. Lacking or insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Social Services prioritization of other projects also contributed to the weaknesses persisting. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Implementing required controls will help to ensure Social Services secures the web application to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-030: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning; Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. Since we first issued this finding during the fiscal year 2018 audit, Social Services remediated some risk management and contingency planning issues. However, Social Services continues to not: ? accurately verify and validate data and system sensitivity ratings; ? create risk assessments for 50 percent of its sensitive systems; ? create system security plans for 52 percent of its sensitive systems; ? perform annual reviews for 99 percent of its existing risk assessment documentation; ? perform annual reviews for 74 percent of its existing system security plan documentation; and ? implement corrective actions identified in risk assessments. We communicated the details of these weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Due to the magnitude of the project, Social Services has not yet remediated all the weaknesses. Additionally, the requirements documented in the policy and the process documented in the procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Without implementing a formal and effective IT risk management program, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should prioritize and dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Completing its corrective action plan will help to ensure the confidentiality, integrity, and availability of the agency's sensitive systems and mission-essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-052: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Social Services Change Management Process Guide details the process Social Services follows to manage changes but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Without doing such, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services' IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-057: Improve Timely Removal of Critical System Access Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-037; 2020-049; 2019-024; 2018-040; 2017-016 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services did not remove access to the claims processing module or the eligibility system timely for individuals who separated from the agency and no longer needed access. For one out of eight (12.5%) users, Medical Assistance Services did not disable system access in the claims processing module within 24 hours of separation. The user retained their system access for 11 days after separation. For three out of 25 (12%) users, Medical Assistance Services did not disable system access in the eligibility system within 24 hours of separation. These three users were contract employees and retained their access to the system between 104 and 123 days after separation. Medical Assistance Services' Access Control Policy requires that "all user accounts must be disabled immediately upon separation or within 24 hours upon receipt by the Office of Compliance and Security" (Compliance and Security). Failing to disable access timely for web- based mission-critical systems threatens the data integrity of the systems. If separated users retain access to the claims processing module or the eligibility system, users are potentially able to view, copy, and edit sensitive information. There are several factors contributing to this issue. First, Medical Assistance Services' internal policy is not in compliance with the Security Standard. The Security Standard requires agencies disable access within 24 hours of separation, not within 24 hours of receipt of notification. Additionally, supervisors are not communicating information on separated employees timely. A separating employee's supervisor must initiate an exit clearance workflow for the system to automatically notify Compliance and Security for removal of system access. For the user of the claims processing module, the supervisor requested access termination more than 24 hours after the employee's separation. Finally, for the three users of the eligibility system, Compliance and Security received the access termination request timely but did not terminate access for more than 24 hours after receipt. In June 2022, Medical Assistance Services implemented several organizational changes, including dissolving Compliance and Security. The responsibility for system access management moved to the division responsible for the system and its applicable business function. Medical Assistance Services is currently updating its internal Access Control policy to ensure it is consistent with the Security Standard and organizational updates. Medical Assistance Services expects to complete the policy and process updates in December 2022. Medical Assistance Services should also train and educate supervisors on the importance of timely notification of separated employees. Finally, Medical Assistance Services should ensure compliance with the Security Standard by removing user access as required. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-059: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2021-038; 2021-027; 2020-025; 2019-027; 2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services did not comply with the Security Standard requirements for removing system access for separated employees. For 13 of the 26 (50%) separations tested from fiscal year 2022, Social Services did not remove system access within 24 hours following each employee's separation date. Untimely removal of access ranged between two and 290 days after each employee's separation date. Section PS-4 of the Security Standard requires an organization to disable information system access within 24 hours of employment termination. To comply with the Security Standard, Social Services created a policy in Section 2.9 of its State/Local Security Officers Procedures Manual (Manual) that requires supervisors to complete the State Employee Separation and Transfer Checklist (Separation Checklist) at least 48 hours in advance of the employee's separation and submit it to the Division Security Officer. The Division Security Officer must then remove the separated employee from Social Services' access management system, which controls access to its internal systems, within 24 hours following the employee's separation date. Upon completion, the Division Security Officer is responsible for submitting the Separation Checklist to other Divisions, such as the Division of Human Resources (Human Resources) and the Central Security Office (Central Security), to make them aware of the separation. Social Services does not appear to monitor compliance with internal policies surrounding access removal for separated employees. Of the 13 employees with access removed more than 24 hours after their separation dates: ? We noted four instances where Social Services was unable to provide the Separation Checklist. As a result, Social Services was unable to demonstrate compliance with its internal policies surrounding access removal for separated employees. ? Of the remaining nine employees with completed Separation Checklists, we noted nine instances of untimely or inaccurate supervisor sign-offs. Specifically, there were seven instances where the supervisor did not submit the Separation Checklist to the Division Security Officer at least 48 hours in advance of the employee's date of separation and two instances where the supervisor did not properly sign off and date the Separation Checklist. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur a potential financial liability should its information become compromised. The Security Standard states that the Agency Head is responsible for security of the agency's IT systems and data. Since Human Resources, Central Security, and the Division Security Officers share ownership of the employee separation and access removal processes, Social Services' Executive Team should identify which division in the agency should be responsible for monitoring compliance with internal policies surrounding access removal for separated employees. Social Services' Executive Team should periodically review the monitoring results and take enforcement actions, as necessary, if the agency is not compliant. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-060: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life technologies in its IT environment and maintains technologies that support mission-essential data on IT systems that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard prohibits using software that is end-of-life and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services does not assign an individual or team with the responsibility to track end- of-life software dates and does not have a formal process to ensure that it upgrades software versions prior to the end-of-life date, which caused the end-of-life software to remain in the environment. Social Services use of the end-of-life software increases the risk that known vulnerabilities will persist in the system without the potential for patching or mitigation. These unpatched vulnerabilities increase the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for end-of-life or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Minimizing the use of end-of-life software will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-064: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process for its case management system. Social Services' case management system authorized over $10 billion in benefit payments from various public assistance programs to beneficiaries during fiscal year 2022. We communicated this weakness to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions. During the fiscal year, Social Services finalized and documented policies with retention requirements. However, Social Services has not developed, documented, and implemented a policy, procedure, and process to operationalize the record retention requirements needed. Federal regulations require different record retention requirements for different federal programs. Additionally, the Virginia Public Records Act (? 42.1-91 of the Code of Virginia) requires each agency to be responsible for ensuring that it preserves, maintains, and makes accessible public-facing records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Further, the Security Standard, Section CP-9-COV, requires the agency implement backup and restoration plans for every IT system identified as sensitive relative to availability that address the retention of the data in accordance with the records retention policy. Without developing, documenting, and implementing a policy, procedure, and process to operationalize record retention requirements, Social Services increases data risk and increases potential exposure to fines, penalties, or other legal consequences. Additionally, Social Services may cause the Commonwealth to spend additional resources to maintain, back up, and protect the information. Social Services should develop and implement a records retention policy and procedure that defines its requirements and processes to ensure that consistent record retention processes can be operationalized across business divisions to ensure compliance with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-066: Conduct Audits of Agency Sensitive Systems Timely Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 VITA's Centralized IT Security Audit Service (Audit Services) conducts IT security audits for contracted agencies. The Commonwealth's Information Technology Security Audit Standard, SEC 502 (Security Audit Standard), Section 2.1, requires agencies to complete security audits for each sensitive system every three years from the last audit completion date. Based on our review of audit completion dates provided by Audit Services, we determined the following: ? During fiscal year 2022, Audit Services completed four of six agency IT security audits after the three-year audit deadline. ? As of June 30, 2022, Audit Services is currently engaged, or has not started, ten agency IT security audits that are past the three-year audit requirement. When an agency contracts with Audit Services, the agency head or designee signs a Memorandum of Understanding (MOU) which outlines the scope of work and pricing. It is the agency's responsibility to ensure the MOU includes all sensitive systems requiring a security audit. A properly defined MOU allows Audit Services to properly price and schedule the security audit. Audit Services audits all the systems in scope for an agency at the same time and issues one audit report covering all systems in scope per the MOU. Audit Services should consider adding information to the MOU related to audit deadlines or planned timeframe for the audit. This added communication will ensure all parties understand when Audit Services plans to complete the audits. Additionally, more information regarding audit timing will allow agencies to determine if they need to obtain a separate audit for specific systems to ensure those systems remain compliant with the Security Audit Standard between the date of the MOU and the anticipated deadline set by Audit Services. Of the four audits Audit Services completed late during fiscal year 2022, two of the delays are due to the agencies requesting postponements. Additionally, of the ten audits that were already late as of June 30, 2022, two are due to agency-requested postponements. The remaining late audits are primarily due to resource constraints within Audit Services. Audit Services should regularly monitor its audit workplan to ensure audit staff complete all IT security audits by the required deadlines. Additionally, Audit Services should evaluate its staffing levels and assess if VITA should contract with an outside audit firm to aid in completing IT security audits. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-090: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services does not have a formal and consistent process for maintaining oversight for three of its IT third-party service providers (providers) that manage and support the Medicaid management system. As a result of an informal and inconsistent process, Medical Assistance Services did not verify or implement three controls required by the Hosted Environment Security Standard. We communicated the three weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Without a formal and consistent process to maintain oversight of its providers, Medical Assistance Services cannot validate whether its providers implement the security controls that meet the requirements in the Hosted Environment Security Standard to protect the agency's sensitive and mission-critical data. While Medical Assistance Services has a formal IT Third Party and Vendor Compliance Management Policy, effective as of December 31, 2021, the agency experienced turnover in its ISO position in June 2022 before the development of a formal procedure. As a result, Medical Assistance Services did not consistently maintain oversight of its providers in accordance with the Hosted Environment Security Standard. Medical Assistance Services should dedicate the necessary resources to develop a formal procedure to maintain oversight of its providers in accordance with its policy and the Hosted Environment Security Standard. Medical Assistance Services should also dedicate the necessary resources to implement and consistently perform the formal oversight process, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-100: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2022, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Security Standard. The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through the ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard Section: SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies' operations. Our audits at various agencies for fiscal year 2022 found critical and highly important security patches that were past the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of successful cyberattack, exploit, and data breach by malicious parties. Additionally, the Security Standard requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard Section: AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2022 found that agencies rely on the ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Certain agencies were unable to obtain access to the audit log information during fiscal year 2022, and thus were not able to comply with the Security Standard requirements related to audit log monitoring. Although the supplier was performing audit logging and monitoring, only a select few agencies have access to the monitoring tool while the supplier is pilot testing the tool. The Commonwealth's risk associated with data confidentiality, integrity and availability increases with agencies not being able to review and monitor their individual audit logs. During fiscal year 2022, VITA and the Multisource Service Integrator (MSI) evaluated the current service level measurements to ensure they align with the Commonwealth's needs. As of December 2022, VITA and the MSI are implementing changes to the service level related to security and vulnerability patching. The changes to this service level include establishing a Common Vulnerabilities and Exposures (CVE) threshold. The new security and vulnerability patching service level will require the ITISP suppliers to install any patch with a CVE score above the threshold within 90 days. VITA continues to work with the managed security supplier to address the agencies' inability to access the audit log information. The supplier replaced the original security incident and event management system with a new managed detection and response (MDR) platform. Currently, only a small number of agencies are piloting the new MDR system. VITA should document the rationale for all changes to the service levels, including the basis for the CVE score threshold selected, and continually reevaluate the service levels as risks change. To ensure all agencies that rely on the ITISP services can comply with the Security Standard, VITA should ensure ITISP suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk per the Security Standard. If VITA determines an ITISP supplier is not meeting a contractual requirement that may have a Security Standard implication, VITA should communicate with the affected agencies and provide guidance on compensating controls and processes the agencies should implement to reduce risk while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-011: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Prior Year Finding Number: 2021-070; 2020-074; 2019-090; 2018-093 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR ? 200.303(a) Known Questioned Costs: $0 The Department of Social Services' (Social Service) Compliance Division (Compliance) continues to not adhere to its established approach to oversee the agency's subrecipient monitoring activities, as outlined in its Agency Monitoring Plan. During fiscal year 2022, Social Services disbursed approximately $588 million in federal funds from roughly 5,000 subawards. According to Social Services' Organizational Structure Report, Compliance is responsible for agency-wide compliance and risk mitigation that helps to ensure adherence to state and federal legal and regulatory standards, including subrecipient monitoring. During the audit, we noted the following deviations from the Agency Monitoring Plan: ? Compliance has not finalized the Agency Monitoring Plan and, as a result, has not communicated it to Subrecipient Monitoring Coordinators within each division of Social Services. Because of the lack of communication, there were deviations from the Agency Monitoring Plan at the division level. For example, the Agency Monitoring Plan requires each division to monitor subrecipients once every three years. However, the Local Review Team and Child Care Subsidy Program Monitoring Plans did not consider this requirement because the Subrecipient Monitoring Coordinators were unaware of this requirement. We communicated this matter to Social Services through the audit finding titled "Finalize the Agency Monitoring Plan and Communicate Responsibilities to Subrecipient Monitoring Coordinators," which we have included as a separate audit finding in this report. ? Compliance continues to not review division monitoring plans to ensure the divisions implemented a risk-based approach for monitoring subrecipients. The Agency Monitoring Plan states that Compliance will use a monitoring plan checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division's plan. As a result of the lack of review, the Division of Benefit Programs' (Benefit Programs) monitoring plan continues to not meet all the requirements outlined in the Agency Monitoring Plan because it does not include a risk-based approach for subrecipient monitoring and does not consider all subrecipients who receive funding from the Temporary Assistance for Needy Families (TANF) federal grant program. We communicated these matters to Social Services through the audit findings titled "Verify that Monitoring Plan Includes All Subrecipient Programmatic Activities" and "Evaluate Subrecipients' Risk of Noncompliance in Accordance with Federal Regulations," which we have included as separate audit findings in this report. ?Compliance continues to not conduct an analysis of subrecipient monitoring review efforts performed by the divisions. As a result, Compliance has not produced quarterly reports of variances and noncompliance to brief Social Services' Executive Team on the agency's subrecipient monitoring activities. Because of the lack of analysis, Compliance was unaware of deviations from the Agency Monitoring Plan occurring at the divisions. For example, Benefit Programs only completed 25 of the 67 (37%) scheduled reviews for the Low-Income Home Energy Assistance Program (LIHEAP) federal grant program. Additionally, Benefit Programs did not upload its monitoring review records to Social Services' data repository timely for management review. As a result, Compliance was unaware that Regional Consultants were deviating from Benefit Programs' monitoring plan. We communicated this matter to Social Services through the audit finding titled "Confirm Monitoring Activities are Conducted in Accordance with the Monitoring Plan," which we have included as a separate audit finding in this report. Without performing the responsibilities in the Agency Monitoring Plan, Compliance cannot provide Social Services' Executive Team with reasonable assurance that the agency complied with the pass-through entity federal requirements at 2 CFR ? 200.332. Title 2 CFR ? 200.303(a) requires pass through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Compliance planned to procure a centralized system to strengthen its monitoring activities but has been unsuccessful in its efforts and has not identified alternative approaches for carrying out the responsibilities in the Agency Monitoring Plan and discussed them with Social Services' Executive Team. Because of the scope of this matter, we consider it to be a material weakness in internal control. Social Services' Executive Team shapes strategies, develops objectives, and collectively resolves issues that are critical to the overall agency performance. Social Services' Executive Team and Compliance should work collaboratively to determine the best approach for carrying out the responsibilities in the Agency Monitoring Plan. Additionally, Social Services' Executive Team and Compliance should hold quarterly meetings to discuss the Agency Monitoring Plan and its activities. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-022: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services has an insufficient governance structure to manage and maintain its information security program in accordance with the Commonwealth's Information Security Standard, SEC 501 (Security Standard). Specifically, Social Services does not assess information security requirements for its information technology (IT) projects and prioritize information security and IT resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. Social Services uses numerous IT systems to carry out its mission and provide essential services to the public. The Security Standard, Section 2.4.2, requires the agency head to maintain an information security program that is sufficient to protect the agency's IT systems and to ensure the information security program is documented and effectively communicated. We communicated the internal control weaknesses to management in a separate document marked Freedom of Information Act (FOIAE) under ? 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The internal control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation or prioritizing information security within the IT environment. Not prioritizing IT resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Additionally, not dedicating the necessary IT resources to information security has hindered Social Services' ability to remediate findings from management recommendations issued throughout prior audits consistently and timely and bring the information security program in compliance with the Security Standard. Because of the scope of this matter, we consider it to be a material weakness in internal control. Social Services should evaluate the most efficient and effective method to bring its IT and security program into compliance with the Security Standard. Social Services should also evaluate its IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the internal control deficiencies discussed in the communication marked FOIAE. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-024: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Personnel Security; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses found during an audit of IT general controls. The audit performed by an external consultant during the period April 1, 2019, through March 31, 2020, resulted in 71 individual control weaknesses out of 100 controls tested, which the consultant grouped in ten findings. As of the end of fiscal year 2022, Medical Assistance Services resolved one of the ten findings and continues to make progress with nine remaining findings, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency's ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to staffing turnover and shortages as well as organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan in June 2022, stating corrective actions are still ongoing for all nine findings and estimates it will complete corrective action for eight of the findings by the end of calendar year 2022 and the last finding by June 2023. Medical Assistance Services should continue to dedicate the necessary resources to ensure timely completion of its corrective action plans and to comply with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-029: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires implementing certain internal controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services cannot ensure adequate protection of its sensitive and mission- critical data without configuring its sensitive web application in accordance with the Security Standard. Lacking or insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Social Services prioritization of other projects also contributed to the weaknesses persisting. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Implementing required controls will help to ensure Social Services secures the web application to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-030: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning; Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. Since we first issued this finding during the fiscal year 2018 audit, Social Services remediated some risk management and contingency planning issues. However, Social Services continues to not: ? accurately verify and validate data and system sensitivity ratings; ? create risk assessments for 50 percent of its sensitive systems; ? create system security plans for 52 percent of its sensitive systems; ? perform annual reviews for 99 percent of its existing risk assessment documentation; ? perform annual reviews for 74 percent of its existing system security plan documentation; and ? implement corrective actions identified in risk assessments. We communicated the details of these weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Due to the magnitude of the project, Social Services has not yet remediated all the weaknesses. Additionally, the requirements documented in the policy and the process documented in the procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Without implementing a formal and effective IT risk management program, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should prioritize and dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Completing its corrective action plan will help to ensure the confidentiality, integrity, and availability of the agency's sensitive systems and mission-essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-052: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Social Services Change Management Process Guide details the process Social Services follows to manage changes but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Without doing such, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services' IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-057: Improve Timely Removal of Critical System Access Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-037; 2020-049; 2019-024; 2018-040; 2017-016 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services did not remove access to the claims processing module or the eligibility system timely for individuals who separated from the agency and no longer needed access. For one out of eight (12.5%) users, Medical Assistance Services did not disable system access in the claims processing module within 24 hours of separation. The user retained their system access for 11 days after separation. For three out of 25 (12%) users, Medical Assistance Services did not disable system access in the eligibility system within 24 hours of separation. These three users were contract employees and retained their access to the system between 104 and 123 days after separation. Medical Assistance Services' Access Control Policy requires that "all user accounts must be disabled immediately upon separation or within 24 hours upon receipt by the Office of Compliance and Security" (Compliance and Security). Failing to disable access timely for web- based mission-critical systems threatens the data integrity of the systems. If separated users retain access to the claims processing module or the eligibility system, users are potentially able to view, copy, and edit sensitive information. There are several factors contributing to this issue. First, Medical Assistance Services' internal policy is not in compliance with the Security Standard. The Security Standard requires agencies disable access within 24 hours of separation, not within 24 hours of receipt of notification. Additionally, supervisors are not communicating information on separated employees timely. A separating employee's supervisor must initiate an exit clearance workflow for the system to automatically notify Compliance and Security for removal of system access. For the user of the claims processing module, the supervisor requested access termination more than 24 hours after the employee's separation. Finally, for the three users of the eligibility system, Compliance and Security received the access termination request timely but did not terminate access for more than 24 hours after receipt. In June 2022, Medical Assistance Services implemented several organizational changes, including dissolving Compliance and Security. The responsibility for system access management moved to the division responsible for the system and its applicable business function. Medical Assistance Services is currently updating its internal Access Control policy to ensure it is consistent with the Security Standard and organizational updates. Medical Assistance Services expects to complete the policy and process updates in December 2022. Medical Assistance Services should also train and educate supervisors on the importance of timely notification of separated employees. Finally, Medical Assistance Services should ensure compliance with the Security Standard by removing user access as required. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-059: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2021-038; 2021-027; 2020-025; 2019-027; 2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services did not comply with the Security Standard requirements for removing system access for separated employees. For 13 of the 26 (50%) separations tested from fiscal year 2022, Social Services did not remove system access within 24 hours following each employee's separation date. Untimely removal of access ranged between two and 290 days after each employee's separation date. Section PS-4 of the Security Standard requires an organization to disable information system access within 24 hours of employment termination. To comply with the Security Standard, Social Services created a policy in Section 2.9 of its State/Local Security Officers Procedures Manual (Manual) that requires supervisors to complete the State Employee Separation and Transfer Checklist (Separation Checklist) at least 48 hours in advance of the employee's separation and submit it to the Division Security Officer. The Division Security Officer must then remove the separated employee from Social Services' access management system, which controls access to its internal systems, within 24 hours following the employee's separation date. Upon completion, the Division Security Officer is responsible for submitting the Separation Checklist to other Divisions, such as the Division of Human Resources (Human Resources) and the Central Security Office (Central Security), to make them aware of the separation. Social Services does not appear to monitor compliance with internal policies surrounding access removal for separated employees. Of the 13 employees with access removed more than 24 hours after their separation dates: ? We noted four instances where Social Services was unable to provide the Separation Checklist. As a result, Social Services was unable to demonstrate compliance with its internal policies surrounding access removal for separated employees. ? Of the remaining nine employees with completed Separation Checklists, we noted nine instances of untimely or inaccurate supervisor sign-offs. Specifically, there were seven instances where the supervisor did not submit the Separation Checklist to the Division Security Officer at least 48 hours in advance of the employee's date of separation and two instances where the supervisor did not properly sign off and date the Separation Checklist. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur a potential financial liability should its information become compromised. The Security Standard states that the Agency Head is responsible for security of the agency's IT systems and data. Since Human Resources, Central Security, and the Division Security Officers share ownership of the employee separation and access removal processes, Social Services' Executive Team should identify which division in the agency should be responsible for monitoring compliance with internal policies surrounding access removal for separated employees. Social Services' Executive Team should periodically review the monitoring results and take enforcement actions, as necessary, if the agency is not compliant. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-060: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life technologies in its IT environment and maintains technologies that support mission-essential data on IT systems that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard prohibits using software that is end-of-life and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services does not assign an individual or team with the responsibility to track end- of-life software dates and does not have a formal process to ensure that it upgrades software versions prior to the end-of-life date, which caused the end-of-life software to remain in the environment. Social Services use of the end-of-life software increases the risk that known vulnerabilities will persist in the system without the potential for patching or mitigation. These unpatched vulnerabilities increase the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for end-of-life or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Minimizing the use of end-of-life software will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-064: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process for its case management system. Social Services' case management system authorized over $10 billion in benefit payments from various public assistance programs to beneficiaries during fiscal year 2022. We communicated this weakness to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions. During the fiscal year, Social Services finalized and documented policies with retention requirements. However, Social Services has not developed, documented, and implemented a policy, procedure, and process to operationalize the record retention requirements needed. Federal regulations require different record retention requirements for different federal programs. Additionally, the Virginia Public Records Act (? 42.1-91 of the Code of Virginia) requires each agency to be responsible for ensuring that it preserves, maintains, and makes accessible public-facing records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Further, the Security Standard, Section CP-9-COV, requires the agency implement backup and restoration plans for every IT system identified as sensitive relative to availability that address the retention of the data in accordance with the records retention policy. Without developing, documenting, and implementing a policy, procedure, and process to operationalize record retention requirements, Social Services increases data risk and increases potential exposure to fines, penalties, or other legal consequences. Additionally, Social Services may cause the Commonwealth to spend additional resources to maintain, back up, and protect the information. Social Services should develop and implement a records retention policy and procedure that defines its requirements and processes to ensure that consistent record retention processes can be operationalized across business divisions to ensure compliance with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-066: Conduct Audits of Agency Sensitive Systems Timely Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 VITA's Centralized IT Security Audit Service (Audit Services) conducts IT security audits for contracted agencies. The Commonwealth's Information Technology Security Audit Standard, SEC 502 (Security Audit Standard), Section 2.1, requires agencies to complete security audits for each sensitive system every three years from the last audit completion date. Based on our review of audit completion dates provided by Audit Services, we determined the following: ? During fiscal year 2022, Audit Services completed four of six agency IT security audits after the three-year audit deadline. ? As of June 30, 2022, Audit Services is currently engaged, or has not started, ten agency IT security audits that are past the three-year audit requirement. When an agency contracts with Audit Services, the agency head or designee signs a Memorandum of Understanding (MOU) which outlines the scope of work and pricing. It is the agency's responsibility to ensure the MOU includes all sensitive systems requiring a security audit. A properly defined MOU allows Audit Services to properly price and schedule the security audit. Audit Services audits all the systems in scope for an agency at the same time and issues one audit report covering all systems in scope per the MOU. Audit Services should consider adding information to the MOU related to audit deadlines or planned timeframe for the audit. This added communication will ensure all parties understand when Audit Services plans to complete the audits. Additionally, more information regarding audit timing will allow agencies to determine if they need to obtain a separate audit for specific systems to ensure those systems remain compliant with the Security Audit Standard between the date of the MOU and the anticipated deadline set by Audit Services. Of the four audits Audit Services completed late during fiscal year 2022, two of the delays are due to the agencies requesting postponements. Additionally, of the ten audits that were already late as of June 30, 2022, two are due to agency-requested postponements. The remaining late audits are primarily due to resource constraints within Audit Services. Audit Services should regularly monitor its audit workplan to ensure audit staff complete all IT security audits by the required deadlines. Additionally, Audit Services should evaluate its staffing levels and assess if VITA should contract with an outside audit firm to aid in completing IT security audits. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-090: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services does not have a formal and consistent process for maintaining oversight for three of its IT third-party service providers (providers) that manage and support the Medicaid management system. As a result of an informal and inconsistent process, Medical Assistance Services did not verify or implement three controls required by the Hosted Environment Security Standard. We communicated the three weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Without a formal and consistent process to maintain oversight of its providers, Medical Assistance Services cannot validate whether its providers implement the security controls that meet the requirements in the Hosted Environment Security Standard to protect the agency's sensitive and mission-critical data. While Medical Assistance Services has a formal IT Third Party and Vendor Compliance Management Policy, effective as of December 31, 2021, the agency experienced turnover in its ISO position in June 2022 before the development of a formal procedure. As a result, Medical Assistance Services did not consistently maintain oversight of its providers in accordance with the Hosted Environment Security Standard. Medical Assistance Services should dedicate the necessary resources to develop a formal procedure to maintain oversight of its providers in accordance with its policy and the Hosted Environment Security Standard. Medical Assistance Services should also dedicate the necessary resources to implement and consistently perform the formal oversight process, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-100: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2022, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Security Standard. The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through the ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard Section: SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies' operations. Our audits at various agencies for fiscal year 2022 found critical and highly important security patches that were past the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of successful cyberattack, exploit, and data breach by malicious parties. Additionally, the Security Standard requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard Section: AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2022 found that agencies rely on the ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Certain agencies were unable to obtain access to the audit log information during fiscal year 2022, and thus were not able to comply with the Security Standard requirements related to audit log monitoring. Although the supplier was performing audit logging and monitoring, only a select few agencies have access to the monitoring tool while the supplier is pilot testing the tool. The Commonwealth's risk associated with data confidentiality, integrity and availability increases with agencies not being able to review and monitor their individual audit logs. During fiscal year 2022, VITA and the Multisource Service Integrator (MSI) evaluated the current service level measurements to ensure they align with the Commonwealth's needs. As of December 2022, VITA and the MSI are implementing changes to the service level related to security and vulnerability patching. The changes to this service level include establishing a Common Vulnerabilities and Exposures (CVE) threshold. The new security and vulnerability patching service level will require the ITISP suppliers to install any patch with a CVE score above the threshold within 90 days. VITA continues to work with the managed security supplier to address the agencies' inability to access the audit log information. The supplier replaced the original security incident and event management system with a new managed detection and response (MDR) platform. Currently, only a small number of agencies are piloting the new MDR system. VITA should document the rationale for all changes to the service levels, including the basis for the CVE score threshold selected, and continually reevaluate the service levels as risks change. To ensure all agencies that rely on the ITISP services can comply with the Security Standard, VITA should ensure ITISP suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk per the Security Standard. If VITA determines an ITISP supplier is not meeting a contractual requirement that may have a Security Standard implication, VITA should communicate with the affected agencies and provide guidance on compensating controls and processes the agencies should implement to reduce risk while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-011: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Prior Year Finding Number: 2021-070; 2020-074; 2019-090; 2018-093 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR ? 200.303(a) Known Questioned Costs: $0 The Department of Social Services' (Social Service) Compliance Division (Compliance) continues to not adhere to its established approach to oversee the agency's subrecipient monitoring activities, as outlined in its Agency Monitoring Plan. During fiscal year 2022, Social Services disbursed approximately $588 million in federal funds from roughly 5,000 subawards. According to Social Services' Organizational Structure Report, Compliance is responsible for agency-wide compliance and risk mitigation that helps to ensure adherence to state and federal legal and regulatory standards, including subrecipient monitoring. During the audit, we noted the following deviations from the Agency Monitoring Plan: ? Compliance has not finalized the Agency Monitoring Plan and, as a result, has not communicated it to Subrecipient Monitoring Coordinators within each division of Social Services. Because of the lack of communication, there were deviations from the Agency Monitoring Plan at the division level. For example, the Agency Monitoring Plan requires each division to monitor subrecipients once every three years. However, the Local Review Team and Child Care Subsidy Program Monitoring Plans did not consider this requirement because the Subrecipient Monitoring Coordinators were unaware of this requirement. We communicated this matter to Social Services through the audit finding titled "Finalize the Agency Monitoring Plan and Communicate Responsibilities to Subrecipient Monitoring Coordinators," which we have included as a separate audit finding in this report. ? Compliance continues to not review division monitoring plans to ensure the divisions implemented a risk-based approach for monitoring subrecipients. The Agency Monitoring Plan states that Compliance will use a monitoring plan checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division's plan. As a result of the lack of review, the Division of Benefit Programs' (Benefit Programs) monitoring plan continues to not meet all the requirements outlined in the Agency Monitoring Plan because it does not include a risk-based approach for subrecipient monitoring and does not consider all subrecipients who receive funding from the Temporary Assistance for Needy Families (TANF) federal grant program. We communicated these matters to Social Services through the audit findings titled "Verify that Monitoring Plan Includes All Subrecipient Programmatic Activities" and "Evaluate Subrecipients' Risk of Noncompliance in Accordance with Federal Regulations," which we have included as separate audit findings in this report. ?Compliance continues to not conduct an analysis of subrecipient monitoring review efforts performed by the divisions. As a result, Compliance has not produced quarterly reports of variances and noncompliance to brief Social Services' Executive Team on the agency's subrecipient monitoring activities. Because of the lack of analysis, Compliance was unaware of deviations from the Agency Monitoring Plan occurring at the divisions. For example, Benefit Programs only completed 25 of the 67 (37%) scheduled reviews for the Low-Income Home Energy Assistance Program (LIHEAP) federal grant program. Additionally, Benefit Programs did not upload its monitoring review records to Social Services' data repository timely for management review. As a result, Compliance was unaware that Regional Consultants were deviating from Benefit Programs' monitoring plan. We communicated this matter to Social Services through the audit finding titled "Confirm Monitoring Activities are Conducted in Accordance with the Monitoring Plan," which we have included as a separate audit finding in this report. Without performing the responsibilities in the Agency Monitoring Plan, Compliance cannot provide Social Services' Executive Team with reasonable assurance that the agency complied with the pass-through entity federal requirements at 2 CFR ? 200.332. Title 2 CFR ? 200.303(a) requires pass through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Compliance planned to procure a centralized system to strengthen its monitoring activities but has been unsuccessful in its efforts and has not identified alternative approaches for carrying out the responsibilities in the Agency Monitoring Plan and discussed them with Social Services' Executive Team. Because of the scope of this matter, we consider it to be a material weakness in internal control. Social Services' Executive Team shapes strategies, develops objectives, and collectively resolves issues that are critical to the overall agency performance. Social Services' Executive Team and Compliance should work collaboratively to determine the best approach for carrying out the responsibilities in the Agency Monitoring Plan. Additionally, Social Services' Executive Team and Compliance should hold quarterly meetings to discuss the Agency Monitoring Plan and its activities. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
Criteria Per 34 CFR section 668.165, if an institution credits a student?s account with a Direct Loan, the institution must notify the student or parent, no earlier than 30 days before the disbursement and no later than 7 days after the disbursement, in writing of the anticipated date and amount of the loan disbursement, the student?s right or parent?s right to cancel all or a portion of that loan or loan disbursement and have the loan proceeds returned to the holder of that loan, and the procedures and time by which the student or parent must notify the institution that he or she wishes to cancel the loan or loan disbursement. Per 2 CFR 200.303, the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition For 10 out of 40 students selected for testwork, the federal direct loan disbursement notification was not sent to the student or parent within the required 30 days before or 7 days after the disbursement was credited to the student?s account. Cause and Effect The University?s internal controls for determining that a loan disbursement notification was sent timely for each disbursement made were not operating effectively. Specifically, the manual review and approval to submit the system-wide loan notification for all disbursements did not occur within the required timeframe. Failing to timely send a disbursement notification can cause a student or parent to not understand their right to cancel the loan and therefore can delay the ability of the right to cancel. Questioned Costs None identified. Sampling The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding in the Prior Year No. Recommendation We recommend the University enhance the precision of the controls over loan disbursements to ensure that all loan disbursements through the Federal Direct Student Loan Program have a written notification sent to the student and/or parents within the required timeline of within 30 days before and 7 days after the disbursement date. Views of Responsible Officials The University of Massachusetts acknowledges that some students did not receive their notifications informing them of the 30 day right-to-cancel for their Federal Direct Loans within the prescribed timeframe of no later than 30 days before, but no later than 7 days after the date of disbursement. The University has implemented an automated communication process with built in internal reviews that will ensure all borrowers are notified within the required timeframe.
2022-022: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services has an insufficient governance structure to manage and maintain its information security program in accordance with the Commonwealth's Information Security Standard, SEC 501 (Security Standard). Specifically, Social Services does not assess information security requirements for its information technology (IT) projects and prioritize information security and IT resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. Social Services uses numerous IT systems to carry out its mission and provide essential services to the public. The Security Standard, Section 2.4.2, requires the agency head to maintain an information security program that is sufficient to protect the agency's IT systems and to ensure the information security program is documented and effectively communicated. We communicated the internal control weaknesses to management in a separate document marked Freedom of Information Act (FOIAE) under ? 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The internal control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation or prioritizing information security within the IT environment. Not prioritizing IT resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. Additionally, not dedicating the necessary IT resources to information security has hindered Social Services' ability to remediate findings from management recommendations issued throughout prior audits consistently and timely and bring the information security program in compliance with the Security Standard. Because of the scope of this matter, we consider it to be a material weakness in internal control. Social Services should evaluate the most efficient and effective method to bring its IT and security program into compliance with the Security Standard. Social Services should also evaluate its IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the internal control deficiencies discussed in the communication marked FOIAE. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-024: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Personnel Security; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses found during an audit of IT general controls. The audit performed by an external consultant during the period April 1, 2019, through March 31, 2020, resulted in 71 individual control weaknesses out of 100 controls tested, which the consultant grouped in ten findings. As of the end of fiscal year 2022, Medical Assistance Services resolved one of the ten findings and continues to make progress with nine remaining findings, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Noncompliance with the required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening the agency's ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to staffing turnover and shortages as well as organizational changes that affected some of its processes. Medical Assistance Services updated its corrective action plan in June 2022, stating corrective actions are still ongoing for all nine findings and estimates it will complete corrective action for eight of the findings by the end of calendar year 2022 and the last finding by June 2023. Medical Assistance Services should continue to dedicate the necessary resources to ensure timely completion of its corrective action plans and to comply with the Security Standard. These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-029: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. Since the prior audit, Social Services has not remediated any of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires implementing certain internal controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services cannot ensure adequate protection of its sensitive and mission- critical data without configuring its sensitive web application in accordance with the Security Standard. Lacking or insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Social Services prioritization of other projects also contributed to the weaknesses persisting. Social Services should dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Implementing required controls will help to ensure Social Services secures the web application to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-030: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning; Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. Since we first issued this finding during the fiscal year 2018 audit, Social Services remediated some risk management and contingency planning issues. However, Social Services continues to not: ? accurately verify and validate data and system sensitivity ratings; ? create risk assessments for 50 percent of its sensitive systems; ? create system security plans for 52 percent of its sensitive systems; ? perform annual reviews for 99 percent of its existing risk assessment documentation; ? perform annual reviews for 74 percent of its existing system security plan documentation; and ? implement corrective actions identified in risk assessments. We communicated the details of these weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Due to the magnitude of the project, Social Services has not yet remediated all the weaknesses. Additionally, the requirements documented in the policy and the process documented in the procedure do not align, which contributed to Social Services not consistently completing risk management documentation due to conflicting roles and responsibilities. Without implementing a formal and effective IT risk management program, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should prioritize and dedicate the necessary resources to remediate the weaknesses discussed in the communication marked FOIAE in accordance with the requirements in the Security Standard. Completing its corrective action plan will help to ensure the confidentiality, integrity, and availability of the agency's sensitive systems and mission-essential functions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-052: Continue Improving IT Change and Configuration Management Process Applicable to: Department of Social Services Prior Year Finding Number: 2021-049; 2020-044; 2019-038 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its IT change and configuration management process to align with the Security Standard. Change management is a key control to evaluate, approve, and verify configuration changes to security components. Two weaknesses remain since our last review, which we communicated to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Social Services Change Management Process Guide details the process Social Services follows to manage changes but does not include all the required elements, which contributed to the weaknesses remaining. Additionally, the change request form does not have the necessary fields to document the required elements. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Without doing such, Social Services cannot assure itself that it is reducing unnecessary risk to the confidentiality, integrity, and availability to its information systems and data. Social Services should resolve the remaining two weaknesses discussed in the communication marked FOIAE in accordance with the Security Standard. Continuing to improve Social Services' IT change and configuration management process will decrease the risk of unauthorized modifications to sensitive systems and help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-057: Improve Timely Removal of Critical System Access Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2021-037; 2020-049; 2019-024; 2018-040; 2017-016 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services did not remove access to the claims processing module or the eligibility system timely for individuals who separated from the agency and no longer needed access. For one out of eight (12.5%) users, Medical Assistance Services did not disable system access in the claims processing module within 24 hours of separation. The user retained their system access for 11 days after separation. For three out of 25 (12%) users, Medical Assistance Services did not disable system access in the eligibility system within 24 hours of separation. These three users were contract employees and retained their access to the system between 104 and 123 days after separation. Medical Assistance Services' Access Control Policy requires that "all user accounts must be disabled immediately upon separation or within 24 hours upon receipt by the Office of Compliance and Security" (Compliance and Security). Failing to disable access timely for web- based mission-critical systems threatens the data integrity of the systems. If separated users retain access to the claims processing module or the eligibility system, users are potentially able to view, copy, and edit sensitive information. There are several factors contributing to this issue. First, Medical Assistance Services' internal policy is not in compliance with the Security Standard. The Security Standard requires agencies disable access within 24 hours of separation, not within 24 hours of receipt of notification. Additionally, supervisors are not communicating information on separated employees timely. A separating employee's supervisor must initiate an exit clearance workflow for the system to automatically notify Compliance and Security for removal of system access. For the user of the claims processing module, the supervisor requested access termination more than 24 hours after the employee's separation. Finally, for the three users of the eligibility system, Compliance and Security received the access termination request timely but did not terminate access for more than 24 hours after receipt. In June 2022, Medical Assistance Services implemented several organizational changes, including dissolving Compliance and Security. The responsibility for system access management moved to the division responsible for the system and its applicable business function. Medical Assistance Services is currently updating its internal Access Control policy to ensure it is consistent with the Security Standard and organizational updates. Medical Assistance Services expects to complete the policy and process updates in December 2022. Medical Assistance Services should also train and educate supervisors on the importance of timely notification of separated employees. Finally, Medical Assistance Services should ensure compliance with the Security Standard by removing user access as required. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-059: Monitor Internal Controls to Ensure Timely Removal of System Access Applicable to: Department of Social Services Prior Year Finding Number: 2021-038; 2021-027; 2020-025; 2019-027; 2018-042 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Personnel Security ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services did not comply with the Security Standard requirements for removing system access for separated employees. For 13 of the 26 (50%) separations tested from fiscal year 2022, Social Services did not remove system access within 24 hours following each employee's separation date. Untimely removal of access ranged between two and 290 days after each employee's separation date. Section PS-4 of the Security Standard requires an organization to disable information system access within 24 hours of employment termination. To comply with the Security Standard, Social Services created a policy in Section 2.9 of its State/Local Security Officers Procedures Manual (Manual) that requires supervisors to complete the State Employee Separation and Transfer Checklist (Separation Checklist) at least 48 hours in advance of the employee's separation and submit it to the Division Security Officer. The Division Security Officer must then remove the separated employee from Social Services' access management system, which controls access to its internal systems, within 24 hours following the employee's separation date. Upon completion, the Division Security Officer is responsible for submitting the Separation Checklist to other Divisions, such as the Division of Human Resources (Human Resources) and the Central Security Office (Central Security), to make them aware of the separation. Social Services does not appear to monitor compliance with internal policies surrounding access removal for separated employees. Of the 13 employees with access removed more than 24 hours after their separation dates: ? We noted four instances where Social Services was unable to provide the Separation Checklist. As a result, Social Services was unable to demonstrate compliance with its internal policies surrounding access removal for separated employees. ? Of the remaining nine employees with completed Separation Checklists, we noted nine instances of untimely or inaccurate supervisor sign-offs. Specifically, there were seven instances where the supervisor did not submit the Separation Checklist to the Division Security Officer at least 48 hours in advance of the employee's date of separation and two instances where the supervisor did not properly sign off and date the Separation Checklist. Social Services administers numerous public assistance programs that collect personally identifiable information and other protected information from beneficiaries. Social Services places its data and reputation at risk by not removing access timely. Additionally, Social Services could incur a potential financial liability should its information become compromised. The Security Standard states that the Agency Head is responsible for security of the agency's IT systems and data. Since Human Resources, Central Security, and the Division Security Officers share ownership of the employee separation and access removal processes, Social Services' Executive Team should identify which division in the agency should be responsible for monitoring compliance with internal policies surrounding access removal for separated employees. Social Services' Executive Team should periodically review the monitoring results and take enforcement actions, as necessary, if the agency is not compliant. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-060: Upgrade End-of-Life Technology Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services uses end-of-life technologies in its IT environment and maintains technologies that support mission-essential data on IT systems that its vendors no longer support. We communicated internal control weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard prohibits using software that is end-of-life and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services' information systems and data. Social Services does not assign an individual or team with the responsibility to track end- of-life software dates and does not have a formal process to ensure that it upgrades software versions prior to the end-of-life date, which caused the end-of-life software to remain in the environment. Social Services use of the end-of-life software increases the risk that known vulnerabilities will persist in the system without the potential for patching or mitigation. These unpatched vulnerabilities increase the risk of successful cyberattack, exploit, and data breach by malicious parties. Further, vendors do not offer operational and technical support for end-of-life or end-of-support technology, which affects data availability by increasing the difficulty of restoring system functionality if a technical failure occurs. Social Services should dedicate the necessary resources to evaluate and implement the internal controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Minimizing the use of end-of-life software will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-064: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process for its case management system. Social Services' case management system authorized over $10 billion in benefit payments from various public assistance programs to beneficiaries during fiscal year 2022. We communicated this weakness to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions. During the fiscal year, Social Services finalized and documented policies with retention requirements. However, Social Services has not developed, documented, and implemented a policy, procedure, and process to operationalize the record retention requirements needed. Federal regulations require different record retention requirements for different federal programs. Additionally, the Virginia Public Records Act (? 42.1-91 of the Code of Virginia) requires each agency to be responsible for ensuring that it preserves, maintains, and makes accessible public-facing records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Further, the Security Standard, Section CP-9-COV, requires the agency implement backup and restoration plans for every IT system identified as sensitive relative to availability that address the retention of the data in accordance with the records retention policy. Without developing, documenting, and implementing a policy, procedure, and process to operationalize record retention requirements, Social Services increases data risk and increases potential exposure to fines, penalties, or other legal consequences. Additionally, Social Services may cause the Commonwealth to spend additional resources to maintain, back up, and protect the information. Social Services should develop and implement a records retention policy and procedure that defines its requirements and processes to ensure that consistent record retention processes can be operationalized across business divisions to ensure compliance with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-066: Conduct Audits of Agency Sensitive Systems Timely Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 VITA's Centralized IT Security Audit Service (Audit Services) conducts IT security audits for contracted agencies. The Commonwealth's Information Technology Security Audit Standard, SEC 502 (Security Audit Standard), Section 2.1, requires agencies to complete security audits for each sensitive system every three years from the last audit completion date. Based on our review of audit completion dates provided by Audit Services, we determined the following: ? During fiscal year 2022, Audit Services completed four of six agency IT security audits after the three-year audit deadline. ? As of June 30, 2022, Audit Services is currently engaged, or has not started, ten agency IT security audits that are past the three-year audit requirement. When an agency contracts with Audit Services, the agency head or designee signs a Memorandum of Understanding (MOU) which outlines the scope of work and pricing. It is the agency's responsibility to ensure the MOU includes all sensitive systems requiring a security audit. A properly defined MOU allows Audit Services to properly price and schedule the security audit. Audit Services audits all the systems in scope for an agency at the same time and issues one audit report covering all systems in scope per the MOU. Audit Services should consider adding information to the MOU related to audit deadlines or planned timeframe for the audit. This added communication will ensure all parties understand when Audit Services plans to complete the audits. Additionally, more information regarding audit timing will allow agencies to determine if they need to obtain a separate audit for specific systems to ensure those systems remain compliant with the Security Audit Standard between the date of the MOU and the anticipated deadline set by Audit Services. Of the four audits Audit Services completed late during fiscal year 2022, two of the delays are due to the agencies requesting postponements. Additionally, of the ten audits that were already late as of June 30, 2022, two are due to agency-requested postponements. The remaining late audits are primarily due to resource constraints within Audit Services. Audit Services should regularly monitor its audit workplan to ensure audit staff complete all IT security audits by the required deadlines. Additionally, Audit Services should evaluate its staffing levels and assess if VITA should contract with an outside audit firm to aid in completing IT security audits. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-090: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(a) Known Questioned Costs: $0 Medical Assistance Services does not have a formal and consistent process for maintaining oversight for three of its IT third-party service providers (providers) that manage and support the Medicaid management system. As a result of an informal and inconsistent process, Medical Assistance Services did not verify or implement three controls required by the Hosted Environment Security Standard. We communicated the three weaknesses to management in a separate document marked FOIAE under ? 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. Without a formal and consistent process to maintain oversight of its providers, Medical Assistance Services cannot validate whether its providers implement the security controls that meet the requirements in the Hosted Environment Security Standard to protect the agency's sensitive and mission-critical data. While Medical Assistance Services has a formal IT Third Party and Vendor Compliance Management Policy, effective as of December 31, 2021, the agency experienced turnover in its ISO position in June 2022 before the development of a formal procedure. As a result, Medical Assistance Services did not consistently maintain oversight of its providers in accordance with the Hosted Environment Security Standard. Medical Assistance Services should dedicate the necessary resources to develop a formal procedure to maintain oversight of its providers in accordance with its policy and the Hosted Environment Security Standard. Medical Assistance Services should also dedicate the necessary resources to implement and consistently perform the formal oversight process, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-100: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 (COVID-19) Federal Award Number and Year: 2205VA5MAP - 2022 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR ? 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2022, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Security Standard. The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through the ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard Section: SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies' operations. Our audits at various agencies for fiscal year 2022 found critical and highly important security patches that were past the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of successful cyberattack, exploit, and data breach by malicious parties. Additionally, the Security Standard requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard Section: AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2022 found that agencies rely on the ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Certain agencies were unable to obtain access to the audit log information during fiscal year 2022, and thus were not able to comply with the Security Standard requirements related to audit log monitoring. Although the supplier was performing audit logging and monitoring, only a select few agencies have access to the monitoring tool while the supplier is pilot testing the tool. The Commonwealth's risk associated with data confidentiality, integrity and availability increases with agencies not being able to review and monitor their individual audit logs. During fiscal year 2022, VITA and the Multisource Service Integrator (MSI) evaluated the current service level measurements to ensure they align with the Commonwealth's needs. As of December 2022, VITA and the MSI are implementing changes to the service level related to security and vulnerability patching. The changes to this service level include establishing a Common Vulnerabilities and Exposures (CVE) threshold. The new security and vulnerability patching service level will require the ITISP suppliers to install any patch with a CVE score above the threshold within 90 days. VITA continues to work with the managed security supplier to address the agencies' inability to access the audit log information. The supplier replaced the original security incident and event management system with a new managed detection and response (MDR) platform. Currently, only a small number of agencies are piloting the new MDR system. VITA should document the rationale for all changes to the service levels, including the basis for the CVE score threshold selected, and continually reevaluate the service levels as risks change. To ensure all agencies that rely on the ITISP services can comply with the Security Standard, VITA should ensure ITISP suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk per the Security Standard. If VITA determines an ITISP supplier is not meeting a contractual requirement that may have a Security Standard implication, VITA should communicate with the affected agencies and provide guidance on compensating controls and processes the agencies should implement to reduce risk while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2022-003 Department of Agriculture Federal Financial Assistance Listing #10.766 Communities Facilities Loans and Grants Cluster Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Within the amended letter of conditions dated August 20, 2014, for the USDA financing, annual audited financial statements are required to be submitted to USDA. In addition, the fiscal year operating budget must be submitted and approved by USDA. Condition: The fiscal year 2021 audit report was either not submitted to USDA or submitted to USDA with no retained documentation to support when the report was submitted. In addition, the FY2023 operating budget was not submitted to USDA in the period under audit. Cause: The Medical Center did not have an internal control process in place to ensure timely submission of the required reports to USDA and the Medical Center did not retain documentation to support when the fiscal year 2021 audit report was submitted to USDA. Effect: The required reports may not have been submitted to USDA. Questioned Costs: None reported. Context/Sampling: Sampling was not used. Repeat Finding from Prior Years: No Recommendation: We recommend implementing a process to ensure timely submission of the annual audit report and operating budget and retain documentation to support when the report and budget are submitted to USDA. Views of Responsible Officials: Management agrees with the finding.
2022-004 Department of Agriculture Federal Financial Assistance Listing #10.766 Communities Facilities Loans and Grants Cluster Special Tests and Provisions Material Weakness in Internal Control over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. The May 13,2014 letter of conditions with USDA state the Medical Center must set aside a reserve fund at a rate of 10% of the annual payment until the reserve account reaches the amount of one full year?s annual payment. The intercreditor and parity agreement for Series 2021 Gross Revenue Medical Center Refunding Note subjects the USDA Series 2016 financing to the same financial covenant compliance requirements relating to days cash on hand and debt service. Condition: No secondary level of review is being performed over the reserve fund balance as compared to the reserve fund requirements, or the days cash on hand and debt service compared to the minimum requirements. Cause: The Medical Center did not have an internal control process in place to ensure a secondary level of review is being performed on the required minimums for the reserve account and financial covenants. Effect: The Medical Center could be in violation of the required minimums if management is not monitoring compliance. Questioned Costs: None reported Context/Sampling: Sampling was not used. Repeat Finding from Prior Year: No Recommendation: We recommend management implement a process and controls ensuring a secondary level of review is completed over the reserve account and the required financial covenant minimums. Views of Responsible Officials: Management agrees with the finding.
Finding 2022-003 Department of Agriculture Federal Financial Assistance Listing #10.766 Communities Facilities Loans and Grants Cluster Reporting Significant Deficiency in Internal Control over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over federal awards that provides reasonable assurance that the Health Center is managing the federal awards in compliance with federal statutes, regulations and terms and conditions of the federal award. Section VI ? Conditions Required After Loan Closing in the Letter of Conditions dated November 1, 2019, for the USDA loan states that the audited financial statements must be provided to USDA within 150 days of year-end. In addition, the operating budget must be submitted to USDA within 30 days prior to the fiscal year-end. Condition: The Health Center?s FY2023 operating budget and prior year audited financial statements were not submitted to USDA within the submission timeframe. Cause: The Health Center?s FY2023 operating budget was not approved prior to the June 1, 2023, deadline and the prior year audited financial statements were not submitted timely. The audited financial statements were approved at the November 2021 board meeting, but not submitted until February 2022. Effect: The required reports are submitted outside of the time frame contained in the Letter of Conditions. Questioned Costs: None reported Context/Sampling: Sampling was not used Repeat Finding from Prior Year: No Recommendation: Management should implement processes and controls relating to the reporting requirements to comply with the Letter of Conditions Response: Management agrees with the finding.
Finding 2022-003 Department of Agriculture Federal Financial Assistance Listing #10.766 Communities Facilities Loans and Grants Cluster Reporting Significant Deficiency in Internal Control over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over federal awards that provides reasonable assurance that the Health Center is managing the federal awards in compliance with federal statutes, regulations and terms and conditions of the federal award. Section VI ? Conditions Required After Loan Closing in the Letter of Conditions dated November 1, 2019, for the USDA loan states that the audited financial statements must be provided to USDA within 150 days of year-end. In addition, the operating budget must be submitted to USDA within 30 days prior to the fiscal year-end. Condition: The Health Center?s FY2023 operating budget and prior year audited financial statements were not submitted to USDA within the submission timeframe. Cause: The Health Center?s FY2023 operating budget was not approved prior to the June 1, 2023, deadline and the prior year audited financial statements were not submitted timely. The audited financial statements were approved at the November 2021 board meeting, but not submitted until February 2022. Effect: The required reports are submitted outside of the time frame contained in the Letter of Conditions. Questioned Costs: None reported Context/Sampling: Sampling was not used Repeat Finding from Prior Year: No Recommendation: Management should implement processes and controls relating to the reporting requirements to comply with the Letter of Conditions Response: Management agrees with the finding.
Finding 2022-003 Department of Agriculture Federal Financial Assistance Listing #10.766 Communities Facilities Loans and Grants Cluster Reporting Significant Deficiency in Internal Control over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over federal awards that provides reasonable assurance that the Health Center is managing the federal awards in compliance with federal statutes, regulations and terms and conditions of the federal award. Section VI ? Conditions Required After Loan Closing in the Letter of Conditions dated November 1, 2019, for the USDA loan states that the audited financial statements must be provided to USDA within 150 days of year-end. In addition, the operating budget must be submitted to USDA within 30 days prior to the fiscal year-end. Condition: The Health Center?s FY2023 operating budget and prior year audited financial statements were not submitted to USDA within the submission timeframe. Cause: The Health Center?s FY2023 operating budget was not approved prior to the June 1, 2023, deadline and the prior year audited financial statements were not submitted timely. The audited financial statements were approved at the November 2021 board meeting, but not submitted until February 2022. Effect: The required reports are submitted outside of the time frame contained in the Letter of Conditions. Questioned Costs: None reported Context/Sampling: Sampling was not used Repeat Finding from Prior Year: No Recommendation: Management should implement processes and controls relating to the reporting requirements to comply with the Letter of Conditions Response: Management agrees with the finding.
Criteria There are three components to reporting for HEERF: 1) public reporting on the (a)(1) Student Aid Portion; 2) public reporting on the (a)(1) Institutional Portion (a)(2) and (a)(3) subprograms (Quarterly Reporting Form), as applicable; and 3) the annual report. The CARES Act 18004(e) and the CRRSAA 314(e) require an institution receiving funds under HEERF I and HEERF II to submit a report to the secretary, at such time in such a manner as the secretary may require. While ARP does not explicitly identify procedures by which institutions must report on their uses of HEERF grant funds, ED exercises this reporting authority under 2 CFR section 200.328 and 2 CFR section 200.329. Annual Reporting (all HEERF Grantees) ED required an annual report from HEERF grantees in April 2022 that included reporting uses of HEERF I CARES Act funds, HEERF II CRRSAA funds, and HEERF III ARP funds for the 2021 calendar year. Quarterly Public Reporting for (a)(1) Institutional Portion, (a)(2), and (a)(3) Funds The CARES, CRRSAA, and ARP institutional quarterly portion reporting requirements involve publicly posting completed forms on the institution?s website. The forms must be conspicuously posted on the institution?s primary website on the same page the reports of the IHE?s activities as to the emergency financial aid grants to students (Student Aid Portion) are posted. IHEs must post this quarterly report form no later than 10 days after the end of each calendar quarter. Quarterly Public Reporting for (a)(1) Student Aid Portion ED requires institutions that received Student Aid Portion awards under CARES Act, CRRSAA and ARP to publicly post certain information on their website. Under the requirements to post student aid public reporting for CRRSAA and ARP, there is a requirement to include certain information on their website. Institutions must publicly post their report as soon as possible, but no later than 30 days after the publication of the notice or 30 days after the date ED first obligated funds under HEERF I, II, or III to the institution for Emergency Financial Aid Grants to Students, whichever comes later. The report must be updated not later than 10 days after the end of each calendar quarter. Further, in accordance with 2 CFR 200.303(a), non-federal entities must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition During our testwork over institutional reporting, it was noted that for one of two quarterly required instances of reporting selected for testing was submitted untimely. This quarterly update was provided 23 days after the date it was required to be updated. Additionally, the required reporting included the University?s final disbursements was not appropriately marked as the final report. Additionally, internal controls were not effective as evidence of review of the reporting prior to posting on the University?s website was not retained by management. As such we could not see evidence the management review control was operating effectively. Cause The University?s HEERF reporting process did not include a requirement to maintain the review documentation and did not operate at a level of precision sufficient to ensure timely and accurate reporting. Effect If appropriate controls are not designed and operating effectively over the HEERF reporting process, HEERF expenditures reported on the University?s website and to U.S. Department of Education may be incomplete, inaccurate, or not posted within the timeframe required resulting in non-compliance. Questioned Costs None noted. Recommendation We recommend that the University implement a implement a requirement to maintain the review documentation and incorporate a detailed review of the various fields of the form to ensure accuracy as well as to ensure the HEERF reporting is completed timely.
Criteria There are three components to reporting for HEERF: 1) public reporting on the (a)(1) Student Aid Portion; 2) public reporting on the (a)(1) Institutional Portion (a)(2) and (a)(3) subprograms (Quarterly Reporting Form), as applicable; and 3) the annual report. The CARES Act 18004(e) and the CRRSAA 314(e) require an institution receiving funds under HEERF I and HEERF II to submit a report to the secretary, at such time in such a manner as the secretary may require. While ARP does not explicitly identify procedures by which institutions must report on their uses of HEERF grant funds, ED exercises this reporting authority under 2 CFR section 200.328 and 2 CFR section 200.329. Annual Reporting (all HEERF Grantees) ED required an annual report from HEERF grantees in April 2022 that included reporting uses of HEERF I CARES Act funds, HEERF II CRRSAA funds, and HEERF III ARP funds for the 2021 calendar year. Quarterly Public Reporting for (a)(1) Institutional Portion, (a)(2), and (a)(3) Funds The CARES, CRRSAA, and ARP institutional quarterly portion reporting requirements involve publicly posting completed forms on the institution?s website. The forms must be conspicuously posted on the institution?s primary website on the same page the reports of the IHE?s activities as to the emergency financial aid grants to students (Student Aid Portion) are posted. IHEs must post this quarterly report form no later than 10 days after the end of each calendar quarter. Quarterly Public Reporting for (a)(1) Student Aid Portion ED requires institutions that received Student Aid Portion awards under CARES Act, CRRSAA and ARP to publicly post certain information on their website. Under the requirements to post student aid public reporting for CRRSAA and ARP, there is a requirement to include certain information on their website. Institutions must publicly post their report as soon as possible, but no later than 30 days after the publication of the notice or 30 days after the date ED first obligated funds under HEERF I, II, or III to the institution for Emergency Financial Aid Grants to Students, whichever comes later. The report must be updated not later than 10 days after the end of each calendar quarter. Further, in accordance with 2 CFR 200.303(a), non-federal entities must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition During our testwork over institutional reporting, it was noted that for one of two quarterly required instances of reporting selected for testing was submitted untimely. This quarterly update was provided 23 days after the date it was required to be updated. Additionally, the required reporting included the University?s final disbursements was not appropriately marked as the final report. Additionally, internal controls were not effective as evidence of review of the reporting prior to posting on the University?s website was not retained by management. As such we could not see evidence the management review control was operating effectively. Cause The University?s HEERF reporting process did not include a requirement to maintain the review documentation and did not operate at a level of precision sufficient to ensure timely and accurate reporting. Effect If appropriate controls are not designed and operating effectively over the HEERF reporting process, HEERF expenditures reported on the University?s website and to U.S. Department of Education may be incomplete, inaccurate, or not posted within the timeframe required resulting in non-compliance. Questioned Costs None noted. Recommendation We recommend that the University implement a implement a requirement to maintain the review documentation and incorporate a detailed review of the various fields of the form to ensure accuracy as well as to ensure the HEERF reporting is completed timely.
U.S. Department of Labor Federal Financial Assistance Listing 17.258/17.259/17.278 WIOA Cluster Activities Allowed or Unallowed Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria ? 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. 2 CFR 200.403 outlines factors affecting the allowability of costs including that these costs ?be necessary and reasonable for the performance of the Federal award and be allocable thereto under these principles? and ?be adequately documented?. Condition ? A portion of the County?s expenditures identified as eligible and claimed under the WIOA Cluster program were disallowed by the United States Department of Labor due the lack of appropriate documentation justifying specific costs charged to the program related to one vendor ? Garcia Professional Services, LLC. Also, the local board?s contract entered into with Garcia Professional Solutions, LLC. did not adequately address the required contract terms as follows: 1. Total dollar value of the contract to justify procurement method utilized. 2. Terms for payment to ensure payments are only made for verified services received and adequately documented. 3. Contract provisions stipulated in Appendix II to Part 200 of the Uniform Guidance, including Equal Employment Opportunity, Rights to Inventions Made Under a Contract or Agreement, Debarment and Suspension, and Byrd Anti-Lobbying Amendment. Cause ? The County made payments based on the local board?s contract and did not have an internal control process in place to ensure allowable activities or unallowed requirements were met. Effect ? Ineligible expenditures were reported under the program. Questioned Costs ? The total amount reported that should have been excluded was $84,000. Context/Sampling ? An initial nonstatistical sample of 7 expenditures were selected for testing, which accounted for $384,133 of $1,239,983 program expenditures. There was one error identified for expenditures without adequate documentation related to Garcia Professional Solutions, LLC. It was determined that there were 12 payments to Garcia Professional Solutions, LLC. in the amount of $84,000 that were charged to the program. Repeat Finding from Prior Years ? No. Recommendation ? We recommend the County implement a control process which includes the applicable activities allowable or unallowed requirements. View of Responsible Officials ? Johnson County disagrees with the underlying premises of this finding. The expenditures referred to above were expenditures of the East Central Iowa Workforce Development Board (ECIWDB) and not direct expenses of the County. The ECIWDB contracted with Johnson County to provide fiscal agent services. The ECIWDB then entered into a contract with Garcia Professional Solutions, LLC (?GPS?) to provide administrative support services for the Board. Iowa Workforce Development did not provide adequate guidance to ECIWDB as to the DOL-required terms and the terms of that services contract between ECIWDB and GPS did not contain any standards of documentation which DOL later claimed applied to said contract. The County had no input into the contract between the ECIWDB and GPS, nor was the County a party to said contract. Any alleged deficiencies within that contract between the ECIWDB and GPS are solely the responsibility of the ECIWDB Board and/or Iowa Workforce Development. In our fiscal agent role, the County was obliged to honor payment requests submitted to the Board; in that regard we had to make payments to GPS provided those payment requests were invoiced to ECIWDB consistent with the ECIWDB-GPS contract, which they were.
U.S. Department of Labor Federal Financial Assistance Listing 17.258/17.259/17.278 WIOA Cluster Subrecipient Monitoring Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria ? 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Subrecipient monitoring requirements are contained in 2 CFR 200.331 through 2 CFR 200.333 and include requirements to identify the award and applicable requirements to the subrecipient and monitor the activities of the subrecipient. Condition ? Iowa Workforce Development did not formally communicate subrecipient monitoring requirements to the County. Consequently, the County did not formally communicate the required information to the subrecipient. No subrecipient agreement was executed. In addition, no monitoring activities were documented. Cause ? The County did not have an internal control process in place to ensure subrecipient monitoring requirements were met. Effect ? Without the proper communication of applicable requirements and monitoring of the subrecipient, there is a possibility that federal statutes, regulations, and the terms and conditions of the federal award were not complied with. Questioned Costs ? None reported. Context/Sampling ? $1,120,541 was passed through to one subrecipient during the year ended June 30, 2022. Repeat Finding from Prior Years ? No. Recommendation ? We recommend the County implement a control process which includes the applicable subrecipient monitoring requirements. View of Responsible Officials ? Johnson County disagrees with the underlying premises of this finding. This finding is due in part to the fiscal agent agreement with Iowa Workforce Development (?IWD?) which does not state that subrecipient monitoring has to be done. Recently, IWD received a finding from the Department of Labor stating that the template fiscal agent agreements imposed upon fiscal agents by IWD improperly placed liability of disallowed costs onto the fiscal agents. According to DOL, IWD?s form of fiscal agent contract was incorrect, i.e., the liability was to stay with the local CEOs. In the wake of the finding, IWD is reissuing the contracts out to the regions to create compliant subrecipient entities within each, and then new fiscal agent agreements will be issued. Additionally, Johnson County will be ending it fiscal agent agreement, and no longer continue to be the fiscal agent as of June 30, 2023.
U.S. Department of Labor Federal Financial Assistance Listing 17.258/17.259/17.278 WIOA Cluster Activities Allowed or Unallowed Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria ? 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. 2 CFR 200.403 outlines factors affecting the allowability of costs including that these costs ?be necessary and reasonable for the performance of the Federal award and be allocable thereto under these principles? and ?be adequately documented?. Condition ? A portion of the County?s expenditures identified as eligible and claimed under the WIOA Cluster program were disallowed by the United States Department of Labor due the lack of appropriate documentation justifying specific costs charged to the program related to one vendor ? Garcia Professional Services, LLC. Also, the local board?s contract entered into with Garcia Professional Solutions, LLC. did not adequately address the required contract terms as follows: 1. Total dollar value of the contract to justify procurement method utilized. 2. Terms for payment to ensure payments are only made for verified services received and adequately documented. 3. Contract provisions stipulated in Appendix II to Part 200 of the Uniform Guidance, including Equal Employment Opportunity, Rights to Inventions Made Under a Contract or Agreement, Debarment and Suspension, and Byrd Anti-Lobbying Amendment. Cause ? The County made payments based on the local board?s contract and did not have an internal control process in place to ensure allowable activities or unallowed requirements were met. Effect ? Ineligible expenditures were reported under the program. Questioned Costs ? The total amount reported that should have been excluded was $84,000. Context/Sampling ? An initial nonstatistical sample of 7 expenditures were selected for testing, which accounted for $384,133 of $1,239,983 program expenditures. There was one error identified for expenditures without adequate documentation related to Garcia Professional Solutions, LLC. It was determined that there were 12 payments to Garcia Professional Solutions, LLC. in the amount of $84,000 that were charged to the program. Repeat Finding from Prior Years ? No. Recommendation ? We recommend the County implement a control process which includes the applicable activities allowable or unallowed requirements. View of Responsible Officials ? Johnson County disagrees with the underlying premises of this finding. The expenditures referred to above were expenditures of the East Central Iowa Workforce Development Board (ECIWDB) and not direct expenses of the County. The ECIWDB contracted with Johnson County to provide fiscal agent services. The ECIWDB then entered into a contract with Garcia Professional Solutions, LLC (?GPS?) to provide administrative support services for the Board. Iowa Workforce Development did not provide adequate guidance to ECIWDB as to the DOL-required terms and the terms of that services contract between ECIWDB and GPS did not contain any standards of documentation which DOL later claimed applied to said contract. The County had no input into the contract between the ECIWDB and GPS, nor was the County a party to said contract. Any alleged deficiencies within that contract between the ECIWDB and GPS are solely the responsibility of the ECIWDB Board and/or Iowa Workforce Development. In our fiscal agent role, the County was obliged to honor payment requests submitted to the Board; in that regard we had to make payments to GPS provided those payment requests were invoiced to ECIWDB consistent with the ECIWDB-GPS contract, which they were.
U.S. Department of Labor Federal Financial Assistance Listing 17.258/17.259/17.278 WIOA Cluster Subrecipient Monitoring Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria ? 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Subrecipient monitoring requirements are contained in 2 CFR 200.331 through 2 CFR 200.333 and include requirements to identify the award and applicable requirements to the subrecipient and monitor the activities of the subrecipient. Condition ? Iowa Workforce Development did not formally communicate subrecipient monitoring requirements to the County. Consequently, the County did not formally communicate the required information to the subrecipient. No subrecipient agreement was executed. In addition, no monitoring activities were documented. Cause ? The County did not have an internal control process in place to ensure subrecipient monitoring requirements were met. Effect ? Without the proper communication of applicable requirements and monitoring of the subrecipient, there is a possibility that federal statutes, regulations, and the terms and conditions of the federal award were not complied with. Questioned Costs ? None reported. Context/Sampling ? $1,120,541 was passed through to one subrecipient during the year ended June 30, 2022. Repeat Finding from Prior Years ? No. Recommendation ? We recommend the County implement a control process which includes the applicable subrecipient monitoring requirements. View of Responsible Officials ? Johnson County disagrees with the underlying premises of this finding. This finding is due in part to the fiscal agent agreement with Iowa Workforce Development (?IWD?) which does not state that subrecipient monitoring has to be done. Recently, IWD received a finding from the Department of Labor stating that the template fiscal agent agreements imposed upon fiscal agents by IWD improperly placed liability of disallowed costs onto the fiscal agents. According to DOL, IWD?s form of fiscal agent contract was incorrect, i.e., the liability was to stay with the local CEOs. In the wake of the finding, IWD is reissuing the contracts out to the regions to create compliant subrecipient entities within each, and then new fiscal agent agreements will be issued. Additionally, Johnson County will be ending it fiscal agent agreement, and no longer continue to be the fiscal agent as of June 30, 2023.
U.S. Department of Labor Federal Financial Assistance Listing 17.258/17.259/17.278 WIOA Cluster Activities Allowed or Unallowed Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria ? 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. 2 CFR 200.403 outlines factors affecting the allowability of costs including that these costs ?be necessary and reasonable for the performance of the Federal award and be allocable thereto under these principles? and ?be adequately documented?. Condition ? A portion of the County?s expenditures identified as eligible and claimed under the WIOA Cluster program were disallowed by the United States Department of Labor due the lack of appropriate documentation justifying specific costs charged to the program related to one vendor ? Garcia Professional Services, LLC. Also, the local board?s contract entered into with Garcia Professional Solutions, LLC. did not adequately address the required contract terms as follows: 1. Total dollar value of the contract to justify procurement method utilized. 2. Terms for payment to ensure payments are only made for verified services received and adequately documented. 3. Contract provisions stipulated in Appendix II to Part 200 of the Uniform Guidance, including Equal Employment Opportunity, Rights to Inventions Made Under a Contract or Agreement, Debarment and Suspension, and Byrd Anti-Lobbying Amendment. Cause ? The County made payments based on the local board?s contract and did not have an internal control process in place to ensure allowable activities or unallowed requirements were met. Effect ? Ineligible expenditures were reported under the program. Questioned Costs ? The total amount reported that should have been excluded was $84,000. Context/Sampling ? An initial nonstatistical sample of 7 expenditures were selected for testing, which accounted for $384,133 of $1,239,983 program expenditures. There was one error identified for expenditures without adequate documentation related to Garcia Professional Solutions, LLC. It was determined that there were 12 payments to Garcia Professional Solutions, LLC. in the amount of $84,000 that were charged to the program. Repeat Finding from Prior Years ? No. Recommendation ? We recommend the County implement a control process which includes the applicable activities allowable or unallowed requirements. View of Responsible Officials ? Johnson County disagrees with the underlying premises of this finding. The expenditures referred to above were expenditures of the East Central Iowa Workforce Development Board (ECIWDB) and not direct expenses of the County. The ECIWDB contracted with Johnson County to provide fiscal agent services. The ECIWDB then entered into a contract with Garcia Professional Solutions, LLC (?GPS?) to provide administrative support services for the Board. Iowa Workforce Development did not provide adequate guidance to ECIWDB as to the DOL-required terms and the terms of that services contract between ECIWDB and GPS did not contain any standards of documentation which DOL later claimed applied to said contract. The County had no input into the contract between the ECIWDB and GPS, nor was the County a party to said contract. Any alleged deficiencies within that contract between the ECIWDB and GPS are solely the responsibility of the ECIWDB Board and/or Iowa Workforce Development. In our fiscal agent role, the County was obliged to honor payment requests submitted to the Board; in that regard we had to make payments to GPS provided those payment requests were invoiced to ECIWDB consistent with the ECIWDB-GPS contract, which they were.