Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.