EIN: 660586667
UEI: J6RKFSB6KL59
Audited by: Smart Solutions CPA Inc.
Oversight agency: 93 [Department of Health and Human Services]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on October 30, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 30, 2026 (126 days ago).
What is a management decision? →FAC accepted this audit on December 24, 2024 — management decision was due June 24, 2025.
Finding 2023-003 - Special Tests and Provisions: Sliding Fee Discounts Name of Federal Agency: U.S. Department of Health and Human Services Federal Program Name and Assistance Listing Number: Health Centers Program Cluster (93.224 & 93.527) Federal Award Identification Number and Year: H8000372 03/01/2022 – 2/28/2023 & 03/01/2023 – 02/29/2024 Criteria In accordance with 42 CFR sections 51c.303(f) and (g), health centers must prepare and apply a sliding fee discount schedule ("SFDS") so that the amounts paid for health center services by eligible patients are adjusted (discounted) based on the patient's ability to pay. Statement of Condition While performing the audit, we noted that the Center was unable to provide supporting documentation to verify that the visit occurred and that the proper amounts were billed and adjusted. We were also unable to obtain documentation to support the patient's income level and family size. As a result, we were unable to determine proper application of the SFDS. Cause The Center suffered a cyber incident in October 2023 that compromised their electronic medical records system. As a result, all patient information, including progress notes and proof of income level and family size, were unable to be recovered. Effect The Center may not have properly calculated the sliding fee or discount given to the patients and the discount given, if any, may not have been based on the patient's ability to pay. Questioned Costs None Context While performing the audit we noted the Center was unable to provide sufficient and appropriate audit evidence to support proper application of the SFDS for any patients who visited the Center prior to the electronic medical record system becoming compromised in October 2023. Identification as a Repeat Finding This finding is not a repeat finding. Recommendation We recommend the Center enhance their data recovery procedures to ensure that information necessary for compliance, in the event it becomes compromised, can be recovered. View of Responsible Officials While Management is in agreement with this finding, we would like to state that during our 2023 HRSA site visit, our sliding fee discount program was found to be in compliance. Due to the cyber-attack, FHC was not able to access its practice management system for 2023. To reduce future breaches, FHC implemented the following changes: The virtual machine hosts were re-initialized, and the latest version of VMWare were installed. Advanced endpoint protection was also installed on all computers and servers; Multi-factor authentication (MFA) for email use was established; the remote workers access was changed to TruGrid, a platform that provides secure remote desktop protocol (RDP) connections. Backup redundancy was established, following the 3-2-1 method of three backups, two different locations, one copy always offline. Servers are constantly replicated in the Cloud, differential backups are run every two hours, and one copy is always kept offline. FHC is confident that these changes will greatly reduce the likelihood of another cyberattack. Frederiksted Health Care has arranged a cybersecurity partnership with High Tide Solutions, a technology firm. High Tide Solutions now provides a suite of services including server management, penetration testing, data backup management, network management, Ransomware protection, cybersecurity training and cloud platform support. As a result of the implementation of the above-mentioned changes, FHC is now confident that we will have the appropriate safeguards in place to protect pertinent data in the event of another cyberattack.
Show full finding ▾Hide full finding ▴Finding 2023-003 - Special Tests and Provisions: Sliding Fee Discounts Name of Federal Agency: U.S. Department of Health and Human Services Federal Program Name and Assistance Listing Number: Health Centers Program Cluster (93.224 & 93.527) Federal Award Identification Number and Year: H8000372 03/01/2022 – 2/28/2023 & 03/01/2023 – 02/29/2024 Criteria In accordance with 42 CFR sections 51c.303(f) and (g), health centers must prepare and apply a sliding fee discount schedule ("SFDS") so that the amounts paid for health center services by eligible patients are adjusted (discounted) based on the patient's ability to pay. Statement of Condition While performing the audit, we noted that the Center was unable to provide supporting documentation to verify that the visit occurred and that the proper amounts were billed and adjusted. We were also unable to obtain documentation to support the patient's income level and family size. As a result, we were unable to determine proper application of the SFDS. Cause The Center suffered a cyber incident in October 2023 that compromised their electronic medical records system. As a result, all patient information, including progress notes and proof of income level and family size, were unable to be recovered. Effect The Center may not have properly calculated the sliding fee or discount given to the patients and the discount given, if any, may not have been based on the patient's ability to pay. Questioned Costs None Context While performing the audit we noted the Center was unable to provide sufficient and appropriate audit evidence to support proper application of the SFDS for any patients who visited the Center prior to the electronic medical record system becoming compromised in October 2023. Identification as a Repeat Finding This finding is not a repeat finding. Recommendation We recommend the Center enhance their data recovery procedures to ensure that information necessary for compliance, in the event it becomes compromised, can be recovered. View of Responsible Officials While Management is in agreement with this finding, we would like to state that during our 2023 HRSA site visit, our sliding fee discount program was found to be in compliance. Due to the cyber-attack, FHC was not able to access its practice management system for 2023. To reduce future breaches, FHC implemented the following changes: The virtual machine hosts were re-initialized, and the latest version of VMWare were installed. Advanced endpoint protection was also installed on all computers and servers; Multi-factor authentication (MFA) for email use was established; the remote workers access was changed to TruGrid, a platform that provides secure remote desktop protocol (RDP) connections. Backup redundancy was established, following the 3-2-1 method of three backups, two different locations, one copy always offline. Servers are constantly replicated in the Cloud, differential backups are run every two hours, and one copy is always kept offline. FHC is confident that these changes will greatly reduce the likelihood of another cyberattack. Frederiksted Health Care has arranged a cybersecurity partnership with High Tide Solutions, a technology firm. High Tide Solutions now provides a suite of services including server management, penetration testing, data backup management, network management, Ransomware protection, cybersecurity training and cloud platform support. As a result of the implementation of the above-mentioned changes, FHC is now confident that we will have the appropriate safeguards in place to protect pertinent data in the event of another cyberattack.
U.S. Department of Health and Human Services, Health Center Program Cluster (Assistance Listing Number 93.224/93.527) AUDIT FINDING Finding 2023-003 Special Tests and Provisions - Sliding Fee Discounts Description of Finding: During the course of the audit, it was noted that the Center was unable to provide supporting documentation to verify that the visit occurred and that the proper amounts were billed and adjusted. We were also unable to obtain documentation to support the patient's income level and family size. As a result, we were unable to determine proper application of the sliding fee discount schedule. Statement of Concurrence: We concur with the finding above. Corrective Action: While Management is in agreement with this finding, we would like to state that during our 2023 HRSA site visit, our sliding fee discount program was found to be in compliance. Due to the cyber-attack, FHC was not able to access its practice management system for 2023. To reduce future breaches, FHC implemented the following changes: The virtual machine hosts were re-initialized, and the latest version of VMWare were installed. Advanced endpoint protection was also installed on all computers and servers; Multi-factor authentication (MFA) for email use was established; the remote workers access was changed to TruGrid, a platform that provides secure remote desktop protocol (RDP) connections. Backup redundancy was established, following the 3-2-1 method of three backups, two different locations, one copy always offline. Servers are constantly replicated in the Cloud, differential backups are run every two hours, and one copy is always kept offline. FHC is confident that these changes will greatly reduce the likelihood of another cyberattack. Frederiksted Health Care has arranged a cybersecurity partnership with High Tide Solutions, a technology firm. High Tide Solutions now provides a suite of services including server management, penetration testing, data backup management, network management, Ransomware protection, cybersecurity training and cloud platform support. As a result of the implementation of the above-mentioned changes, FHC is now confident that we will have the appropriate safeguards in place to protect pertinent data in the event of another cyberattack. Name of Contact Person: Jacquelynn Rhymer-George Chief Financial Officer Tel. No.: (340) 772-1992 E-mail: jrgeorge@fhc-inc .net Projected Completion Date: 12/31/24 If HRSA has questions regarding this Plan, please call Jacquelyn Rhymer-George at (340) 772-1992 or jrgeorge@fhc-inc net. Sincerely Yours, Jacquelynn Rhymer-George Chief Financial Officer
FAC accepted this audit on November 10, 2023 — management decision was due May 10, 2024.
FAC accepted this audit on September 29, 2022 — management decision was due March 29, 2023.
FAC accepted this audit on October 28, 2021 — management decision was due April 28, 2022.
FAC accepted this audit on November 8, 2020 — management decision was due May 8, 2021.
FAC accepted this audit on September 19, 2019 — management decision was due March 19, 2020.
FAC accepted this audit on September 11, 2018 — management decision was due March 11, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on September 28, 2017 — management decision was due March 28, 2018.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in U.S. Virgin Islands →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.