2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
775 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

FY End: 2023-09-30
Bmc Health System, Inc.
Compliance Requirement: AHN
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non...

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

« 1 773 774 776 777 2002 »