EIN: 480996330
UEI: FYNBDWDMRZ44
Data as of August 27, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on December 14, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 14, 2024 (804 days ago).
What is a management decision? →The University did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $-0- Context: The University has not implemented multi-factor authentication on all systems containing personally identifiable information (PII), implemented all required safeguards under the revised legislation, and implemented a frequency of reviews on critical vendors. Cause: The University has made significant progress in addressing and documenting compliance with the updated requirements of GLBA and has a couple of remaining areas on the road map to complete. Effect: The University may have unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable Recommendation: We recommend the University allocate sufficient resources to address all updated requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Show full finding ▾Hide full finding ▴Gramm-Leach-Bliley Act (GLBA) Compliance DEPARTMENT OF EDUCATION ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, and 84.379-Student Financial Assistance Cluster Federal Award Identification #: 2022-2023 Financial Aid Year Condition: The University did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $-0- Context: The University has not implemented multi-factor authentication on all systems containing personally identifiable information (PII), implemented all required safeguards under the revised legislation, and implemented a frequency of reviews on critical vendors. Cause: The University has made significant progress in addressing and documenting compliance with the updated requirements of GLBA and has a couple of remaining areas on the road map to complete. Effect: The University may have unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable Recommendation: We recommend the University allocate sufficient resources to address all updated requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Planned Corrective Action: • The Finding addressed three areas of concern. This CAP will address them as follows: • Multi-Factor Authentication (MFA) Not Implemented on all systems: o MNU is working to integrate Elucian Banner with Microsoft Entra ID Single Sign On, which will then enforce MFA. This is planned for completion in January 2024. o MNU will work with the National Student Clearinghouse to enforce MFA for all users by December 31, 2023 • Implementation of frequency of reviews on critical vendors: o MNU will add the following systems for review to the annual Risk Assessment, conducted in June of each year: • Active Directory • CashNet • Clover-Go • Implementation of all required safeguards under the revised legislation: o MNU will adopt a formal data retention policy, specifying that customer (student) financial information shall not be kept more than 2 years since the date of last access, unless otherwise required by law or regulation. o MNU will perform an audit of student financial data as part of the annual review process to ensure that data is not being retained past the expiration window. Person Responsible for Corrective Action Plan: Mark Leinwetter, IT Director Anticipated Date of Completion: • MFA Implementation: 1/31/24 • Vendor Reviews: 6/30/24 • Data Retention Policy: 2/28/24
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.