EIN: 046138072
UEI: JWJCD6DL2C91
Audited by: CliftonLarsonAllen LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 26, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 26, 2026 (12 days ago).
What is a management decision? →FAC accepted this audit on January 31, 2025 — management decision was due July 31, 2025.
FAC accepted this audit on January 9, 2024 — management decision was due July 9, 2024.
Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our testing of the College’s information technology, we noted the following items in the University’s written security program did not meet the following compliance requirements: Identify the approval of the appropriate individual leading the written information security program. Identify documentation that the written information security program was approved by an appropriate individual. Identify a periodic inventory of data, noting where it is collected, stored, and transmitted. Identify information regarding secure development practices for applications. Identify information regarding multi-factor authentication. Identify a specific retention period. Identify a change management policy. Identify documentation of maintaining a log of authorized users’ activity while looking for unauthorized data. Identify documentation that shows regular testing and monitoring of safeguards the College has implemented. Identify documentation that relates to the implementation of policies and procedures to ensure that personnel are able to enact information security programs. Identify how the College will oversee its information system service providers. Identify information on how the written information security program is evaluated and adjusted based on monitoring results. Cause: The College has continued to make progress in updating the College’s written security program to become compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College designate an individual to oversee the information security function and work to update the College’s written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.038 (Federal Perkins Loan Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program), 93.364 (Nursing Student Loans) Federal Award Identification Number and Year: N/A; 2022-2023 Award Period: July 1, 2022 – June 30, 2023 Pass-Through Agency: N/A Pass-Through Numbers: N/A Type of Finding: Significant Deficiency in Internal Control over Compliance Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Condition: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our testing of the College’s information technology, we noted the following items in the University’s written security program did not meet the following compliance requirements: Identify the approval of the appropriate individual leading the written information security program. Identify documentation that the written information security program was approved by an appropriate individual. Identify a periodic inventory of data, noting where it is collected, stored, and transmitted. Identify information regarding secure development practices for applications. Identify information regarding multi-factor authentication. Identify a specific retention period. Identify a change management policy. Identify documentation of maintaining a log of authorized users’ activity while looking for unauthorized data. Identify documentation that shows regular testing and monitoring of safeguards the College has implemented. Identify documentation that relates to the implementation of policies and procedures to ensure that personnel are able to enact information security programs. Identify how the College will oversee its information system service providers. Identify information on how the written information security program is evaluated and adjusted based on monitoring results. Cause: The College has continued to make progress in updating the College’s written security program to become compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College designate an individual to oversee the information security function and work to update the College’s written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.
U.S. Department of Education 2023-001 Student Financial Assistance Cluster – Assistance Listing Number: 84.007, 84.003, 84.038, 84.063, 84.268, 93.364 Recommendation: We recommend the College designate an individual to oversee the information security function and work to update the College’s written security program to ensure compliance with all standards. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College recognized the need to improve their security program and data governance, and this was a catalyst in their decision to outsource the management of their Information Technology functional area. On July 15, 2023, The College engaged Ellucian as its Information Technology partner. Ellucian will be working, along with management, to develop a security program for the College. The College will be establishing appropriate data governance and security protocols and controls as part of the overall security program. The College anticipates having a security program written, approved, and employed by June 30, 2024. Name(s) of the contact person(s) responsible for corrective action: Tana Boone, Vice President of Finance and Administration Planned completion date for corrective action plan: June 2024
FAC accepted this audit on January 12, 2022 — management decision was due July 12, 2022.
The Institution did not submit 2 of the required quarterly reports on their website in the time prescribed by the Department. Questioned Costs: None. Context: During our testing, we noted that the required information was not posted to the Institution?s website in the time prescribed by the Department for 2 our of the 4 Student Aid Portion Reports. Cause: The College did not have someone tracking the requirements to ensure that they posted the reporting timely. Effect: The College is not in compliance with the reporting requirement. Repeat Finding: Yes Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding. "
Show full finding ▾Hide full finding ▴"Federal Agency: Department of Education Federal Program: Title: Student Financial Assistance Cluster CFDA Numbers: 84.425E Higher Education Emergency Relief Fund Student Portion Award Period: July 1, 2020 to June 30, 2021 Type of Finding: Other Matters and Significant Deficiency in Internal Control over Compliance Criteria or Specific Requirement: Section 18004(e) of the Coronavirus Aid, Relief, and Economic Security Act (?CARES Act? or the ?Act?)), directs institutions receiving funds under Section 18004 of the Act to submit (in a time and manner required by the Secretary) a report to the Secretary describing the use of funds distributed from the Higher Education Emergency Relief Fund (?HEERF?). Condition: The Institution did not submit 2 of the required quarterly reports on their website in the time prescribed by the Department. Questioned Costs: None. Context: During our testing, we noted that the required information was not posted to the Institution?s website in the time prescribed by the Department for 2 our of the 4 Student Aid Portion Reports. Cause: The College did not have someone tracking the requirements to ensure that they posted the reporting timely. Effect: The College is not in compliance with the reporting requirement. Repeat Finding: Yes Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding. "
"United States Department of Education Hampshire College respectfully submits the following corrective action plan for the year ended June 30, 2021. Audit period: July 01, 2020 through June 30, 2021 The findings from the schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINDINGS?FEDERAL AWARD PROGRAMS AUDITS United States Department of Education Other Matters and Significant Deficiency in Internal Control over Compliance Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College has designated a staff person to coordinate the reporting requirements. This individual works with various staff to ensure that the reporting requirements are met. Name of the contact person responsible for corrective action: Kristin Hmieleski, Director of Financial Aid. Planned completion date for corrective action plan: Corrective action was taken. If the United States Department of Education has questions regarding this plan, please call Kristin Hmieleski, Director of Financial Aid, 413-549-4600. "
2020-001
Failure to comply with the requirement to have error response files filed and accepted within the 10-day time frame. Questioned Costs: None. Context: During our testing, we noted instances where error reports were not corrected within the required 10-day timeframe. Cause: Error batches returned by NSLDS to NSC (the College's servicer) were not communicated to the school. Effect: Failure to comply with timely enrollment reporting error correction requirements, and failure to correct misreported information to NSLDS. Repeat Finding: No Recommendation: We recommend the College implement additional controls to ensure timely reporting, processing, and tracking of SSCR error files, error file responses, and file receipt acknowledgements for data submitted to NSLDS by the Clearinghouse. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding. "
Show full finding ▾Hide full finding ▴"Federal Agency: Department of Education Federal Program: Title: Student Financial Assistance Cluster CFDA Numbers: Various Award Period: July 1, 2020 to June 30, 2021 Type of Finding: Other Matters and Significant Deficiency in Internal Control over Compliance Criteria or Specific Requirement: Student Status Confirmation Reports (SSCRs) submitted to the National Student Loan Data System (NSLDS) by the National Student Clearinghouse to correct enrollment reporting errors were not accepted timely. Condition: Failure to comply with the requirement to have error response files filed and accepted within the 10-day time frame. Questioned Costs: None. Context: During our testing, we noted instances where error reports were not corrected within the required 10-day timeframe. Cause: Error batches returned by NSLDS to NSC (the College's servicer) were not communicated to the school. Effect: Failure to comply with timely enrollment reporting error correction requirements, and failure to correct misreported information to NSLDS. Repeat Finding: No Recommendation: We recommend the College implement additional controls to ensure timely reporting, processing, and tracking of SSCR error files, error file responses, and file receipt acknowledgements for data submitted to NSLDS by the Clearinghouse. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding. "
United States Department of Education Hampshire College respectfully submits the following corrective action plan for the year ended June 30, 2021. Audit period: July 01, 2020 through June 30, 2021 The findings from the schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINDINGS?FEDERAL AWARD PROGRAMS AUDITS United States Department of Education Other Matters and Significant Deficiency in Internal Control over Compliance Recommendation: We recommend the College implement additional controls to ensure timely reporting, processing, and tracking of SSCR error files, error file responses, and file receipt acknowledgements for data submitted to NSLDS by the Clearinghouse. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College has designated a staff person to coordinate the SSCR requirements. This individual will ensure that SSCR error files and responses are reviewed and submitted timely and that the SSCR requirements are met. Name of the contact person responsible for corrective action: Rachael Graham, Director of Central Records. Planned completion date for corrective action plan: Corrective action was taken. If the United States Department of Education has questions regarding this plan, please call Rachael Graham, Director of Central Records, 413-549-4600.
FAC accepted this audit on April 29, 2021 — management decision was due October 29, 2021.
The Institution did not have the required reporting on their website by June 4, 2020. Questioned Costs: None. Context: During our testing, we noted that the required information was not posted to the Institution?s website in the time prescribed by the Department. Cause: The College did not have someone tracking the requirements to ensure that they posted the reporting timely. Effect: The College is not in compliance with the reporting requirement. Repeat Finding: No Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴Federal Agency: Department of Education Federal Program: Title: Student Financial Assistance Cluster CFDA Numbers: 84.425E Higher Education Emergency Relief Fund Student Portion Award Period: July 1, 2019 to June 30, 2020 Type of Finding: Significant Deficiency in Internal Control over Compliance Criteria or Specific Requirement: Section 18004(e) of the Coronavirus Aid, Relief, and Economic Security Act (?CARES Act? or the ?Act?)), directs institutions receiving funds under Section 18004 of the Act to submit (in a time and manner required by the Secretary) a report to the Secretary describing the use of funds distributed from the Higher Education Emergency Relief Fund (?HEERF?). Each participating HEERF institution must upload this information on the Institution's website within 30 days of the signed Certification Agreement or 30 days after the electronic announcement dated May 6, whichever is later. Condition: The Institution did not have the required reporting on their website by June 4, 2020. Questioned Costs: None. Context: During our testing, we noted that the required information was not posted to the Institution?s website in the time prescribed by the Department. Cause: The College did not have someone tracking the requirements to ensure that they posted the reporting timely. Effect: The College is not in compliance with the reporting requirement. Repeat Finding: No Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding.
United States Department of Education Hampshire College respectfully submits the following corrective action plan for the year ended June 30, 2020. Audit period: July 01, 2019 through June 30, 2020 The findings from the schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINDINGS?FEDERAL AWARD PROGRAMS AUDITS United States Department of Education Significant Deficiency in Internal Control over Compliance Recommendation: We recommend the College have a procedure in place to ensure that all reporting requirements are met timely. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College has designated a staff person to coordinate the reporting requirements. This individual works with various staff to ensure that the reporting requirements are met. Name of the contact person responsible for corrective action: Kristin Hmieleski, Director of Financial Aid. Planned completion date for corrective action plan: Corrective action was taken. If the United States Department of Education has questions regarding this plan, please call Kristin Hmieleski, Director of Financial Aid, 413-549-4600.
FAC accepted this audit on March 12, 2020 — management decision was due September 12, 2020.
Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College did not designate an individual to coordinate the information security program; did not perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) which are (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures and maintain documented safeguards for identified risks. Cause: The organization uses a third-party IT service provider for IT related tasks and relied on that service provider to ensure all compliance requirements are met. However, the organization should have an individual designated internally to assure compliance with the requirements of the Gramm-Leach-Bliley Act. The organization did not perform an IT risk assessment tailored specifically to the organization, identify risks or address risks identified as required by the Gramm-Leach-Bliley Act. Effect: The student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College designate an individual to oversee the information security function, engage a third-party or perform the risk assessment for the three areas required by the Gramm-Leach-Bliley Act and ensure that there are documented safeguards for identified risks. Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2019 ? 001 Federal Agency: Department of Education Federal Program: Title: Student Financial Assistance Cluster CFDA Numbers: Various Award Period: July 1, 2018 through June 30, 2019 Type of Finding: ? Significant Deficiency in Internal Control over Compliance ? Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Condition: Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College did not designate an individual to coordinate the information security program; did not perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) which are (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures and maintain documented safeguards for identified risks. Cause: The organization uses a third-party IT service provider for IT related tasks and relied on that service provider to ensure all compliance requirements are met. However, the organization should have an individual designated internally to assure compliance with the requirements of the Gramm-Leach-Bliley Act. The organization did not perform an IT risk assessment tailored specifically to the organization, identify risks or address risks identified as required by the Gramm-Leach-Bliley Act. Effect: The student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College designate an individual to oversee the information security function, engage a third-party or perform the risk assessment for the three areas required by the Gramm-Leach-Bliley Act and ensure that there are documented safeguards for identified risks. Views of responsible officials: There is no disagreement with the audit finding.
Significant Deficiency 2019-001 Student Financial Aid Cluster ? CFDA No. Various Recommendation: We recommend the College designate an individual to oversee the information security function, engage a third-party or perform the risk assessment for the three areas required by the Gramm-Leach-Bliley Act and ensure that there are documented safeguards for identified risks. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College has designated a staff person to coordinate the requirements of the Gramm-Leach-Bliley Act (GLBA). This individual will work with information technology staff to ensure that the requirements of the GLBA are met, and that there are documented safeguards for identified risks. Name of contact person: Andy Korenewsky, Senior Associate Director of Financial Aid Planned completion date for corrective action plan: June 30, 2020
During our testing, we noted one out of the 40 student?s tested for eligibility were not properly awarded subsidized Stafford loans The student was overawarded $2,815 of subsidized loans. Questioned Costs: $2,815 Context: Cause: The College did not appropriately determine the student?s level of education when awarding the Subsidized Stafford Loan Effect: The Institution is awarding subsidized Stafford loans for which the student is not eligible. However, the overawarded subsidized loan can be corrected by awarding an unsubsidized loan in place of it. Repeat Finding: No Recommendation: We recommend that the College review their awarding procedures and implement procedures to ensure the Stafford loans are awarded within the annual and aggregate limits. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2019 ? 002 Federal Agency: Department of Education Federal Program: Title: Student Financial Assistance Cluster CFDA Numbers: 84.268 ? Federal Direct Student Loans Award Period: July 1, 2018 to June 30, 2019 Type of Finding: Significant Deficiency in Internal Control over Compliance Other Matter Criteria or Specific Requirement: Per the Code of Federal Regulations, 34 CFR 673.5, students may not be awarded need based aid in excess of their calculated need. In addition, 34 CFR 685.203(j) states that in no case may a loan amount exceed the student?s estimated cost of attendance for the period of enrollment for which the loan is intended less the student?s estimated financial assistance for that period and in the case of Direct Subsidized Loans, the borrower?s expected family contribution for that period. Condition: During our testing, we noted one out of the 40 student?s tested for eligibility were not properly awarded subsidized Stafford loans The student was overawarded $2,815 of subsidized loans. Questioned Costs: $2,815 Context: Cause: The College did not appropriately determine the student?s level of education when awarding the Subsidized Stafford Loan Effect: The Institution is awarding subsidized Stafford loans for which the student is not eligible. However, the overawarded subsidized loan can be corrected by awarding an unsubsidized loan in place of it. Repeat Finding: No Recommendation: We recommend that the College review their awarding procedures and implement procedures to ensure the Stafford loans are awarded within the annual and aggregate limits. Views of responsible officials and planned corrective actions: There is no disagreement with the audit finding.
Significant Deficiency 2019-002 Student Financial Aid Cluster ? CFDA No. 84.268 Recommendation: We recommend the College should review their awarding procedures and implement procedures to ensure the Stafford loans are awarded within the annual and aggregate limits. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Beginning in Fall 2019, the College has modified our procedure for processing Stafford loans. Before disbursing Stafford loan funds, we review and confirm the year in school to determine the correct amount each student may borrow. We also re-determine the subsidized loan eligibility of each student. We will continue this practice for the remainder of the 2019-20 year and for future years. All financial aid staff have been trained in the annual and aggregate limits and how to determine subsidized loan eligibility. Name of contact person: Andy Korenewsky, Senior Associate Director of Financial Aid Planned completion date for corrective action plan: The College has implemented a plan.
FAC accepted this audit on February 4, 2019 — management decision was due August 4, 2019.
FAC accepted this audit on January 22, 2018 — management decision was due July 22, 2018.
FAC accepted this audit on March 30, 2017 — management decision was due September 30, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Massachusetts →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.