← Back to home

HAWKEYE AREA COMMUNITY ACTION PROGRAM, INC.Non-Profit

EIN: 420898405

UEI: CK1MDQAWQ9G5

Audited by: WIPFLI LLP

Oversight agency: 93 [Department of Health and Human Services]

View federal awards & risk assessment →

Data as of August 28, 2026

HAWKEYE AREA COMMUNITY ACTION PROGRAM, INC.10 audit years2 findings
10
Audit Years
2
Total Findings
0
Repeat Findings
$32.8M
Federal Awards Expended (FY 2025)

FY 2025-09-30

$32,760,552 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 9, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 9, 2026 (9 days from today).

What is a management decision? →

FY 2024-09-30

$33,104,077 federal awards expendedNo findings recorded this year

FAC accepted this audit on June 30, 2025 — management decision was due December 30, 2025.

FY 2023-09-30

LOW-RISK AUDITEE$34,507,992 federal awards expended

FAC accepted this audit on March 6, 2025 — management decision was due September 6, 2025.

2023-001
Activities Allowed or Unallowed / Cost Allowability
MATERIAL WEAKNESS

Subsequent to the fiscal year end, HACAP experienced a security breach of their electronic financial information by an outside party which denied HACAP access to their computer servers. Although several attempts were made to recover the financial information, HAPCAP was unable to retrieve essential electronic financial information needed to complete the audit. With the inability to retrieve the information, HACAP had to recreate the financial information manually causing significant delays in reconciling accounts and completion of the audit. Effect: As a result of the deficiencies in adequately safeguarding of electronic financial information and the inability to recreate the electronic financial information using back-ups systems, a material weakness in internal control over financial reporting exists. Cause: HACAP's internal controls over their electronic financial information did not adequately safeguard their financial information and prevent access from outside parties. In addition, HACAP's back-ups of the electronic financial information were not effective in recreating the financial information necessary to complete the audit. Repeat: No Auditor's Recommendations: We recommend HACAP implement procedures to ensure electronic records are secured and adequately backed-up. View of Responsible Officials: Management agrees with the finding and has developed a written corrective action plan.No findings related to the the financial statements.

Show full finding ▾
Full finding narrative

Internal Controls over Electronic Financial Information Criteria or Specific Requirement: 2 CFR part 200 (Uniform Guidance) requires grantees to have effective control over, and accountability for, all funds, property, and other assets. Condition: Subsequent to the fiscal year end, HACAP experienced a security breach of their electronic financial information by an outside party which denied HACAP access to their computer servers. Although several attempts were made to recover the financial information, HAPCAP was unable to retrieve essential electronic financial information needed to complete the audit. With the inability to retrieve the information, HACAP had to recreate the financial information manually causing significant delays in reconciling accounts and completion of the audit. Effect: As a result of the deficiencies in adequately safeguarding of electronic financial information and the inability to recreate the electronic financial information using back-ups systems, a material weakness in internal control over financial reporting exists. Cause: HACAP's internal controls over their electronic financial information did not adequately safeguard their financial information and prevent access from outside parties. In addition, HACAP's back-ups of the electronic financial information were not effective in recreating the financial information necessary to complete the audit. Repeat: No Auditor's Recommendations: We recommend HACAP implement procedures to ensure electronic records are secured and adequately backed-up. View of Responsible Officials: Management agrees with the finding and has developed a written corrective action plan.No findings related to the the financial statements.

Corrective Action Plan

Hawkeye Area Community Action Program, Inc. (HACAP) has migrated our financial accounting software to a data center managed by a 3'' party. A full backup of the database is done daily to both the cloud and to a hard drive that is securely stored. Person(s) Responsible: Paula Mahan, Jim McGoldrock Timing for Implementation: Immediate action was taken, and the change was made as soon as the data breach was discovered in October 2023.

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles →
2023-002
Reporting
SIGNIFICANT DEFICIENCY

The September 30, 2023 audit and reporting package is being submitted after the required due date. Effect: HACAP is not in compliance with federal regulations regarding audit timing and represents a significant deficiency in internal control over major program reporting. Cause: Due to restricted access to computer servers and having to rebuild electronic records, HACAP audit and data collection submission was not done on time. Repeat: No Auditor's Recommendations: HACAP should take steps to ensure that its financial records are available in a timely manner to allow the audit to begin sufficiently before the audit due date. View of Responsible Officials: Management agrees with the finding and has developed a written corrective action plan.

Show full finding ▾
Full finding narrative

Late Audit Submission Criteria or Specific Requirement: 2 CFR section 200.512(a) requires the reporting package and data collection form be submitted to the Federal Audit Clearinghouse the earlier of 30 calendar days after the reports are received from the auditors or nine months after the end of the audit period. Condition: The September 30, 2023 audit and reporting package is being submitted after the required due date. Effect: HACAP is not in compliance with federal regulations regarding audit timing and represents a significant deficiency in internal control over major program reporting. Cause: Due to restricted access to computer servers and having to rebuild electronic records, HACAP audit and data collection submission was not done on time. Repeat: No Auditor's Recommendations: HACAP should take steps to ensure that its financial records are available in a timely manner to allow the audit to begin sufficiently before the audit due date. View of Responsible Officials: Management agrees with the finding and has developed a written corrective action plan.

Corrective Action Plan

The 2023 audit for Hawkeye Area Community Action Program, Inc (HACAP) was delayed due to a loss of financial data that was stored on an internal server because of a data breach. The back-up of the financial data was also stored on an internal server, was compromised as well, resulting in a complete loss of information. The financial information had to be rebuilt based on support documentation, and the reconstruction of the data took place over the course of several months. HACAP has migrated our financial accounting software to a data center managed by a 3rd party. A full backup of the database is done daily to both the cloud and to a hard drive that is securely stored. Person(s) Responsible: Jason Fisher, Cindy Johnson, Jim McGoldrick Timing for Implementation: Immediate/Completed

About Reporting →

FY 2022-09-30

LOW-RISK AUDITEE$45,886,171 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 7, 2023 — management decision was due August 7, 2023.

FY 2021-09-30

LOW-RISK AUDITEE$30,194,530 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 1, 2022 — management decision was due August 1, 2022.

FY 2020-09-30

LOW-RISK AUDITEE$22,843,846 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 10, 2021 — management decision was due August 10, 2021.

FY 2019-09-30

LOW-RISK AUDITEE$21,279,563 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 20, 2020 — management decision was due August 20, 2020.

FY 2018-09-30

LOW-RISK AUDITEE$18,711,040 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 4, 2019 — management decision was due August 4, 2019.

FY 2017-09-30

LOW-RISK AUDITEE$18,224,503 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 29, 2018 — management decision was due July 29, 2018.

FY 2016-09-30

LOW-RISK AUDITEE$19,080,971 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 31, 2017 — management decision was due July 31, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Iowa

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.