EIN: 362169145
UEI: EKXBBU5MVJN5
Audited by: Grant Thornton LLP
Oversight agency: 84 [Department of Education]
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on October 29, 2019. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 29, 2020 (2312 days ago).
What is a management decision? →Per discussion with both the Director of IT and the Interim Director of Student Financial Services, Elmhurst College (the College) has not yet performed a risk assessment to address the compliance requirements noted above, and as such, they have not yet documented a safeguard for the risks, as no risks have been identified. Context: Although the College has named someone to coordinate its information security program (#1 above) and has plans in place to work with a third party service provider on compliance with this requirement, the College is currently not in compliance related to risk assessment and related safeguards (#2 and #3 above). Cause: Turnover in the College?s student financial aid department may have contributed to the delay in implementing the necessary policies and procedures. Effect: Without an effective, documented security program in place, the College may not be adequately protecting personal, nonpublic information in their custody or control. Questioned costs: None Repeat Finding: No Recommendation: We recommend that management continue with its plan to work with a third party vendor, to document and implement policies and procedures for conducting the required risk assessments and implementing the related safeguards. Views of Responsible Officials: We agree with the details of this finding and will implement the procedures outlined in our Corrective Action Plan.
Show full finding ▾Hide full finding ▴Finding 2019-001: Special Tests: Gramm-Leach-Bliley Act Federal Agency and Program: U.S. Department of Education Student Financial Assistance Cluster Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)) Under these regulations, an institution must establish that they have implemented the core elements of the rule, which are: (1) The institution has named someone to coordinate its information security program. (2) It has conducted a risk assessment covering employee training and management, networks and information systems, and incident response. (3) It has implemented safeguards to address the identified risks in those areas. Condition: Per discussion with both the Director of IT and the Interim Director of Student Financial Services, Elmhurst College (the College) has not yet performed a risk assessment to address the compliance requirements noted above, and as such, they have not yet documented a safeguard for the risks, as no risks have been identified. Context: Although the College has named someone to coordinate its information security program (#1 above) and has plans in place to work with a third party service provider on compliance with this requirement, the College is currently not in compliance related to risk assessment and related safeguards (#2 and #3 above). Cause: Turnover in the College?s student financial aid department may have contributed to the delay in implementing the necessary policies and procedures. Effect: Without an effective, documented security program in place, the College may not be adequately protecting personal, nonpublic information in their custody or control. Questioned costs: None Repeat Finding: No Recommendation: We recommend that management continue with its plan to work with a third party vendor, to document and implement policies and procedures for conducting the required risk assessments and implementing the related safeguards. Views of Responsible Officials: We agree with the details of this finding and will implement the procedures outlined in our Corrective Action Plan.
Finding 2019-001: Special Tests: Gramm-Leach-Bliley Act Federal Agency and Program: U.S. Department of Education Student Financial Assistance Cluster Elmhurst College is committed to protecting the confidential information entrusted to it by its students, faculty, alumni, employees and other constituents of the College community. The College maintains an information security program designed to protect the confidentiality, integrity, and availability of the information entrusted to it. This program is based on and informed by the National Institute of Standards Information Security standard and customized as reasonable for the College?s size and its specific circumstances. A full risk assessment was conducted in 2016 by GreyCastle Security, the College?s cybersecurity services provider. A subsequent risk assessment is currently scheduled in the first half of 2020. The combined results of the current and past tests will be evaluated in light of a security roadmap for the coming year. 1. Employee training and management - the College administers multiple phishing exercises on a regular basis. The College has engaged GreyCastle Security to host on campus cybersecurity awareness events in April 2017 and 2018 with additional events planned for the end of October 2019. The College will continue to hold regular training sessions for employees and management. 2. Networks and information systems - the College has implemented and completed vulnerability scanning of both the internal and external environment. The College is working towards addressing the identified risks. 3. Incident Response - the College has engaged GreyCastle Security to draft an Incident Response Plan. The College completed an Incident Response Table-top test to understand any potential weaknesses with the Incident Response plan as it is being developed. Contact person(s) responsible for corrective action: Under the direction of the College?s Vice President of Operations and Technology, Daniel Gibson of GreyCastle Security is contracted to be the College?s Chief Information Security Officer. Anticipated completion date: As described above, many of the necessary action have already been completed and will continue to be assessed as part of the College?s contract with GreyCastle Security. For those items that have not yet been completed, the College anticipates implementation by June 2020.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.