← Back to home

Housing Authority of the City of Decatur, GeorgiaLocal Government

EIN: 586002907

UEI: FZELGUSE4AY5

Audited by: CohnReznick LLP

Oversight agency: 14 [Department of Housing and Urban Development]

View federal awards & risk assessment →

Showing data from September 2, 2026 — the Federal Audit Clearinghouse is under high demand right now, so this couldn't be refreshed. This is the most recent data on record, not necessarily today's.

Housing Authority of the City of Decatur, Georgia9 audit years1 findings
9
Audit Years
1
Total Findings
0
Repeat Findings
$17.6M
Federal Awards Expended (FY 2024)

FY 2024-12-31

LOW-RISK AUDITEE$17,567,702 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on September 23, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by March 23, 2026 (164 days ago).

What is a management decision? →
2024-001
Eligibility
MATERIAL WEAKNESS

During the year ended December 31, 2024, a Housing Specialist employee violated HUD’s TRACS Rules of Behavior and the Privacy Act of 1974 by emailing EIV reports containing information of 10 applicants to the employee’s personal email address immediately prior to termination of employment. Cause: The employee had authorized access to the EIV information as part of the normal duties associated with their position. The employee had signed the Rules of Behavior, and participated in annual cyber training as required by HUD; however, the employee was discovered to have circumvented the controls and emailed EIV information to their personal email address immediately prior to termination of employment. Effect or Potential Effect: Tenant applicants and tenant participants of the housing voucher program are at risk of having personally identifiable information (PII) exposed and misused by the employee. Questioned Costs:None Context: An employee who had authorized access to EIV for the performance of their duties in the Housing Choice Voucher (HCV) program was discovered to have emailed themselves private information of 10 housing choice voucher applicants. Identification as a Repeat Finding: This finding is not a repeat finding. Recommendation: We recommend that the Authority reviews its internal controls to reduce the risk of unauthorized access to and/or misuse of PII contained within the EIV reports in the future to ensure compliance with eligibility requirements. Views of Responsible Officials: Shortly after the employee’s separation from the Authority, management discovered that the individual had sent documents to their personal email address immediately prior to departure. Upon discovery, management promptly notified legal counsel and the Authority’s cybersecurity insurance provider. The employee’s laptop was subsequently sent to the designated vendor for a forensic inspection to determine the extent of the data compromise. The final report confirmed that approximately 10 households’ personally identifiable information (PII) had been affected. Notification letters were issued to those households with instructions on how to monitor their credit and review potential impacts. To date, no households have reported any negative consequences to the Authority. As part of the Authority’s standard internal controls, all HCV employees with access to EIV are required to sign the Rules of Behavior and complete HUD’s annual cybersecurity training. In addition, the Authority maintains physical security measures and general IT controls onsite to reduce risks associated with unauthorized access. After this incident, the Authority implemented several additional measures to strengthen data protection practices. Specifically: • Issued a new Information Protection Policy and Confidentiality Agreement, which all employees are required to review and sign. • Conducted an all-staff training session to review the new policy in detail and reinforce best practices for safeguarding participant information. • The Chief Executive Officer reiterated the Authority’s commitment to data security and emphasized that any violation of information protection policies will result in disciplinary action, up to and including termination of employment, as well as potential legal prosecution.

Show full finding ▾
Full finding narrative

Name of Federal Agency: U.S. Department of Housing and Urban Development Federal Program Name and Assistance Listing Number: Housing Voucher Cluster: 14.879 Mainstream Vouchers Program. 14.871 - Section 8 Housing Choice Vouchers Program. Federal Award Identification Number and Year: ACC A-3096 2024 Compliance Requirements: Eligibility Type of Finding: Material Weakness in Controls Criteria In accordance with the Computer Matching and Privacy Protection Act of 1988, HUD requires all authorized users of the Enterprise Income Verification system (EIV) to comply with the Tenant Rental Assistance Certification System (TRACS) Rules of Behavior as well as adhere to the Privacy Act of 1974. Condition: During the year ended December 31, 2024, a Housing Specialist employee violated HUD’s TRACS Rules of Behavior and the Privacy Act of 1974 by emailing EIV reports containing information of 10 applicants to the employee’s personal email address immediately prior to termination of employment. Cause: The employee had authorized access to the EIV information as part of the normal duties associated with their position. The employee had signed the Rules of Behavior, and participated in annual cyber training as required by HUD; however, the employee was discovered to have circumvented the controls and emailed EIV information to their personal email address immediately prior to termination of employment. Effect or Potential Effect: Tenant applicants and tenant participants of the housing voucher program are at risk of having personally identifiable information (PII) exposed and misused by the employee. Questioned Costs:None Context: An employee who had authorized access to EIV for the performance of their duties in the Housing Choice Voucher (HCV) program was discovered to have emailed themselves private information of 10 housing choice voucher applicants. Identification as a Repeat Finding: This finding is not a repeat finding. Recommendation: We recommend that the Authority reviews its internal controls to reduce the risk of unauthorized access to and/or misuse of PII contained within the EIV reports in the future to ensure compliance with eligibility requirements. Views of Responsible Officials: Shortly after the employee’s separation from the Authority, management discovered that the individual had sent documents to their personal email address immediately prior to departure. Upon discovery, management promptly notified legal counsel and the Authority’s cybersecurity insurance provider. The employee’s laptop was subsequently sent to the designated vendor for a forensic inspection to determine the extent of the data compromise. The final report confirmed that approximately 10 households’ personally identifiable information (PII) had been affected. Notification letters were issued to those households with instructions on how to monitor their credit and review potential impacts. To date, no households have reported any negative consequences to the Authority. As part of the Authority’s standard internal controls, all HCV employees with access to EIV are required to sign the Rules of Behavior and complete HUD’s annual cybersecurity training. In addition, the Authority maintains physical security measures and general IT controls onsite to reduce risks associated with unauthorized access. After this incident, the Authority implemented several additional measures to strengthen data protection practices. Specifically: • Issued a new Information Protection Policy and Confidentiality Agreement, which all employees are required to review and sign. • Conducted an all-staff training session to review the new policy in detail and reinforce best practices for safeguarding participant information. • The Chief Executive Officer reiterated the Authority’s commitment to data security and emphasized that any violation of information protection policies will result in disciplinary action, up to and including termination of employment, as well as potential legal prosecution.

Corrective Action Plan

CORRECTIVE ACTION PLAN August28, 2025 Cognizant oversight agency: U.S. Department of Housing and Urban Development The Housing Authority of the City of Decatur, Georgia respectfully submits the following corrective action plan for the year ended December 31 , 2024. Audit Firm: CohnReznick LLP 3560 Lenox Road, Suite 2900 Atlanta, Georgia 30326 Audit period: for the year ended December 31, 2024 The finding from the December 31 , 2024 schedule of findings and questioned costs is discussed below. The finding is numbered consistently with the number assigned in the schedule. FINDING-FEDERAL AWARD PROGRAMS AUDIT DEPARTMENT OF HOUSING AND URBAN DEVELOPMENT 2024-001 Housing Voucher Cluster -AL Nos. 14.871 , 14.879 Recommendation: the Authority reviews its internal controls to reduce the risk of unauthorized access to and/or misuse of PII contained within the EIV reports in the future to ensure compliance with eligibility requirements. Action Taken: As part of the Authority's standard internal controls, all HCV employees with access to EIV are required to sign the Rules of Behavior and complete HUD's annual cybersecurity training. In addition, the Authority maintains physical security measures and general IT controls onsite to reduce risks associated with unauthorized access. Since the incident occurred, the Authority has implemented several additional measures to strengthen data protection practices. Specifically: •Issued a new Information Protection Policy and Confidentiality Agreement, which all employees are required to review and sign. ·Conducted an all-staff training session to review the new policy in detail and reinforce best practices for safeguarding participant information. •The Chief Executive Officer reiterated the Authority's commitment to data security and emphasized that any violation of information protection policies will result in disciplinary action, up to and including termination of employment, as well as potential legal prosecution. If the U.S. Department of Housing and Urban Development has questions regarding this plan, please call Larry H. Padilla, CEO at 404-270-2101. Larry H. Padilla CEO/Executive Director

About Eligibility →

FY 2023-12-31

LOW-RISK AUDITEE$9,378,829 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 12, 2024 — management decision was due February 12, 2025.

FY 2022-12-31

LOW-RISK AUDITEE$7,833,489 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 6, 2023 — management decision was due February 6, 2024.

FY 2021-12-31

LOW-RISK AUDITEE$8,242,163 federal awards expendedNo findings recorded this year

FAC accepted this audit on September 19, 2022 — management decision was due March 19, 2023.

FY 2020-12-31

LOW-RISK AUDITEE$7,843,555 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 10, 2021 — management decision was due February 10, 2022.

FY 2019-12-31

LOW-RISK AUDITEE$9,742,986 federal awards expendedNo findings recorded this year

FAC accepted this audit on July 13, 2020 — management decision was due January 13, 2021.

FY 2018-12-31

LOW-RISK AUDITEE$7,750,448 federal awards expendedNo findings recorded this year

FAC accepted this audit on July 10, 2019 — management decision was due January 10, 2020.

FY 2017-12-31

LOW-RISK AUDITEE$7,491,319 federal awards expendedNo findings recorded this year

FAC accepted this audit on July 12, 2018 — management decision was due January 12, 2019.

FY 2016-12-31

LOW-RISK AUDITEE$8,374,181 federal awards expendedNo findings recorded this year

FAC accepted this audit on July 25, 2017 — management decision was due January 25, 2018.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Georgia

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.