The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-045 Payments for Non-Emergent Medical Transportation ClaimsPrior to July 2020, in 55 counties, the Department worked with various county offices to have them broker Non-Emergent Medical Transportation (NEMT) services for Medicaid recipients, including rides to and from Medicaid medical appointments, personal mileage reimbursement, and trip-related meals and lodging. For example, these counties arranged the rides with transportation providers, submitted the claims or had providers submit claims for reimbursement to the Department, and passed on reimbursements to providers as needed. For the remaining nine counties, the Department contracted with IntelliRide to serve as the NEMT broker for services in those areas. From July 1, 2020, to August 31, 2021, when the Department contracted with IntelliRide to be the statewide broker, most recipients throughout the state scheduled NEMT rides by contacting IntelliRide through its call center, website chat function, or smartphone applications. IntelliRide scheduled rides and assigned transportation providers to them, and had providers upload trip information into IntelliRide?s EcoLane transportation scheduling system. EcoLane maintains information related to recipients? requests for rides and provider trip information, such as the trip date and time, names of the recipient and driver, and scheduled pick-up and destination addresses. IntelliRide submitted claims through the Department?s interChange system (interChange) requesting payments for providers? NEMT services, paid providers for their services, and received reimbursement from the Department. In addition, the Department paid NEMT claims submitted directly by NEMT providers. In Fiscal Year 2021, from July 1, 2020, through February 28, 2021 (the audit period), the Department paid 362,110 claims for NEMT services totaling about $33.2 million, as shown in the following table. In September 2021, the Department plans to transition back to IntelliRide brokering services in nine counties, while the NEMT providers in the remaining counties will broker their own services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote What audit work was performed and how were the results measured? The purpose of the audit work was to determine whether the Department has ensured that NEMT claims adhere to the following federal and state requirements. ? NEMT trips were to be brokered through, and all claims submitted by, the statewide broker, Intelliride. According to state regulations and the Department?s NEMT Billing Manual, all NEMT trips during Fiscal Year 2021 had to be authorized by the statewide broker, IntelliRide [10 CCR 2505-10 8.014.7.A]. This means that each recipient?s NEMT ride request should have been sent to IntelliRide for approval or authorization before the trip, and any unauthorized trips should ?not be reimbursed or paid? [Billing Manual]. According to the Department, it allowed NEMT providers time to transition to working with IntelliRide because some providers were reluctant to join the statewide brokerage and the Department needed time to onboard providers. By Fall 2020, most providers should have been working with IntelliRide to schedule NEMT rides. The Department told us that six NEMT providers received its express permission to bypass IntelliRide to schedule rides and submit claims directly to the Department because the providers are unique, such as only serving recipients with disabilities or receiving federal grant funding to provide NEMT. To assess whether IntelliRide brokered most NEMT services in the State and submitted the related claims in line with regulations and its contract, we reviewed the Department?s aggregate data for the 128,998 NEMT claims paid from December 2020 through February 2021. ? The Department must pay claims based on accurate service rates and trip mileage. Non-taxi NEMT services, such as wheelchair and mobility vehicle services, have base rates and mileage rates set by the Department. IntelliRide tracks the mileage of each NEMT trip in EcoLane and submits mileage claims to the Department?s interChange system. The Public Utilities Commission (PUC) sets the rate for each permitted taxi provider, which generally includes a rate for the first trip mile and a different rate for each additional mile. According to the Department?s NEMT Billing Manual and NEMT Rate Schedule for Fiscal Year 2021, taxi claims should have been paid at the rate set by the PUC. For example, if a taxi company?s PUC rate was $4 for the first mile and $2 for each additional mile, the Department should have paid $6 for a two-mile NEMT trip claim. To verify that the Department paid NEMT claims based on the correct trip mileage and rates, we reviewed the trip mileage and rates for 362,110 NEMT claims paid from July 2020 through February 2021, and PUC documentation on the taxi rates for permitted taxi companies. ? Claims must be supported with accurate and complete documentation confirming the service provided. Both IntelliRide and providers that submit claims for NEMT services must keep and be able to furnish accurate, complete supporting documentation for all claims [42 USC 1396a(27), 42 CFR ?? 431.17 and 433.32, and 10 CCR 2505-10 8.014.3.C and 8.014.6.B]. For example, a claim must be supported by medical documentation showing that the type of vehicle was needed to transport the recipient, and documentation from the transportation provider showing the trip occurred and when the recipient was picked-up and dropped-off. IntelliRide should only submit a claim to the Department after IntelliRide confirms the trip has been completed and marks the status complete in EcoLane [IntelliRide Policies and Procedures]. If an NEMT provider does not show up for a trip, IntelliRide should mark the trip as ?cancelled? in EcoLane. Payments for Medicaid claims that lack supporting documentation for the services provided are unallowable, meaning they should not be paid. IntelliRide or the Department must maintain documentation from recipients? medical providers showing why certain NEMT services, like transportation in a wheelchair van or with an escort, are medically necessary [10 CCR 2505-10 8.014.7.B and 8.014.5.D.1; Billing Manual]. To verify that there was support for NEMT claims, we reviewed IntelliRide data in EcoLane for all 362,110 NEMT claims paid from July 2020 through February 2021, and Department documentation for a sample of 85 NEMT paid claims?75 selected randomly from the four NEMT service areas of the state, and 10 that were the highest paid NEMT claims. ? NEMT services must be medically necessary. NEMT services shall only be provided to recipients with no other means to attend medically necessary, non-emergency treatment covered by Medicaid [42 USC 1396a(70); 42 CFR 431.53; 10 CCR 2505-10 8.014.5.B]. To verify that NEMT claims were only paid for recipients to access medical care, we reviewed the Department?s data on paid medical claims to determine if the recipients related to 22 sampled NEMT claims paid in December 2020 had a corresponding medical appointment. For another 61 paid NEMT claims that involved IntelliRide scheduling and submitting claims for trips every day in December for two recipients, we reviewed whether the recipients had paid medical claims corresponding with the trips. ? Prior authorization is required for air ambulance. The Department must grant prior authorization for the use of an NEMT air ambulance before the trip occurs in order for the claim to be paid [10 CCR 2505-10 8.014.7.D.1.b]. To verify that the Department granted prior authorization for air ambulance trips, we reviewed the use of air ambulances in 11 paid claims from July 2020 to February 2021. ? Recipients are to receive the least-costly NEMT transportation option appropriate for their medical condition. For example, recipients should only ride in a vehicle for recipients with mobility needs when they have a mobility issue or if there is a lack of access to public transportation [10 CCR 2505-10 8.014.6.B, 42 USC 1396(a(70), and 42 CFR 440.170(a)(4)]. Higher-cost NEMT services, such as ambulance and wheelchair van services, must be supported with documentation of the recipient?s need for the specific higher-cost services [10 CCR 2505-10 8.014.5.B.1.b]. To determine whether recipients received the least costly NEMT services to meet their needs, we reviewed documentation submitted by medical or transportation providers to IntelliRide or the Department for the 85 sampled NEMT claims. ? Taxi providers must be permitted by the PUC to provide NEMT taxi rides. To provide NEMT rides by taxi and receive payment for them, the provider must maintain a common carrier permit issued by the PUC [10 CCR 2505-10 8.014.3.B.4.a]. To verify that the providers that were paid for taxi claims had been permitted to provide taxi services, we reviewed the 33,791 NEMT claims for taxi services from July 2020 to February 2021. What problems were identified? The Department paid $3.5 million directly to 66 NEMT providers for claims that were not brokered by Intelliride. From December 2020 through February 2021, 26,890 of the approximately 129,000 NEMT claims paid by the Department (21 percent), totaling about $3.5 million, were not brokered through IntelliRide, which violated state regulations requiring all NEMT services to be brokered through the statewide brokerage in effect at the time. The following chart shows the amounts the Department paid for claims submitted directly by NEMT providers compared to its payments for claims submitted by IntelliRide from July 2020 through February 2021. During these months, the number of claims that providers submitted directly to the Department decreased as providers transitioned to working with IntelliRide to broker NEMT rides; however, as of February 2021, the Department was still paying about $1 million in monthly claims that were submitted directly by providers. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote The Department paid 36,910 NEMT claims totaling $5.5 million, which either violated or may have violated federal and/or state regulations. The claims were for unallowable services or were overpaid, and resulted in $291,597 in known questioned costs and $5,180,962 in likely questioned costs for Medicaid. A questioned cost is a payment that ?resulted from a violation or possible violation of a statute, regulation, or the terms and conditions of a Federal award, including for funds used to match Federal funds? or ?the costs, at the time of the audit, [that] are not supported by adequate documentation?? [2 CFR 200.84]. A known questioned cost reflects a violation that the auditor confirmed; a likely questioned cost is the auditor?s best estimate of a potential violation [2 CFR 200.516(a)(3)]. Known and likely questioned costs should be investigated by the Department and recovered, as appropriate, because Medicaid overpayments are recoverable regardless of whether they occurred due to an error by the Department, entity acting on behalf of the Department, or a provider [Section 25.5-4-301(2), C.R.S.]. We found the following problems resulting in $291,597 in known questioned costs: ? Claims paid with no support that services were provided. For 3,958 of the 362,110 NEMT claims (1 percent), which totaled $258,115 paid from July 2020 to February 2021, IntelliRide or providers submitted the claims without any documentation showing that recipients received the NEMT services from the providers listed in the claim. The $258,115 is known questioned costs and includes: o 3,323 claims totaling $163,985 submitted by IntelliRide with no documentation in EcoLane of a ride being scheduled or provided. o 619 claims totaling $61,431 submitted by IntelliRide for which EcoLane showed the scheduled ride was cancelled. o 16 sampled claims totaling $32,699 submitted by providers directly to the Department had no documentation that an NEMT service occurred because the providers did not send the Department documentation for their claims. Upon our request, the Department attempted to obtain supporting documentation from providers for these claims but was unable to obtain any. ? Overpayments due to incorrect mileage and taxi rates. For 466 of the 321,099 mileage and taxi claims (less than 1 percent), the Department overpaid IntelliRide. Specifically, for 50 of the 287,308 mileage claims (less than 1 percent), the mileage submitted by IntelliRide that the Department paid was more than the ride mileage that IntelliRide documented in EcoLane. For 416 of the 33,791 (1 percent) claims submitted by IntelliRide on behalf of providers that were permitted to operate as taxis, the Department paid a higher rate than the providers? set PUC rate. The following table breaks out the overpayments that we identified, which totaled $6,759 in known questioned costs. We did not find issues with the rate amounts that the Department paid for non-mileage and non-taxi services. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Examples of these overpayments include: o An overpayment of $48 for a claim submitted by IntelliRide for a taxi provider that billed the wrong taxi rate. The Department paid $60 for a 4-mile trip, when it should have paid $12 based on the PUC rate of $3 per mile. o An overpayment of $79 for a claim submitted by IntelliRide on behalf of a provider because the claim showed the trip was 76 miles, but the EcoLane data showed the trip was 38 miles. The Department paid $157, when it should have paid $78. ? Unallowable rides, not for medical appointments. For 61 claims showing NEMT trips every day in December 2020 for two recipients, there were no medical claims corresponding to their trips, so it appears that either NEMT was used repeatedly to transport these recipients to unallowable destinations or the provider did not provide the trips claimed. The NEMT provider reported to IntelliRide that these trips were completed even though the recipients did not attend any medical appointments that month. IntelliRide submitted the 61 NEMT claims and its EcoLane data showed that the NEMT providers self-reported that the trips were completed. However, IntelliRide confirmed that these trips were not used to access medical care. The issues we identified resulted in $2,674 of known questioned costs. ? Air ambulance claims paid without prior authorization. None of the 11 air ambulance NEMT claims had supporting documentation that the provider requested or received prior authorization from the Department before the trip occurred. These 11 claims to three providers resulted in $23,122 in known questioned costs. ? Claims paid for trips that were not the least costly, medically necessary, and/or for approved escorts. For seven of the 85 sampled claims (8 percent), IntelliRide submitted the claims without having required documentation from medical providers. Specifically, four claims lacked documentation to support the medical necessity for the type of vehicle used (either mobility vehicle, taxi, or wheelchair van); the other three claims lacked documentation of the recipient?s need for an escort to support the associated cost, which indicates that the three sampled NEMT trips were provided to an escort ineligible to ride with the recipient. The issues we identified for the seven claims resulted in $927 of known questioned costs. In addition, we found the following problems resulting in $5,180,962 in likely questioned costs, which are estimated potential violations of federal requirements that we could not confirm due to a lack of documentation: ? $4.8 million paid for taxi claims without mileage. For 29,049 taxi claims totaling $4,763,071, the Department paid the claims without ensuring taxi providers were paid at their PUC per-mile rate. These claims were submitted directly to the Department by 10 permitted taxi providers. The Department required providers to submit claims showing only the number of one-way trips driven, not the number of miles driven. As a result, the Department could not ensure that these taxi claims were paid at the correct PUC rates, as required in its Billing Manual and Rate Schedule. The Department paid the full amount that each taxi provider requested, as long as the claim was not more than $1,000 per one-way trip. For example, the Department paid $4,000 to one taxi provider for a claim showing four one-way trips for a recipient on a single day. Based on the claim amount, the taxi provider would have had to have driven the recipient on four 400-mile, one-way trips that day to justify this amount, because the taxi provider?s PUC rate is $4 for the first mile and $2.50 for each additional mile. Since the Department did not obtain the miles driven for each one-way trip from taxi providers for these 29,049 claims, we could not determine whether the payments were accurate based on each provider?s PUC rate, as required. ? $409,575 paid for taxi claims for providers not permitted as taxis. For 3,284 NEMT claims for taxi services from eight providers, the providers were not permitted by the PUC to operate as taxis. For example, one provider was paid for an NEMT taxi claim for $5,875 for 12 trips, or $490 per trip. Since these providers were not permitted as taxis, they did not have PUC-set taxi rates, so we could not determine how much these providers should have been paid. ? $4,718 paid for trips that may not have been to attend medical services. As of April 2021, 13 of the 22 sampled NEMT claims (59 percent) for trips in December 2020 had no medical claims for dates corresponding to the NEMT trips. Department staff told us that Medicaid medical claims are typically submitted and paid within 3 months of the date of service, but that there is a possibility that medical providers had not yet submitted medical claims for the recipients since federal regulations technically allow providers up to 12 months to submit claims [42 CFR 447.45(d)(1)]. In addition, six of these 13 recipients had both Medicaid and other types of medical insurance, such as Medicare. According to the Department, it is possible that the six recipients used NEMT trips to access medical services but the Department did not have a Medicaid claim for the services because they were paid by the other types of insurance, which is allowed by state regulations [10 CCR 2505-10 8.014.5.B.2]. Therefore, we could not determine whether the NEMT trips associated with the 13 claims had been for recipients to attend medical services. ? $3,598 paid for trips that may not have been completed. For 61 of the 362,110 paid claims (less than 1 percent), the scheduled trips were not marked as complete in EcoLane, so we could not determine whether they had been completed. Why did these problems occur? The Department lacks effective internal controls over NEMT claims to ensure they are appropriate and consistently comply with federal and state requirements. According to federal regulations [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls to provide reasonable assurance that federal funds are spent in compliance with federal requirements. We identified the following areas where Department controls are lacking for NEMT claims: Lack of Department information technology (IT) Controls in interChange ? No IT controls to prevent providers from bypassing broker. From December 2020 through February 2021, the Department paid NEMT providers directly for unsupported NEMT trips because the Department did not have IT controls in interChange to deny claims for trips that were not brokered through IntelliRide, as required at the time. As of September 1, 2021, the Department plans to require only the NEMT providers operating in nine metro-Denver counties to broker trips through IntelliRide, so the Department needs IT controls to ensure providers in these counties work with IntelliRide to schedule all trips and submit related claims. ? Lack of IT and other controls to ensure proper payments for NEMT taxi services. InterChange is programmed to pay each NEMT taxi claim based on one-way trips, but the Department has not implemented an IT or other control to ensure that NEMT taxi claims are paid at the providers? current PUC-approved per-mile rates, and that the Department only pays taxi rates when the provider is permitted by the PUC to operate as a taxi. Department staff stated that the only IT control the Department has built into interChange to help ensure proper payment of taxi claims is limiting payments for taxi claims to no more than $1,000 per one-way trip, and that this control is in accordance with the NEMT Billing Manual and Rate Schedule. However, Department staff also acknowledged that there is a conflict within the Billing Manual that requires taxi claims to be based on the number of one-way trips, but also paid based on per-mile PUC rates. By setting the limit based only on the number of one-way trips instead of providers? PUC per-mile rate, this Department IT control is not effective at ensuring taxi claims are paid properly. To ensure accurate payments for NEMT taxi claims, the Department will need methods, such as IT controls in interChange, and clarification in the Billing Manual and Rate Schedule, to ensure taxi providers are paid based on set rates, and ensure each taxi provider is permitted. ? No IT controls to ensure required prior authorizations. Air ambulance services were paid without the Department?s prior authorization for the services because the Department does not have IT controls to ensure prior authorization before payment. If the Department does not implement IT controls to ensure appropriate prior authorizations of NEMT services, the Department will need to develop manual processes to ensure that NEMT services receive required authorization prior to paying the related claims. Lack of Department Monitoring of NEMT Services and Claims ? Insufficient methods to ensure appropriate payment and collect necessary documentation from providers that bypass the statewide brokerage. Although the Department reviewed NEMT provider supporting documentation for NEMT services in 2019, the Department did not do so in 2020 or 2021, and had no process to require the providers that bypassed the statewide brokerage to submit documentation to support their NEMT claims before they were paid. According to the Department, in September 2021, it plans to require providers in nine counties covered by the IntelliRide brokerage contract to provide and submit claims through IntelliRide; however, NEMT providers in the remaining 55 counties will be submitting NEMT claims directly to the Department. Therefore, it is important that the Department develop a process to ensure that providers in these 55 counties maintain required documentation for each claim. ? Lack of monitoring to ensure Intelliride submits accurate mileage claims and collects necessary documentation. The Department does not conduct reviews of IntelliRide?s documentation in EcoLane to ensure it submits claims for accurate mileage and maintains support for claims submitted to or paid by the Department. For example, the Department does not reconcile its NEMT claims data from interChange and IntelliRide?s EcoLane system data to ensure each claim is supported. Furthermore, the Department has never completed a file review of IntelliRide?s supporting documentation for NEMT claims, such as when the Department contracted with IntelliRide to be a regional broker prior to becoming the statewide broker. ? No method to ensure NEMT service claims are for rides for medical treatment and the least costly. The Department does not conduct any reconciliation of its interChange data on NEMT trip claims to its interChange data on Medicaid medical claims to ensure NEMT claims are only paid for recipients to access medical care. The Department also does not require confirmation from medical providers that recipients used NEMT to access necessary medical care. For example, NEMT providers told us that before the start of the IntelliRide statewide brokerage contract, they either called medical providers to confirm that the recipients? NEMT trips were to access medical appointments or collected medical providers? signatures for each NEMT trip. In addition, the Department has no controls to ensure providers that submit claims directly to the Department are providing the least costly NEMT service appropriate to each recipient, such as public transportation when it is accessible and appropriate. For example, IntelliRide instructs its staff to attempt to schedule the lowest-cost NEMT service based on recipients? mobility needs and access to public transportation; however, the Department has no such method to ensure services are the least costly when NEMT providers schedule services for recipients. As of September 2021, the Department plans to have the recipients who live in the 55 counties not served by IntelliRide begin scheduling their rides directly with the NEMT providers of their choosing, yet the Department has not developed a method to ensure recipients in these areas receive the lowest-cost services appropriate for their needs. ? Potentially insufficient Department staffing to monitor NEMT claims effectively. For Fiscal Year 2021, the Department was appropriated three full-time equivalent (FTE) staff to oversee NEMT claims; however, the Department had two vacancies in these positions from July 2020 through May 2021 that it did not fill, so there was only one Department staff overseeing NEMT and the IntelliRide statewide contract during the audit time period. In June 2021, the Department added an additional FTE staff member to assist in administering the NEMT benefit. Why do these problems matter? Likely federal recovery of funds used for improper payments. Section 25.5-4-301(2), C.R.S., states that any overpayments of claims to providers are recoverable and ?are recoverable regardless of whether the overpayment is the result of an error by the state department? an entity acting on behalf of [the department], or the provider or any agent of the provider.? Our audit identified $291,597 in known questioned costs, of which about $145,797 is the federal portion of funds that the federal government may recover. We also identified $5,180,962 in likely questioned costs, of which $2,590,480 is the federal portion of funds that could be recovered if the payments are determined to have not been appropriate. The following table shows the questioned costs and federal portions for each problem we identified. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote When providers bypass broker controls, service quality is not monitored. When the Department allows some NEMT providers to bypass the IntelliRide broker, and does not obtain documentation to support their claims, the Department is unable to monitor the services of these providers. Additionally, when the Department does not monitor providers that bypass the statewide broker, the Department is applying different and possibly inadequate standards for the providers that bypass compared to the providers that work with IntelliRide. Although the Department plans for IntelliRide to no longer be the statewide NEMT broker for all 64 counties beginning September 2021, IntelliRide will continue to administer NEMT trips for nine Front Range counties that account for the majority of NEMT trips. It is important that all NEMT trips in these counties be brokered through IntelliRide so that the Department can monitor the quality of the trips and IntelliRide?s oversight of them. Risk of fraud, waste, and abuse. When the Department pays NEMT claims that are not supported by documentation of the service, medical documentation showing NEMT was for medical treatment, or the required prior authorizations, there is a significant risk of misappropriation of federal and state funds by providers and/or recipients. In addition, the eight providers not permitted as taxis that submitted taxi claims appear to have set their own rates of payment at a significantly higher rate, since the PUC did not permit or set rates for these providers. While we did not identify confirmed fraud by recipients or providers due to a lack of supporting documentation for claims, the problems identified demonstrate waste of public funds and potential abuse of the Medicaid program. When the Department overpays Medicaid funds and pays for unallowable services, there are fewer funds available to service the recipients who need them. In addition, there is no federal or state limit on payments for NEMT services, so it is important that the Department ensure Medicaid recipients receive appropriate transportation to medical treatment, while also ensuring the Department is acting as a good steward of federal and state funds. See Schedule of Findings and Questioned Costs for chart/table Character Limit Exceeded See Statewide Single Audit Report
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-043 Managed Care Entities? Periodic Audit Reporting On November 9, 2020, CMS adopted a final rule (Final Rule) revising the regulations governing managed care programs. The Final Rule was meant to streamline the existing Medicaid and CBHP managed care regulatory framework. Further, it adopted procedures and standards to ensure accountability and strengthen program integrity safeguards. The Department is responsible for complying with these federal program integrity regulations, some of which include requirements to monitor MCE compliance submission requirements, conduct periodic audits of submitted MCE data, and then post the periodic audits publicly on the Department?s website. These periodic audits are done to determine the accuracy and completeness of the (1) encounter and, (2) financial data submitted by each MCE, which are described as follows: ? Encounter Data. The Department?s contracts with the MCEs require each MCE to submit Medical Encounter Claims (Encounter Data) to the Department. Encounter Data includes services provided by any of the MCE?s providers, including, but not limited to, services delivered by medical groups, practices, clinics, physicians, or any other providers. MCEs must submit Encounter Data on a monthly basis on the last business day of the month. The Department then contracts with an independent external quality review organization to review the information and supporting documentation, and then the external organization issues a report on the data submitted by each MCE. ? Financial Data. The Department?s contracts with the MCEs require each MCE to complete a Department-provided financial reporting template that contains a breakdown of the MCE?s administrative and medical costs for a 12-month period (July through June). These templates are required to be completed and submitted to the Department by January 15 each year. The Department performs an initial review of the information, and then sends the completed templates to an independent CPA firm for final review and issuance of a report on the data submitted by each MCE. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s internal controls over and compliance with federal program integrity requirements for MCEs during Fiscal Year 2021. The audit work included making inquiries of Department staff regarding the Department?s documented policies and procedures over the MCE periodic audits. For each MCE, we reviewed the Department?s MCE contract, the financial reporting template submitted during Fiscal Year 2021, and the report issued by the Department?s contracted independent organization. Lastly, we reviewed the Department?s website to determine whether the Department posted the periodic audit results on their website. How were the results of the audit work measured? Federal regulations [42 CFR 438.602] detail the Department?s responsibilities associated with MCE program integrity. These include the following: ? Federal regulation [42 CFR 602(e)] requires the Department to periodically conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by each MCE. ? Federal regulation [42 CFR 438.602(g)(4)] requires that the results of the periodic audits for each MCE be publicly posted on the Department?s website. The Department?s MCE contracts require all MCEs to submit Encounter Data electronically to the Department on a monthly basis. The Department?s MCE contracts also require all MCEs to submit annual financial information, including annual financial statements and the Department provided financial reporting template. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards that provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Green Book. Under Paragraph 16.01, the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? Overall, we found that the Department did not obtain complete financial data from the MCEs during Fiscal Year 2021 and did not post the audited results of the financial data to the Department?s website. Specifically, we found the following: ? Financial Data Reporting Template. For 2 out of the 10 (20 percent) financial reporting templates we reviewed, the MCE did not fill out the reporting template completely. As a result, the reporting templates were missing supporting information and explanations that assist the Department in their initial review of the MCE financial data, such as the MCE?s methodology for calculating administrative and medical costs submitted with the reporting template. ? Posting Incomplete Periodic Audits to the Department?s Website. For 10 of the 10 (100 percent) MCEs, we found that the Department failed to post the results of the financial data audits to its website. Pursuant to federal regulations, the audits must include information on encounter and financial data for each MCE and be posted to the Department?s website. We were able to verify that the Department did, however, post the results of the encounter audits to its website for all 10 MCEs. Why did these problems occur? The Department lacked adequate controls over ensuring compliance with federal program integrity requirements for MCEs. Specifically, the Department did not have written policies and procedures for performing the initial review of the financial data reporting templates before they are sent to the CPA firm for final review. In addition, the Department did not have written policies and procedures for ensuring all periodic audit information is posted to its website, including the results of the financial data audits. Why do these problems matter? As a recipient of federal funds, the Department is ultimately responsible for ensuring that it is in compliance with federal regulations. By not confirming that the MCE financial data templates are complete, there is a risk that the reports issued by the contracted CPA firm could be inaccurate or incomplete, which could lead to the Department not properly monitoring the managed care program. In addition, by posting incomplete periodic audit information to its website, the Department risks failing to comply with federal program integrity requirements for MCEs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2021-043 The Department of Health Care Policy and Financing (Department) should strengthen its internal controls by developing and implementing written policies and procedures for periodic audits that detail the process for (1) performing the initial review of the financial data reporting templates submitted by Managed Care Entities, and (2) posting complete periodic audit results on the Department?s website in accordance with federal regulations. Response Department of Health Care Policy and Financing Agree Implementation Date: December 2022 The Department did not have strong enough controls for the initial checks on the financial data reporting templates. This process has been updated and will be rectified in coming cycles. The Department has modified its templates in order to address the concerns provided by the auditors including signatures and supplemental reporting. Written policies and procedures for the validation and audit of the templates are being developed currently and will be in place and effective in December 2022. The Department will be correcting this error by posting the audit results along with other quality and audit reports on the following site: https://hcpf.colorado.gov/quality-and-health-improvement-reports.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-054 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-041 MEDICAID ELIGIBILITY?MISSING SOCIAL SECURITY NUMBERS A beneficiary?s application includes information such as a Social Security Number (SSN), birth certificate, and supporting documentation for income. Local counties and MA sites are responsible for administering the benefits application process, entering the required data for eligibility determination into CBMS, and approving or denying applicants? eligibility. For example, Medicaid caseworkers enter and document each applicant?s SSN into CBMS. Caseworkers determine participants? eligibility to receive Medicaid benefits through CBMS. The CBMS eligibility data, including SSNs, feeds into Colorado interChange, which pays providers for the services they render to Medicaid beneficiaries. If there is a change to an SSN, including removing an SSN in CBMS, this change should feed directly into Colorado interChange. Additionally, children in foster care are automatically eligible for Medicaid; the TRAILS system that supports the foster care program at the Department of Human Services also interfaces with Colorado interChange on a daily basis to update foster care beneficiaries? eligibility information and pay providers for the services rendered. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls that were in place over the Medicaid eligibility process during Fiscal Year 2019, and to determine whether the Department complied with federal and state Medicaid requirements during this timeframe. During our audit, we requested a list of all Medicaid claims for medical services that were submitted and paid through Colorado interChange from July 1, 2018, through March 31, 2019. This list included claims made on behalf of approximately 1.1 million beneficiaries. We analyzed the data to identify any Medicaid claims payments made during July 1, 2018, through March 31, 2019, on behalf of beneficiaries who did not have an SSN in Colorado interChange on the date of the claims payment, and found a total of 524,092 claims paid on behalf of 46,772 beneficiaries. From this listing, we excluded any of the claims payments made on behalf of a beneficiary who was exempted from providing an SSN under federal and state regulations. For example, we removed claims payments for beneficiaries who were under the age of 1; beneficiaries who were in foster care and, therefore, were automatically deemed eligible for Medicaid; beneficiaries who had applied to the Social Security Administration for an SSN at the time of the payment; beneficiaries who received medical care as an emergency service; and beneficiaries who had chosen to opt out of providing an SSN due to allowed religious reasons. After we removed these exempted beneficiaries from the population, the list included 2,870 beneficiaries that appeared to be missing an SSN in Colorado interChange and who had Medicaid claims payments made on their behalf from July 1, 2018, through March 31, 2019. We then reviewed these remaining beneficiaries, and the related separate payments made on their behalf during this time period, to determine whether these beneficiaries had an SSN in Colorado interChange at the time of the claims payments and whether the individuals were eligible for Medicaid benefits in accordance with federal regulations and Department procedures. HOW WERE THE RESULTS OF THE AUDIT WORK MEASURED? SSN REQUIREMENTS. Federal regulations [42 CFR 435.910 and 42 CFR 435.117(b)] state that the Department must require an SSN for each individual requesting Medicaid benefits, with the exception of newborns under the age of 1, or ?Eligible Needy Newborns,? and individuals who refuse ?to obtain an SSN because of well-established religious objections.? Federal regulation [42 CFR 435.145(b)(2)] states that the Department must provide Medicaid benefits to individuals who are in the foster care program. Section 472 of the Social Security Act does not require a child to provide an SSN in order to be eligible for the foster care program. State regulations [10 CCR 2505-10 8.100.3.I.1, 8.100.4.B.1.a, and 8.100.4.G.7.a] also require that every individual who applies for and receives Medicaid benefits must provide an SSN, or an application for an SSN, with their application for Medicaid. The regulation specifically states: An applicant?s or client?s refusal to furnish or apply for a Social Security Number affects the family?s eligibility for assistance as follows: i) that person cannot be determined eligible for the Medical Assistance Program; and/or ii) if the person with no SSN or proof of application for SSN is the only dependent child on whose behalf assistance is requested or received, assistance shall be denied or terminated. The regulation also states that newborns under the age of 1 and ?members of religious groups whose faith will not permit them to obtain Social Security Numbers shall be exempt from providing a Social Security Number.? Eligibility data, including SSNs, is required to be collected and entered into CBMS at the time of application or upon another event, such as the beneficiary turning 1 year old. Because this information is maintained within CBMS, and CBMS feeds eligibility information into Colorado interChange, eligible beneficiaries should have an SSN in Colorado interChange. MONITORING. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in the Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Green Book Paragraph 16.01, Perform Monitoring Activities, states the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. TRAINING. Department training procedures indicate that when a local county or MA site caseworker needs to update an SSN in CBMS, he or she must call the Office of Information Technology (OIT) Service Desk within the Office of the Governor, for approval of the change. According to Department staff, once the OIT Service Desk reviews and approves the change, the information will be updated within CBMS; if the OIT Service Desk does not approve the change to the SSN, then the updated information will be rejected within CBMS. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY? We identified 2,870 beneficiaries who were required to have an SSN but did not have an SSN documented in Colorado interChange and had Medicaid claims paid on their behalf sometime between July 1, 2018, and March 31, 2019. In total, Colorado interChange paid approximately $4,540,920 in Medicaid claims for these beneficiaries during the time period noted. In August 2019, we informed the Department of the issues we identified and Department staff performed additional follow-up based on our findings, which included analyzing information contained in CBMS compared to our results from Colorado interchange; the Department confirmed in January 2020, the Department confirmed that 1,590 of these beneficiaries had never had an SSN recorded in CBMS since they were first found eligible for Medicaid benefits, and therefore, would never have had an SSN in Colorado interChange. Because these individuals were required by federal and state regulations to provide an SSN at the time of application or upon another event, as applicable, the lack of documented SSNs in both CBMS and Colorado interChange indicated that these individuals appeared to be ineligible for the Medicaid claims payments that were made on their behalf during the fiscal year. The Department indicated that the remaining 1,280 beneficiaries without an SSN in Colorado interChange did not have an SSN in CBMS at the time of the claim but had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. Since the individuals lacked an SSN within Colorado interChange at the time of the Fiscal Year 2019 claims payments, and based on the documentation provided by the Department, we were unable to determine whether the individuals had submitted an SSN at the time of application or upon another event as required and, therefore, whether they were eligible for the Medicaid services they received. Overall, for the 1,590 beneficiaries noted, we identified known questioned costs of $2,285,757 for the period of July 1, 2018, through March 31, 2019; $1,142,879 of these costs were paid with federal grant funds. For the 1,280 beneficiaries noted, we identified likely questioned costs of $2,255,163 for the period of July 1, 2018, through March 31, 2019. We further analyzed 49 of the 1,590 beneficiaries noted above to identify reasons for missing SSNs and found that: ? Beneficiaries in CBMS were not eligible; however, they were marked as ?eligible? within Colorado interChange. ? Beneficiaries were incorrectly enrolled in the Eligible Needy Newborn Program even though they were all over the age of 1; as a result, although the Department had not required them to provide an SSN, they continued to receive benefits during July 1, 2018, through March 31, 2019. ? Beneficiaries were exempted from obtaining an SSN for unallowable reasons including ?incomplete documents? and ?illness? categories, and CBMS processed their eligibility and Colorado interChange made payments on their behalf; however, neither federal nor state regulations allow such exemptions. The Department has indicated that they are performing additional research on the issues regarding the 1,280 beneficiaries that had an SSN ?at some point? during Fiscal Year 2019 or prior within CBMS. WHY DID THESE PROBLEMS OCCUR? For 1,280 beneficiaries identified who were missing an SSN in Colorado interChange and CBMS at the time of the claim, but had an SSN ?at some point? within CBMS during Fiscal Year 2019 or prior, the Department provided the following possible explanation: The SSN was removed due to caseworkers failing to contact the OIT Service Desk for proper approval for changes to SSN information in CBMS. Other problems with missing SSNs were related to: ? CBMS ISSUES. CBMS was not programmed to appropriately deny an applicant?s eligibility for Medicaid when the individual did not have an SSN in CBMS and did not have an allowed exception noted in CBMS. Rather, CBMS allowed the SSN field to be left blank, regardless of the reason noted for the missing SSN and whether the reason was allowed as an exemption by federal and state regulations. In addition, the SSN in CBMS could be deleted at any time by the caseworker or the OIT Service Desk and CBMS was not programmed to alert the caseworker to follow up if an SSN had been deleted from the file. ? SYSTEM INTERFACE ISSUES AND LACK OF A RECONCILIATION PROCESS. CBMS was not interfacing with Colorado interChange appropriately to update beneficiaries? eligibility information. Some beneficiaries who were deemed ?ineligible? for Medicaid in CBMS were listed as ?eligible? in Colorado interChange and payments were made on their behalf during the fiscal year. Furthermore, the Department lacked an effective internal control process for reconciling Medicaid beneficiaries? eligibility information in CBMS to the eligibility information in Colorado interChange to ensure that the information was consistent in both systems, and that the beneficiary was appropriately deemed either ?eligible? or ?ineligible? in accordance with federal and state regulations. ? LACK OF EFFECTIVE REVIEWS, TRAINING, AND MONITORING. The Department was not effectively monitoring and training Medicaid local county and MA site caseworkers on required approvals for any changes to beneficiaries? SSNs. Further, the Department did not have an effective review process to ensure that beneficiaries were enrolled in the correct Medicaid program. WHY DO THESE PROBLEMS MATTER? As the state Medicaid agency, it is essential for the Department to ensure that Medicaid eligibility determinations are made appropriately and in accordance with state and federal regulations. This includes ensuring accurate processing of information used to determine Medicaid eligibility results in Medicaid benefits being provided to and paid on behalf of only eligible individuals. Since CBMS and Colorado interChange determine eligibility and issue payments on behalf of other federal programs, such as the CBHP, these issues could result in erroneous eligibility determinations or payments for other programs. Ultimately, the federal government may disallow federal funds for Medicaid program expenditures that do not adhere to regulations, and the State would be required to bear the cost of these errors. See Schedule of Findings and Questioned Costs for chart/table RECOMMENDATION 2019-043 The Department of Health Care Policy and Financing should improve its internal controls over Medicaid eligibility by: A Researching and, if feasible, instituting a mechanism for identifying Medicaid cases in the Colorado Benefits Management System (CBMS) that lack a Social Security Number. B Researching and resolving CBMS and Colorado interChange interface issues to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries and establishing an effective reconciliation process between CBMS and Colorado interChange to ensure that Medicaid beneficiaries? eligibility information is consistent in both systems. C Effectively training and monitoring local counties and Medical Assistance sites to ensure that caseworkers are obtaining and documenting the Office of Information Technology Service Desk?s approval for changes to beneficiaries? Social Security Numbers, and that beneficiaries are enrolled in the correct Medicaid program. D Researching the cases identified in our audit to determine whether these beneficiaries were eligible and that the payments made on their behalf were appropriate, in accordance with federal and state regulations. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN) unless they meet certain acceptable exceptions at initial application. Since CBMS is a shared system between the Department and the Department of Human Services and any change would impact all cases in CBMS, the Department cannot guarantee that a system change can be implemented. The Department can agrees to research on the feasibility of instituting a mechanism for identifying Medicaid cases in CBMS that lack a social security number and, if feasible, implement a CBMS change by July 2022. B AGREE. IMPLEMENTATION DATE: JULY 2021. The Department agrees to research and resolve Colorado Benefits Management System (CBMS), and Colorado interChange system interface issues identified in the audit. The Department implemented a system change in June of 2018 that allows retroactive changes in eligibility to be correctly synced between the systems. The majority of the impacted cases are historical cases that will be manually corrected by June 2020. Additional cases involve detailed research, review, and potential outreach to case workers to correct the case file or verify the eligibility status of the impacted members. The Department will take the appropriate actions to notify impacted members if necessary. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2021-22. C AGREE. IMPLEMENTATION DATE: JULY 2021. The Department provides training to counties and Medical Assistance sites that beneficiaries applying for Medical Assistance must supply a Social Security Number (SSN) or supply verification that they have applied for an SSN, unless they meet certain acceptable exceptions. This information has been communicated to the counties since 2004 and is part of our ongoing training materials. The Department cannot agree to establish any additional review process at this time. The Department can agree to work with counties and Medical Assistance sites to identify any additional training related to missing SSN and implement additional training by July 2021. D DISAGREE. The Department disagrees with the Total Known Questioned Costs of $2,285,757 identified in the audit report since Department cannot verify the results. The Department is still attempting to reconcile various reports to understand the finding identified through this audit. CBMS currently has functionality in place for members requesting Medical Assistance that they must supply a Social Security Number (SSN), unless they meet certain acceptable exceptions at initial application. The Department does not have the resources to research the thousands of cases that the auditor identified through data mining techniques, a new methodology for the first time this year. If the auditor is changing methodologies, the Department requires additional resources and timely notice to request resources through the budget process. AUDITOR?S ADDENDUM: The beneficiaries identified through our testing were required by Medicaid regulations to provide an SSN at the time of application or upon another event, as applicable, and the SSN is documented in CBMS and uploaded to Colorado interChange [State regulations 10 CCR 2505-10, 8.100.3.I.1 and 8.100.4.B.1.a and 8.100.4.G.7.a]. Because the noted beneficiaries lacked an SSN within Colorado interChange at the time claims payments were made on their behalf, we questioned the beneficiaries? eligibility. The Department is responsible for ensuring that only individuals who are appropriately deemed eligible for Medicaid receive benefits. Therefore, it is the Department?s responsibility to identify and remove ineligible individuals from the Medicaid program and to prevent the inappropriate payment of claims on their behalf. In addition, generally accepted government auditing standards (GAGAS) (paragraph 3.18), require that ?In all matters relating to the GAGAS engagement, auditors and audit organizations must be independent from an audited entity.? Additionally, paragraph 3.42 states that ?Examples of circumstances that create undue influence threats for an auditor?include (b) [e]xternal interference with the selection or application of engagement procedures or in the selection of transactions to be examined.? Therefore, it is imperative that our decisions related to audit approaches and testing methods be made without department influence or persuasion.
The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and a Significant Deficiency were communicated to the Department of Health Care Policy and Financing (Department) in previous years and have not been remediated as of June 30, 2022 because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and the complete recommendations can be found within Section IV: Prior Audit Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table See Schedule of Findings and Questioned Costs for footnote Finding 2021-056 The following findings and recommendations relating to internal control deficiencies classified as Material Weaknesses and Significant Deficiencies were communicated to the Department of Health Care Policy and Financing (Department) in the previous year and have not been remediated as of June 30, 2021, because the original implementation dates provided by the Department were in a subsequent fiscal year. These complete findings and recommendations can be found within the original report and within Section III: Prior Federal Recommendations of this report. See Schedule of Findings and Questioned Costs for chart/table. Finding 2020-044 PROVIDER ELIGIBILITY Medicaid and CBHP cover a variety of medical and related services, which are provided by provider types such as clinics and hospitals, managed care organizations such as health plans or independent physicians, as well as individual medical providers working within these entities or individually. As of June 30, 2019, the Department had enrolled approximately 71,000 entities and individuals for providing services under Medicaid and CBHP. The Department is ultimately responsible for determining if providers are eligible to participate in Medicaid and CBHP. However, the Department has contracted with a fiscal agent, currently DXC Technology Services, LLC (DXC), to act on its behalf in determining Medicaid and CBHP provider eligibility. A fiscal agent is a contractor that performs certain provider enrollment and claims processing activities, including accepting, processing, evaluating, and approving or rejecting applications. The fiscal agent also assesses the providers into one of three risk categories?limited, moderate, and high?to ensure that appropriate federal and state regulations are applied during the provider enrollment process. Providers that want to enroll must complete an application within Colorado interChange and provide documentation, including a current business and/or medical license, showing that they fulfill all enrollment requirements. Once the enrollment process is complete, the Department enters into agreements with the providers that are found to be eligible. WHAT WAS THE PURPOSE OF OUR AUDIT WORK AND WHAT WORK WAS PERFORMED? The purpose of the audit work was to review the Department?s internal controls over Medicaid and CBHP provider eligibility and enrollment processing, and to determine whether the Department complied with federal Medicaid and CBHP provider eligibility requirements during Fiscal Year 2019. Additionally, the purpose of our work was to determine the Department?s progress in implementing our Fiscal Year 2017 and 2018 recommendations related to provider eligibility and enrollment. At that time, we recommended that the Department improve its controls over Medicaid and CBHP provider eligibility determination and enrollment to ensure that it complies with federal and state requirements related to data verification, documentation including current provider licenses, monitoring policies and procedures, appropriate indication of results of database matches, and consistent display of provider information within Colorado interChange. The Department agreed with our recommendations and stated that it would implement them by Fiscal Year 2019. We reviewed a sample of 25 Medicaid provider applications for individual, company, and managed care providers that were deemed eligible and received payments during Fiscal Year 2019 through Colorado interChange for services provided. We obtained and reviewed the provider application information entered into Colorado interChange, as well as the supporting documentation uploaded into Colorado interChange by providers, to determine whether these providers were accurately deemed eligible to receive Medicaid payments and whether the required documents were present in accordance with federal and state regulations. In addition, we conducted interviews with Department staff regarding its procedures over Medicaid provider eligibility and enrollment. We also obtained a detailed Suspension Listing from the Department of Regulatory Agencies, which contained health care provider business and medical licenses that were terminated during Fiscal Year 2019. We compared the Suspension Listing with provider information in Colorado interChange to determine if the Department made inappropriate claims payments to unlicensed providers during the fiscal year. Because CBHP is operated through Medicaid, and the processes followed for provider eligibility and enrollment for CBHP providers are the same as the processes for Medicaid providers, our testing looked at compliance for both programs. WHAT PROBLEMS DID THE AUDIT WORK IDENTIFY AND HOW WERE THE RESULTS MEASURED? We found that the Department did not fully comply with federal and state Medicaid regulations for provider eligibility during Fiscal Year 2019. Specifically, although we did not identify enrollment issues with the Department?s processing of providers who were newly enrolled during Fiscal Year 2019, we found at least one issue related to ongoing eligibility with all 25 sampled providers we tested: ? DATABASE MATCHES AND DISPLAY OF PROVIDER INFORMATION. We identified the following database match functionality issues with 24 of 25 providers (96 percent) tested: ? For 23 of 25 providers (92 percent) that included individual, company, and managed care providers, Colorado interChange showed that the provider?s owners, agents, and managing employees? SSNs were not verified against federal databases, as required. Specifically, the SSN check box within Colorado interChange indicated ?N,? meaning ?No verification was performed with the database.? Additionally, for one of 25 providers (4 percent) that was a managed care organization, the organization was enrolled in Colorado interChange in April 2019 and showed that the SSNs had been verified, but SSNs for two individuals who worked under this provider that were listed on the application were shown as ?N? within the system. ? For eight of 25 providers (32 percent) that included companies, Colorado interChange showed that the providers? Federal Employee Identification Numbers (FEIN) were not verified against federal and state databases, as required. Specifically, the FEIN check box within Colorado interChange indicated ?N.? ? For 13 of 25 providers (52 percent), Colorado interChange did not present the data of owners, agents, and managing employees information consistently between various screens within Colorado interChange. For example, when a provider noted owners, agents, or managing employees on its application, that information was not reflected in Colorado interChange outside of the application screen even though there is a section in Colorado interChange that should list the owners? information. According to federal regulation [42 CFR 455.436] and requirements established by the ACA [Patient Protection and Affordable Care Act (2010), Section 6401(a)], the Department must check federal databases to confirm providers? identity and determine whether providers are excluded from participating in the Medicaid program; this verification must also occur, if applicable, against providers? owners, agents, and managing employees. For example, the Department must check the federal exclusion databases at least monthly to ensure that the providers, owners, agents, and managing employees are not excluded from participating in the Medicaid program. Colorado interChange is designed to display provider application information consistently between various screens within the system, such as name, SSN, FEIN, and/or National Provider Identification number (NPI), with various federal and/or state databases to identify potential errors and to flag the application for a required caseworker manual review. According to Department staff, when Colorado interChange successfully verifies provider-provided information against another state or federal database, Colorado interChange should separately mark each verified data field on the application to note the successful match. Conversely, if Colorado interChange does not match a given field against a database, it should also be identified in the system. As a result of these issues, we were unable to determine if Colorado interChange performed the required matches and if any discrepancies in provided information were identified and presented to DXC, the fiscal agent, for a manual review to verify eligibility, as required. ? DOCUMENTATION. The Department did not maintain sufficient documentation within Colorado interChange for the receipt date of the fingerprints from the provider, the collection of application fees, and site visits, as follows: ? For four of 25 providers (16 percent) tested, the Department?s fiscal agent failed to fill in the receipt date field within Colorado interChange to indicate when fingerprints were received from enrolling providers. After bringing this issue to the Department?s attention, the Department provided fingerprinting documentation in November 2019 to support that these providers submitted fingerprints within 30 days of Department request in accordance with federal regulation; however, that receipt date information had not been documented in Colorado interChange as of November 2019. ? For one of 25 providers (4 percent) tested, the provider was assessed as high risk but the provider?s file did not contain evidence that an application fee was collected or that the fiscal agent conducted a site visit, as required. Under federal requirements [Sub Regulatory Guidance for State Medicaid Agencies (SMA): Revalidation (2016-001(3))], the Department ?must be able to produce documentation to support each of the provider screening and enrollment requirements,? such as requirements for fiscal agent-conducted site visits of moderate and high risk providers during the enrollment and revalidation process. Federal regulation [42 CFR 455.432] states that the State Medicaid Agency or their fiscal agent must conduct pre- and post-enrollment site visits of providers who are deemed as moderate or high risk to the Medicaid program. The purpose of the site visits is to verify that the information submitted to the state Medicaid agency is accurate and to determine compliance with federal and state enrollment requirements. Additionally, the Department?s contract with DXC requires the fiscal agent to maintain detailed documentation and procedures for Medicaid provider enrollment. Federal regulation [42 CFR 455.434] requires that, for any provider assessed by the Department as high risk, the Department must obtain fingerprints from the provider, including fingerprints for any person(s) who has a 5 percent or more direct or indirect ownership interest in the provider and furnishes medical or pharmaceutical services or supplies. The provider must submit the fingerprints within 30 days, upon request by the Department. Federal regulation [42 CFR 455.460(a)] states that the Department must collect the applicable application fee prior to executing a provider agreement from a prospective or re-enrolling provider, with certain limited exceptions. According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal control over its federal awards that provides reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with guidance in Green Book Paragraph 16.01, Perform Monitoring Activities, which states that the Department ?should establish and operate monitoring activities to monitor [its] internal control system and evaluate the results.? Monitoring activities include reviewing reports, observing operations, and ensuring that activities are carried out in accordance with the federal grant agreement. ? INELIGIBLE PROVIDERS: Based on our review of the suspended license listing from the Department of Regulatory Agencies, we identified three providers that had their licenses suspended during part of Fiscal Year 2019 but continued to be shown as active in Colorado interChange, as follows: ? One provider had its license suspended between February 11, 2019, and March 27, 2019; however, during this timeframe, the provider continued to bill claims and receive payments from Colorado interChange. After we questioned the Department about the issue, the Department issued a demand for payment letter dated October 18, 2019, to the provider for $15,061 in payments that were inappropriately paid. We consider these $15,061 payments to be known questioned costs; $7,531 of these payments were made with federal grant funds. ? Two providers had suspended licenses as of September 21, 2018, and February 25, 2019, respectively, but showed as active in Colorado interChange through June 30, 2019, and therefore appeared eligible to bill claims and receive payments. Based on additional testing, we determined that no payments were made to these providers after their licenses were suspended and did not identify any questioned costs associated with these two providers. Federal regulation [42 CFR 455.412] requires that the Department must have a method for verifying that any provider purporting to be licensed in accordance with the laws of any State is licensed by such State and confirm that the provider?s license has not expired and that there are no current limitations on the provider?s license. This federal regulation requires the Department to verify that the providers meet required licensure standards initially, and it is best practice for the Department to verify that the providers meet these standards on an ongoing basis to ensure that there are no current limitations on the provider?s license. In addition, state regulation [10 CCR 2505-10 8.125.9, Verification of Provider Licenses] states, ?If a provider is required to possess a license or certification in order to provide services or supplies in the State of Colorado, then that provider must be so licensed as a condition of enrollment as a Medicaid provider. As a condition of enrollment, any required licenses must be active without any current limitations.? Under the federal regulation, Requirements for Estimating Improper Payments in Medicaid and CHIP [42 CFR 431.958], ?Improper payment means any payment that should not have been made or that was made in an incorrect amount (including overpayments and underpayments) under statutory, contractual, administrative, or other legally applicable requirements; and payment means any payment to a provider, insurer, or managed care organization for a Medicaid or CHIP beneficiary?? WHY DID THESE PROBLEMS OCCUR? The Department did not have adequate internal controls in place over provider eligibility and claims payment processes related to the monitoring of DXC, its fiscal agent, during Fiscal Year 2019 to ensure that it complied with federal and state regulations. Specifically, Colorado interChange required fixes that were in various stages of correction during Fiscal Year 2019. According to the Department, Colorado interChange required a system fix in December 2018 in order to properly mark and/or display results related to federal and state database checks going forward; however, the system fix did not completely resolve the display issues to accurately indicate whether the data matches had occurred, and the Department did not retroactively make corrections to any cases that erroneously indicated that their information had not been verified. Rather, the Department stated that the inconsistent display issue related to providers that enrolled in the program when Colorado interChange was initially implemented and that this will be addressed after these providers are revalidated in Fiscal Year 2020 or when a provider updates their information, whichever occurs first. Additionally, the Department indicated that Colorado interChange did not have an automated system alert to check with the Department of Regulatory Agencies? license database on a regular basis to notify the fiscal agent and/or the Department that a license had expired. Although the Department reported that they had an interim manual process to ensure that expired licenses were identified and that subsequent steps were taken to ensure that providers remained eligible throughout the fiscal year to provide Medicaid services, the manual process did not identify and/or address the instances that we identified through our audit. Finally, we noted that the Department lacked an effective monitoring process over DXC, its fiscal agent, to ensure that the required documentation was maintained in accordance with Uniform Guidance, as the monitoring policies and procedures referred to as Provider Enrollment Audit Process were still in the draft stage during Fiscal Year 2019 and had not been formalized. WHY DO THESE PROBLEMS MATTER? By not ensuring that appropriate internal controls, including system controls and monitoring, are in place over the Medicaid provider eligibility and enrollment processes, the Department cannot ensure that all Medicaid providers are eligible or qualified to participate in the program. Additionally, without instituting a process to regularly update provider licensure information and to ensure that provider information contained in Colorado interChange is consistent and accurate, the Department cannot ensure that the enrolled providers are appropriately screened and are eligible to receive payments. Ensuring that providers contained in Colorado interChange are qualified to provide services is especially important because Colorado interChange is also used for provider eligibility determination for CBHP. Overall, the State could risk losing federal Medicaid and CBHP funding if it allows non-qualified providers to bill and be paid for services provided for these programs. RECOMMENDATION 2019-046 The Department of Health Care Policy and Financing (Department) should improve its controls over Medicaid and Children?s Basic Health Plan (CBHP) program provider eligibility determination and enrollment to ensure that it complies with federal and state requirements by: A Working with its fiscal agent to ensure that Colorado interChange performs all required database matches and properly displays results of Social Security Number and Federal Employer Identification Number verifications for all providers. B Establishing an effective process to ensure that provider licensing information contained in Colorado interChange is current, that any expired licenses are identified, and that any ineligible providers are disallowed from providing Medicaid and CBHP services and receiving payments in accordance with Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). C Formalizing the Department?s monitoring policies and procedures called Provider Enrollment Audit Process over the fiscal agent to ensure required documentation is maintained in accordance with Uniform Guidance. D Ensuring that Colorado interChange displays provider information consistently throughout the system. RESPONSE DEPARTMENT OF HEALTH CARE POLICY AND FINANCING A AGREE. IMPLEMENTATION DATE: JULY 2022. The Department is working with its Fiscal Agent to ensure all required database screenings are performed and clearly identified in the Colorado interChange. An issue was identified in a prior year, FY 2018-19, that not all screening information was consistent. There was also a concern that initial screenings might miss some individuals due to the way data was formatted when transferred from LexisNexis. The issue was resolved by the Fiscal Agent prior to FY 2019-20. The Fiscal Agent is continuing to conduct manual reviews of all screening results to ensure compliance. A separate process to screen providers monthly is executed by the Department's Program Integrity Section. Through this process, no providers were found to have been enrolled incorrectly and, as necessary, the Department took appropriate action if there were changes to a provider's information. The Department is working with its Fiscal Agent to properly display results of Social Security Number and Federal Employer Identification Number verifications for all providers and automate the review process. The Department's implementation date reflects that the Department will complete the improvements and be in compliance with the Recommendation for the entirety of FY 2022-23. B DISAGREE. The Department finds that the Colorado interChange is working as designed, that the Fiscal Agent is appropriately enrolling providers, and that the Department is in compliance with the federal regulations regarding enrolling and revalidating providers. The Department is compliant with 42 CFR ? 455.436, which requires providers to be screened at enrollment and revalidation. All providers are assessed for eligibility requirements at enrollment and revalidation and are then screened monthly to identify any changes. For the licensing issue identified in this audit report, the Department performed the appropriate actions to recover funds within less than a month of the incident, which is compliant with federal regulation 42 CFR ? 455.436(c)(2). AUDITOR?S ADDENDUM: As noted in the finding, we found issues with the Department?s ongoing verification and monitoring of providers? eligibility that failed to prevent improper payments to an ineligible provider during the fiscal year. In addition, the Department did not send notification to recover funds from the provider until October 2019, or 8 months after the provider?s license was suspended. C AGREE. IMPLEMENTATION DATE: JULY 2020. The Department finalized the Fiscal Agent monitoring policies and procedures in December 2019 and therefore was unable to be in full compliance for the entire FY 2019-20. The Department's implementation date reflects that the Department will be in compliance with the Recommendation for the entirety of FY 2020-21. D DISAGREE. There was an initial system configuration on some early enrollments that prevented populating the requested information in the visible provider subsystem tabs for the auditor to review. The verification functionality happens within the provider portal and not in the visible provider subsystem tabs that the auditor reviews. However, no functionality or data was lost, the information only appeared and was stored in the provider portal. The Department implemented a solution so that the information will be displayed in the provider subsystem. This change is pending the next update the providers make and the data will be visible in the provider subsystem. The Department will not be making historical changes to the system. The Department has worked with the Fiscal Agent to resolve the issues which led to the finding and does not believe that expending additional resources to display historical information in both the provider portal and the provider subsystem is the best use of resources. The Department can produce the information manually. AUDITOR?S ADDENDUM: The data inconsistency issues we identified through our audit were based on our reviews of Colorado interChange through the access provided to us by the Department. As noted in the finding, inconsistent information within the provider eligibility screens used for Medicaid and CBHP increases the risk of inaccurate reviews of provider eligibility and ultimately, inappropriate enrollment screening. Therefore, as our recommendation states, the Department should ensure that Colorado interChange displays provider information consistently. The recommendation did not include restatement of historical information.
Finding 2022-043 Medicaid Claims Payments Individuals and families apply for Medicaid at their local county departments of human/social services or at MA sites. Medicaid caseworkers make the determinations of participants? eligibility to receive Medicaid benefits through CBMS. Children in the State?s foster care program, whose information is documented in the TRAILS system, are automatically determined eligible for Medicaid benefits. The Medicaid eligibility data in CBMS and TRAILS feeds into Colorado interChange, which pays providers for the services that beneficiaries receive. CBMS and TRAILS interface with Colorado interChange on a daily basis to update eligibility information, such as a beneficiary?s eligibility status and/or termination of benefits in Colorado interChange. According to the Department, Colorado interChange is programmed to make only allowable Medicaid claims payments on behalf of eligible beneficiaries in accordance with federal and state Medicaid rules and regulations. Thus, Colorado interChange should stop paying Medicaid claims when a beneficiary is no longer eligible for Medicaid. On March 18, 2020, the Act was enacted. The Act provided a temporary increase in the federal share of Medicaid and CBHP assistance from January 1, 2020 until the end of the PHE. The Act also required that the Department maintain Medicaid and CBHP eligibility for beneficiaries enrolled as of March 1, 2020, through the end of the COVID-19 PHE, except for the required terminations noted within the CMS waivers, such as out-of-state residency, termination upon the beneficiary?s request, and death of the beneficiary. On March 26, 2020, CMS approved waivers for a number of Medicaid and CBHP requirements that resulted in, for example, the expansion of benefits to include all uninsured individuals; suspension of beneficiary deductibles, copayments, coinsurance, and other cost sharing charges and fees; coverage of COVID-19 vaccines and testing; and the suspension of the requirement for a provider to have a current license if their license expired during the COVID-19 PHE. In addition, the State implemented, with CMS? approval, Medicaid continuous enrollment as a condition of receiving the temporary increase in federal assistance. During continuous enrollment, beneficiaries could not be disenrolled due to changes in circumstances (i.e., changes in household composition, employment, income and resources) until the end of the COVID-19 PHE. On December 29, 2022 the CCA was enacted. Under the CCA, continuous enrollment and the temporary increase in federal assistance are no longer linked to the end of the COVID-19 PHE. The continuous enrollment condition will end on March 31, 2023 and the increase in federal assistance will start to gradually reduce in April 2023, fully ending in December 2023. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to review the Department?s progress in implementing our Fiscal Year 2019 audit recommendation related to its internal controls over Medicaid claims payments. During that audit, we recommended that the Department improve its Medicaid controls by researching and resolving CBMS, TRAILS, and Colorado interChange interface issues we identified during our audit to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. We specifically identified a TRAILS and CBMS eligibility mismatch issue related to the daily interfaces between CBMS and Colorado interChange and between TRAILS and Colorado interChange. As a result, some individuals who were deemed ineligible for Medicaid in CBMS and TRAILS were indicated as eligible in Colorado interChange at the time of payments; therefore, Colorado interChange made payments on their behalf. The Department researched the specific errors we identified during the audit and manually corrected the eligibility status of those beneficiaries, but the Department had not fully researched the error or identified and corrected all of the cases affected by the errors at that time. As such, we also recommended that the Department identify and correct any additional cases affected by the system issues noted in our audit. The Department agreed with the recommendation and stated that it would implement them by July 2021. As part of our audit work, we discussed the Department?s progress in implementing our audit recommendation with Department staff. According to the Department, it worked with the Department of Human Services (DHS) during Fiscal Year 2022 to develop a plan to eliminate the issues, including the TRAILS eligibility mismatch issue, we identified in the Fiscal Year 2019 audit. In order to address our recommendation that the Department identify and correct any additional cases affected by the system issues noted during our Fiscal Year 2019 audit, the Department developed an eligibility reconciliation report that compares beneficiary records with an active eligibility span in Colorado interChange, in order to identify any records that were not reported in the monthly eligibility file from CBMS. Department staff reported that they are reviewing the reconciliation report monthly to identify any beneficiary records that need updating in CBMS. Beneficiaries may show up on the reconciliation report either because (1) Colorado interChange rejected the beneficiary?s eligibility due to a data integrity issue, or (2) there was a system defect in CBMS, Colorado interChange, or TRAILS that caused a mismatch issue. Data integrity issues include issues such as a missing mailing address or last name?these issues can be manually fixed in CBMS. System defect issues are generally more complex and require Department staff to research the problem and identify the system that caused the error (CBMS, Colorado interChange, or TRAILS), and then work with the appropriate staff to correct the issue. As part of our audit, we requested copies of the Department?s eligibility reconciliation reports for Fiscal Year 2022 and asked the Department if it identified any additional cases affected by the system issues we identified, and if so, if they had they corrected the issues. How were the results of the audit work measured? We measured the results of our audit against the following: ? Federal regulation [42 CFR 447.56(e)(2), Limitations on Premiums and Cost Sharing] states that federal funding will not be provided for payments made by the Department to providers for services rendered to individuals who are not eligible for Medicaid. ? The Act [Section 2, Division F, Sec. 6008, Temporary Increase of Medicaid FMAP] temporarily increased the federal medical assistance percentage (FMAP) by 6.2 percentage points, effective from January 1, 2020 until the end of the PHE. The Act requires states to maintain Medicaid and Children?s Health Insurance Program (CHIP) eligibility for beneficiaries enrolled as of March 1, 2020 through the end of the PHE (with certain exceptions) in order to receive the increased FMAP assistance (the ?continuous enrollment requirement?). The PHE remained in effect during the entirety of Fiscal Year 2022 through June 30, 2022. ? According to federal regulation [2 CFR 200.303(a)], the Department, as a recipient of federal funds, must establish and maintain effective internal controls over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions. These internal controls should be in compliance with the Standards for Internal Control in the Federal Government (Green Book), published by the U.S. Government Accountability Office, Paragraph 16.01, Perform Monitoring Activities, which states that the Department should establish and operate monitoring activities to monitor its internal control system and evaluate the results. Monitoring activities include reviewing reports, performing reconciliations, and observing operations. What problems did the audit work identify? We determined that the Department did not fully implement our Fiscal Year 2019 recommendation related to Medicaid claims payments by the July 2021 due date it originally provided. Specifically, while the Department has started working with DHS on a plan to resolve the TRAILS eligibility mismatch issues and started preliminary work on the project, the project was still ongoing as of June 30, 2022. In addition, the Department?s system enhancements to CBMS and Colorado interChange were not fully executed because of the ongoing PHE. Once the PHE ends and the Department executes the system enhancements, the Department has indicated the system will begin to correct the CBMS and Colorado interChange mismatches. Finally, although the Department has identified additional beneficiary records that require updating in CBMS, it did not correct the identified issues in the system. Specifically, the Department identified approximately 32,800 separate beneficiaries that were flagged as having an eligibility issue through the Fiscal Year ending June 30, 2022. However, per Department staff, they are unable to tell which beneficiaries had data integrity issues versus those that were caused by a system defect. Once the continuous enrollment period ends and the Department is able to fully execute the system enhancements noted above, the Department reports that the systems will sync any error the Department has identified and will be manually corrected. Why did these problems occur? The Department indicated that it did not fully execute the CBMS and Colorado interChange system enhancements because of the Act?s ongoing continuous enrollment requirement. Specifically, because the Department was required to maintain Medicaid and CBHP beneficiaries enrolled as of March 1, 2020 through the entirety of Fiscal Year 2022 due to the continuous enrollment requirements in place, they were unable to fully execute the CBMS and Colorado interChange system enhancements that would fix the data integrity issues identified during the Fiscal Year 2019 audit. Why do these problems matter? Making payments to ineligible individuals can result in the Department having to repay the federal government for the federal portion of the overpayments. Further, because Colorado interChange makes payments on behalf of other federal programs, such as CBHP, system issues with Colorado interChange could result in erroneous payments for other programs. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-043 The Department of Health Care Policy and Financing should strengthen its internal controls over Medicaid claim payments by: A. Continuing to work with the Department of Human Services to fully implement the plan to eliminate the Colorado interChange issues between Colorado Benefits Management System (CBMS), TRAILS, and Colorado interChange to ensure that Colorado interChange only pays provider claims on behalf of eligible beneficiaries. B. Continuing to review the monthly eligibility reconciliation reports and identifying beneficiary records that need updating, and making necessary corrections in CBMS once the continuous enrollment condition ends. Response Department of Health Care Policy and Financing A. Partially Agree Implementation Date: April 2023 The Department and CBMS teams have strengthened their internal controls to ensure payments are only made to providers for eligible members. The Department and CBMS teams will update all member records identified on the Monthly Reconciliation report once the Public Health Emergency ends. TRAILS team has provided additional training to the Case Managers to prevent data integrity issues being submitted to CBMS and interChange; however, the TRAILS team does not plan to update the system's internal controls until funding is available. Auditor?s Addendum Our responsibility under federal audit regulations is to report to the federal government when we identify Medicaid payments that may not have been made on behalf of eligible individuals or costs that we question as appropriate. It is ultimately the Department?s responsibility to have internal controls in place over its federal awards which provide reasonable assurance that the Department is managing its federal grants in compliance with federal statutes, regulations, and the award terms and conditions B. Agree Implementation Date: April 2023 The Department agrees to review the monthly eligibility reconciliation report and is looking forward to resolving the member records once the Public Health Emergency ends to fully resolve the audit finding.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Finding 2022-064 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide emergency financial assistance to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF I) Program. The federal Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the federal American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Each of the University?s campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (DOE) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements of the HEERF program there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The DOE specified that the Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The University?s campuses are required to submit the annual report directly to the DOE. During Fiscal Year 2022, each University campus was required to complete and post 8 reports (four Student Aid and four Institutional) to their website. During Fiscal Year 2022, the University?s three campuses in total expended approximately $60 million in HEERF grant funds: $27 million was expended by the Boulder campus, $10.5 million was expended by the Colorado Springs campus, and $22.5 million was expended by the Denver campus. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over and complied with the HEERF grant reporting requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls over the HEERF grant reporting requirements. In addition, we tested 11 of the 12 student reports and 3 of the 12 institutional reports posted by the University during Fiscal Year 2022 to determine whether the University campuses posted the required information on each campus? website accurately, and by the federal due dates. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? The DOE issued a notice on May 13, 2021, requiring institutions to publicly post their required HEERF reports on the institution?s website as soon as possible, but no later than 30 days after the publication of the notice, or 30 days after the date the DOE first obligated funds under HEERF I, II, or III to the institution for emergency financial assistance to students; whichever comes later. The institution is required to post the report no later than 10 days after the end of each calendar quarter, after the initial posting. ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problem did the audit work identify? We identified 2 out of the 14 reports tested (14.3 percent) that did not meet the HEERF grant report posting requirements. Specifically, the University of Colorado, Colorado Springs Campus, did not post the required information for the HEERF Student Aid Portion on its website for two of four quarters of Fiscal Year 2022 timely. First, the University posted the quarter-ending September 30, 2021 report to its website on December 23, 2021, or 74 days after the deadline of October 10. Second, the University did not post the quarter-ending March 31, 2022 report, which was due April 10, 2022, until October 2022, after we notified them of the error; this was approximately 6 months late. We did not identify any issues with the accuracy of the reports, and we found that the other two campuses in the University of Colorado System posted the required information on their respective websites as required by federal regulations. Why did this problem occur? The University?s Colorado Springs campus did not have adequate internal controls in place to ensure it complied with the HEERF grant reporting requirements. Specifically, the Colorado Springs Campus did not have appropriate policies and procedures in place for identifying and researching changes in HEERF reporting requirements. The federal government updated and provided a new form for HEERF reporting in September 2021 that included a section for institutional information but inadvertently excluded student information from the form. Because the form no longer required the student information, the Colorado Springs campus staff inaccurately assumed that the student information was no longer required to be reported. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in the DOE Certification and Agreement that is signed and agreed to by the University. By failing to report required information in accordance with federal regulations, the University failed to comply with the requirements of the HEERF program and potentially risks repercussions from the DOE as specified in the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-064 The University of Colorado?s Colorado Springs campus should strengthen its internal controls over and ensure that it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by establishing policies and procedures for identifying and researching changes in HEERF reporting requirements and posting reports to the campus website as required by federal regulations. Response University of Colorado Agree Implementation Date: Implemented Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting. This process has been duplicated with the annual reporting process. Before the annual report is submitted a review will be done to verify the report figures match the CU financials for the calendar year.
Finding 2022-062 Higher Education Emergency Relief Fund Student Aid Finding The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to higher education institutions, including the University, under the HEERF program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA) was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. Since March 11, 2021, the University has been awarded $45.6 million in HEERF grant funds through the American Rescue Plan (ARP), otherwise known as HEERF III. Of this award, the University was provided both 1) Student Aid monies, along with 2) Institutional Aid monies. Student Aid monies must be used to provide financial aid grants to students (including students exclusively enrolled in distance education), which may be used for ?any component of the student?s cost of attendance or for emergency costs that arise due to coronavirus, such as tuition, food, housing, healthcare (including mental health care), or childcare. Institutional Aid monies may be used to defray expenses associated with coronavirus (including lost revenue, reimbursement for expenses already incurred, technology costs associated with a transition to distance education, faculty and staff trainings, and payroll) and to make additional financial grants to students. During Fiscal Year 2022, the University spent $21.0 million for the Student Aid portion and $20.2 million for the Institutional portion of HEERF III funds. For the Student Aid portion of the HEERF III funding, the University divided the funding into different groups. The University developed a written plan (that applied during Fiscal Year 2022) for each group and a control process for awarding the monies to students. One of the groups of funding was to be awarded to students with unpaid balances in their tuition or auxiliary accounts with past due balances incurred during the 2020-2021 or 2021-2022 academic years. A team of University employees (CARES Team) was tasked with identifying those students, then contacting those students and asking if they would like the University to apply the student?s HEERF award to pay down the student?s account balance or pay it to the student directly. Once the student informed the University of their election, then the University awarded and disbursed the funds. What was the purpose of our audit work and what was performed? The purpose of the audit work was to determine whether the University was in compliance with the HEERF program regulations for awarding and paying the Student Aid portion of the HEERF funding, and whether proper controls were in place over the program during Fiscal Year 2022. Our testing included conducting interviews with management and selecting a sample of 60 disbursements made to students during Fiscal Year 2022 to test controls and compliance. We performed testing on the 60 disbursements to determine whether awards and disbursements were made in accordance with the University?s documented plan. How were the results of the audit work measured? In accordance with HEERF III requirements, the University must prioritize student aid distributions to students with exceptional needs. In addition, the University must have a documented plan to distribute funds to students. Federal regulations [2 CFR 200.303] require any non-federal grant award recipient to establish and maintain effective internal control over the federal award that provides reasonable assurance that the grant award recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. Lastly, student aid application best practices discourage employees from awarding aid to family members. What problem did the audit work identify? Based on interviews with University management, the University identified that a University employee inappropriately provided $700 in HEERF Student Aid funding to the employee?s family member who was a student at the University but was not eligible to receive the funds. Specifically, the CARES Team selected students to receive these funds that met the following criteria: 1) Student was enrolled in the Fall of 2021 or Spring 2022, 2) student had past due balances incurred during the 2020-2021 or 2021-2022 academic years, 3) the student was in good academic standing, and 4) they were participating in a payment plan or in the College Completion Advising program. The student was not selected by the CARES Team as eligible to receive these funds. During our testing of additional 60 student disbursement transactions we found no other exceptions. Why did this problem occur? The University has not established proper segregation of duties to prevent University employees from awarding federal funding to a member of their family. Specifically, the employee had access rights within the University?s financial aid system that granted the employee the ability to both award and disburse federal funds without another employee reviewing or approving. In addition, the University did not have a written policy, as recommended by industry best practices, that prohibits employees from applying aid to family members? accounts. Why does this problem matter? Federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the University to the federal granting agency. Without ensuring adequate segregation of duties within the University?s financial aid system for awarding and disbursing federal funds, the University increases the risk that fraud could occur. In the instance identified, the University recovered the funding from the student. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-062 Metropolitan State University of Denver (University) should improve its internal controls over federal Higher Education Emergency Relief Funds by instituting appropriate segregation of duties over the awarding of federal funds to students. This should include requiring that no one employee can both award then disburse aid to students and developing and implementing a formal written policy that prohibits University employees from awarding financial aid to their family members. Response Metropolitan State University Agree Implementation Date: June 2023 In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
Finding 2022-063 Higher Education Emergency Relief Fund Reporting Compliance Finding The CARES Act was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the (HEERF Program. CRRSAA was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the University has been awarded a total of $86.3 million in HEERF funding. From inception through June 30, 2022, the University spent $35.4 million for the HEERF program Student Aid Portion and $48.9 million for the HEERF program Institutional Portion. The University reports that it will spend the remaining amount of funding during Fiscal Year 2023. The University signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate the University?s acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the federal ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the University?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 5 of the 8 HEERF reports submitted by the University during Fiscal Year 2022 to determine whether the reports were posted on the University?s primary website or submitted directly to the ED by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after the award date, and to update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA require an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the University, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The University signed a HEERF Certification and Agreement to accept the funding and acknowledge its responsibilities under the grant; therefore, the University was responsible under the Agreement to ensure that it complied with HEERF reporting and other requirements. What problems did the audit work identify? We determined that 2 out of 5 reports tested (40 percent) did not meet the HEERF grant report posting requirements. Specifically: ? The University did not post the HEERF CRRSAA Student quarterly report for the quarter ending September 30, 2021 on the University?s primary website, as required. ? The University published the HEERF ARP Student quarterly report for the quarter ending March 31, 2022 on May 26, 2022?46 days past the due date of April 10, 2022. No issues were noted on the accuracy of the financial information on this report. Why did these problems occur? The University did not implement adequate internal controls to ensure it complied with the HEERF grant reporting requirements. Specifically, the University did not have appropriate policies and procedures in place to ensure that staff submit the required reports within federally required timeframes. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-063 Metropolitan State University of Denver (University) should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing and documenting policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the University?s website the required reports within federally required timeframes. In addition, the University should ensure that all the HEERF reports that are currently required to be posted are on the website. Response Metropolitan State University Agree Implementation Date: December 2022 In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
Finding 2022-059 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF I) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund (Assistance Listing No. 84.425). The HEERF program contains two portions: the Student Aid portion (Assistance Listing No. 84.425E) and the Institutional portion, which is made up of the following: HEERF Institutional Aid Portion (Assistance Listing No. 84.425F), HEERF Minority Serving Institutions (Assistance Listing No. 84.425L), HEERF Strengthening Institutions Program (Assistance Listing No. 84.425M), Institutional Resilience and Expanded Postsecondary Opportunity (Assistance Listing No. 84.425P), and HEERF Supplemental Assistance to Institutions of Higher Education program (Assistance Listing No. 84.425S). Amounts provided to students through HEERF are considered to be ?Emergency Financial Aid Grants to Students? under the Program. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent approximately $97.8 million for the HEERF program Student Aid portion which is used to award Emergency Financial Aid Grants to students and $113.9 million for the HEERF Institutional Portion, which is used to support the colleges. $117.3 of this amount was expended by the System during Fiscal Year 2022. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the ED to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The annual report is to be submitted directly to the ED. The ED has specified certain criteria that must be included in each report. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over, and complied with, the HEERF Institutional and Student Aid grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 25 of the 117 HEERF reports submitted by the System?s campuses during Fiscal Year 2022 to determine whether the reports were posted on each campus? primary website (quarterly reports) or submitted to ED (annual reports) by the federal due dates. Furthermore, for the Student Aid Quarterly Report we requested from each Campus the underlying support for the reports, which consisted of student data detailing how much aid was awarded and the methods the campuses used to determine which students would receive Emergency Financial Aid Grants. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? On May 13, 2021, the ED published in the Federal Register a notice for student aid public reporting under CRRSAA and ARP, which requires that institutions publicly post certain information on their website. The following information must appear in a format and location that is easily accessible to the public: o An acknowledgement that the institution signed and returned to the ED the Certification and Agreement and the assurance that the institution has used the applicable amount of funds designated under the CRRSAA and ARP programs to provide Emergency Financial Aid Grants to Students. o The total amount of funds that the institution will receive or has received from the ED pursuant to the institution's Certification and Agreement for Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total amount of Emergency Financial Aid Grants distributed to students under the CRRSAA and ARP programs as of the date of submission (i.e., as of the initial report and every calendar quarter thereafter). o The estimated total number of students at the institution that are eligible to receive Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total number of students who have received an Emergency Financial Aid Grant to students under the CRRSAA and ARP programs. o The method(s) used by the institution to determine which students receive Emergency Financial Aid Grants and how much they would receive under the CRRSAA and ARP programs. o Any instructions, directions, or guidance provided by the institution to students concerning the Emergency Financial Aid Grants. ? Federal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that federal reports are accurate and report complete information. Appropriate supporting documentation is evidence of such internal controls. What problems did the audit work identify? We identified issues with 5 of the 25 Fiscal Year 2022 reports we tested (20 percent). Specifically, Front Range Community College (FRCC), Pueblo Community College (PCC), and Lamar Community College (LCC) could not provide appropriate supporting documentation for one or more of the following data elements in five of the Student Aid Quarterly Reports: student data detailing (a) the total amount of Emergency Financial Aid Grants distributed to students, (b) the total number of students eligible to receive Emergency Financial Aid Grants and/or (c) the total number of students at the institution who have received an Emergency Financial Aid Grant. The specific issues we found the following: ? FRCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended September 30, 2021 as 20,684; based on our review, we determined the supported number was 20,782. ? FRCC reported the total number of students at the institution who have received an Emergency Financial Aid Grant for the quarter ended June 30, 2022 as 20,385 (student portion) and 3,207 (institutional portion); based on our review, we determined the supported numbers were 20,401 and 3,222, respectively. ? LCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended June 30, 2022 as 1,007; based on our review, we determined the supported number was 1,034. In addition, the amount disbursed directly to student emergency financial aid grants to date was reported as 961 and total for all HEERF funds was 1,124; based on our review, we determined the supported numbers were 988 and 1,151, respectively. ? PCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarters ending September 30, 2021 and December 31, 2021 as 3,191; based on our review, we determined this amount could not be supported and PCC did not provide a revised count. Why did these problems occur? FRCC, PCC, and LCC campuses did not have procedures in place to ensure that supporting documentation was maintained for its Student Aid Quarterly Reporting. Employee turnover in the FRCC Controller position and FRCC, PCC, and LCC Student Financial Aid Director positions further contributed to FRCC, PCC, and LCC?s inability to locate or recreate the supporting documentation. Why do these problems matter? It is important for FRCC, PCC, and LCC to ensure that they obtain and maintain appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining FRCC, PCC, and LCC?s compliance with specific federal program requirements. This issue could lead to inaccurate federal reporting and potential noncompliance, which could result in the federal government requiring FRCC, PCC, and LCC to return funds or a negative impact to the System?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-059 Front Range Community College, Lamar Community College, and Pueblo Community College campuses should strengthen their internal controls over federal reporting and ensure they comply with the Higher Education Emergency Relief Fund reporting requirements by reviewing reports for accuracy and developing procedures for ensuring the required maintenance of all related supporting documentation. Response Front Range Community College Agree Implementation Date: September 2022 Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Response Lamar Community College Agree Implementation Date: July 2022 The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Response Pueblo Community College Agree Implementation Date: October 2022 Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Finding 2022-064 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide emergency financial assistance to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF I) Program. The federal Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the federal American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Each of the University?s campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (DOE) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements of the HEERF program there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The DOE specified that the Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The University?s campuses are required to submit the annual report directly to the DOE. During Fiscal Year 2022, each University campus was required to complete and post 8 reports (four Student Aid and four Institutional) to their website. During Fiscal Year 2022, the University?s three campuses in total expended approximately $60 million in HEERF grant funds: $27 million was expended by the Boulder campus, $10.5 million was expended by the Colorado Springs campus, and $22.5 million was expended by the Denver campus. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over and complied with the HEERF grant reporting requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls over the HEERF grant reporting requirements. In addition, we tested 11 of the 12 student reports and 3 of the 12 institutional reports posted by the University during Fiscal Year 2022 to determine whether the University campuses posted the required information on each campus? website accurately, and by the federal due dates. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? The DOE issued a notice on May 13, 2021, requiring institutions to publicly post their required HEERF reports on the institution?s website as soon as possible, but no later than 30 days after the publication of the notice, or 30 days after the date the DOE first obligated funds under HEERF I, II, or III to the institution for emergency financial assistance to students; whichever comes later. The institution is required to post the report no later than 10 days after the end of each calendar quarter, after the initial posting. ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problem did the audit work identify? We identified 2 out of the 14 reports tested (14.3 percent) that did not meet the HEERF grant report posting requirements. Specifically, the University of Colorado, Colorado Springs Campus, did not post the required information for the HEERF Student Aid Portion on its website for two of four quarters of Fiscal Year 2022 timely. First, the University posted the quarter-ending September 30, 2021 report to its website on December 23, 2021, or 74 days after the deadline of October 10. Second, the University did not post the quarter-ending March 31, 2022 report, which was due April 10, 2022, until October 2022, after we notified them of the error; this was approximately 6 months late. We did not identify any issues with the accuracy of the reports, and we found that the other two campuses in the University of Colorado System posted the required information on their respective websites as required by federal regulations. Why did this problem occur? The University?s Colorado Springs campus did not have adequate internal controls in place to ensure it complied with the HEERF grant reporting requirements. Specifically, the Colorado Springs Campus did not have appropriate policies and procedures in place for identifying and researching changes in HEERF reporting requirements. The federal government updated and provided a new form for HEERF reporting in September 2021 that included a section for institutional information but inadvertently excluded student information from the form. Because the form no longer required the student information, the Colorado Springs campus staff inaccurately assumed that the student information was no longer required to be reported. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in the DOE Certification and Agreement that is signed and agreed to by the University. By failing to report required information in accordance with federal regulations, the University failed to comply with the requirements of the HEERF program and potentially risks repercussions from the DOE as specified in the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-064 The University of Colorado?s Colorado Springs campus should strengthen its internal controls over and ensure that it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by establishing policies and procedures for identifying and researching changes in HEERF reporting requirements and posting reports to the campus website as required by federal regulations. Response University of Colorado Agree Implementation Date: Implemented Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting. This process has been duplicated with the annual reporting process. Before the annual report is submitted a review will be done to verify the report figures match the CU financials for the calendar year.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Finding 2022-059 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF I) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund (Assistance Listing No. 84.425). The HEERF program contains two portions: the Student Aid portion (Assistance Listing No. 84.425E) and the Institutional portion, which is made up of the following: HEERF Institutional Aid Portion (Assistance Listing No. 84.425F), HEERF Minority Serving Institutions (Assistance Listing No. 84.425L), HEERF Strengthening Institutions Program (Assistance Listing No. 84.425M), Institutional Resilience and Expanded Postsecondary Opportunity (Assistance Listing No. 84.425P), and HEERF Supplemental Assistance to Institutions of Higher Education program (Assistance Listing No. 84.425S). Amounts provided to students through HEERF are considered to be ?Emergency Financial Aid Grants to Students? under the Program. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent approximately $97.8 million for the HEERF program Student Aid portion which is used to award Emergency Financial Aid Grants to students and $113.9 million for the HEERF Institutional Portion, which is used to support the colleges. $117.3 of this amount was expended by the System during Fiscal Year 2022. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the ED to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The annual report is to be submitted directly to the ED. The ED has specified certain criteria that must be included in each report. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over, and complied with, the HEERF Institutional and Student Aid grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 25 of the 117 HEERF reports submitted by the System?s campuses during Fiscal Year 2022 to determine whether the reports were posted on each campus? primary website (quarterly reports) or submitted to ED (annual reports) by the federal due dates. Furthermore, for the Student Aid Quarterly Report we requested from each Campus the underlying support for the reports, which consisted of student data detailing how much aid was awarded and the methods the campuses used to determine which students would receive Emergency Financial Aid Grants. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? On May 13, 2021, the ED published in the Federal Register a notice for student aid public reporting under CRRSAA and ARP, which requires that institutions publicly post certain information on their website. The following information must appear in a format and location that is easily accessible to the public: o An acknowledgement that the institution signed and returned to the ED the Certification and Agreement and the assurance that the institution has used the applicable amount of funds designated under the CRRSAA and ARP programs to provide Emergency Financial Aid Grants to Students. o The total amount of funds that the institution will receive or has received from the ED pursuant to the institution's Certification and Agreement for Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total amount of Emergency Financial Aid Grants distributed to students under the CRRSAA and ARP programs as of the date of submission (i.e., as of the initial report and every calendar quarter thereafter). o The estimated total number of students at the institution that are eligible to receive Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total number of students who have received an Emergency Financial Aid Grant to students under the CRRSAA and ARP programs. o The method(s) used by the institution to determine which students receive Emergency Financial Aid Grants and how much they would receive under the CRRSAA and ARP programs. o Any instructions, directions, or guidance provided by the institution to students concerning the Emergency Financial Aid Grants. ? Federal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that federal reports are accurate and report complete information. Appropriate supporting documentation is evidence of such internal controls. What problems did the audit work identify? We identified issues with 5 of the 25 Fiscal Year 2022 reports we tested (20 percent). Specifically, Front Range Community College (FRCC), Pueblo Community College (PCC), and Lamar Community College (LCC) could not provide appropriate supporting documentation for one or more of the following data elements in five of the Student Aid Quarterly Reports: student data detailing (a) the total amount of Emergency Financial Aid Grants distributed to students, (b) the total number of students eligible to receive Emergency Financial Aid Grants and/or (c) the total number of students at the institution who have received an Emergency Financial Aid Grant. The specific issues we found the following: ? FRCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended September 30, 2021 as 20,684; based on our review, we determined the supported number was 20,782. ? FRCC reported the total number of students at the institution who have received an Emergency Financial Aid Grant for the quarter ended June 30, 2022 as 20,385 (student portion) and 3,207 (institutional portion); based on our review, we determined the supported numbers were 20,401 and 3,222, respectively. ? LCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended June 30, 2022 as 1,007; based on our review, we determined the supported number was 1,034. In addition, the amount disbursed directly to student emergency financial aid grants to date was reported as 961 and total for all HEERF funds was 1,124; based on our review, we determined the supported numbers were 988 and 1,151, respectively. ? PCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarters ending September 30, 2021 and December 31, 2021 as 3,191; based on our review, we determined this amount could not be supported and PCC did not provide a revised count. Why did these problems occur? FRCC, PCC, and LCC campuses did not have procedures in place to ensure that supporting documentation was maintained for its Student Aid Quarterly Reporting. Employee turnover in the FRCC Controller position and FRCC, PCC, and LCC Student Financial Aid Director positions further contributed to FRCC, PCC, and LCC?s inability to locate or recreate the supporting documentation. Why do these problems matter? It is important for FRCC, PCC, and LCC to ensure that they obtain and maintain appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining FRCC, PCC, and LCC?s compliance with specific federal program requirements. This issue could lead to inaccurate federal reporting and potential noncompliance, which could result in the federal government requiring FRCC, PCC, and LCC to return funds or a negative impact to the System?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-059 Front Range Community College, Lamar Community College, and Pueblo Community College campuses should strengthen their internal controls over federal reporting and ensure they comply with the Higher Education Emergency Relief Fund reporting requirements by reviewing reports for accuracy and developing procedures for ensuring the required maintenance of all related supporting documentation. Response Front Range Community College Agree Implementation Date: September 2022 Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Response Lamar Community College Agree Implementation Date: July 2022 The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Response Pueblo Community College Agree Implementation Date: October 2022 Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.
Finding 2022-062 Higher Education Emergency Relief Fund Student Aid Finding The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to higher education institutions, including the University, under the HEERF program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA) was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. Since March 11, 2021, the University has been awarded $45.6 million in HEERF grant funds through the American Rescue Plan (ARP), otherwise known as HEERF III. Of this award, the University was provided both 1) Student Aid monies, along with 2) Institutional Aid monies. Student Aid monies must be used to provide financial aid grants to students (including students exclusively enrolled in distance education), which may be used for ?any component of the student?s cost of attendance or for emergency costs that arise due to coronavirus, such as tuition, food, housing, healthcare (including mental health care), or childcare. Institutional Aid monies may be used to defray expenses associated with coronavirus (including lost revenue, reimbursement for expenses already incurred, technology costs associated with a transition to distance education, faculty and staff trainings, and payroll) and to make additional financial grants to students. During Fiscal Year 2022, the University spent $21.0 million for the Student Aid portion and $20.2 million for the Institutional portion of HEERF III funds. For the Student Aid portion of the HEERF III funding, the University divided the funding into different groups. The University developed a written plan (that applied during Fiscal Year 2022) for each group and a control process for awarding the monies to students. One of the groups of funding was to be awarded to students with unpaid balances in their tuition or auxiliary accounts with past due balances incurred during the 2020-2021 or 2021-2022 academic years. A team of University employees (CARES Team) was tasked with identifying those students, then contacting those students and asking if they would like the University to apply the student?s HEERF award to pay down the student?s account balance or pay it to the student directly. Once the student informed the University of their election, then the University awarded and disbursed the funds. What was the purpose of our audit work and what was performed? The purpose of the audit work was to determine whether the University was in compliance with the HEERF program regulations for awarding and paying the Student Aid portion of the HEERF funding, and whether proper controls were in place over the program during Fiscal Year 2022. Our testing included conducting interviews with management and selecting a sample of 60 disbursements made to students during Fiscal Year 2022 to test controls and compliance. We performed testing on the 60 disbursements to determine whether awards and disbursements were made in accordance with the University?s documented plan. How were the results of the audit work measured? In accordance with HEERF III requirements, the University must prioritize student aid distributions to students with exceptional needs. In addition, the University must have a documented plan to distribute funds to students. Federal regulations [2 CFR 200.303] require any non-federal grant award recipient to establish and maintain effective internal control over the federal award that provides reasonable assurance that the grant award recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. Lastly, student aid application best practices discourage employees from awarding aid to family members. What problem did the audit work identify? Based on interviews with University management, the University identified that a University employee inappropriately provided $700 in HEERF Student Aid funding to the employee?s family member who was a student at the University but was not eligible to receive the funds. Specifically, the CARES Team selected students to receive these funds that met the following criteria: 1) Student was enrolled in the Fall of 2021 or Spring 2022, 2) student had past due balances incurred during the 2020-2021 or 2021-2022 academic years, 3) the student was in good academic standing, and 4) they were participating in a payment plan or in the College Completion Advising program. The student was not selected by the CARES Team as eligible to receive these funds. During our testing of additional 60 student disbursement transactions we found no other exceptions. Why did this problem occur? The University has not established proper segregation of duties to prevent University employees from awarding federal funding to a member of their family. Specifically, the employee had access rights within the University?s financial aid system that granted the employee the ability to both award and disburse federal funds without another employee reviewing or approving. In addition, the University did not have a written policy, as recommended by industry best practices, that prohibits employees from applying aid to family members? accounts. Why does this problem matter? Federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the University to the federal granting agency. Without ensuring adequate segregation of duties within the University?s financial aid system for awarding and disbursing federal funds, the University increases the risk that fraud could occur. In the instance identified, the University recovered the funding from the student. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-062 Metropolitan State University of Denver (University) should improve its internal controls over federal Higher Education Emergency Relief Funds by instituting appropriate segregation of duties over the awarding of federal funds to students. This should include requiring that no one employee can both award then disburse aid to students and developing and implementing a formal written policy that prohibits University employees from awarding financial aid to their family members. Response Metropolitan State University Agree Implementation Date: June 2023 In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
Finding 2022-063 Higher Education Emergency Relief Fund Reporting Compliance Finding The CARES Act was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the (HEERF Program. CRRSAA was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the University has been awarded a total of $86.3 million in HEERF funding. From inception through June 30, 2022, the University spent $35.4 million for the HEERF program Student Aid Portion and $48.9 million for the HEERF program Institutional Portion. The University reports that it will spend the remaining amount of funding during Fiscal Year 2023. The University signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate the University?s acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the federal ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the University?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 5 of the 8 HEERF reports submitted by the University during Fiscal Year 2022 to determine whether the reports were posted on the University?s primary website or submitted directly to the ED by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after the award date, and to update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA require an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the University, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The University signed a HEERF Certification and Agreement to accept the funding and acknowledge its responsibilities under the grant; therefore, the University was responsible under the Agreement to ensure that it complied with HEERF reporting and other requirements. What problems did the audit work identify? We determined that 2 out of 5 reports tested (40 percent) did not meet the HEERF grant report posting requirements. Specifically: ? The University did not post the HEERF CRRSAA Student quarterly report for the quarter ending September 30, 2021 on the University?s primary website, as required. ? The University published the HEERF ARP Student quarterly report for the quarter ending March 31, 2022 on May 26, 2022?46 days past the due date of April 10, 2022. No issues were noted on the accuracy of the financial information on this report. Why did these problems occur? The University did not implement adequate internal controls to ensure it complied with the HEERF grant reporting requirements. Specifically, the University did not have appropriate policies and procedures in place to ensure that staff submit the required reports within federally required timeframes. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-063 Metropolitan State University of Denver (University) should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing and documenting policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the University?s website the required reports within federally required timeframes. In addition, the University should ensure that all the HEERF reports that are currently required to be posted are on the website. Response Metropolitan State University Agree Implementation Date: December 2022 In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-058 Pueblo Community College should strengthen their internal controls over procurement, suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures and that staff perform procedures to verify contracted entities are not excluded or disqualified from receiving federal funds. B. Ensuring staff maintain supporting documentation for procurements and suspension and debarment checks. C. Providing training and cross-training to existing employees over procurement, suspension and debarment requirements. Response Pueblo Community College A. Agree Implementation Date: September 2022 Going forward, the Director of Purchasing will perform all Sam.Gov searches. The secondary reviews to ensure compliance for the System's procurement and suspension and debarment procedures will be conducted by the Vice President of Administration and Finance. B. Agree Implementation Date: September 2022 The corresponding documents supporting procurement transactions and suspension and debarment checks will be scanned and filed along with the Purchase order. C. Agree Implementation Date: September 2022 Training will be provided to fiscal and grant staff for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase documentation.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-057 Otero College should strengthen their internal controls over procurement and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements and State procurement policies by: A. Ensuring the secondary reviewer enforces compliance with the Colorado Community College System?s (System) procurement procedures. B. Ensuring staff maintain supporting documentation for procurements. C. Providing training and cross-training to existing employees over procurement requirements. Response Otero College A. Agree Implementation Date: August 2022 Otero College has adopted the system offices Sole Source justification form that will be posted to the State procurement site, requires supervisory approval, and has put that into place as of August 2022. B. Agree Implementation Date: August 2022 Otero College will ensure they maintain supporting documentation for procurements. C. Agree Implementation Date: August 2022 Otero College has a new procurement official that has attended various trainings regarding procurement rules.
Findings 2022-056, 2022-057, and 2022-058 Higher Education Emergency Relief Fund (HEERF) Procurement Compliance The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: The Student Aid portion [ALN 84.425E] and the Institutional portion, which is made up of the following: ? HEERF Institutional Aid Portion (ALN 84.425F); ? HEERF Minority Serving Institutions (ALN 84.425L); ? HEERF Strengthening Institutions Program (ALN 84.425M); ? Institutional Resilience and Expanded Postsecondary Opportunity (ALN 84.425P); ? HEERF Supplemental Assistance to Institutions of Higher Education program (ALN 84.425S). Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent a total of approximately $97.8 million for the HEERF program Student Aid portion and $113.9 million for the HEERF Institutional Portion. During Fiscal Year 2022, the System spent $71.9 million for the Student Aid portion and $45.1 million for the Institutional Portion; of this amount, $28.7 million represented the System?s procurement for goods and services. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements, each campus is required to follow the State?s procurement policies and procedures. Federal procurement regulations also require that each campus include any clauses required by federal regulations in every HEERF-related purchase order or other contract. In addition, non-federal entities, including the System and its campuses, are prohibited from contracting with or making subawards under ?covered transactions? to parties that are suspended or debarred from doing business with the federal government. ?Covered transactions? include those procurement contracts for goods and services awarded under a grant or cooperative agreement. In order to comply with federal suspension and debarment requirements, the campuses can perform a search in the federal System of Award Management (SAM) website, which tracks the entities that the federal government has determined are ineligible to receive federal funding; collect a certification from the entity; or add a clause or condition to the contract. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System?s campuses had effective internal controls in place over, and complied with, federal procurement and suspension and debarment requirements for the HEERF grant during Fiscal Year 2022. As part of our audit work, we reviewed the campuses? internal controls over the HEERF grant procurement requirements. In addition, we tested a sample of 60 of the campuses? HEERF-related 435 procurement transactions, totaling $18.8 million, to determine if the campuses were in compliance with federal procurement requirements, and whether the campuses? contractors were suspended, debarred, or otherwise excluded from participating in the contract by the federal government, through verification on the SAM website exclusions listing. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? Federal regulation [2 CFR 180.220] states that a contract for goods or services is a covered transaction if awarded as a grant or payment for specified use and if the amount of the contract is expected to equal or exceed $25,000. Also, federal regulation [2 CFR 180.300] requires that when a non-federal entity enters into a covered transaction with another entity, the non-federal entity must verify that the person or entity they intend to do business with is not excluded or disqualified from receiving federal funds. This can be done by: (1) checking the SAM exclusions, (2) collecting a certification from that entity, or (3) adding a clause or condition to the covered transaction with that entity. ? Federal regulation [2 CFR 200.303] states that the System and its campuses, as recipients of federal funds, must establish and maintain effective internal control over their federal awards that provides reasonable assurance that the System?s campuses are managing the federal awards in compliance with federal statutes, regulations, and the award terms and conditions. ? Federal regulation [2 CFR 200.318] states that the System must document procurement procedures. The System and its campuses utilize Colorado Revised Statute Section 24, Government -State, Procurement Code; Articles 101- 112, as their procurement policy. Relevant sections of the policy include: o R-24-103-201-01 Purchasing Thresholds - (b) Small purchases are goods and services purchases costing less than $150,000. Goods and services between $25,000 and $150,000 may be purchased using a documented quote process, described in rule R-24-103-204-01. o R-24-103-201-01 Purchasing Thresholds - (c) Invitation for bids, described in rule R-24-103-202-01, request for proposals, described in rule R-24-103-203, and invitations to negotiate, described in rule R-24-103-208-03, may be used for goods or services estimated to exceed the small purchase threshold of $150,000. o R-24-103-205 Sole Source Procurements -Contracts may be awarded by use of a sole source procurement only if the following conditions are met: (a) A sole source procurement is justified when there is only one good or service that can reasonably meet the need and there is only one vendor who can provide the good or service. A requirement for a particular proprietary item (i.e., a brand name specification) does not justify a sole source procurement if there is more than one potential bidder or offeror for that item; (b) The procurement official or his or her designee shall make a written determination that a procurement is sole source, setting forth the reasons. In cases of reasonable doubt, competition should be solicited. Any request by a using agency that a procurement be restricted to one potential contractor shall be accompanied by an explanation as to why no other contractors will be suitable or acceptable to meet the need. What problems did the audit work identify? We identified at least one issue with 34 of the 60 transactions tested (57 percent), which resulted in a total of $3,254,216 in known federal questioned costs. In total, we identified 43 errors within the 34 transactions tested. Specifically, we identified the following: ? Community College of Aurora (CCA) and Pueblo Community College (PCC) could not provide documentation to support that suspension and debarment verification procedures were performed for nine transactions we reviewed for CCA and for 21 transactions we reviewed for PCC. We confirmed through additional audit work that none of the vendors were suspended or debarred; as a result, we determined that these errors did not result in questioned costs. ? Otero College (OC) did not complete the required Sole Source justification for four transactions. These errors resulted in $1,535,455 of questioned costs. ? PCC did not perform a request for proposals for two transactions which exceeded $150,000 and did not obtain documented quotes for seven transactions which were between $25,000 and $150,000, as required. These errors resulted in questioned costs of $1,718,761. Why did these problems occur? OC and PCC did not have adequate internal controls in place to ensure they complied with HEERF procurement requirements. In addition, CCA and PCC did not have adequate internal controls in place to ensure they complied with HEERF suspension and debarment requirements. Specifically, at OC and PCC, the secondary reviewer did not require staff follow procedures in place for procurement. At PCC the secondary reviewer also did not ensure that staff searched the federal System of Award Management to verify that entities it contracted with were not suspended, debarred, or otherwise excluded from participating in a contract for federal funds. In addition, they did not provide training over grant processes related to state procurement rules, such as training on requirements for staff to maintain appropriate supporting documentation for procurement-related verifications and procurement decisions. Further, CCA and OC experienced staff turnover in key positions, and existing employees could not locate the supporting documentation. Why do these problems matter? It is important for CCA, OC, and PCC to ensure that they obtain and maintain appropriate documentation to support procurement decisions, especially when they are the basis for determining CCA, OC, and PCC?s compliance with specific HEERF program requirements. In addition, CCA and PCC?s failure to perform procedures to ensure an entity is not suspended or debarred could result in the System paying funds to an entity that is disallowed from receiving such funds, thereby exposing the State to increased business risk and potential federal disallowances. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-056 Community College of Aurora should strengthen their internal controls over suspension and debarment and ensure they comply with the Higher Education Emergency Relief Fund (HEERF) requirements by: A. Ensuring staff maintain supporting documentation of suspension and debarment checks. B. Providing training and cross-training to existing employees over suspension and debarment requirements. Response Community College of Aurora A. Agree Implementation Date: October 2022 Beginning in October 2022, the duty was moved from the Principal Investigator or instructional staff previously responsible for this step to the Director of Purchasing to ensure compliance for all grant transactions. B. Agree Implementation Date: October 2022 Training will be provided for identifying when suspension and debarment must be checked for vendors of federal programs, processes and websites to access, and methodology for documenting with the purchase, to fiscal and grant staff
Finding 2022-063 Higher Education Emergency Relief Fund Reporting Compliance Finding The CARES Act was signed into law on March 27, 2020, and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the (HEERF Program. CRRSAA was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Since April 2020, the University has been awarded a total of $86.3 million in HEERF funding. From inception through June 30, 2022, the University spent $35.4 million for the HEERF program Student Aid Portion and $48.9 million for the HEERF program Institutional Portion. The University reports that it will spend the remaining amount of funding during Fiscal Year 2023. The University signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (ED) to indicate the University?s acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The ED specified that Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The annual report is to be submitted directly to the federal ED. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University had adequate internal controls in place over and complied with HEERF Institutional and Student Aid Portion grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the University?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 5 of the 8 HEERF reports submitted by the University during Fiscal Year 2022 to determine whether the reports were posted on the University?s primary website or submitted directly to the ED by the federal due dates and complied with federal regulations. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? For the Student Aid Portion, beginning on May 6, 2020, the ED required institutions to publicly post certain information on their website, including the number of awards distributed to students, the total amount awarded, and the methodologies used by the institution to determine which students receive awards, no later than 30 days after the award date, and to update that information every 45 days thereafter (by posting a new report). ? On August 31, 2020, the ED revised the reporting requirement by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. This revision from every 45 days to a calendar quarter was effective for the first calendar quarter report due by October 10, 2020, and covering the period from after the institution?s last report through the end of the calendar quarter on September 30, 2020. ? For the Institutional Portion, a federal form filled out by the institution must be posted on the institution?s website covering aggregate expenditure amounts for each calendar quarter (September 30, December 31, March 31, and June 30) and concluding after an institution has spent the institutional portion of their HEERF Funds. The institution must post their first report by October 30, 2020, the first quarter of 2021 report by July 20, 2021, and post all other reports no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, and July 10). ? Section 18004(e) of the CARES Act and Section 314(e) of the CRRSAA require an institution receiving funds under HEERF to submit a report to the Secretary of the ED at ?such time in such a manner as the Secretary may require?. ? Federal regulation [2 CFR 200.334] states that ?financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for Federal awards that are renewed quarterly or annually, from the date of the submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient.? The instructions for the Quarterly HEERF Reporting Form notes, ?any changes or updates after the initial posting must be conspicuously noted after initial posting and the date of the change must be noted in the `Date of Report? line.? ? Federal regulation [2 CFR 200.303] states that the University, as a federal grant recipient, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? The University signed a HEERF Certification and Agreement to accept the funding and acknowledge its responsibilities under the grant; therefore, the University was responsible under the Agreement to ensure that it complied with HEERF reporting and other requirements. What problems did the audit work identify? We determined that 2 out of 5 reports tested (40 percent) did not meet the HEERF grant report posting requirements. Specifically: ? The University did not post the HEERF CRRSAA Student quarterly report for the quarter ending September 30, 2021 on the University?s primary website, as required. ? The University published the HEERF ARP Student quarterly report for the quarter ending March 31, 2022 on May 26, 2022?46 days past the due date of April 10, 2022. No issues were noted on the accuracy of the financial information on this report. Why did these problems occur? The University did not implement adequate internal controls to ensure it complied with the HEERF grant reporting requirements. Specifically, the University did not have appropriate policies and procedures in place to ensure that staff submit the required reports within federally required timeframes. Why do these problems matter? Federal oversight agencies, including ED, depend on accurate reports to measure program results and states? compliance with federal requirements. By failing to report the HEERF spending information in accordance with federal regulations, the University failed to comply with the requirements of the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-063 Metropolitan State University of Denver (University) should strengthen its internal controls over reporting and ensure it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by developing and documenting policies and procedures for identifying and researching the specific reporting requirements and ensuring that staff post to the University?s website the required reports within federally required timeframes. In addition, the University should ensure that all the HEERF reports that are currently required to be posted are on the website. Response Metropolitan State University Agree Implementation Date: December 2022 In December 2022, the Office of Financial Aid strengthened its internal control over the reporting requirements for the Higher Education Emergency Relief Fund (HEERF), by adding the report due dates to the internal operational calendar. Additional level reviews were also added to the submission process before the required reports will be sent to the Department of Education and posted on the financial aid website.
Finding 2022-064 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide emergency financial assistance to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the University under the Higher Education Emergency Relief Fund (HEERF I) Program. The federal Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the federal American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal COVID-19 ? Education Stabilization Fund [ALN 84.425]. The HEERF program contains two portions: the Student Aid Portion [ALN 84.425E] and the Institutional Portion [ALN 84.425F]. Each of the University?s campuses separately signed an agreement titled the ?Certification and Agreement? with the U.S. Department of Education (DOE) to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the requirements of the HEERF program there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The DOE specified that the Student Aid Portion and Institutional Portion reports needed to be posted to an institution?s website at specified times. The University?s campuses are required to submit the annual report directly to the DOE. During Fiscal Year 2022, each University campus was required to complete and post 8 reports (four Student Aid and four Institutional) to their website. During Fiscal Year 2022, the University?s three campuses in total expended approximately $60 million in HEERF grant funds: $27 million was expended by the Boulder campus, $10.5 million was expended by the Colorado Springs campus, and $22.5 million was expended by the Denver campus. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the University?s campuses had adequate internal controls in place over and complied with the HEERF grant reporting requirements for Fiscal Year 2022. As part of our audit work, we tested the University?s campuses? internal controls over the HEERF grant reporting requirements. In addition, we tested 11 of the 12 student reports and 3 of the 12 institutional reports posted by the University during Fiscal Year 2022 to determine whether the University campuses posted the required information on each campus? website accurately, and by the federal due dates. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? The DOE issued a notice on May 13, 2021, requiring institutions to publicly post their required HEERF reports on the institution?s website as soon as possible, but no later than 30 days after the publication of the notice, or 30 days after the date the DOE first obligated funds under HEERF I, II, or III to the institution for emergency financial assistance to students; whichever comes later. The institution is required to post the report no later than 10 days after the end of each calendar quarter, after the initial posting. ? Federal regulation [2 CFR 200.303] states that the System?s campuses, as federal grant recipients, must ?establish and maintain effective internal controls over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulation, and the terms and conditions of the Federal award.? What problem did the audit work identify? We identified 2 out of the 14 reports tested (14.3 percent) that did not meet the HEERF grant report posting requirements. Specifically, the University of Colorado, Colorado Springs Campus, did not post the required information for the HEERF Student Aid Portion on its website for two of four quarters of Fiscal Year 2022 timely. First, the University posted the quarter-ending September 30, 2021 report to its website on December 23, 2021, or 74 days after the deadline of October 10. Second, the University did not post the quarter-ending March 31, 2022 report, which was due April 10, 2022, until October 2022, after we notified them of the error; this was approximately 6 months late. We did not identify any issues with the accuracy of the reports, and we found that the other two campuses in the University of Colorado System posted the required information on their respective websites as required by federal regulations. Why did this problem occur? The University?s Colorado Springs campus did not have adequate internal controls in place to ensure it complied with the HEERF grant reporting requirements. Specifically, the Colorado Springs Campus did not have appropriate policies and procedures in place for identifying and researching changes in HEERF reporting requirements. The federal government updated and provided a new form for HEERF reporting in September 2021 that included a section for institutional information but inadvertently excluded student information from the form. Because the form no longer required the student information, the Colorado Springs campus staff inaccurately assumed that the student information was no longer required to be reported. Why does this problem matter? The University is obligated to adhere to specified requirements as outlined in the DOE Certification and Agreement that is signed and agreed to by the University. By failing to report required information in accordance with federal regulations, the University failed to comply with the requirements of the HEERF program and potentially risks repercussions from the DOE as specified in the Certification and Agreement. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-064 The University of Colorado?s Colorado Springs campus should strengthen its internal controls over and ensure that it complies with the Higher Education Emergency Relief Fund (HEERF) reporting requirements by establishing policies and procedures for identifying and researching changes in HEERF reporting requirements and posting reports to the campus website as required by federal regulations. Response University of Colorado Agree Implementation Date: Implemented Management agrees. After the notification of the missing HEERF report in December 2021, the UCCS Controller proposed a ?cross-check? process to ensure all future reporting is in compliance and reported in a timely manner. This process is used for both the quarterly and annual reporting process. In the quarterly reporting process, the UCCS Controller completes the institutional report and emails the report to the UCCS Financial Aid office Senior Executive Director for verification of the amounts and the data submitted. The Senior Executive Director then enters the student aid portion?s information and provides this to the UCCS Controller for verification of the data. Once verified, the report is uploaded to the UCCS website and a confirmation email is sent to the UCCS Controller as well as the heerfreporting@ed.gov for verification of completion of the website posting. This process has been duplicated with the annual reporting process. Before the annual report is submitted a review will be done to verify the report figures match the CU financials for the calendar year.
Finding 2022-062 Higher Education Emergency Relief Fund Student Aid Finding The Coronavirus Aid, Relief, and Economic Security (CARES) Act was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to higher education institutions, including the University, under the HEERF program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA) was signed into law on December 27, 2020 and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. Since March 11, 2021, the University has been awarded $45.6 million in HEERF grant funds through the American Rescue Plan (ARP), otherwise known as HEERF III. Of this award, the University was provided both 1) Student Aid monies, along with 2) Institutional Aid monies. Student Aid monies must be used to provide financial aid grants to students (including students exclusively enrolled in distance education), which may be used for ?any component of the student?s cost of attendance or for emergency costs that arise due to coronavirus, such as tuition, food, housing, healthcare (including mental health care), or childcare. Institutional Aid monies may be used to defray expenses associated with coronavirus (including lost revenue, reimbursement for expenses already incurred, technology costs associated with a transition to distance education, faculty and staff trainings, and payroll) and to make additional financial grants to students. During Fiscal Year 2022, the University spent $21.0 million for the Student Aid portion and $20.2 million for the Institutional portion of HEERF III funds. For the Student Aid portion of the HEERF III funding, the University divided the funding into different groups. The University developed a written plan (that applied during Fiscal Year 2022) for each group and a control process for awarding the monies to students. One of the groups of funding was to be awarded to students with unpaid balances in their tuition or auxiliary accounts with past due balances incurred during the 2020-2021 or 2021-2022 academic years. A team of University employees (CARES Team) was tasked with identifying those students, then contacting those students and asking if they would like the University to apply the student?s HEERF award to pay down the student?s account balance or pay it to the student directly. Once the student informed the University of their election, then the University awarded and disbursed the funds. What was the purpose of our audit work and what was performed? The purpose of the audit work was to determine whether the University was in compliance with the HEERF program regulations for awarding and paying the Student Aid portion of the HEERF funding, and whether proper controls were in place over the program during Fiscal Year 2022. Our testing included conducting interviews with management and selecting a sample of 60 disbursements made to students during Fiscal Year 2022 to test controls and compliance. We performed testing on the 60 disbursements to determine whether awards and disbursements were made in accordance with the University?s documented plan. How were the results of the audit work measured? In accordance with HEERF III requirements, the University must prioritize student aid distributions to students with exceptional needs. In addition, the University must have a documented plan to distribute funds to students. Federal regulations [2 CFR 200.303] require any non-federal grant award recipient to establish and maintain effective internal control over the federal award that provides reasonable assurance that the grant award recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the award. Lastly, student aid application best practices discourage employees from awarding aid to family members. What problem did the audit work identify? Based on interviews with University management, the University identified that a University employee inappropriately provided $700 in HEERF Student Aid funding to the employee?s family member who was a student at the University but was not eligible to receive the funds. Specifically, the CARES Team selected students to receive these funds that met the following criteria: 1) Student was enrolled in the Fall of 2021 or Spring 2022, 2) student had past due balances incurred during the 2020-2021 or 2021-2022 academic years, 3) the student was in good academic standing, and 4) they were participating in a payment plan or in the College Completion Advising program. The student was not selected by the CARES Team as eligible to receive these funds. During our testing of additional 60 student disbursement transactions we found no other exceptions. Why did this problem occur? The University has not established proper segregation of duties to prevent University employees from awarding federal funding to a member of their family. Specifically, the employee had access rights within the University?s financial aid system that granted the employee the ability to both award and disburse federal funds without another employee reviewing or approving. In addition, the University did not have a written policy, as recommended by industry best practices, that prohibits employees from applying aid to family members? accounts. Why does this problem matter? Federal funds that are misapplied or used for unallowable purposes could be subject to repayment from the University to the federal granting agency. Without ensuring adequate segregation of duties within the University?s financial aid system for awarding and disbursing federal funds, the University increases the risk that fraud could occur. In the instance identified, the University recovered the funding from the student. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-062 Metropolitan State University of Denver (University) should improve its internal controls over federal Higher Education Emergency Relief Funds by instituting appropriate segregation of duties over the awarding of federal funds to students. This should include requiring that no one employee can both award then disburse aid to students and developing and implementing a formal written policy that prohibits University employees from awarding financial aid to their family members. Response Metropolitan State University Agree Implementation Date: June 2023 In January 2023, the Executive Director of Financial Aid and Scholarships implemented a code of conduct that addresses and prohibits University personnel from awarding financial aid to their family members or other persons considered conflicts of interest. The Office of Financial Aid and Scholarships will draft policy by June 30, 2023, to address the segregation of duties that prohibits awarding and disbursing federal, state, or institutional funding to students by one employee.
Finding 2022-059 Higher Education Emergency Relief Fund (HEERF) Reporting Compliance The federal Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 and appropriated federal funds to provide economic aid to the American people negatively impacted by the COVID-19 pandemic. As part of the CARES Act, funds were given to the System under the Higher Education Emergency Relief Fund (HEERF I) Program. The Coronavirus Response and Relief Supplemental Appropriations Act, 2021 (CRRSAA), was signed into law on December 27, 2020, and authorized additional funding under the HEERF program (HEERF II). Finally, the American Rescue Plan Act of 2021 (ARP), enacted on March 11, 2021, authorized a third round of funding (HEERF III) in order for higher education institutions to serve students and ensure learning continues during the COVID-19 pandemic. The HEERF Program is one of the subprograms of the federal Education Stabilization Fund (Assistance Listing No. 84.425). The HEERF program contains two portions: the Student Aid portion (Assistance Listing No. 84.425E) and the Institutional portion, which is made up of the following: HEERF Institutional Aid Portion (Assistance Listing No. 84.425F), HEERF Minority Serving Institutions (Assistance Listing No. 84.425L), HEERF Strengthening Institutions Program (Assistance Listing No. 84.425M), Institutional Resilience and Expanded Postsecondary Opportunity (Assistance Listing No. 84.425P), and HEERF Supplemental Assistance to Institutions of Higher Education program (Assistance Listing No. 84.425S). Amounts provided to students through HEERF are considered to be ?Emergency Financial Aid Grants to Students? under the Program. Since April 2020, the System has been awarded a total of approximately $255.6 million in HEERF funding. From inception through June 30, 2022, the System spent approximately $97.8 million for the HEERF program Student Aid portion which is used to award Emergency Financial Aid Grants to students and $113.9 million for the HEERF Institutional Portion, which is used to support the colleges. $117.3 of this amount was expended by the System during Fiscal Year 2022. The System reports that it will spend the remaining amount of funding during Fiscal Year 2023 and beyond. Each of the System?s 13 campuses separately signed an agreement titled the ?Certification and Agreement? with the ED to indicate each campus? acceptance of the HEERF funding and the applicable terms and requirements. Under the HEERF program requirements, there are three components to reporting: (1) public reporting on the Student Aid Portion; (2) public reporting on the Institutional Portion, and (3) the annual report, which includes summarized information on the Student Aid and Institutional Portions for the reporting period. The annual report is to be submitted directly to the ED. The ED has specified certain criteria that must be included in each report. What was the purpose of our audit work and what work was performed? The purpose of the audit work was to determine whether the System had adequate internal controls in place over, and complied with, the HEERF Institutional and Student Aid grant reporting requirements for Fiscal Year 2022. As part of our audit work, we reviewed the System?s internal controls over the HEERF grant reporting requirements. In addition, we tested a sample of 25 of the 117 HEERF reports submitted by the System?s campuses during Fiscal Year 2022 to determine whether the reports were posted on each campus? primary website (quarterly reports) or submitted to ED (annual reports) by the federal due dates. Furthermore, for the Student Aid Quarterly Report we requested from each Campus the underlying support for the reports, which consisted of student data detailing how much aid was awarded and the methods the campuses used to determine which students would receive Emergency Financial Aid Grants. How were the results of the audit work measured? We measured the results of our audit work against the following requirements: ? On May 13, 2021, the ED published in the Federal Register a notice for student aid public reporting under CRRSAA and ARP, which requires that institutions publicly post certain information on their website. The following information must appear in a format and location that is easily accessible to the public: o An acknowledgement that the institution signed and returned to the ED the Certification and Agreement and the assurance that the institution has used the applicable amount of funds designated under the CRRSAA and ARP programs to provide Emergency Financial Aid Grants to Students. o The total amount of funds that the institution will receive or has received from the ED pursuant to the institution's Certification and Agreement for Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total amount of Emergency Financial Aid Grants distributed to students under the CRRSAA and ARP programs as of the date of submission (i.e., as of the initial report and every calendar quarter thereafter). o The estimated total number of students at the institution that are eligible to receive Emergency Financial Aid Grants to Students under the CRRSAA and ARP programs. o The total number of students who have received an Emergency Financial Aid Grant to students under the CRRSAA and ARP programs. o The method(s) used by the institution to determine which students receive Emergency Financial Aid Grants and how much they would receive under the CRRSAA and ARP programs. o Any instructions, directions, or guidance provided by the institution to students concerning the Emergency Financial Aid Grants. ? Federal Uniform Guidance [2 CFR 200.303] requires that recipients of federal awards have internal controls in place to ensure that federal reports are accurate and report complete information. Appropriate supporting documentation is evidence of such internal controls. What problems did the audit work identify? We identified issues with 5 of the 25 Fiscal Year 2022 reports we tested (20 percent). Specifically, Front Range Community College (FRCC), Pueblo Community College (PCC), and Lamar Community College (LCC) could not provide appropriate supporting documentation for one or more of the following data elements in five of the Student Aid Quarterly Reports: student data detailing (a) the total amount of Emergency Financial Aid Grants distributed to students, (b) the total number of students eligible to receive Emergency Financial Aid Grants and/or (c) the total number of students at the institution who have received an Emergency Financial Aid Grant. The specific issues we found the following: ? FRCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended September 30, 2021 as 20,684; based on our review, we determined the supported number was 20,782. ? FRCC reported the total number of students at the institution who have received an Emergency Financial Aid Grant for the quarter ended June 30, 2022 as 20,385 (student portion) and 3,207 (institutional portion); based on our review, we determined the supported numbers were 20,401 and 3,222, respectively. ? LCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarter ended June 30, 2022 as 1,007; based on our review, we determined the supported number was 1,034. In addition, the amount disbursed directly to student emergency financial aid grants to date was reported as 961 and total for all HEERF funds was 1,124; based on our review, we determined the supported numbers were 988 and 1,151, respectively. ? PCC reported the total number of students eligible to receive Emergency Financial Aid Grants for the quarters ending September 30, 2021 and December 31, 2021 as 3,191; based on our review, we determined this amount could not be supported and PCC did not provide a revised count. Why did these problems occur? FRCC, PCC, and LCC campuses did not have procedures in place to ensure that supporting documentation was maintained for its Student Aid Quarterly Reporting. Employee turnover in the FRCC Controller position and FRCC, PCC, and LCC Student Financial Aid Director positions further contributed to FRCC, PCC, and LCC?s inability to locate or recreate the supporting documentation. Why do these problems matter? It is important for FRCC, PCC, and LCC to ensure that they obtain and maintain appropriate documentation to support amounts reported to federal awarding agencies, especially when they are the basis for determining FRCC, PCC, and LCC?s compliance with specific federal program requirements. This issue could lead to inaccurate federal reporting and potential noncompliance, which could result in the federal government requiring FRCC, PCC, and LCC to return funds or a negative impact to the System?s future federal program funding. See Schedule of Findings and Questioned Costs for chart/table Recommendation 2022-059 Front Range Community College, Lamar Community College, and Pueblo Community College campuses should strengthen their internal controls over federal reporting and ensure they comply with the Higher Education Emergency Relief Fund reporting requirements by reviewing reports for accuracy and developing procedures for ensuring the required maintenance of all related supporting documentation. Response Front Range Community College Agree Implementation Date: September 2022 Moving forward the Director of Financial Aid will engage the Restricted Funds Accountants in a quality assurance review of both dollars spent, type of fund, and student counts before it is submitted for final review and publishing by the Director of Resource Development and Senior Grant Administrator. The most recently submitted information for the quarterly report of September 30, 2022 will be sent to the Restricted Funds Accountants to validate that FRCC has been and will continue to be in compliance for quarterly HEERF reporting. Response Lamar Community College Agree Implementation Date: July 2022 The Financial Aid Director and the Controller will compile their reporting support on the shared drive they utilize for other routine purposes as well, to ensure clear documentation of the numbers reported. The original report containing errors was corrected, validated, and reposted. All past year?s reporting data was made available on the shared drive as of July 2022. Response Pueblo Community College Agree Implementation Date: October 2022 Each quarter Financial aid will obtain and compare Cognos and Banner disbursement reports for accuracy. Once the unduplicated student count is determined it will be sent to the Vice President of Student Success to validate and approve going forward. Financial aid will ensure staff maintain supporting documentation for any institutional expenditures information that was obtained from the fiscal office. Disbursement and expenditure data will be compiled for the Department of Education?s Quarterly Report by the submission deadline and will be submitted as PDF to webmaster for posting on PCC?s website and a copy emailed to a contact at the Department of Education and will archive the submission for future reference.