MIDAMERICA NAZARENE UNIVERSITY AND AFFILIATES

EIN: 480996330

UEI: FYNBDWDMRZ44

Data as of August 27, 2026

MIDAMERICA NAZARENE UNIVERSITY AND AFFILIATES10 audit years1 findings
10
Audit Years
1
Total Findings
0
Repeat Findings

FY 2023-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on December 14, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 14, 2024 (804 days ago).

What is a management decision? →
2023-001
Special Tests & Provisions

The University did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $-0- Context: The University has not implemented multi-factor authentication on all systems containing personally identifiable information (PII), implemented all required safeguards under the revised legislation, and implemented a frequency of reviews on critical vendors. Cause: The University has made significant progress in addressing and documenting compliance with the updated requirements of GLBA and has a couple of remaining areas on the road map to complete. Effect: The University may have unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable Recommendation: We recommend the University allocate sufficient resources to address all updated requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Show full finding ▾
Full finding narrative

Gramm-Leach-Bliley Act (GLBA) Compliance DEPARTMENT OF EDUCATION ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, and 84.379-Student Financial Assistance Cluster Federal Award Identification #: 2022-2023 Financial Aid Year Condition: The University did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $-0- Context: The University has not implemented multi-factor authentication on all systems containing personally identifiable information (PII), implemented all required safeguards under the revised legislation, and implemented a frequency of reviews on critical vendors. Cause: The University has made significant progress in addressing and documenting compliance with the updated requirements of GLBA and has a couple of remaining areas on the road map to complete. Effect: The University may have unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable Recommendation: We recommend the University allocate sufficient resources to address all updated requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

Gramm-Leach-Bliley Act (GLBA) Compliance Planned Corrective Action: • The Finding addressed three areas of concern. This CAP will address them as follows: • Multi-Factor Authentication (MFA) Not Implemented on all systems: o MNU is working to integrate Elucian Banner with Microsoft Entra ID Single Sign On, which will then enforce MFA. This is planned for completion in January 2024. o MNU will work with the National Student Clearinghouse to enforce MFA for all users by December 31, 2023 • Implementation of frequency of reviews on critical vendors: o MNU will add the following systems for review to the annual Risk Assessment, conducted in June of each year: • Active Directory • CashNet • Clover-Go • Implementation of all required safeguards under the revised legislation: o MNU will adopt a formal data retention policy, specifying that customer (student) financial information shall not be kept more than 2 years since the date of last access, unless otherwise required by law or regulation. o MNU will perform an audit of student financial data as part of the annual review process to ensure that data is not being retained past the expiration window. Person Responsible for Corrective Action Plan: Mark Leinwetter, IT Director Anticipated Date of Completion: • MFA Implementation: 1/31/24 • Vendor Reviews: 6/30/24 • Data Retention Policy: 2/28/24

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.