Finding 50693 (2022-001)

Significant Deficiency
Requirement
N
Questioned Costs
-
Year
2022
Accepted
2023-10-01
Audit: 41715
Organization: Centra Health, Inc. (VA)
Auditor: Bdo USA PC

AI Summary

  • Core Issue: Centra failed to conduct the required Gramm-Leach-Bliley Act risk assessment for 2022, leading to non-compliance.
  • Impacted Requirements: The institution must designate personnel for information security, perform a risk assessment, and document safeguards as per 16 CFR 314.
  • Recommended Follow-Up: Centra should enhance internal controls, assign responsibility for the information security program, and ensure compliance with all GLBA requirements moving forward.

Finding Text

2022-001 ? Special tests and provisions Information on Federal Program(s) - Federal Pell Grant (ALN: 84.063); Federal Direct Loans (ALN: 84.268) Criteria or Specific Requirement ? The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act because they appear to be significantly engaged in wiring funds to consumers. Under an institution?s Program Participation Agreement with the ED and the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, with particular attention to information provided to institutions by ED or otherwise obtained in support of the administration of the federal student financial aid programs. Accordingly, the Gramm-Leach-Bliley Act of the Special tests and provisions (N) compliance requirement states that the institution must designate an employee or employees to coordinate the information security program, perform a risk assessment that addresses the three required areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Condition ? During our review of the special tests and provisions (N) compliance requirement, we noted that Centra did not perform the Gramm-Leach-Bliley Act risk assessment during the year under audit and therefore was not in compliance with the requirement. Cause ? Insufficient internal controls and administrative oversight with respect to the Special tests and provisions (N) compliance requirement. Effect or Potential Effect ? Centra is not in compliance with the Gramm-Leach-Bliley Act requirement for the year ended December 31, 2022. Questioned Costs ? None. Context ? Centra did not perform the Gramm-Leach-Bliley Act risk assessment for the year under audit. Recommendation - We recommend that Centra maintain appropriate internal controls and administrative oversight in order to comply with the special tests and provisions (N) compliance requirement and to designate an employee or employees to coordinate the information security program, perform a risk assessment that addresses the three required areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Views of Responsible Officials ? Centra management agrees with this finding. While Centra had information security measures in place during the 2022 audit year, Centra was not aware of the specific GLBA requirements and did not complete the required risk assessment or have a designated individual responsible for coordinating the assessment. Centra has taken measures to ensure compliance going forward.

Categories

Student Financial Aid Subrecipient Monitoring Matching / Level of Effort / Earmarking Internal Control / Segregation of Duties Special Tests & Provisions

Other Findings in this Audit

  • 50692 2022-001
    Significant Deficiency
  • 50694 2022-002
    Significant Deficiency
  • 627134 2022-001
    Significant Deficiency
  • 627135 2022-001
    Significant Deficiency
  • 627136 2022-002
    Significant Deficiency

Programs in Audit

ALN Program Name Expenditures
93.498 Provider Relief Fund $36.13M
84.268 Federal Direct Student Loans $1.82M
84.063 Federal Pell Grant Program $538,897
93.243 Substance Abuse and Mental Health Services_projects of Regional and National Significance $128,046
93.461 Covid-19 Testing for the Uninsured $89,942
84.425 Education Stabilization Fund $12,084
93.398 Cancer Research Manpower $3,250